2015/6/21 UPKI project update Yasuo Okabe Academic Center for Computing and Media Studies Kyoto University.

Slides:



Advertisements
Similar presentations
UPKI Inter-University Authentication and Authorization Platform for Japanese Cyber-Science Infrastructure Yasuo OKABE Academic Center for Computing and.
Advertisements

eduroam Delegate Authentication System with Shibboleth SSO
Kento Aida, Tokyo Institute of Technology Grid Working Group Meeting Aug. 27 th, 2003 Tokyo Institute of Technology Kento Aida.
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Dartmouth PKI Certificate Deployment June 2004 Fed Ed Meeting.
Toward Production Level Operation of Authentication System for High Performance Computing Infrastructure in Japan Eisaku Sakane and Kento Aida National.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
Federation of Campus PKI and Grid PKI for Academic GOC Management Conformable to APGrid PMA National Institute of Informatics, JAPAN Toshiyuki Kataoka,
TF-EMC2 February 2006, Zagreb Deploying Authorization Mechanisms for Federated Services in the EDUROAM Architecture (DAME) -Technical Project Proposal-
Windows Vista And Longhorn Server PKI Enhancements Avi Ben-Menahem Lead Program Manager Windows Security Microsoft Corporation.
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
The PKI Lab at Dartmouth. Dartmouth PKI Lab R&D to make PKI a practical component of a campus network Multi-campus collaboration sponsored by the Mellon.
CAMP - June 4-6, Copyright Statement Copyright Robert J. Brentrup and Mark J. Franklin This work is the intellectual property of the authors.
Public Key Infrastructure from the Most Trusted Name in e-Security.
Virginia Tech Overview of Tech Secure Enterprise Technology Initiatives e-Provisioning Group Frank Galligan Fed/Ed.
Course 6421A Module 7: Installing, Configuring, and Troubleshooting the Network Policy Server Role Service Presentation: 60 minutes Lab: 60 minutes Module.
May 30 th – 31 st, 2006 Sheraton Ottawa. Microsoft Certificate Lifecycle Manager Saleem Kanji Technology Solutions Professional - Windows Server Microsoft.
EduRoam Australia Project Experience in location independent wireless networking with international collaboration with TERENA EduRoam Project 19 th APAN.
F. Guilleux, O. Salaün - CRU Middleware activities in French Higher Education.
Computing Research Center, High Energy Accelerator Organization (KEK) KEK Grid CA Go Iwai The 2 nd APGrid PMA Meeting at Osaka Univ.
Grid security in NAREGI project NAREGI the Japanese national science grid project is doing research and development of grid middleware to create e- Science.
Grid security in NAREGI project July 19, 2006 National Institute of Informatics, Japan Shinichi Mineo APAN Grid-Middleware Workshop 2006.
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
NAREGI CA Updates Kento Aida NAREGI CA/NII Kento Aida, National Institute of Informatics APGrid PMA meeting 04/20/2008.
ArcGIS Server and Portal for ArcGIS An Introduction to Security
Eduroam JP and development of UPKI roaming Yoshikazu Watanabe*, Satoru Yamano* Hideaki Goto**, Hideaki Sone** * NEC Corporation, Japan ** Tohoku University,
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
National Computational Science National Center for Supercomputing Applications National Computational Science NCSA-IPG Collaboration Projects Overview.
Module 9: Fundamentals of Securing Network Communication.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
Introduction of NAREGI-CA National Institute of Informatics JAPAN Toshiyuki Kataoka, July 19, 2006 APAN Grid-Middleware Workshop, Singapore.
Jun Adachi & Masamitsu Negishi National Institute of Informatics, Japan NII October 23, 2006 Beijing, China Cyber Science Infrastructure for.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
Athens – integrated AMS services Ed Zedlewski JISC/CNI Conference Edinburgh, June 2002.
1 UPKI-Federation based on Shibboleth National Institute of Informatics Motonori Nakamura Toshiyuki Kataoka, Kyoto University Yasuo Okabe.
Next Steps: becoming users of the NGS Mike Mineter
National Computational Science National Center for Supercomputing Applications National Computational Science GSI Online Credential Retrieval Requirements.
Kento Aida, Tokyo Institute of Technology Grid Working Group Aug. 29 th, 2003 Tokyo Institute of Technology Kento Aida.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Welcome to the Grid Middleware Workshop ☆ Joint workshop of Grid WG and Middleware WG Middleware Working Group at a glance 20 th APAN (Taipei, Aug. 2005)
KEK GRID CA updates Takashi Sasaki Computing Research Center KEK.
UPKI Activities - July NII & UPKI Initiative Hideaki Sone, Tohoku University.
National Institute of Advanced Industrial Science and Technology GGF12 Workshop on Operational Security for the Grid Cross-site authentication and access.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
The Roadmap of NAREGI Security Services Masataka Kanamori NAREGI WP
APGridPMA Update Eric Yen APGridPMA August, 2014.
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
1 US Higher Education Root CA (USHER) Update Fed/Ed Meeting December 14, 2005 Jim Jokl University of Virginia.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
New open source CA development as Grid research platform.
Module Overview Installing and Configuring a Network Policy Server
Guidelines for auditing Grid CAs
NAREGI-CA Development of NAREGI-CA NAREGI-CA Software CP/CPS Audit
Organized by governmental sector (National Institute of information )
GGUS Partnership between FZK and ASCC
Goals Introduce the Windows Server 2003 family of operating systems
Public Key Infrastructure from the Most Trusted Name in e-Security
Jan. 24th, 2003 Kento Aida (TITECH) Sissades Tongsima (NECTEC)
Presentation transcript:

2015/6/21 UPKI project update Yasuo Okabe Academic Center for Computing and Media Studies Kyoto University

2015/6/22 UPKI ― Inter-University Authentication and Authorization Platform for CSI  Conducted by NII and the information infrastructure centers in 7 universities Supported by Ministry of Education, Science and Technology Campus AAI UPKI common specification UPKI A 大アクセスポイント B 大の教授 B 大職員 A 大学 B 大学 C 大学 C 大電子コンテンツ B 大アクセスポイント Wireles LAN roaming C 大事務システム

NII International Workshop on Cyber Science Infrastructure 3 UPKI: concept  Targets various applications SSO of Web services Digital Signature/Encryption by S/MIME Network Services wireless LAN roaming and VPN Grid computing  Utilization of PKI “U” stands University/Universal/Ubiquitous Deployment of Grid/PKI middleware for national academic AA infrastructure

2015/6/24 Planned Schedule of UPKI Developing, deploying and fostering new applications UPKI common Specification Applications UPKI Initiative 2006 FY 2007 FY 2008 FY founded ・ Gathering common interests and opinions, and feedback, ・ Interoperability check, knowledge transfer, publicity, tutorial works, … Campus PKI specification Model design Outsource model Campus PKI CP/CPS template Outsource model 2009 FY and later CA software Development of CA software package Distribution and support for deployment of CA software package Insource model, multi-university cooperative model Wireless LAN roaming Single Sign On to Web Services S/MIME ・ Deployment of campus PKI at each university ・ Connecting universities ・ Federation of applications etc.

2015/6/25 Ongoing Subprojects  Designing Common CP/CPS, Profiles, …  Development and Deployment of “NAREGI-CA” Certificate Authority Middleware  PKI based Applications InterUniversity Web SSO SAML2.0/Shibboleth + PKI Wireless LAN Roaming 802.1X, EduRoam compatible ( VPN Secure Service via S/MIME Supercomputing Grid etc.

2015/6/26 UPKI three layer Architecture Shibboleth/SAML

2015/6/27 Subprojects by NII  UPKI common CP/CPS 【 WP1 】  Public server certificate 【 WP2 】  Inter-University W-LAN roaming 【 WP3 】  SSO for Digital Library Service by NII and other universities via Shibboleth/SAML 【 WP4 】  Development of CA middleware 【 WP5 】  Deployment of S/MIME signature/encryption architecture 【 WP6 】

2015/6/28 Operation Models of CA Insource Univ RA IA Univ. provider Full outsource RA IA IA outsource Univ provider IA RA CP/CPS

2015/6/29 NAREGI National Research Grid Initiative   collaboration projects among industry, academic sector and the government.

2015/6/210 NAREGI Grid Middleware stack

2015/6/211 Nationwide Academic Grid Networks over SuperSINET (experimental) AIST (Tsukuba) Kyushu I. Tech. NAREGI Grid network Kyushu U. I. Molecular Sci. (Okazaki) Tokyo I. Tech. Osaka U. NII NAREGI core NAREGI NII Cluster NAREGI IMS Cluster Doshisha SD 8-center Grid Computing WG network Hokkaido U. Tohoku U. U. Tokyo Nagoya U. Doshisha U. Kyoto U. Kyushu U.

2015/6/212 NAREGI Certification Service CA Software (NAREGI-CA) Policy Management Management(NAREGI-PMA) Operation (NII GOC CA) - CP/CPS -Satisfy APGrid minimum requirement minimum requirement - CA/RA - UI (Character, Web) - Operation of CA - Authorized by the APGrid PMA Production Level CA PMA Production Level CA

2015/6/213 NAREGI-CA  A full-fledged CA (Certificate Authority) Software for PKI  Originally developed for Grid computing, but can be used for general purpose  Free open source software Ver2.0 (May ) Ver2.0 (May ) is available at  Research collaboration Audit of CA :AIST, JapanAudit of CA :AIST, Japan PMA for international cooperation : APGRIDPMA for international cooperation : APGRID  User Sites NAREGI, AIST, Several UniversitiesNAREGI, AIST, Several Universities

2015/6/214 Comparison among CA softwares Product nameIssue of Certif. CRL periodi cal LDAPHSMMultip le CA Profile manage ment HW token Operat or Loggi ng NAREGI CA file, bulk, WEB, LCMP ○○○○○○○○ OpenSSL file ×××○×××× Microsoft Certificate Server WEB, LDAP ○ △ (Active Directory only) △ (Domain Controll er onlu) × △ (Domain Controller only) ○× △ (Event logging) Entrust Authority CMP, bulk, LDAP,WEB, SCEP ○○○×○○○○ ○ : available 、 × : not available 、△: some restriction

2015/6/215  License ID management Transfer authentication responsibility to Local RA  Grid operation extensions Assistance of Grid-mapfile creation  Dual interfaces for certificate request Web & command line enrollment  CA/RA architecture Independent Registration Authority (RA) Server Practical CP/CPS Template NAREGI-CA Software Features

2015/6/216 NAREGI-CA Architecture RA (Registration Authority) CA (Certificate Authority) Local RA (Site Administrator) End User &Host Administrator Site Administrator ① Get License ID ② Authorize to pass License ID ④ Pass License ID & Public Key ⑦ Get Certificate ⑤ Send CSR ⑥ Issue Certificate ③ Generate a Key Pair ⑧ Get Grid Map file

2015/6/217 CA Administrator CARA RA Administrator IC Card Enhanced procedure to issue certificate User CA Administrator RA Administrator RA Operator User License ID Identify Issue Certificate RACA Apply License ID Identify Authorize Issue Certificate Application Server (web) Management Server (web) Delegate Challenge PIN License ID

2015/6/218 CampusCA Issue Certificate Campus PKI Grid PKI NAREGI CA Super Computer Grid System Super Computer Issue Certificate Request Certificate (Use IC Card as credential) LDAP NAREGI RA IC Card Certificate for Grid System Access User Campus-Grid PKI Federation

2015/6/219 UPKI Initiative  Founded in 16 Aug 2006  Sponsored by NII AAI TWG  Mission Gathering interests and opinions of not only universities but also industries  AAI TWG UPKI Initiative Univ Tech. College J. College Common specification join Research Institute Hokkaido UTohoku UU. TokyoNagoya U Kyoto UOsaka UKyushu U KEKTokyo Tech NII NII CSI Headquarter Opinions and comments etc.

NII International Workshop on Cyber Science Infrastructure 20 Summary  UPKI national academic authentication and authorization infrastructure project has started. Conducted by NII and the information infrastructure centers in the 7 universities As a basic platform of Cyber Science Infrastructure  We have started later, so we have get some advantages  International federation/collaboration is a very important issue.

2015/6/221 APAN Middleware Working Group APAN (Asia-Pacific Advanced Networking)  20 th APAN (Taipei, Aug. 2005) National Authentication and Authorization Infrastructure and NREN (proposed session)  21 st APAN (Tokyo, Jan. 2006) Middleware Workshop (full day) Middleware Working Group is approved for a period of two years  22 nd APAN (Singapore, today) Grid Middleware Workshop  23 rd APAN (Manila, Jan. 2007) Grid Middleware Workshop  24 th APAN (Xian, Aug. 2007) Middleware Workshop