100 likes | 274 Views
Identity Management Spacecraft ID Security CCSDS Security WG Fall 2005 Atlanta, GA USA. Howard Weiss NASA/JPL/SPARTA hsw@sparta.com +1-410-872-1515 September 2005. Agenda. 14 September 2005
E N D
Identity ManagementSpacecraft ID SecurityCCSDS Security WG Fall 2005 Atlanta, GA USA Howard Weiss NASA/JPL/SPARTA hsw@sparta.com +1-410-872-1515 September 2005
Agenda • 14 September 2005 • 0900-0915: Welcome, opening remarks, logistics, agenda bashing, 0915-0930: Review results of Spring 2005 SecWG meeting in Athens Mtg Notes • 0930-1000: RASDS Review wrt Security Architecture (Kenny) • 1000-1030: coffee break • 1030-1200: Security Architecture Document Discussions (Kenny) • 1200-1330: Lunch • 1330-1400:Review CNES Mission Security Req Development using EDIOS (Pechmalbec/Belbus) • 1400-1500: Encryption Algorithm Trade Study (Weiss) • 1500-1530: coffee break • 1530-1700: Authentication/Integrity Algorithm Trade Study (Weiss) • 15 September 2005 • 0900-1000: Key management discussion (Kenny) • 1000-1030: Coffee break • 1030-1100: Identity Management, Spacecraft IDs (Weiss) • 1100-1130: CNES Interconnection Rules (Pechmalbec/Belbus) • 1130-1300: Lunch • 1300-1400: CNES Security Development Process (Pechmalbec/Belbus) • 1400-1500: Security Policy Document/Common Criteria (Weiss)
Discussion Topics • Identity management • Who, what, where, when, how? • Spacecraft ID security • Publicly available on SANA web site? • Other info (e.g., ground site locations, etc) • Security issue or not?
Background Discussions • Identity management • User IDs • Passwords • Public keys/certificates • Role-based access controls (?)
Identity Management • Who should be concerned about this? • Security WG? • Information Architecture WG? • Other? • If SecWG should be concerned about this: • What should be done? • Who should do it? • Is this a SANA job to manage and control? • Based on SecWG guidance and policy?
Identity Management • Discussion/Conclusions • …..
Spacecraft IDs • Spacecraft IDS are currently available for viewing on the CCSDS web page • 10-bit ID field viewable at www.ccsds.org • Space Assigned Numbering Authority (SANA) is in a formulation stage • Analogous to the IETF’s Internet Assigned Numbering Authority (IANA). • SANA web site to contain all sorts of space mission numbering assignments • Question: should spacecraft IDs be visible?
Spacecraft IDs • Security Issue – • Visible spacecraft IDs? • Or not a security issue? • Do we rely on spacecraft IDs to be kept secret? • Should we? Why? • What is the threat if a spacecraft ID is well known? • Should we be basing any security/protection on a spacecraft ID? • Analogous to basing security on the knowledge of an IP address. • What about other publicly available information • Ground site locations? • Totality of other publicly available information?
Spacecraft IDs • Discussion/Conclusions: • ……..