The NIH PKI Pilots Peter Alterman, Ph.D. … again.

Slides:



Advertisements
Similar presentations
NIH-EDUCAUSE PKI Interoperability Project Electronic Grant Application With Multiple Digital Signatures Peter Alterman, Ph.D. Director of Operations Office.
Advertisements

EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
Program Managers Forum
Federal PKI Architecture Update
The U.S. Federal PKI Richard Guida, P.E. Chair, Federal PKI Steering Committee Chief Information Officers Council
Ongoing Efforts to Build The US Federal PKI Bridge
Stanley J. Choffrey (202) The Federal Bridge Certification Authority Evolving Issues in Electronic Data Collection January.
15June’061 NASA PKI and the Federal Environment 13th Fed-Ed PKI Meeting 15 June ‘06 Presenter: Tice DeYoung.
Copyright Judith Spencer This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Identity Standards (Federal Bridge Certification Authority – Certificate Lifecycle) Oct,
NIH – EDUCAUSE PKI Interoperability Pilot Update Peter Alterman, Ph.D. Director of Operations, Office of Extramural Research, NIH and Senior Advisor to.
PKI in US Higher Education TAGPMA Meeting, March 2006 Rio De Janeiro, Brazil.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
Assuring e-Trust always 1 Guaranteeing Electronic Trust at all times.
Uncle Sam, Meet The PKI! Richard Guida Chair, Federal PKI Steering Committee Michèle Rubenstein Department of the Treasury,
The U.S. Federal PKI and the Federal Bridge Certification Authority
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
The 4BF The Four Bridges Forum Higher Education Bridge Certificate Authority.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
Higher Education Bridge Certificate Authority (HEBCA) Project Progress Fed/Ed December 2004.
NIH-EDUCAUSE Interoperability Project, Phase 3: Fulfilling the Promise Dartmouth PKI Implementation Workshop Peter Alterman, Ph.D. Assistant CIO for E-Authentication.
Federal Bridge Certification Authority n Background n Overview n EMA Challenge Test structure n Participants n Results n Conclusions and lessons learned.
Richard Guida, P.E. Member, Government Information Technology Services Board Chair, Federal PKI Steering Committee
Copyright, 1996 © Dale Carnegie & Associates, Inc. Digital Certificates Presented by Sunit Chauhan.
HEBCA – Higher Education Bridge Certification Authority Presented by Scott Rea and Mark Franklin, Fed/Ed Meeting, 12/14/2005.
The E-Authentication Initiative An Overview Peter Alterman, Ph.D. Assistant CIO for e-Authentication, NIH and Chair, Federal PKI Policy Authority The E-Authentication.
1 USHER Update Fed/ED December 2007 Jim Jokl University of Virginia.
The Federal Bridge Certification Authority – Description and Current Status Peter Alterman, Ph.D. Senior Advisor to the Chair, Federal PKI Steering Committee.
The U.S. Federal PKI, 2004: Report to EDUCAUSE Peter Alterman, Ph.D. Assistant CIO for E-Authentication National Institutes of Health.
1 Digital Credential for Higher Education John Gardiner August 11, 2004.
NIH-Educause PKI Pilot: Phase Two Electronic Grant Application With Multiple Digital Signatures Peter Alterman, Ph.D. Director of Operations Office of.
EDUCAUSE PKI Working Group Where Are We and Where are We Going.
Deploying a Certification Authority for Networks Security Prof. Dr. VICTOR-VALERIU PATRICIU Cdor.Prof. Dr. AUREL SERB Computer Engineering Department Military.
Transforming Education Through Information Technologies Common Solutions Group, January, 2002 (Sanibel Island) HEBCA: Higher Education.
Bridging Higher Education PKIs PKI Summit, August 2006 Snowmass, Colorado.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian.
X.509/PKI There is progress.... Topics Why PKI? Why not PKI? The Four Stages of X.509/PKI Other sectors Federal Activities - fBCA, NIH Pilot, ACES, other.
The Evolving U.S. Federal PKI Richard Guida Chair, Federal PKI Steering Committee Federal Chief Information Officers Council
1 June Richard Guida Stephanie Evans Johnson & Johnson Director, WWIS WWIS SAFE Infrastructure Overview.
Bridge Certification Architecture A Brief Demo by Tim Sigmon and Yuji Shinozaki June, 2000.
Digital Signatures A Brief Overview by Tim Sigmon April, 2001.
HEPKI-PAG Policy Activities Group David L. Wasley University of California.
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Update on PKI Activities in the Spanish Academic Network PKI-COORD November 26, Amsterdam.
Federal and State PKI Bridge Evolution: Cutting Across Stovepipes EDUCAUSE 2000 October 12th, 2000.
PKI and the U.S. Federal E- Authentication Architecture Peter Alterman, Ph.D. Assistant CIO for e-Authentication National Institutes of Health Internet2.
Internet2 Middleware PKI: Oy-vey! Michael R. Gettes Principal Technologist Georgetown University
The Federal PKI Or, How to Herd Worms Peter Alterman Senior Advisor, Federal PKI Steering Committee.
PKI Summit August 2004 Technical Issues to Deploying PKI on Campuses.
Leveraging Campus Authentication for Grid Scalability Jim Jokl Marty Humphrey University of Virginia Internet2 Meeting April 2004.
PKI: News from the Front and views from the Back Ken Klingenstein, Project Director, Internet2 Middleware Initiative Chief Technologist, University of.
The Evolving Federal PKI Gary Moore Entrust Technologies Richard Guida Chair, Federal PKI Steering Committee.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
1 Federal Identity Management Initiatives Federal Identity Management Initatives David Temoshok Director, Identity Policy and Management GSA Office of.
The FBCA Architecture: Lessons Learned Tim Polk, NIST March 9, 2001.
Higher Ed Bridge CA Extending Trust Across Higher Education - And Beyond David L. Wasley University of California.
Bridge Certification Architecture A Brief Overview by Tim Sigmon May, 2000.
HEBCA – The Operating Authority July 2005 Dartmouth PKI Summit.
Electronic Security and PKI Richard Guida Chair, Federal PKI Steering Committee Chief Information Officers Council
Federal PKI Update Peter Alterman, Ph.D. Chair, Federal PKI Policy Authority.
Trusted Electronic Communications for Federal Student Aid Mark Luker Vice President EDUCAUSE Copyright Mark Luker, This work is the intellectual.
Peter Alterman, Ph.D. Chair, Federal PKI Policy Authority Meet FedFed.
Interoperability and the Evolving Federal PKI Richard Guida, P.E. Member, Government Information Technology Services Board Chair, Federal PKI Steering.
Federal Initiatives in IdM Dr. Peter Alterman Chair, Federal PKI Policy Authority.
U.S. Federal e-Authentication Initiative
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Technical Approach Chris Louden Enspier
Inter-institutional Trust Fabric Overview and Synergies
Presentation transcript:

The NIH PKI Pilots Peter Alterman, Ph.D. … again

A Simplified Description of the NIH Extramural Research Business Process NIH publishes RFAs and other announcements of research topics and training opportunities NIH publishes RFAs and other announcements of research topics and training opportunities Researchers submit applications for funding under a number of mechanisms Researchers submit applications for funding under a number of mechanisms Applications are reviewed by independent study sections 3 – 4X/year Applications are reviewed by independent study sections 3 – 4X/year Approved applications are ranked Approved applications are ranked Grants are funded by score and mission relevance Grants are funded by score and mission relevance Annual reports submitted Annual reports submitted Noncompeting renewals make up bulk of ~40k grants issued annually (about $13B!) Noncompeting renewals make up bulk of ~40k grants issued annually (about $13B!)

Currently, NIH Extramural Business Process is ALL PAPER

Phase I: PKI-enable an Adobe I-form Version of a PHS-398, Application for Research Grant Allergy Institute created an electronic version of the application form Allergy Institute created an electronic version of the application form NIH and Digital Signature Trust working to allow attachment of two TrustID digital signatures to the completed I-form NIH and Digital Signature Trust working to allow attachment of two TrustID digital signatures to the completed I-form Institutions will acquire TrustID digsigs courtesy of NIH, download I-form, complete dummy application, sign (PI and AOR) and return to NIH as attachment Institutions will acquire TrustID digsigs courtesy of NIH, download I-form, complete dummy application, sign (PI and AOR) and return to NIH as attachment NIH will transfer attachment to local hard disk, then validate signatures using E-lock Assured Office client NIH will transfer attachment to local hard disk, then validate signatures using E-lock Assured Office client Some platform and process constraints understood in pilot Some platform and process constraints understood in pilot Outcomes: Outcomes: demonstration of successful creation, signing and validating of I- form 398 demonstration of successful creation, signing and validating of I- form 398 Identification of areas requiring further development Identification of areas requiring further development

What it Looks Like NIH CA And Directory University 3 End users University 1 end-users University 2 end-users trust path trust paths Actually DST CA for Pilot NIH test user

Phase II: Replace NIH-supplied Digital Certificate with Institution’s Digital Certificate (in multiple flavors) UAB, UW-M and UCOP UAB, UW-M and UCOP TrustID cert (no-brainer, already done in Phase I) TrustID cert (no-brainer, already done in Phase I) VeriSign cert VeriSign cert Netscape IPlanet cert Netscape IPlanet cert NIH cross-certifies with the Fed Bridge at the test level of assurance NIH cross-certifies with the Fed Bridge at the test level of assurance Educause sets up the HE Bridge Educause sets up the HE Bridge Fed Bridge and HE Bridge cross-certify at the test level of assurance Fed Bridge and HE Bridge cross-certify at the test level of assurance Institutions cross-certify with the HE Bridge at the test level Institutions cross-certify with the HE Bridge at the test level NIH validates certs using modified E-Lock product NIH validates certs using modified E-Lock product Validation path runs through Fed Bridge to HE Bridge to Institutions’ CRLs Validation path runs through Fed Bridge to HE Bridge to Institutions’ CRLs

Remember This? Slightly Modified… Fed Bridge CA And Directory HE Bridge CA And Directory NIH CA, Directory, End user CA, Directory, CRL, end users CA,Directory, CRL, end users Validation path Validation paths Actually DST CA for Pilot

The Federal Bridge Certification Authority – Description and Current Status Peter Alterman, Ph.D. Senior Advisor to the Chair, Federal PKI Steering Committee and Acting Director, Federal Bridge Certification Authority

The FBCA Architecture Bridge CA And Directory Bridge CA And Directory CA, Directory, End users CA, Directory, End users CA,Directory, End users Trust paths

FBCA Overview Designed for the purpose of creating trust paths between among PKI domains Designed for the purpose of creating trust paths between among PKI domains Issues cross-certificates to Member CAs only Issues cross-certificates to Member CAs only Employs a distributed, NOT a hierarchical, model Employs a distributed, NOT a hierarchical, model Commercial products participate within the membrane of the Bridge OR interoperate with products within the membrane Commercial products participate within the membrane of the Bridge OR interoperate with products within the membrane Develops cross certificates within the membrane to bridge the gap among dissimilar products Develops cross certificates within the membrane to bridge the gap among dissimilar products

FBCA Goals Leverage emerging Federal Agency PKIs to create a unified Federal PKI Leverage emerging Federal Agency PKIs to create a unified Federal PKI Limit workload on Agency CA staff Limit workload on Agency CA staff Support Agency use of: Support Agency use of: Any FIPS-approved cryptographic algorithm Any FIPS-approved cryptographic algorithm A broad range of commercial CA products A broad range of commercial CA products Propagate policy information to certificate users in different Agencies Propagate policy information to certificate users in different Agencies

FBCA Operation Issues Cross-Certificates to Participating CAs only Issues Cross-Certificates to Participating CAs only FPKI Steering Committee oversees FBCA development and operations FPKI Steering Committee oversees FBCA development and operations Documentation Documentation Enhancements Enhancements Client-side software Client-side software Operates in accordance with Policy Authority and FPKISC direction Operates in accordance with Policy Authority and FPKISC direction

FBCA Management Hierarchy Steering Committee oversees FBCA development and operations Steering Committee oversees FBCA development and operations Direct Operational Authority Direct Operational Authority Bridge Documentation Bridge Documentation Enhancements Enhancements Policy Authority determines participants and levels of cross- certification Policy Authority determines participants and levels of cross- certification Administers Certificate Policy Administers Certificate Policy Approves requests to cross-certify Approves requests to cross-certify Enforces compliance by member organizations Enforces compliance by member organizations GSA named Operational Authority GSA named Operational Authority Operates in accordance with Policy Authority and Steering Committee direction Operates in accordance with Policy Authority and Steering Committee direction

Current Status - August 10, 2001 Policy Authority approved final documentation on June 18, 2001 Policy Authority approved final documentation on June 18, 2001 Certificate Policy Certificate Policy Certification Practices Statement Certification Practices Statement Independent Compliance Analysis Independent Compliance Analysis FBCA “open and ready for business” at the GSA/FTS WillowWoods facility operated by Mitretek Systems on June 7, 2001 FBCA “open and ready for business” at the GSA/FTS WillowWoods facility operated by Mitretek Systems on June 7, 2001 Prototyping/Compatibility lab continues operational off-site Prototyping/Compatibility lab continues operational off-site Hot backup site nearing completion Hot backup site nearing completion C & A Audit under way by KPMG C & A Audit under way by KPMG Three federal agencies and one state government preparing documentation for application for interoperability with Bridge: NASA, NFC, FDIC, Illinois Three federal agencies and one state government preparing documentation for application for interoperability with Bridge: NASA, NFC, FDIC, Illinois

What Will It Take to Use the FBCA? Policy mapping of certificate policies Policy mapping of certificate policies Sharing annual audits Sharing annual audits Careful management of cross-certificates to limit transitive trust (exclusion trees) Careful management of cross-certificates to limit transitive trust (exclusion trees) Directory interoperability and synchronization Directory interoperability and synchronization Client software for certificate path discovery and processing Client software for certificate path discovery and processing

Next Steps Continue to bring federal agencies into interoperability Continue to bring federal agencies into interoperability Bring additional products into Bridge membrane and/or verify interoperability with products in membrane: working with RSA, Cylink, Spyrus and talking with VeriSign and Microsoft Bring additional products into Bridge membrane and/or verify interoperability with products in membrane: working with RSA, Cylink, Spyrus and talking with VeriSign and Microsoft Pursue interoperability with State PKIs Pursue interoperability with State PKIs Pursue interoperability with Nation of Canada Pursue interoperability with Nation of Canada Pursue interoperability with non-government sector bridges Pursue interoperability with non-government sector bridges

References Federal PKI Steering Committee Website: Federal PKI Steering Committee Website: FBCA Page: FBCA Page: NIST PKI Website: NIST PKI Website: