1Copyright © 2011, Printer Working Group. All rights reserved. PWG -Imaging Device Security (IDS) Working Group April 6, 2011 Cupertino, CA PWG F2F Meeting.

Slides:



Advertisements
Similar presentations
Printer Working Group Face-to-Face Meeting December 8, 2010
Advertisements

1Copyright © 2007, Printer Working Group. All rights reserved. Web-based Imaging Management System Working Group Printer Working Group Face-to-Face Meeting.
1Copyright © 2008, Printer Working Group. All rights reserved. Web-based Imaging Management System Working Group Printer Working Group Face-to-Face Meeting.
1 Copyright © 2013 The Printer Working Group. All rights reserved. Printer Working Group Plenary Session May 14, 2013 PWG F2F Meeting Cupertino, CA Michael.
1 Copyright © 2013 The Printer Working Group. All rights reserved. Printer Working Group Plenary Session May 14, 2013 PWG F2F Meeting Cupertino, CA Michael.
1Copyright © 2011, Printer Working Group. All rights reserved. MPSA/PWG Power Management Survey Results for WIMS WG Session Printer Working Group Face-to-Face.
1Copyright © 2013 The Printer Working Group. All rights reserved. IEEE-ISTO Printer Working Group Semantic Model WG – CWMP Printer/MFD Data Model Broadband.
IPP Printer State Extensions IPP Working Group 19 February 2007 Maui Craig Whittle / Ira McDonald.
1Copyright © 2008, Printer Working Group. All rights reserved. Imaging Device Security (IDS) Working Group Longmont, CO - PWG F2F Meeting June 25, 2008.
1Copyright © 2009, Printer Working Group. All rights reserved. PWG -Imaging Device Security (IDS) Working Group Irvine, CA - PWG F2F Meeting April 29,
1 Copyright © 2012 The Printer Working Group. All rights reserved. IPP Working Group Session August 7, 2012 Redmond, WA PWG F2F Meeting.
1 Copyright © 2009, Printer Working Group. All rights reserved. PWG Plenary Status Report IPP Working Group 14 October 2009 Cupertino, CA - PWG F2F Meeting.
1Copyright © 2008, Printer Working Group. All rights reserved. PWG Plenary Status Report MFD Working Group August 14, 2008 Camas, WA PWG F2F Meeting.
1Copyright © 2009 Printer Working Group. All rights reserved. 1 IPP Working Group Session 24 June 2009 Rochester, NY - PWG F2F Meeting.
1Copyright © 2009, Printer Working Group. All rights reserved. PWG -Imaging Device Security (IDS) Working Group Seattle area, WA IDS-Microsoft F2F Meeting.
1Copyright © 2010, Printer Working Group. All rights reserved. PWG Plenary TCG Activity Summary December 2010 Irvine, CA – PWG Meeting Ira McDonald (High.
1Copyright © 2013 The Printer Working Group. All rights reserved. IEEE-ISTO Printer Working Group Semantic Model WG – CWMP Printer/MFD Data Model Broadband.
1 Copyright © 2010, Printer Working Group. All rights reserved. – Page 1 WIMS WG – Status Update PWG Power Management Project 4 August 2010 Bagsvaerd,
1Copyright © 2009 Printer Working Group. All rights reserved. 1Copyright © 2009, Printer Working Group. All rights reserved. IPP Working Group 17 February.
1Copyright © 2010, Printer Working Group. All rights reserved. Workgroup for Imaging Management Solutions Workgroup Session Printer Working Group/WIMS.
1Copyright © 2011 The Printer Working Group. All rights reserved. Workgroup for Imaging Management Solutions (WIMS/PMP) April 5, 2011 Cupertino, CA PWG.
Copyright © 2009, Printer Working Group. All rights reserved. 1 ISTO Printer Working Group Standards in Imaging and Manageability Lee Farrell Chairman.
1Copyright © 2010, Printer Working Group. All rights reserved. PWG -Imaging Device Security (IDS) Working Group October 20, 2010 Lexington, KY PWG F2F.
1Copyright © 2008, Printer Working Group. All rights reserved. PWG Plenary Status Report WIMS/CIM Working Group February 7, 2008 Irvine, CA PWG F2F Meeting.
Copyright © 2010, Printer Working Group. All rights reserved. 1 ISTO Printer Working Group Standards in Imaging and Manageability Lee Farrell Chairman.
1Copyright © 2009 Printer Working Group. All rights reserved. 1 IPP Working Group Session 18 August 2009 Redmond, WA - PWG F2F Meeting.
1Copyright © 2012, Printer Working Group. All rights reserved. PWG Plenary Status Report IDS Working Group August 6, 2012 Redmond, WA PWG F2F Meeting Joe.
1 Copyright © 2010, Printer Working Group. All rights reserved. PWG Plenary Status Report IPP Working Group 10 February 2010 Scottsdale, AZ - PWG F2F Meeting.
1Copyright © 2008, Printer Working Group. All rights reserved. PWG Plenary Status Report IPP Working Group 28 April 2009 Mt Laurel, NJ - PWG F2F Meeting.
1 Copyright © 2013 The Printer Working Group. All rights reserved. The Printer Working Group Semantic Model Working Group Camas, WA Daniel Manchala (Xerox)
1 Copyright © 2009, Printer Working Group. All rights reserved. PWG Plenary Status Report IPP Working Group 9 December 2009 Austin, TX - PWG F2F Meeting.
1Copyright © 2008, Printer Working Group. All rights reserved. PWG Plenary Status Report WIMS/CIM Working Group February 7, 2008 Irvine, CA PWG F2F Meeting.
1Copyright © 2010, Printer Working Group. All rights reserved. PWG Plenary Status Report MFD Working Group February, 2010 Scottsdale, AZPWG F2F Meeting.
1Copyright © 2010, Printer Working Group. All rights reserved. PWG -Imaging Device Security (IDS) Working Group Bagsværd, Denmark- PWG F2F Meeting August.
1Copyright © 2009 Printer Working Group. All rights reserved. 1Copyright © 2009, Printer Working Group. All rights reserved. IPP Working Group Session.
1Copyright © 2010, Printer Working Group. All rights reserved. PWG Plenary Status Report IDS Working Group August 4, 2010 Bagsværd, Denmark- PWG F2F Meeting.
1Copyright © 2008, Printer Working Group. All rights reserved. Imaging Device Security (IDS) Working Group Camas, WA - PWG F2F Meeting August 13, 2008.
1Copyright © 2008, Printer Working Group. All rights reserved. Web-based Imaging Management System Working Group Printer Working Group Face-to-Face Meeting.
1 Copyright © 2009, Printer Working Group. All rights reserved. IPP Working Group Session 9 December 2009 Austin, TX - PWG F2F Meeting.
1Copyright © 2009, Printer Working Group. All rights reserved. Workgroup for Imaging Management Solutions Workgroup Session Printer Working Group/WIMS.
1 Copyright © 2013 The Printer Working Group. All rights reserved. The Printer Working Group Semantic Model Working Group Thursday, Aug 8, 2013 Camas,
1Copyright © 2008, Printer Working Group. All rights reserved. PWG Plenary Status Report IPP Working Group 19 August 2009 Redmond, WA - PWG F2F Meeting.
1Copyright © 2010, Printer Working Group. All rights reserved. PWG -Imaging Device Security (IDS) Working Group Webster, NY- PWG F2F Meeting June 11, 2010.
1 Copyright © 2009, Printer Working Group. All rights reserved. 1 IPP Working Group Session 14 October 2009 Cupertino, CA - PWG F2F Meeting.
1Copyright © 2011, Printer Working Group. All rights reserved. PWG -Imaging Device Security (IDS) Working Group February 3, 2011 Wailea-Makena, HI PWG.
1Copyright © 2011, Printer Working Group. All rights reserved. PWG Plenary Status Report IDS Working Group February 2, 2011 Wailea-Makena, HI PWG F2F Meeting.
1Copyright © 2008, Printer Working Group. All rights reserved. PWG Plenary Status Report IPPv2 Working Group 18 February 2009 Waikoloa, HI - PWG F2F Meeting.
1 Copyright © 2010, Printer Working Group. All rights reserved. IPP Working Group Session 10 February 2010 Scottsdale, AZ - PWG F2F Meeting.
1 Copyright © 2010, Printer Working Group. All rights reserved. IPP Working Group Session 10 February 2010 Scottsdale, AZ - PWG F2F Meeting.
1Copyright © 2010, Printer Working Group. All rights reserved. PWG Plenary Status Report Workgroup for Imaging Management Solutions (WIMS/PMP) Printer.
1Copyright © 2013 The Printer Working Group. All rights reserved. IEEE-ISTO Printer Working Group BBF SP benefits from CWMP Printer/MFD Ira McDonald (PWG.
1Copyright © 2008, Printer Working Group. All rights reserved. PWG Imaging Device Security (IDS) Working Group Lexington, KY – P2600 Meeting October 24,
P HDSS 6/2/20151 P2600 Hardcopy Device and System Security October 2008 Working Group Meeting Don Wright Director of Standards Lexmark International.
PWG Plenary Status Imaging Device Security (IDS) Working Group
IPP Workgroup Session, Day 1
Printer Working Group Plenary Session
Cloud Imaging Model Working Group
IPP Workgroup Session, Day 1
Semantic Model Working Group
IPP Workgroup Session, Day 1
PWG Plenary Status IPPv2 Working Group
Semantic Model Workgroup Status
Semantic Model Workgroup
Semantic Model Workgroup
Semantic Model Workgroup
Semantic Model Working Group
Semantic Model Working Group
IPP Workgroup Session, Day 1
IPP Workgroup Session, Day 1
Semantic Model Workgroup Session
Presentation transcript:

1Copyright © 2011, Printer Working Group. All rights reserved. PWG -Imaging Device Security (IDS) Working Group April 6, 2011 Cupertino, CA PWG F2F Meeting Joe Murdock (Sharp) Brian Smithson (Ricoh)

2Copyright © 2011, Printer Working Group. All rights reserved. Agenda 9:00 – 9:15Administrative Tasks 9:15 – 9:45 Discussion on NAC (Direction and Attributes) 9:45 – 10:15TNC Binding Discussion 10:15 – 10:45Common Criteria 10:45 – 11:00Break 11:45 – 11:30Common Log 11:30 – 12:00IDS Charter Review 12:00 – 13:00Lunch 13:00 – 13:45IAA and Security Ticket 13:45 – 14:00Wrap up and adjournment 14:00 – 15:30Open Printing

3Copyright © 2011, Printer Working Group. All rights reserved. Administrative Tasks Select minute-taker Introductions IP policy statement: This meeting is conducted under the rules of the PWG IP policy. If you dont agree, the Winchester Mystery House is open, if you can find it. Approve Minutes from March 24 conference Call

4Copyright © 2011, Printer Working Group. All rights reserved. IDS WG Officers IDS WG Chairs Joe Murdock (Sharp) Brian Smithson (Ricoh) IDS WG Secretary: Brian Smithson (Ricoh) IDS WG Document Editors: HCD-ATR: Jerry Thrasher (Lexmark) HCD-NAP: Joe Murdock (Sharp), Brian Smithson (Ricoh) HCD-TNC: Ira McDonald (Samsung), Jerry Thrasher (Lexmark), Brian Smithson (Ricoh) HCD-HR (Health Remediation): Joe Murdock (Sharp) HCD-NAP-SCCM: Joe Murdock (Sharp) IDS-Log: Mike Sweet (Apple) IDS-IAA: Joe Murdock (Sharp) IDS-Model: Ira McDonald, Joe Murdock, Ron Nevo

5Copyright © 2011, Printer Working Group. All rights reserved. Action Items Action Item #Entry dateAssigneeTypeActionStatusDisposition 3312/10/2009Randy Turner Ron Nevo SHVRandy Turner will contact Symantec (when appropriate) to encourage discussion with the PWG about a SHV. 3412/10/2009Randy Turner Ron Nevo RemediationRandy Turner will investigate Symantecs products and their method(s) to remediate noncompliant endpoints. Ron Nevo will take over this activity. Randy will pass on his contacts to Ron. Need to indicate to Symantec that we really don't need too much proprietary information from them, but want to give them our information. Can we get Symantec to attend the April meeting in Cupertino? 443/11/2010Jerry Thrasher Ira McDonald Brian Smithson NEA BindingTCG TNC Binding document Make it a TCG document, not an IETF NEA document 586/11/2010Joe Murdock and Ira McDonald SCCMCreate a first draft SCCM binding spec based on the NAP binding specC HMS is releasing R3 of SCCM and also a beta of "R-next", while at the same time adding power management; WIMS group may also be interested. On hold due to priorities. 6710/28/2010Joe Murdock Ira McDonald authWrite IDS-Identification-Authentication-and-Authorization-Framework specification Pdirection is not "recommendations only", it is "requirements and recommendations" (pointing to existing standards) because there will be a conformance section 7312/9/2010Joe Murdock Ira McDonald Ron Nevo reqts specstart an IDS common requirements spec to include out-of-scope and terminology sections Base on new PWG template 762/3/2011Bill Wagner, Brian Smithson MPSAData security article: Bill to draft, Brian to finish 772/3/2011Joe MurdockNAP BindingNeeds a prototype 792/3/2011Joe MurdockCommon ReqtsChange name from IDS-CR to IDS-REQ 802/3/2011Joe Murdock, Brian Smithson WG adminUpdate the description of the IDS WG to include scope that is larger than just NAC/NAP/etc do this after Mike makes the new PWG web site and wiki pages 812/3/2011Joe MurdockIDS-LOGFind the user role definitions in the IA&A or schema documents and import them into the LOG document 832/24/2011Brian Smithson SDPropose a schedule for teleconferences with NIAP PAlternate with SC meeting, Thursdays at 2pm-3pm EST 843/10/2011Joe MurdockWG AdminReview IDS Charter to make sure it still reflect new directions. Add discussion as a F2F topic P 853/24/2011Brian Smithson SDFinal review of project charter and send to SC for approval make it initial draft in advance of F2F

6Copyright © 2011, Printer Working Group. All rights reserved. Stable Documents HCD-Assessment-Attributes ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-idsattributes pdf Stable (needs a binding prototype) HCD-NAP Binding ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-napsoh pdf Stable HCD-NAC Business Case White Paper ftp://ftp.pwg.org/pub/pwg/ids/white/tb-ids-hcd-nac-business-case pdf Final

7Copyright © 2011, Printer Working Group. All rights reserved. Active Document Status HCD-TNC Binding Initial Draft still under development HCD-Health Remediation ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-remediation pdf Initial Draft HCD-NAP-SCCM Binding On hold IDS Charter ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-charter pdf IDS-Log ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-log pdf Draft IDS-Identification-Authentication-Authorization ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-iaa pdf Draft IDS-Model ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-model pdf Draft

8Copyright © 2011, Printer Working Group. All rights reserved. NAC HCD Remediation specification Rename to HCD Health Remediation to limit scope to NAC Health attributes? Remediation may spill out to other aread of IDS work. These should probably be in a separate document? The current spec is driven by health assessment, but the larger function of remediation also includes things like monitoring and enforcing site policy that isnt strictly related to system health NAC discussions at RSA seem to indicate that NAC is being used not just (or even to) authenticate systems onto a network, but is now being used as a means to kick systems off the network. This is not necessarily associated with any particular bad set of health attributes, but just youre misbehaving, get off my network. Does this have any effect of our current thinking of NAC for Imaging devices?

9Copyright © 2011, Printer Working Group. All rights reserved. NAC New NAC Attributes HCD_SysLog_URI (string) The HCD_SysLog_URI attribute is a variable length string that specifies the location(s) where the HCD's system log is to be stored. Locations are provided as a URI and MUST conform to RFC When multiple locations are provided, the log is to be written to locations in the order indicated by the list, starting with the first provided location. If no explicate HCD_SysLog_URI locations have been defined by a system administrator, the system default internal log location MUST be returned HCD_SysLog_Enabled (boolean) The HCD_SysLog_Enabled attribute is a Boolean value that indicates if system logging is enabled for the device. If system logging is disabled (HCD_SysLog_Enabled = FALSE) then any value set for HCD_SysLog_URI is ignored. NAC IDS Authentication Service Attribute Additional IDS Security Attributes?

HCD-TNC Binding Real-time document editing Copyright © 2011, Printer Working Group. All rights reserved.

11Copyright © 2011, Printer Working Group. All rights reserved. IEEE Supporting Documents NIAP CC Status Common Criteria Support Documents Project Charter ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids2600sd-charter pdf 2 Week review period Send to Steering Committee for acceptance

12Copyright © 2011, Printer Working Group. All rights reserved. IDS Log Document Review ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-log rev.pdf ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-log pdf ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-log docx

13Copyright © 2011, Printer Working Group. All rights reserved. IDS Charter Review ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-charter docx ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-charter pdf

IDS IAA XML Schema ftp://ftp.pwg.org/pub/pwg/ids/white/ids-security xsd IDS-IAA Specification ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-iaa docx ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-iaa pdf IDS-Model Specification ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-model docx ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-model pdf IDS-IAA Bindings IPP* Security Ticket in JPS3? PWG Cloud Registration/Discovery Bindings? Advertisement of supported security capabilities? Add a supported security element to the security ticket? Overload of xxxSecurity? A separate element in the system or service capabilities? In the semantic model, the system object would provide all supported methods, while each service (system, print, etc.) would list only those used by the service. Physical hardware security requirements (e.g. encrypted disk, etc.) Copyright © 2011, Printer Working Group. All rights reserved.

15Copyright © 2011, Printer Working Group. All rights reserved. Cloud Consideration in the Security Ticket How does the printer advertise it's public key? How best to pass the public key through a cloud manage/provider directly to the user? Do we add public key to the identity element? Need to consider what to encrypt Cant just encrypt the whole data stream In a cloud environment, want to provide end-to-end encryption of job data, but the job ticket (or at least the security ticket) needs to be readable by the cloud print provider and manager so they can match security requirements between the user, devices and services. Cloud Job privacy How to avoid tracking of a job or partial interception. Provide a way to explicitly hide job origination information? Runs contrary to the IDS logging assumptions, but is this appropriate for the cloud use model?

16Copyright © 2011, Printer Working Group. All rights reserved. Wrap up Review of new action items and open issues Conference call / F2F schedule Next Conference call April 21/28, 2011 Adjournment