11 Identity Management Spacecraft ID Security CCSDS Security WG Fall 2005 Atlanta, GA USA Howard Weiss NASA/JPL/SPARTA September 2005
22 Agenda 14 September 2005 – : Welcome, opening remarks, logistics, agenda bashing, : Review results of Spring 2005 SecWG meeting in Athens Mtg Notes Mtg Notes – : RASDS Review wrt Security Architecture (Kenny) – : coffee break – : Security Architecture Document Discussions (Kenny) – : Lunch – :Review CNES Mission Security Req Development using EDIOS (Pechmalbec/Belbus) – : Encryption Algorithm Trade Study (Weiss) – : coffee break – : Authentication/Integrity Algorithm Trade Study (Weiss) 15 September 2005 – : Key management discussion (Kenny) – : Coffee break – : Identity Management, Spacecraft IDs (Weiss) – : CNES Interconnection Rules (Pechmalbec/Belbus) – : Lunch – : CNES Security Development Process (Pechmalbec/Belbus) – : Security Policy Document/Common Criteria (Weiss)
33 Discussion Topics Identity management – Who, what, where, when, how? Spacecraft ID security – Publicly available on SANA web site? – Other info (e.g., ground site locations, etc) – Security issue or not?
44 Background Discussions Identity management – User IDs – Passwords – Public keys/certificates – Role-based access controls (?)
55 Identity Management Who should be concerned about this? – Security WG? – Information Architecture WG? – Other? If SecWG should be concerned about this: – What should be done? – Who should do it? – Is this a SANA job to manage and control? » Based on SecWG guidance and policy?
66 Identity Management Discussion/Conclusions – …..
77 Spacecraft IDs Spacecraft IDS are currently available for viewing on the CCSDS web page – 10-bit ID field viewable at Space Assigned Numbering Authority (SANA) is in a formulation stage – Analogous to the IETF’s Internet Assigned Numbering Authority (IANA). – SANA web site to contain all sorts of space mission numbering assignments Question: should spacecraft IDs be visible?
88 Spacecraft IDs Security Issue – – Visible spacecraft IDs? Or not a security issue? Do we rely on spacecraft IDs to be kept secret? – Should we? Why? – What is the threat if a spacecraft ID is well known? – Should we be basing any security/protection on a spacecraft ID? » Analogous to basing security on the knowledge of an IP address. What about other publicly available information – Ground site locations? – Totality of other publicly available information?
99 Spacecraft IDs Discussion/Conclusions: – ……..