Presentation is loading. Please wait.

Presentation is loading. Please wait.

SEC-2014-0417-Identity_of_registrar_CSE Identity of Registrar CSE Group Name: SEC, ARC and PRO Source:FUJITSU Meeting Date: 2014-09-18 Agenda Item: Authentication.

Similar presentations


Presentation on theme: "SEC-2014-0417-Identity_of_registrar_CSE Identity of Registrar CSE Group Name: SEC, ARC and PRO Source:FUJITSU Meeting Date: 2014-09-18 Agenda Item: Authentication."— Presentation transcript:

1 SEC-2014-0417-Identity_of_registrar_CSE Identity of Registrar CSE Group Name: SEC, ARC and PRO Source:FUJITSU Meeting Date: 2014-09-18 Agenda Item: Authentication

2 SEC-2014-0417-Identity_of_registrar_CSE SP’s domain Introduction Security TS recommend to use TLS for communication between AE and CSE It is not clear which identity should be used on the certificate of CSE side AE-2 AE-1 Mutual Auth over TLS Mutual Auth DNS Who? Mutual Auth Who? Mutual Auth Who? 2

3 SEC-2014-0417-Identity_of_registrar_CSE Possible Options Option-A: IP independent (CSE-ID ?) – Registrar’s certificate should be delivered to AE on provisioning (1-to-1 trust relationship) – Revocation management of cert. should be matter Option-B: – M2M SP runs root CA and root CA’s certificate will be provisioned Option-C: IP dependent (reverse DNS name) – DNS reverse query may ease to detect fake CSE – DNS registration could be matter 3


Download ppt "SEC-2014-0417-Identity_of_registrar_CSE Identity of Registrar CSE Group Name: SEC, ARC and PRO Source:FUJITSU Meeting Date: 2014-09-18 Agenda Item: Authentication."

Similar presentations


Ads by Google