310 likes | 578 Views
Technical Track Session. E-Authentication Overview & Technical Approach. Scott Lowery. E-Authentication – Technical Approach. Agenda E-Authentication Overview Policy Framework Technical Approach Interoperability Lab. Policy Infrastructure:.
E N D
Technical Track Session E-Authentication Overview & Technical Approach Scott Lowery
E-Authentication – Technical Approach Agenda • E-Authentication Overview • Policy Framework • Technical Approach • Interoperability Lab
Policy Infrastructure: 2. Establish standard methodology for e-Authentication risk assessment (ERA) 1. Establish e-Authentication risk and assurance levels for Governmentwide use (OMB M-04-04 Federal Policy Notice 12/16/03) 3. Establish technical assurance standards for e-credentials and credential providers (NIST Special Pub 800-63 Authentication Technical Guidance) 4. Establish methodology for evaluating credentials/providers on assurance criteria (Credential Assessment Framework) 6. Establish common business rules for use of trusted 3rd-party credentials 5. Establish trust list of trusted credential providers for govt-wide (and private sector) use
E-Authentication – Technical Approach • Agenda • E-Authentication Overview • Technical Approach • Assertion Based Authentication • Certificate Based Authentication • Interoperability Lab
E-Authentication – Technical Approach • Agenda • E-Authentication Overview • Technical Approach • Assertion Based Authentication • Overview • Management • SAML (Security Assertion Markup Language)as an Adopted Scheme • Certificate Based Authentication • Interoperability Lab
AAs CSs Base Case
Step #3: After Selecting their AA the user is redirected back to the CS as usual CSP ID Startingat the CS
Step #2: The user is Redirected to the portal With the CS and AA IDs Step #3: The user is cookied and redirected to the CS SpecializedPortals
E-Authentication – Technical Approach • Agenda • E-Authentication Overview • Technical Approach • Assertion Based Authentication • Overview • Management • SAML as an Adopted Scheme • Certificate Based Authentication • Interoperability Lab
Evaluate new Scheme against requirements Assess COTS Interoperability Start Scheme Adoption Lifecycle Migrate, Translate, or Both. Pilot Adopt EmergingTechnology
Scheme Translator SchemeTranslator
E-Authentication – Technical Approach • Agenda • E-Authentication Overview • Technical Approach • Assertion Based Authentication • Overview • Management • SAML as an Adopted Scheme • Certificate Based Authentication • Interoperability Lab
E-Authentication – Technical Approach • Agenda • E-Authentication Overview • Technical Approach • Assertion Based Authentication • Certificate Based Authentication • Interoperability Lab
Step #1: User goes to Portal to select the AA and the CS ValidationService
Step #1: User goes to Portal to select the AA and the CS LocalValidation
CertificatesAt LowerAssuranceApplications Scheme Translator Step #4: The ST uses the validation service to validate the certificate
E-Authentication – Technical Approach • Agenda • E-Authentication Overview • Technical Approach • Interoperability Lab • Product Testing • Technical Support • CS / AA Testing
AAs CSs • COTS (Commercial Off The Shelf) Product Testing • Scheme compliance • Interoperability
Evaluate new Scheme against requirements Assess COTS Interoperability Start Scheme Adoption Lifecycle Migrate, Translate, or Both. Pilot Adopt • Product Testing • See List of Approved Vendors
COTS Product Testing • Certificate Validation
E-Authentication Architecture Evolution • Architecture Working Group • Evaluating Evolving Standards • Scheme Translators
E-Authentication Interoperability Lab • Technical Support • Interoperability Testing • SAML Conformance Testing • Acceptance Testing • Approved Product List • Cookbook / Recipes • Extensive Experience in All These Areas
E-Authentication – Technical Approach • Agenda • E-Authentication Overview • Technical Approach • Interoperability Lab
Resources • http://www.cio.gov/eauthentication interoplab@enspier.com • Additional Contacts Chris Louden - 703-299-3444 Chris.louden@enspier.com Andrew Chiu - 703-299-3444 Andrew.chiu@enspier.com Steve Lazerowich - 703-299-3444 Steve.lazerowich@enspier.com David Simonetti - 410-356-2260 David.simonetti@enspier.com
Contact Information I appreciate your feedback and comments. I can be reached at: Scott Lowry scott@enspier.com 202-236-8221