Federation of Campus PKI and Grid PKI for Academic GOC Management Conformable to APGrid PMA National Institute of Informatics, JAPAN Toshiyuki Kataoka,

Slides:



Advertisements
Similar presentations
UPKI Inter-University Authentication and Authorization Platform for Japanese Cyber-Science Infrastructure Yasuo OKABE Academic Center for Computing and.
Advertisements

eduroam Delegate Authentication System with Shibboleth SSO
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Report on Attribute Certificates By Ganesh Godavari.
Public Key Infrastructure (PKI) Providing secure communications and authentication over an open network.
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
2015/6/21 UPKI project update Yasuo Okabe Academic Center for Computing and Media Studies Kyoto University.
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
CNI Fall 1998 Access Management Requirements and Approaches Joan Gargano California Digital Library
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
F. Guilleux, O. Salaün - CRU Middleware activities in French Higher Education.
Computing Research Center, High Energy Accelerator Organization (KEK) KEK Grid CA Go Iwai The 2 nd APGrid PMA Meeting at Osaka Univ.
Grid security in NAREGI project NAREGI the Japanese national science grid project is doing research and development of grid middleware to create e- Science.
Grid security in NAREGI project July 19, 2006 National Institute of Informatics, Japan Shinichi Mineo APAN Grid-Middleware Workshop 2006.
Tweaking the Certificate Lifecycle for the UK eScience CA John Kewley NGS Support Centre Manager & Service Manager for the UK e-Science CA
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
NAREGI CA Updates Kento Aida NAREGI CA/NII Kento Aida, National Institute of Informatics APGrid PMA meeting 04/20/2008.
Configuring Directory Certificate Services Lesson 13.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
Module 9: Fundamentals of Securing Network Communication.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
TERENA TF-EMC2 Workshop David Groep,
Introduction of NAREGI-CA National Institute of Informatics JAPAN Toshiyuki Kataoka, July 19, 2006 APAN Grid-Middleware Workshop, Singapore.
PKI Activities at Virginia September 2000 Jim Jokl
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
User Certificate Application: ASGCCA. Agenda Introduction ASGCCA User Responsibilities Certificate application form RA verify identity of users User generate.
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
1 UPKI-Federation based on Shibboleth National Institute of Informatics Motonori Nakamura Toshiyuki Kataoka, Kyoto University Yasuo Okabe.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Module 2: Introducing Windows 2000 Security. Overview Introducing Security Features in Active Directory Authenticating User Accounts Securing Access to.
Welcome to the Grid Middleware Workshop ☆ Joint workshop of Grid WG and Middleware WG Middleware Working Group at a glance 20 th APAN (Taipei, Aug. 2005)
KEK GRID CA updates Takashi Sasaki Computing Research Center KEK.
UPKI Activities - July NII & UPKI Initiative Hideaki Sone, Tohoku University.
National Institute of Advanced Industrial Science and Technology GGF12 Workshop on Operational Security for the Grid Cross-site authentication and access.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
The Roadmap of NAREGI Security Services Masataka Kanamori NAREGI WP
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Co-ordination & Harmonisation of Advanced e-Infrastructures for Research and Education Data Sharing Research Infrastructures Grant Agreement n
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
NECTEC-GOC CA A Brief Status Report 13 th APGrid PMA Face-to-Face meeting March 24 th, 2014 Large-Scale Simulation Research Laboratory Information Communications.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
Soapbox (S-Series) Certificate Validation Jens Jensen, STFC.
AEGIS Certification Authority
Guidelines for auditing Grid CAs
NAREGI-CA Development of NAREGI-CA NAREGI-CA Software CP/CPS Audit
HellasGrid CA & euGridPMA
Organized by governmental sector (National Institute of information )
The New Virtual Organization Membership Service (VOMS)
NAAS 2.0 Features and Enhancements
جايگاه گواهی ديجيتالی در ايران
Public Key Infrastructure from the Most Trusted Name in e-Security
Presentation transcript:

Federation of Campus PKI and Grid PKI for Academic GOC Management Conformable to APGrid PMA National Institute of Informatics, JAPAN Toshiyuki Kataoka, Kento Aida, Shinichi Mineo APAN 24 Middleware Session, Xi’An Aug.28, 2007

2 OUTLINE NAREGI Certification Service UPKI Common Specifications UPKI Enhancement of CA System Grid Operation Center Plan Issues

NAREGI-CA Certification Service

4 ● Publication of scientific results from academia Human Resource Development and strong organization NAREGI Middleware Virtual Organization For science 1-1 CyberScience Infrastructure for Advanced Science (by NII) for Advanced Science (by NII) To Innovate Academia and Industry UPKI ★ ★ ★ ★ ★ ★ ★ ☆ Super-sinet: a next generation network infrastructure supported by NII and 7 National Computer Centers Cyber Science Infrastructure 北海道大学 東北大学 東京大学 NIINII 名古屋大学 京都大学 大阪大学 九州大学 (東京工業大学、早稲田大学、高 エネルギー加速器研究機構等) Scientific Repository Industry Liaison and Social Benefit Global Contribution

5 1-2 NAREGI Certification Authority NAREGI (National Research Grid Initiative) PJ develops grid middleware. NAREGI CA is operated by NAREGI PJ, and it issues certificates for development and doing research using NAREGI grid middleware NAREGI CA is a member of APGrid - NAREGI CA is authorized by the APGrid PMA as a Production Level CA. - NAREGI PMA is a member of APGrid PMA. NAREGI CA issues certificates to NAREGI project members (National Institute of informatics, Institute for Molecular Science)

6 Certificate Users Host Administrators RA Administrator CA Operator Application for bulk license ID Issuance of bulk license ID ① Preparation License ID request Receive request, Inspection ② License ID request Certificate request ③ Issuance request ④ Revoke request ⑤ Reissuance request Receive request, Issuance/Revoke certificate Retrieve data for creating map file Make data for creating map file ⑥ Retrieve data for creating map file NAREGI CA User site Account Registration Request Account Registration 1-3 NAREGI CA operation

UPKI Common Specifications

8 2-1 UPKI Architecture Web サーバ NII Pub CA Web Srv. Web サーバ S/MIME Other Pub CA S/MIME Web Srv. 学内用 A Univ. CA EE 学内用 B Univ. CA EE A Univ. NAREGI CA EE B Univ. NAREGI CA Campus PKI Open Domain PKI NAREGI PKI S/MIME Auth, Sign, Encrypt. Sign, Encrypt. Auth, Sign, Encrypt. Grid Computing Proxy EE Proxy EE Student, Faculty Server, Super Computer Student, Faculty Server, Super Computer

9 2-2 UPKI Activities Web サーバ NII Pub CA Web Srv. Web サーバ S/MIME Other Pub CA S/MIME Web Srv. 学内用 A Univ. CA EE 学内用 B Univ. CA EE A Univ. NAREGI CA EE B Univ. NAREGI CA Campus PKI Open Domain PKI NAREGI PKI S/MIME Auth, Sign, Encrypt. Sign, Encrypt. Auth, Sign, Encrypt. Grid Computing Proxy EE Proxy EE Student, Faculty Server, Super Computer Student, Faculty Server, Super Computer NAREGI-CA Enhancement NAREGI-CA Pack UPKI Common Specification Server Certificates S/MIME Certificates Eduroam

UPKI Common Specifications Web サーバ NII Pub CA Web Srv. Web サーバ S/MIME Other Pub CA S/MIME Web Srv. 学内用 A Univ. CA EE 学内用 B Univ. CA EE A Univ. NAREGI CA EE B Univ. NAREGI CA Campus PKI Open Domain PKI NAREGI PKI S/MIME Auth, Sign, Encrypt. Sign, Encrypt. Auth, Sign, Encrypt. Grid Computing Proxy EE Proxy EE Student, Faculty Server, Super Computer Student, Faculty Server, Super Computer UPKI Common Specifications

11 UPKI Common Specifications   Campus PKI procurement guidelines   Campus PKI CP/CPS templates Campus PKI model   Two outsource models and one insource model Developed and Published for outsource model   Only available in JAPANESE! 2-4 UPKI Common Specifications Campus CP/CPS templates Deployment of campus PKI at each universities - -Connecting universities - - Federation of applications 2008 Campus PKI Spec. Outsource modelInsource model Multi-university cooperative model Outsource modelInsource model Multi-university cooperative model -To promote Campus PKI deployment PKI deployment -To reduce cost -To keep multi-university cooperativity cooperativity

12 Insource Univ RA IA Univ. provider Full outsource RA IA IA outsource Univ provider IA RA CP/CPS 2-5 Operation Models of CA

UPKI Enhancement of CA System

Enhancement in UPKI Enhancement for actual operation of CA/RA at universities; 1. To split and delegate RA. 2. To provide staffs/students means to apply by themselves. 3. To issue grid certificate by identification of campus certificate.

Enhancement in UPKI (1),(2) 1. To split and delegate RA. - Created RA/LRA operator authorities split from RA administrator authorities. - Secure delegation by using IC card. - Delegation to hierarchized institutions in universities for actual operation. 2. To provide staffs/students means to apply by themselves. - Easy application of registration, issuance, and revocation from the web. - Secure application by using challenge PIN. - Reduced burden of RA operation.

16 CA Administrator CARA RA Administrator IC Card 3-3 Enhanced Procedure To Issue Certificate CA Administrator RA Administrator RA Operator User License ID Issue Certificate RACA Apply Identify Approve Issue Certificate Application Server (web) Management Server (web) Delegate Challenge PIN License ID Local RA User Identify Apply License ID

Enhancement in UPKI (3) 3. To issue grid certificate by identification of campus certificate. - Cooperation of Grid CA and Campus CA. - Reduced burden of RA operation. - Any certificate can be issued for other AP.

18 CampusCA Issue Certificate Campus PKI Grid PKI NAREGI CA Super Computer Grid System Super Computer Issue Certificate Request Certificate (Use IC Card as credential) LDAP NAREGI RA IC Card Certificate for Grid System Access User 3-5 Campus-Grid PKI Federation

Grid Operation Center Plan

Grid Operation Center Plan GOC CA issues certificates to authorized members of CSI using grid Operation will be compliant with APGrid policies Cooperate with many universities and research institutes

Operation models of GOC GOC will operate three models. (1) LRA in GOC operates registration; GOC will inspect user documents, and face to face identification. (2)LRA in university operates registration; University will inspect user documents, and face to face identification. (3)Use Campus certificate as an identification to issue grid certificate; University will inspect user documents, but skip face to face identification.

Issues

Issue 1 - User Identification - APGrid PMA minimum CA requirements; “In order for an RA to validate the identity of a person, the subject must contact the RA personally and present photo-id and/or valid official documents showing that the subject is an acceptable end entity as defined in the CP/CPS document of the CA.” - Campus PKI CPS template; “The information of students or faculties will be collected on admission and stored in database in universities. Campus PKI CA will issue campus certificate by using and trusting the collected information in the database” -> Is it proper and feasible to use Campus certificate as an identification for issuing grid certificate? -> Add a following term to Campus PKI CPS template? “photo-id and/or valid official documents in the case of using campus certificate as an identification for grid certificate.”

Issue 2 - On revocation of campus certificate; - For the grid certificate that has issued by identifying with campus certificate -> Keep the grid certificate valid? -> Revoke the grid certificate? How? Check CRL of campus certificate?

Issue 3 - Audit - GOC : APGrid PMA will do mutual audit - LRA in universities: GOC will audit? - CA for campus PKI in universities: Need audit? and who?