Presentation is loading. Please wait.

Presentation is loading. Please wait.

Don Wright Director of Standards Lexmark International

Similar presentations


Presentation on theme: "Don Wright Director of Standards Lexmark International"— Presentation transcript:

1 Don Wright Director of Standards Lexmark International don@lexmark.com
P2600 Hardcopy Device and System Security July 2006 Working Group Meeting Don Wright Director of Standards Lexmark International 4/17/2019

2 Agenda Items Wednesday/Thursday, July 26-27 Welcome & Introductions
Update and Approve Agenda Review and approve June Minutes IEEE Patent Policy Review 2006 Meeting Schedule 2007 Meeting Schedule Update on TCG Update on INCITS CS1 Working Group Review of Action Items from June Meeting Topics from 4/17/2019

3 Agenda Items Wednesday/Thursday, July 26-27 Document Review of PPs
A (High) PP B (Enterprise) PP C (Public) PP D (SoHo) PP PP Annexes Merged Document Review Clause 8 Clause 9 Other items Next meeting details Summarize and record action items 4/17/2019

4 Minutes from June Meeting
Minutes were published shortly after the meeting. They are available at: Any corrections or changes? 4/17/2019

5 Instructions for the WG Chair
At Each Meeting, the Working Group Chair shall: Show slides #1 and #2 of this presentation Advise the WG membership that: The IEEE’s patent policy is consistent with the ANSI patent policy and is described in Clause 6 of the IEEE-SA Standards Board Bylaws; Early disclosure of patents which may be essential for the use of standards under development is encouraged; Disclosures made of such patents may not be exhaustive of all patents that may be essential for the use of standards under development, and that neither the IEEE, the WG, nor the WG Chairman ensure the accuracy or completeness of any disclosure or whether any disclosure is of a patent that, in fact, may be essential for the use of standards under development. Instruct the WG Secretary to record in the minutes of the relevant WG meeting: That the foregoing advice was provided and the two slides were shown; That an opportunity was provided for WG members to identify or disclose patents that the WG member believes may be essential for the use of that standard; Any responses that were given, specifically the patents and patent applications that were identified (if any) and by whom. 4/17/2019 (Not necessary to be shown) Approved by IEEE-SA Standards Board – March 2003 (Revised March 2005)

6 IEEE-SA Standards Board Bylaws on Patents in Standards
IEEE standards may include the known use of essential patents and patent applications provided the IEEE receives assurance from the patent holder or applicant with respect to patents whose infringement is, or in the case of patent applications, potential future infringement the applicant asserts will be, unavoidable in a compliant implementation of either mandatory or optional portions of the standard [essential patents]. This assurance shall be provided without coercion. The patent holder or applicant should provide this assurance as soon as reasonably feasible in the standards development process. This assurance shall be provided no later than the approval of the standard (or reaffirmation when a patent or patent application becomes known after initial approval of the standard). This assurance shall be either: a) A general disclaimer to the effect that the patentee will not enforce any of its present or future patent(s) whose use would be required to implement either mandatory or optional portions of the proposed IEEE standard against any person or entity complying with the standard; or b) A statement that a license for such implementation will be made available without compensation or under reasonable rates, with reasonable terms and conditions that are demonstrably free of any unfair discrimination. This assurance is irrevocable once submitted and accepted and shall apply, at a minimum, from the date of the standard's approval to the date of the standard's withdrawal. 4/17/2019 Slide #1 Approved by IEEE-SA Standards Board – March 2003 (Revised February 2006)

7 Inappropriate Topics for IEEE WG Meetings
Don’t discuss the validity/essentiality of patents/patent claims Don’t discuss the cost of specific patent use Don’t discuss licensing terms or conditions Don’t discuss product pricing, territorial restrictions, or market share Don’t discuss ongoing litigation or threatened litigation Don’t be silent if inappropriate topics are discussed… do formally object. If you have questions, contact the IEEE-SA Standards Board Patent Committee Administrator at or visit This slide set is available at 4/17/2019 Slide #2 Approved by IEEE-SA Standards Board – March 2003 (Revised March 2005)

8 Officers No Change Chair: Don Wright, Lexmark
Vice Chair: Lee Farrell, Canon Secretary: Brian Smithson, Ricoh Main Editors: Non-PP clauses: Jerry Thrasher, Lexmark PP clauses: Brian Smithson, Ricoh No Change 4/17/2019

9 2006 Meeting Schedule Sept. 6-7, Waterloo, ON Canada @ Equitrac
TCG on Sept. 8 (tentative) Oct , Lexington Lexmark With PWG, FSG, OSDL Dec , El Segundo, Peerless 4/17/2019

10 Schedule Schedule Clauses 1-9, Informative Annex Protection Profiles
Ready for merging May & June meeting reviews Protection Profiles Still Waiting for July draft of CCV3 into the PPs by Sept? PPs reviewed and iterate 1 or 2 times Complex changes: who knows? Complete draft out of December meeting 4/17/2019

11 Schedule Schedule January 2007 February March
Form IEEE ballot body Engage with CC Eval Labs February Start Balloting Start Evaluation of PPs March April -- (Will need group meeting) Reconcile comments from IEEE and Eval Labs May – June - July Recirculations September RevCom / Standards Board Approval 4/17/2019

12 2007 Meeting Schedule January – finish draft if we don’t finish in Dec. Potentially weeks of Jan 8, Feb 19 (more likely) April – handle comments from sponsor ballot Potentially April or week of 23rd Late May – handle comments from 1st re-circulation Potentially week of May 21st or May 28th Mid-July – handle comments from 2nd re-circulation (if needed) Potentially week of July 23rd Cut-off for drafts to RevCom is August 17th 4/17/2019

13 Trusted Computing Group
Update 4/17/2019

14 INCITS CS1 : Cyber-Security
Update 4/17/2019

15 Group General Action Items from June
Update web site with Sept meeting details – complete Convert PP-A to CIM EAL 3 – (due in July) – awaiting CCV3 drafts Harmonize Subject/Object implementation – (waiting for CCV3, part 2) PAR Change to get Scope and Purpose to match the draft – submitted to NesCom 4/17/2019

16 Action Items from Previous Meetings
Any update on CCV3 plans from NIAP? Presentation from the PP team on mandating of encryption in PP-A and PP-B. (AI #198) Others? Review entries in P2600-action-items excel spreadsheet 4/17/2019

17 Issues raised on e-mail
Various Topics (Smithson of 6/30) T.UD.PHY.OUTPUT proposals Use only OE.LOCATION and OE.TRAIN to mitigate T.UD.PHY.OUTPUT Require the use of a technical solution in environment A Require the use of a technical solution in environments A and B Would an App Note that allows O.ACCESS instead of OE.LOCATION to mitigate the threat work? Decision: O.ACCESS for PP-A but not for PP-B (no oe.location or oe.train in PP-A) Decision: Do not require O.I&A for either PP-A or PP-B for this threat Putting T.DOS.FAX threats back into the protection profiles Decision: T.DOS.FAX should be there and the HCD should recover after a DOS attack on the FAX App Note  Human intervention may be required if the DOS attack exhausts the HCD’s consumables Proposals regarding threat/objective changes Tentative Decision: Leave O.DELETE and O.PROTECT in PP-A and PP-B Discuss further on July 27th 4/17/2019

18 Issues raised on e-mail
Update group on CC Vendors’ Forum (Private Sukert of 7/5) Several presentations at ICCC Will probably meet as a group at ICCC P2600 members: Alan S, Brian S, Jerry T Subjects, Objects, and beyond (Smithson) Next step: Brian will write up a few SFRs to see how this structure works Also: Each company should bounce this proposal off their implementation teams 4/17/2019

19 Issues raised on e-mail
Assets – Should availability be included in any or all PPs? Change name to “HCD Availability” It is an “asset” in PP-A, PP-B & PP-C Update PPs and Clauses 1-9 Wording of T.UD.ACC.NORMAL definition Updated full description, add RIP to acronyms Others? 4/17/2019

20 Document Section Status
Editors Assigned: Clauses 1-9 & non-PP Annexes: Jerry Thrasher Protection Profiles: Brian Smithson PP-A -- Ron Nevo PP-B -- Brian Smithson PP-C -- Nancy Chen, Alan Sukert PP-D -- Carmen Aubry 4/17/2019

21 Document Review Drafts needing most review Merged Draft Clauses 8 & 9
Not reviewed at June meeting Protection Profiles A B C D (no update?) PP Annexes 4/17/2019

22 Document Review: PP-A Review Draft number 21a
Now Protection Profile A, EAL 3 Freas’ two s of 7/16 Thoughts on adding FIA_QAD to PP-A and PP-B Proposal: for one-factor authentication (password) at least 4 numeric characters for PP-B at least 8 characters (from alphanumeric and special sets) for PP-A Two- & three-factor authentication quality are not specified FPT_RIP.1 vs FPT_RIP.2 On hold waiting for CCV3.1 Sameer’s comments via on 7/21 4/17/2019

23 Document Review: PP-B Review Draft number 21b
Now Protection Profile B, EAL 2 Reviewed changes since last time Will align with wording changes in PP-A 4/17/2019

24 Document Review: PP-C Review Draft number 21a
Now Protection Profile C, EAL 2 Reviewed changes since last time Will align with wording changes in PP-A 4/17/2019

25 Document Review: PP-D Review Draft number 19c
Now Protection Profile D, EAL 1 No new document to review 4/17/2019

26 Other Work Items Develop benefits to help pay for PP certification
Value proposition? Don and Brian S. Compliance clause Products are required to be compliant with one or more of the protection profiles in Annexes A-D Other potentially required threat mitigations highlighted in Clause 8. Draft? 4/17/2019

27 Next Meeting Details September 6-7
Equitrac 450 Phillip Street Waterloo, ON, N2L 5J2 Canada Nearby Hotels: Waterloo Inn ( St. Jacobs Best Western ( Walper Terrace ( Delta ( Holiday Inn ( Radisson ( Driving directions from the Toronto airport are available here: 4/17/2019

28 Next Meeting Details 4/17/2019

29 Future Meetings Note well: Lexington – expect 2 full days: 9AM – 6PM
El Segundo – expect 2 full days: 9AM – 6PM 4/17/2019

30 Mailing List and Web Site
Listserv run by the IEEE An archive is available on the web site Subscribe via a note to: containing the line: subscribe stds-2600 Only subscribers may send to the mailing list. No Change 4/17/2019


Download ppt "Don Wright Director of Standards Lexmark International"

Similar presentations


Ads by Google