Admin API for Secure Environment Group Name: SEC Source: Giesecke & Devrient Meeting Date:
Introduction To manage Secure Environments TS-0003 includes a “Security Administration” service responsible for the management of security (sensitive) functions and data within the SE “SE management” SE management can take place locally or remotely In TP 18, the need to have dedicated API for administrative operation regarding security (in general) was agreed 2
Open topics Reference point for „SE / security administration“ has to be defined Dependency between Security Management and SE management need to be clarified Relation between Credential Management and SE Management need to be clarified 3
Proposal Reference point for SE / security administration – Mcs shall be used as reference point for SE administration SE management vs security management – Security features are encapsulated within an SE – The SE can be virtual or physical, e.g. unprotected memory area storing credentials is an SE with security level = 0 – SE management = security management SE management vs. credential management – Credentials are stored within the SE – The SE can be virtual or physical, e.g. an unprotected memory area storing credentials is an SE with security level = 0 – SE management = credential management (i.e. uses SE management functions) SE management shall also include mechanisms to manage (create, delete, update) sensitive functions such as cryptographic algorithms 4
Consequences Mcs reference point need to be accessible locally (within Field Domain) and remotely Mcs layer need to “translate” SE management API into SE technology dependent API – e.g. for secure elements, translation from oneM2M API into secure element (GP) APIs need to be done – Restful vs Service oriented approach – oneM2M API need to consider functionality of underlying technologies and their capabilities – Resources as proposed in SEC R01- RESTful_Administration_API_discussion need further study Currently SE management focus on Field Domain Node – Secure Environments within the infrastructure are currently out of scope 5