US PKI and Bridge PKIScott ReaeFormsDigital Signatures_第1頁
US PKI and Bridge PKIScott ReaeFormsDigital Signatures_第2頁
US PKI and Bridge PKIScott ReaeFormsDigital Signatures_第3頁
US PKI and Bridge PKIScott ReaeFormsDigital Signatures_第4頁
US PKI and Bridge PKIScott ReaeFormsDigital Signatures_第5頁
已閱讀5頁,還剩11頁未讀, 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡介

1、PKI in US Higher EducationTAGPMA Meeting, March 2006 Rio De Janeiro , Brazil2HEBCA : Higher Education Bridge Certificate Authority Bridge Certificate Authority for US Higher Education Modeled on FBCA Provides cross-certification between the subscribing institution and the HEBCA root CA Flexible poli

2、cy implementations through the mapping process The HEBCA root CA and infrastructure hosted at Dartmouth College Facilitates inter-institutional trust between participating schools Facilitates inter-federation trust between US Higher Education community and external entities3HEBCA Project What will i

3、t provide? The HEBCA Project will create and maintain three new Certificate Authority (CA) systems for EDUCAUSE and will also house the existing HEBCA Prototype CA The three CA systems to be created are: HEBCA Test CA HEBCA Development CA HEBCA Production CA The HEBCAs will be used to cross-certify

4、Higher Education PKI trust anchors to create a bridged trust network The HEBCA Test CA will also be cross-certified with the Prototype FBCA (other emerging Bridge CAs are also targets) and the HEBCA production CAs will be cross-certified with the production FBCA. 4HEBCA Project What does it look lik

5、e?(Artists impression only)5HEBCA Policy Authority The HEBCA PA establishes policy for and oversees operation of the HEBCA. HEBCA PA activities include approve and certify the Certificate Policy (CP) and Certification Practices Statement (CPS) for the HEBCA set policy for accepting applications for

6、cross-certification and interoperation with the HEBCA certify the mapping of policy between the HEBCA CP and applicants CPs establish any needed constraints in cross-certification documents represent the HEBCA in establishing its own cross-certification with other PKI bridges set policy governing op

7、eration of the HEBCA oversee the HEBCA Operational Authority keep the HEBCA Membership and the HEPKI Council informed of its decisions and activities. 6HEBCA Operating AuthorityThe HEBCA OA is the organization that is responsible for the issuance of HEBCA certificates when so directed by the HEBCA P

8、A, the posting of those certificates and any Certificate Revocation Lists (CRLs) or Certificate Authority Revocation Lists (CARLs) into the HEBCA repository, and maintaining the continued availability of the repository to all parties relying on HEBCA certificates. Specific responsibilities of the HE

9、BCA OA include: Management and operation of the HEBCA infrastructure; Management of the registration process; Completion of the applicant identification and authentication process; and Complying with all requirements and representations of the Certificate Policy. Key personnel from the Dartmouth PKI

10、 Laboratory were chosen as the HEBCA Operating Authority by the HEBCA PA under the direction of EDUCAUSE (the project sponsor).7HEBCA What is the value presented by this initiative? HEBCA facilitates a trust fabric across all of US Higher Education so that credentials issued by participating institu

11、tions can be used (and trusted) globally e.g. signed and/or encrypted email, digitally signed documents (paperless office), etc can all be trusted inter-institutionally and not just intra-institutionally Extensions to the Higher Education trust infrastructure into external federations is also possib

12、le and proof of concept work with the FBCA (via BCA cross-certification) has demonstrated this inter-federation trust extension Single credential accepted globally Potential for stronger authentication and possibly authorization of participants in grid based applications Contributions provided to th

13、e Path Validation and Path Discovery development efforts Facilitates compliance with legal requirements (GPEA, HIPAA)8USHER : US Higher Education Root Trusted Root for US Higher Education Only signs subordinate CA certificates Bootstraps institutional PKIs by providing policy infrastructure and a CA

14、 The USHER root CA and infrastructure hosted at Dartmouth College Facilitates inter-institutional trust between participating schools Different levels of assurance supported9USHER Project What will it provide? The USHER Project will create and maintain four new Certificate Authority (CA) systems for

15、 Internet2 and will share the existing HEBCA infratsructure The four CA systems to be created are: USHER Foundation CA USHER Basic CA* USHER Medium CA* USHER High CA*Not officially named yet The USHERs will be used to provide institutions of higher education PKI trust anchors with a common policy Th

16、e USHER CAs may also be potentially cross-certified with the HEBCA to allow interoperation outside the USHER community. 10USHER Policy Authority The USHER PA establishes policy for and oversees operation of the USHER initiatives. USHER PA activities include approve and certify the Certificate Policy

17、 (CP) and Certification Practices Statement (CPS) for the USHER set policy for accepting applications for CA issuance under USHER CAs represent the USHER in establishing cross-certification with other PKI bridges e.g. HEBCA set policy governing operation of the USHER CAs oversee the USHER Operationa

18、l Authority keep the USHER Membership informed of its decisions and activities. 11Solving Silos of TrustDept-1InstitutionDept-1Dept-1SubCACASubCASubCASubCACASubCASubCASubCACASubCASubCAUSHERHEBCAFBCA12 ProposedInter-federationsFBCACA-1CA-2CA-nCross-certHEBCADartmouthWisconsinTexasUniv-NUVAUSHER DSTAC

19、ESCross-certsSAFEAeroNIHCA-1CA-2CA-3CA-413HEBCA Project - OverviewHEBCA PA and CP oversiteHEBCAInfrastructureCARootCertHEBCADirectoryCrossCertPairCrossCertPairCrossCertPairCrossCertPairRootCertCrossCertPairCACRLsRootCertCrossCertPairCACRLs University 1 PKIUniversity 2 PKIBorder DirBorder DirRootCert

20、CrossCertPairCACRLsBorder DirFBCA PKIOther CrossCertified PKIsRODFBCAReferralUniversity 1ReferralUniversity 2ReferralCRLsRootCertFBCA PA and CP oversiteFBCA InfrastructureCARootCertFBCADirectoryCrossCertPairCrossCertPairCrossCertPairCrossCertPairRootCertCrossCertPairCACRLsRootCertCrossCertPairCACRLs

21、DST ACES PKIOther CrossCertified PKIBorder DirBorder DirX.500 DSP Protocol(ChainingAgreements) betweenFBCA and CrossCertified PKI providerRootCertCrossCertPairCACRLsBorder DirHEBCA PKIOther CrossCertified PKIsCRLsRootCertX.500 Based DirectoryDirectories Interconnect via Chaining (X.500 DSP)LDAP Base

22、d Directory Utilizing the Registry of Directories Utilizing LDAP Referrals14HEBCA Project - ProgressWhats been done so far? Operational Authority (OA) contractor engaged (Dartmouth PKI Lab) MOA with commercial vendor for infrastructure hardware (Sun) MOA with commercial vendor for CA software and li

23、censes (RSA) Policy Authority formed Prototype HEBCA operational and cross-certified with the Prototype FBCA (new Prototype instantiated by HEBCA OA) Prototype Registry of Directories (RoD) deployed at Dartmouth Draft of Production HEBCA CP produced Draft of Production HEBCA CPS produced Preliminary Policy Mapping completed with FBCA Test HEBCA CA deployed and cross-certified with the Prototype FBCA Test HEBCA RoD deployed Production HEBCA development phase underway Infras

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

最新文檔

評論

0/150

提交評論