Burton Group Catalyst Meeting xxxxxxxxx Stephen Wilson Chair, OASIS PKI Adoption TC The OASIS PKI Adoption TC Objectives and Work Program Burton Group.

Slides:



Advertisements
Similar presentations
Multi-Application in Smart Card-based Devices Christophe Colas, Chief Software Architect August 2002.
Advertisements

Overview of US Federal Identity Management Initiatives Peter Alterman, Ph.D. Chair, Federal PKI Policy Authority and Asst. CIO E-Authentication, NIH.
Slide 1/7 03/17/03 56th IETF San Francisco CA, March 16-21, 2003 “EAP support in smartcards” My name is Pascal Urien, ENST Draft-urien-EAP-smartcard-01.txt.
Federated Digital Rights Management Mairéad Martin The University of Tennessee TERENA General Assembly Meeting Prague, CZ October 24, 2002.
August 2004 Providing Industry-wide Security and Identity Management Solutions.
Overview of OASIS SOA Reference Architecture Foundation (SOA-RAF)
HIT Standards Committee: Digital Certificate Trust – Policy Question for HIT Policy Committee March 29, 2011.
6/1/20151 Digital Signature and Public Key Infrastructure Course:COSC Instructor:Professor Anvari Student ID: Name:Xin Wen Date:11/25/00.
Page 1 Issues in and perspectives on electronic authentication of health professionals Pascal POITEVIN Marketing and Communication manager GIP-CPS e-Health.
The OASIS IDtrust (I M The OASIS IDtrust (Identity and Trusted Infrastructure ) Member Section For more information please see:
Digital Identities for Networks and Convergence Joao Girao, Amardeo Sarma.
Click to edit Master title style OASIS PKI Workshop.
Sentry: A Scalable Solution Margie Cashwell Senior Sales Engineer Sept 2000 Margie Cashwell Senior Sales Engineer
Public Key Superstructure It’s PKI Jim, but not as we know it! 7 th Annual “IDtrust” Symposium 5 March 2008, Gaithersburg MD, USA Stephen Wilson Lockstep.
Authentication choices! Vincent van Kooten: Business Sales Manager Benelux Distributed by -
© Southampton City Council Sean Dawtry – Southampton City Council Implementing a PKI The Southampton Pathfinder for Smart Cards in public services.
Stephen Wilson Chair, PKI Adoption Technical Committee Managing Director, Lockstep, Australia PKIA Goals for 2007 Stephen Wilson Chair, PKI Adoption Technical.
Obstacles to PKI Deployment and Usage – Conclusions Relevant to pki4ipsec Steve Hanna, Co-chair, OASIS PKI TC.
Obstacles to PKI Deployment and Usage - Survey Results and Draft Action Plan Steve Hanna, Co-chair, OASIS PKI TC.
Burton Group Catalyst Meeting Barcelona, Spain 22 October 2007 June Leung OASIS PKI Adoption TC The OASIS PKI Adoption TC Objectives and Case Studies Burton.
Burton Group Catalyst Workshop June Leung on behalf of Stephen Wilson Chair, OASIS PKI Adoption TC The OASIS PKI Adoption TC Objectives and Work Program.
OASIS PKI Action Plan – Overcoming Obstacles to PKI Deployment and Usage Steve Hanna, Co-Chair, OASIS PKI Technical Committee.
HITSP – enabling healthcare interoperability 1 enabling healthcare interoperability 1 Standards Harmonization HITSP’s efforts to address HIT-related provisions.
1 DoD Public Key-Enabling (PK-E) of Applications 1st Annual PKI Research Workshop NIST 4/25/02.
Alcatel Identity Server Alcatel SEL AG. Alcatel Identity Server — 2 All rights reserved © 2004, Alcatel What is an Identity Provider?  
National Strategies for Digital Identity Management UNCITRAL Colloquium on Electronic Commerce February 2011, New York Laurent Bernat – OECD Secretariat.
Controller of Certifying Authorities Public Key Infrastructure for Digital Signatures under the IT Act, 2000 : Framework & status Mrs Debjani Nag Deputy.
Deploying a Certification Authority for Networks Security Prof. Dr. VICTOR-VALERIU PATRICIU Cdor.Prof. Dr. AUREL SERB Computer Engineering Department Military.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
Strength in diversity: lessons learnt from the Stork* projects Antonio Lioy Politecnico di Torino Dip. Automatica e Informatica.
Copyright OASIS, 2001 OASIS Election & Voter Services Technical Committee John Borras Office of e-Envoy Cabinet Office UK Government May 2002.
F. Guilleux, O. Salaün - CRU Middleware activities in French Higher Education.
APKIF WWCWG Meeting Beijing 4 November 2005 Stephen Wilson OASIS Liaison Representative to APKIF Managing Director, Lockstep Consulting The OASIS Third.
PKI interoperability and policy in the wireless world.
Standard of Electronic Health Record
PKI Forum Sydney 2000 Members Meeting Stephen Wilson Chair -- Certification Forum of Australia Director -- PricewaterhouseCoopers beTRUSTed PKI in Australia.
New Technologies and Travel Documents ICAO 12 th Meeting of the Facilitation Division Cairo March 23, 2004.
Security Protocols and E-commerce University of Palestine Eng. Wisam Zaqoot April 2010 ITSS 4201 Internet Insurance and Information Hiding.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
PKI Forum Mission “The PKI Forum is an international, not-for-profit, multi- vendor and end-user alliance whose purpose is to accelerate the adoption and.
PKI Survey Chet Ensign OASIS Individual Member Chet Ensign OASIS Individual Member Study on the Use of PKI in OASIS Standards March 26th, 2008.
Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate
Geneva, Switzerland, April 2012 Introduction to session 7 - “Advancing e-health standards: Roles and responsibilities of stakeholders” ​ Marco Carugi.
1 Using GSM/UMTS for Single Sign-On 28 th October 2003 SympoTIC 2003 Andreas Pashalidis and Chris J. Mitchell.
Standards in E government Harm Jan van Burg OASIS E-gov Technical Committee Oasis adoption forum, London October 17,
Standards for e-Enabled Elections: The work of the OASIS Election & Voter Services Technical Committee John Borras Chair Technical Committee
Cloud Computing, Policy Management and Standardization Europe Identity Conference 2011 John Sabo, Director Global Government Relations, CA Technologies.
User Interface Requirement for the Internet X.509 PKI Jaeho Yoon (on behalf of Tae K. Choi) KOREA INFORMATION SECURITY AGENCY August 4, 2004.
OASIS Trust Elevation Elevate Trust in Electronic Identities Gershon Janssen, Member OASIS Trust Elevation TC
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
/ 8 FEIDHE Electronic Identification in Finnish Higher Education Janne Kanner FEIDHE Electronic Identification in Finnish Higher Education.
OASIS Cloud Authorization TC (CloudAuthZ) Rakesh Radhakrishnan, TC Member.
Electronic Security and PKI Richard Guida Chair, Federal PKI Steering Committee Chief Information Officers Council
Fundamental Digital Electronics
A look at progress in the development of eHealth in the European Region Results and recommendations from the 2016 report “From Innovation to Implementation:
Expectations for the New Secure Network Age panel discussion Asia PKI Forum Conference Tokyo 24 February 2005 Stephen Wilson (OASIS liaison to APKIF) PKI.
OASIS Juan Carlos Cruellas – UPC Stefan Drees - DSS-X co-chair Nick Pope – Thales eSecurity OASIS Digital Signature Services and ETSI standards Juan Carlos.
OASIS IDtrust Member Section June Leung Chair, OASIS IDtrust Member Section Steering Committee
Federal Initiatives in IdM Dr. Peter Alterman Chair, Federal PKI Policy Authority.
Frank Schipplick Work Package Coordinator WP1 - eSignatures.
RSA Conference Europe 2000 Welcome to RSA Conference Europe 2000
The Future Digital Identity Landscape in Europe Stefane Mouille/Detlef Houdeau World eID Congress, 27th of Sep. 2017, Marseille, France.
New Technologies and Travel Documents
The Internet of Things (IoT)
Standard of Electronic Health Record
Technical Approach Chris Louden Enspier
My name is Pascal Urien, ENST
NEW PRODUCT INTRODUCTION CONEKT™ Mobile Smartphone Access Control Identification Solution June 2018.
Install AD Certificate Services
Presentation transcript:

Burton Group Catalyst Meeting xxxxxxxxx Stephen Wilson Chair, OASIS PKI Adoption TC The OASIS PKI Adoption TC Objectives and Work Program Burton Group Catalyst Meeting xxxxxxxxx Stephen Wilson Chair, OASIS PKI Adoption TC

The PKI environment c n PKI is resurgent n Embedded PKI is commonplace n We’re all in the midst of a paradigm shift to identity plurality n Digital Certificates can be about relationships as well as (or instead of) personal identity n Successful PKI has always been application specific, not general purpose

Resurgent, embedded PKI n Closed (vertical) schemes l US PIV, Identrus, ICAO e-passports, CableLabs, Skype, BankID (Sweden) n Health smartcards l France, Germany, Taiwan, Italy, Austria, Australia … n Digital Credentials l US Patent Office, France, Taiwan, Australia …

Identity plurality n “Identity 2.0” (archetype: Cardspace) l Too soon to tell precise outcomes l But it’s a progressive re-think of identity, context, privacy, control etc. l Fundamental concept is plurality of identities. n Stephen Kent’s critique: “For big CAs, there is an implicit assumption that a single certificate is all that a user should need. This assumes that one identity is sufficient for all applications, which contradicts experience”

The top five obstacles According to OASIS Surveys 1 & 2: 1. Software applications don’t support PKI 2. Costs too high 3. PKI poorly understood 4. Too much focus on technology (not need) 5. Poor interoperability

PKIA TC: Fresh objectives n Continue to overcome obstacles with targeted practical initiatives that improve understanding of PKI n Disseminate case studies n Develop position papers that de-mystify legal, governance and interoperability issues and modernise the PKI message so it reflects real needs n Liaise more closely with other OASIS efforts, esp. under the umbrella of the new IDtrust Member Section

Embedded PKI application: Device authentication Some of the oldest, most successful PKIs are for device authentication: n GSM SIM cards n SSL server certificates n IPsec VPN devices n Cable Open TV set-top boxes

Embedded PKI application: Skype n Each Skype subscriber receives a digital certificate embedded in Skype install n “Zero User Interface” (ZUI) principle; i.e. Subscriber unaware of their certificate! n

Embedded PKI application: Medicos’ smartcards n France (500,000) n Taiwan (300,000) n Australia (10,000) l wide range of PKI enabled lodgments l electronic prescribing in development l certificates represent doctor’s qualifications l wholesale supply to hospitals etc.

OASIS PKI Technical Committee Stephen Wilson