170 likes | 365 Views
Security WG: Report of the Fall 2008 Meeting. DIN, Berlin Germany October 17, 2008 Howard Weiss NASA/JPL/SPARTA hsw@sparta.com +1-443-430-8089. Meeting Agenda. 13 October 2008 08:00 – 09:00 : CCSDS Plenary 09:00 – 12:00 : Systems Engineering Area (SEA) Plenary
E N D
Security WG:Report of the Fall 2008 Meeting DIN, Berlin Germany October 17, 2008 Howard Weiss NASA/JPL/SPARTA hsw@sparta.com +1-443-430-8089
Meeting Agenda • 13 October 2008 • 08:00 – 09:00: CCSDS Plenary • 09:00 – 12:00: Systems Engineering Area (SEA) Plenary • 14 October 2008 (09:00 – 12:00) • Space Data Link Layer Security BOF • 15 October 2008 (09:00 – 17:00) • Welcome, opening remarks, logistics, agenda bashing, introduction for new attendees + Review of document progress and results of Spring 2008 meeting • Document Status (encryption, authentication, key management, mission planners) • “Big Picture” discussions (Black) • 1200-1300: Lunch • Security Architecture Document Discussions (Black) • Mission Planner’s Guide (Biggerstaff) • 16 October 2008 (09:00 – 17:00) • Key Management (Fischer) • Application Layer Security (Pajevski/Weiss) • 1200-1300: Lunch • Other discussions (from last meeting): • “Color” of books (magenta vs. blue) • Encryption & authentication application-specific parameters • Common Criteria for mission security profiles (knit docs together) • Agency security implementations (approach, requirements, security services) • Meeting with DTN BOF (tentative) • 17 October 2008 • 1300-1700: SEA Wrap-up Plenary
Executive Summary • Attendees from BNSC, ESA/ESOC, ESA/ESRIN, ESA/ESTEC, DLR, ASI, CAST, NASA/GSFC, NASA/JSC, NASA/MSFC, and NASA/JPL. CNES did not attend (a baby is due). • NASA and ESA participation from multiple, respective Agency centers continues to be the norm. • Joint meeting held with Space Link to begin a BOF for Space Link Layer Security Standardization • Reviewed the comments on the latest revision of the SecWG Security Architecture. With respect to the ongoing work in the SLS-BOF, we will add link layer security to the architecture core. • Encryption document out for pre-review review. • Authentication document completed w/security section and submitted to secretariat. • Discussed application layer security. • Discussed color of books. • Reviewed key management green and magenta books. • Reviewed mission planners guide. • Discussed the use of Common Criteria to create “space” Protection Profiles again • Discussed future work areas.
Summary of Goals and Deliverables • Discussion on the “big picture” of what the SecWG is doing and plans to do. • Security Architecture document will be revised based: new link layer security column will be added to the “core” combinatorics table. • Continue making good progress on Key Management green book. Stuck on KM magenta book pending information on current KM schemes used by the Agencies. • Excellent progress continues on Mission Planners Guide. • Good discussion on application layer security and what could be used to provide “security shims” including the potential application of security integrated into messaging frameworks (e.g., AMS, SM&C). • Still mixed opinions on the use of the Common Criteria to write unambiguous security documents using an ISO standard language and format. Backburner pending some demonstration of its use. • Continue to work with other Areas and their WGs with respect to security. • Joint mtg w/SLS to create space link layer security BOF • Joint mtg DTN-BOF
SEA Area MID-TERM REPORT SUMMARY TECHNICAL STATUS • Security WG • Goal: • Working Status: Active _X_ Idle ____ • Summary progress: Four documents actively being produced (Security Architecture, Key Management (2), Mission Planners Guide). All docs green. • Progress since last meeting: Authentication doc completed. Positive movement on Security Architecture doc, mission planners guide and KM. Link layer sec proposal • Problems and Issues: Resources – Excellent right now but need to ensure continued participation from all member agencies
Open Issues • None
Resource Problems • Resources appear to be adequate to perform the current tasks. • Resources are increasing: • ESA has provided additional resources • NASA has provided additional resources • We keep seeing and getting more interest
Risk Management Update • Must ensure that the current trend of additional resources remains and that resources don’t shrink.
Cross Area WG / BOF Issues • Joint meeting with SLS to create a new dual-area BOF • NASA (JSC, JPL, GSFC) proposal for link layer protocol • Joint meeting with DTN
Resolutions to be Sent to CESG and Then to CMC • Resolution from link layer security BOF to charter as WG (from Gilles Moury)
New Working Items, New BOFs, etc. • Common Criteria Protection Profiles (backburner) • Joint SLS/SEC Space Link Security BOF -> WG