Presentation is loading. Please wait.

Presentation is loading. Please wait.

P2600 - HDSS 6/2/20151 P2600 Hardcopy Device and System Security October 2008 Working Group Meeting Don Wright Director of Standards Lexmark International.

Similar presentations


Presentation on theme: "P2600 - HDSS 6/2/20151 P2600 Hardcopy Device and System Security October 2008 Working Group Meeting Don Wright Director of Standards Lexmark International."— Presentation transcript:

1 P2600 - HDSS 6/2/20151 P2600 Hardcopy Device and System Security October 2008 Working Group Meeting Don Wright Director of Standards Lexmark International don@lexmark.com

2 6/2/2015 P2600 - HDSS Opening Agenda Items Self Introductions Approval of the Agenda

3 6/2/2015 P2600 - HDSS Agenda Items Friday, October 24  Welcome/Introductions/Announcements  Update and Approve Agenda  Review and approve September Minutes  IEEE Patent Policy Review  2008 Meeting Schedule  Update on PWG IDS/TCG (Thrasher)  Update on INCITS CS1 Working Group (Thrasher)  Report from ICCC #9 (Smithson)  Update of CC Vendor's Forum (Smithson)  Review of Action Items from September Meeting  PP Evaluation ad hoc status (Nevo)

4 6/2/2015 P2600 - HDSS Agenda Items Friday, October 24  Evaluation Status (Smithson/atsec)  Issues raised on e-mail Making NVS applicable only to TSF Data in OpEnv B  Protection Profiles version 39 PP-A PP-B PP-C PP-D Comments  Guide to P2600 PPs ad hoc status (Sukert) Version 39 Comments

5 6/2/2015 P2600 - HDSS Agenda Items Friday, October 24  Production Printing Profile (Sukert) Version 39 Comments?  Schedule Review  Other items  Posting and Comment deadlines for the December Meeting  Next meeting details

6 6/2/2015 P2600 - HDSS Minutes from September Meeting Minutes were published shortly after the meeting. They are available at: http://grouper.ieee.org/groups/2600/minutes/ P2600-minutes-Sep2008.pdf http://grouper.ieee.org/groups/2600/minutes/ P2600-minutes-Sep2008.pdf Any additions, deletions or corrections to the September minutes?

7 6/2/2015 P2600 - HDSS The IEEE-SA strongly recommends that at each WG meeting the chair or a designee:  Show slides #1 through #4 of this presentation  Advise the WG attendees that: The IEEE’s patent policy is consistent with the ANSI patent policy and is described in Clause 6 of the IEEE-SA Standards Board Bylaws; Early identification of patent claims which may be essential for the use of standards under development is strongly encouraged; There may be Essential Patent Claims of which the IEEE is not aware. Additionally, neither the IEEE, the WG, nor the WG chair can ensure the accuracy or completeness of any assurance or whether any such assurance is, in fact, of a Patent Claim that is essential for the use of the standard under development.  Instruct the WG Secretary to record in the minutes of the relevant WG meeting: That the foregoing information was provided and that slides 1 through 4 (and this slide 0, if applicable) were shown; That the chair or designee provided an opportunity for participants to identify patent claim(s)/patent application claim(s) and/or the holder of patent claim(s)/patent application claim(s) of which the participant is personally aware and that may be essential for the use of that standard Any responses that were given, specifically the patent claim(s)/patent application claim(s) and/or the holder of the patent claim(s)/patent application claim(s) that were identified (if any) and by whom.  The WG Chair shall ensure that a request is made to any identified holders of potential essential patent claim(s) to complete and submit a Letter of Assurance.  It is recommended that the WG chair review the guidance in IEEE-SA Standards Board Operations Manual 6.3.5 and in FAQs 12 and 12a on inclusion of potential Essential Patent Claims by incorporation or by reference. Note: WG includes Working Groups, Task Groups, and other standards-developing committees with a PAR approved by the IEEE-SA Standards Board. Instructions for the WG Chair (Optional to be shown)

8 6/2/2015 P2600 - HDSS Participants, Patents, and Duty to Inform All participants in this meeting have certain obligations under the IEEE-SA Patent Policy. Participants:  “Shall inform the IEEE (or cause the IEEE to be informed)” of the identity of each “holder of any potential Essential Patent Claims of which they are personally aware” if the claims are owned or controlled by the participant or the entity the participant is from, employed by, or otherwise represents “Personal awareness” means that the participant “is personally aware that the holder may have a potential Essential Patent Claim,” even if the participant is not personally aware of the specific patents or patent claims  “Should inform the IEEE (or cause the IEEE to be informed)” of the identity of “any other holders of such potential Essential Patent Claims” (that is, third parties that are not affiliated with the participant, with the participant’s employer, or with anyone else that the participant is from or otherwise represents)  The above does not apply if the patent claim is already the subject of an Accepted Letter of Assurance that applies to the proposed standard(s) under consideration by this group ( Quoted text excerpted from IEEE-SA Standards Board Bylaws subclause 6.2) Early identification of holders of potential Essential Patent Claims is strongly encouraged No duty to perform a patent search Slide #1

9 6/2/2015 P2600 - HDSS Patent Related Links All participants should be familiar with their obligations under the IEEE- SA Policies & Procedures for standards development. Patent Policy is stated in these sources:  IEEE-SA Standards Boards Bylaws http://standards.ieee.org/guides/bylaws/sect6-7.html#6  IEEE-SA Standards Board Operations Manual http://standards.ieee.org/guides/opman/sect6.html#6.3  Material about the patent policy is available at http://standards.ieee.org/board/pat/pat-material.html Slide #2 If you have questions, contact the IEEE-SA Standards Board Patent Committee Administrator at patcom@ieee.org or visit http://standards.ieee.org/board/pat/index.html This slide set is available at http://standards.ieee.org/board/pat/pat-slideset.ppt

10 6/2/2015 P2600 - HDSS Call for Potentially Essential Patents If anyone in this meeting is personally aware of the holder of any patent claims that are potentially essential to implementation of the proposed standard(s) under consideration by this group and that are not already the subject of an Accepted Letter of Assurance:  Either speak up now or  Provide the chair of this group with the identity of the holder(s) of any and all such claims as soon as possible or  Cause an LOA to be submitted Slide #3

11 6/2/2015 P2600 - HDSS Other Guidelines for IEEE WG Meetings All IEEE-SA standards meetings shall be conducted in compliance with all applicable laws, including antitrust and competition laws.  Don’t discuss the interpretation, validity, or essentiality of patents/patent claims.  Don’t discuss specific license rates, terms, or conditions. Relative costs, including licensing costs of essential patent claims, of different technical approaches may be discussed in standards development meetings. Technical considerations remain primary focus  Don’t discuss or engage in the fixing of product prices, allocation of customers, or division of sales markets.  Don’t discuss the status or substance of ongoing or threatened litigation.  Don’t be silent if inappropriate topics are discussed … do formally object. --------------------------------------------------------------- See IEEE-SA Standards Board Operations Manual, clause 5.3.10 and “Promoting Competition and Innovation: What You Need to Know about the IEEE Standards Association's Antitrust and Competition Policy” for more details. Slide #4

12 6/2/2015 P2600 - HDSS 2008 Meeting Schedule December 11-12: Plantation, FL @ Equitrac

13 6/2/2015 P2600 - HDSS PWG-IDS/Trusted Computing Group Update

14 14Copyright © 2008, Printer Working Group. All rights reserved. PWG Imaging Device Security (IDS) Working Group Lexington, KY – P2600 Meeting October 24, 2008

15 15Copyright © 2008, Printer Working Group. All rights reserved. Purpose of the effort The industry is moving beyond basic authentication for access to corporate networks to a fairly detailed assessment of the device that is connecting before being allowed to access the network. Examples of what’s being measured for PC Clients: OS Type, Version, Patch Level Anti-virus Type, Version, Definition Level, Is Active Hardcopy Devices attach to networks, but there’s no standard set of metrics that is used to assess an HCD. Our Goal is to provide these metrics!!!

16 16Copyright © 2008, Printer Working Group. All rights reserved. Work Items for the WG What We’re Doing Defining a standard set of metrics that might be measured or assessed in Hardcopy Devices to gauge if they should be given access to a network Defining example “bindings” for how these metrics are used in the individual network assessment protocols. What We’re NOT Doing We are NOT defining any new assessment protocols or assessment extensions to existing authentication protocols. We are NOT endorsing any of the competing network assessment protocols (NEA/TNC, NAC, NAP), but plan to enable Hardcopy Devices to participate in any/all of them.

17 17Copyright © 2008, Printer Working Group. All rights reserved. Working Group Officers IDS WG Chairs: Peter Cybuck (Sharp), Ron Bergman (Ricoh) IDS WG Secretary: Lee Farrell (Canon) IDS WG Document Editors: Jerry Thrasher (Lexmark), Ron Nevo (Sharp) Brian Smithson

18 18Copyright © 2008, Printer Working Group. All rights reserved. Status Reviewed Network Assessment Protocols Cisco NAC (Network Access Control) TCG TNC (Trusted Network Connect) Microsoft NAP (Network Access Protection) IETF NEA (Network Endpoint Assessment) NAP has been targeted to be the first candidate Well documented (public documents) Supported in MS O/S versions Current effort is to Complete Assessment Attribute Specification. Complete the binding to NAP for HCD Attributes. Define the required NAP protocol stack support. Next Step Start an HCD to NEA binding document

19 19Copyright © 2008, Printer Working Group. All rights reserved. Schedule Q1 2008: Initial education and Study Specify Network Assessment Protocols COMPLETE Develop (Use Cases) and Requirements COMPLETE Q2 2008: Draft Proposals Required Minimal Attribute Set COMPLETE Extended Attribute Set COMPLETE Q3 2008: HCD Health Assessment Attributes Spec IN REVIEW NAP Binding Spec Proposal IN REVIEW Q4 2008: Complete HCD Attributes Spec Finalize NAP Binding Spec Start NEA Binding Spec

20 20Copyright © 2008, Printer Working Group. All rights reserved. Current Documentation HCD Health Assessment Attributes Spec ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-idsattributes10-20080917.pdf (.doc)ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-idsattributes10-20080917.pdf HCD Health Assessment NAP Binding Spec ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-napsoh10-20081008.pdf (.doc)ftp://ftp.pwg.org/pub/pwg/ids/wd/wd-ids-napsoh10-20081008.pdf Microsoft NP Protocols ftp://ftp.pwg.org/pub/pwg/ids/white/Microsoft%20NAP%20Protocols.pdf (.ppt)ftp://ftp.pwg.org/pub/pwg/ids/white/Microsoft%20NAP%20Protocols.pdf

21 21Copyright © 2008, Printer Working Group. All rights reserved. General Teleconferences are held bi-weekly at 1 pm EDT The teleconference schedule: November 6 November 20 December 3-5 (Face to Face meeting) Contact Information Email distribution list ids@pwg.orgids@pwg.org To subscribe to the IDS mail list see: http://www.pwg.org/mailhelp.html

22 6/2/2015 P2600 - HDSS INCITS CS1 : Cyber-Security Update Thrasher

23 6/2/2015 P2600 - HDSS CS1 Update International SC27 Plenary held in October

24 6/2/2015 P2600 - HDSS 9 th International Common Criteria Conference Update Smithson

25 6/2/2015 P2600 - HDSS CC Vendors Forum Update Smithson

26 6/2/2015 P2600 - HDSS Action Items from Previous Meetings Review entries in P2600-action-items excel spreadsheet  Pre-meeting Spreadsheet http://grouper.ieee.org/groups/2600/actionitems/P2600- action-items-20081016.xls http://grouper.ieee.org/groups/2600/actionitems/P2600- action-items-20081016.xls

27 6/2/2015 P2600 - HDSS Old Business PP Evaluation ad hoc (Nevo) Evaluation Status (Smithson/atsec)

28 6/2/2015 P2600 - HDSS Issues raised on e-mail Making NVS applicable only to TSF Data in OpEnv B  Comment #56 in http://grouper.ieee.org/groups/2600/Sponsor Ballot/P2600.X/P2600-2-Sponsor-Ballot- b01v02.pdf http://grouper.ieee.org/groups/2600/Sponsor Ballot/P2600.X/P2600-2-Sponsor-Ballot- b01v02.pdf  Aubrey Note Aubrey Note  Smithson Response Smithson Response

29 6/2/2015 P2600 - HDSS Protection Profiles Protection Profiles (version 39)  PP-A PP-A  PP-B PP-B  PP-C PP-C  PP-D PP-D  Comments Comments

30 6/2/2015 P2600 - HDSS PP Guide Ad Hoc Team Current Status:  PP Guide Version 39a postedVersion 39a  Comments Comments

31 6/2/2015 P2600 - HDSS Production Printing Protection Profile Production Printing Profile Status  PP-E Version 39a postedVersion 39a  Comments?  Joint meeting with AFP Consortium (slides)slides

32 6/2/2015 P2600 - HDSS Project Schedule

33 6/2/2015 P2600 - HDSS Other Items 2009 Meeting Plan  February 19-20 Waikoloa Beach Marriott 69-275 Waikoloa Beach Drive Waikoloa, Hawaii (along the Kona Coast) Details to follow Others Items?

34 6/2/2015 P2600 - HDSS December Meeting Deadlines All PPs are under change control  All comments must be in the tool  The editor may not make changes EXCEPT based on submitted and accepted comments. Posting of Documents: November 27, 2008 Posting of Comments: December 4, 2008

35 6/2/2015 P2600 - HDSS Next Meeting Details December 11 & 12  Equitrac 1000 South Pine Island Road, Suite 900 Plantation, FL 33324  Nearest airport: Fort Lauderdale  No hotel block

36 6/2/2015 P2600 - HDSS Next Meeting Location Map

37 6/2/2015 P2600 - HDSS Next Meeting Location Map

38 6/2/2015 P2600 - HDSS Thanks! See you in Florida!!

39 6/2/2015 P2600 - HDSS Back-up Charts BACK-UP CHARTS

40 6/2/2015 P2600 - HDSS Mailing List and Web Site Web Site: http://grouper.ieee.org/groups/2600 http://grouper.ieee.org/groups/2600 Mailing list:  Listserv run by the IEEE  An archive is available on the web site  Subscribe via a note to: listserv@listserv.ieee.org containing the line: subscribe stds-2600 listserv@listserv.ieee.org  Only subscribers may send e-mail to the mailing list. No Change


Download ppt "P2600 - HDSS 6/2/20151 P2600 Hardcopy Device and System Security October 2008 Working Group Meeting Don Wright Director of Standards Lexmark International."

Similar presentations


Ads by Google