Download presentation
Presentation is loading. Please wait.
Published byGeorgina Lambert Modified over 9 years ago
1
Mapping Company Classification Policy to the S/MIME Security Label Weston Nicolls wnicolls@telenisus.com S/MIME Working Group Meeting December 13, 2000
2
Telenisus Corporation2 Purpose Informational RFC Build on Security Label feature defined in ESS for S/MIME - RFC 2634 Show how Security Label can used to implement an organizational security policy
3
Telenisus Corporation3 3 rd Draft Classification Policies and Examples for: –Amoco Corporation General, Confidential, Highly Confidential –Caterpillar Inc Public, Confidential Green, Confidential Yellow, Confidential Red –Whirlpool Corporation Public, Internal, Confidential
4
Telenisus Corporation4 3 rd Draft Security Categories syntax and examples Attribute Owner Clearance examples Privacy Mark examples
5
Telenisus Corporation5 Security Category Syntax SecurityCategories ::= SET SIZE (1..ub-security-categories) OF SecurityCategory ub-security-categories INTEGER ::= 64 SecurityCategory ::= SEQUENCE { type[0] OBJECT IDENTIFIER value[1] ANY DEFINED BY type } -- defined by type
6
Telenisus Corporation6 Security Category Syntax One example of a SecurityCategory syntax is SecurityCategoryValues, as follows. When id-securityCategoryValues is present in the SecurityCategory type field, then the SecurityCategory value field could take the form of SecurityCategoryValues as follows: SecurityCategoryValues ::= SEQUENCE OF UTF8String
7
Telenisus Corporation7 Example ESSSecurityLabel: security-policy-identifier: id-tsp-3 security-classification: 9 privacy-mark: ATTORNEY-CLIENT PRIVILEGED INFORMATION security-categories: SEQUENCE OF SecurityCategory SecurityCategory #1 type: id-tsp-4 value: LAW DEPARTMENT USE ONLY
8
Telenisus Corporation8 Example Clearance Attribute (passes access control check): Clearance: policyId: id-tsp-3 classList BIT STRING: Bits 0, 1, 2, 9 are set to TRUE securityCategories: SEQUENCE OF SecurityCategory SecurityCategory #1 type: id-tsp-4 value: LAW DEPARTMENT USE ONLY
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.