80 likes | 169 Views
Which PKI Approach for Which Application Domain?. 3 rd Annual PKI R&D Workshop. Russel F Weiser. April 2004. Other Industries. Health Care. Secure Messaging. Authentication. X.509. Document Signing. Secure Transports. Govt. Financial. Which PKI? -- X.509 A Perspective.
E N D
Which PKI Approach for Which Application Domain? 3rd Annual PKI R&D Workshop Russel F Weiser April 2004
Other Industries Health Care Secure Messaging Authentication X.509 Document Signing Secure Transports Govt Financial Which PKI? -- X.509 A Perspective Which Applications? • Document Signing • Authentication • Secure Messaging • Secure Transports What Industries or Trust Domains? • Government • Health Care • Financial • Others
Application Govt. Health Care Financial Other Industries Document Signing Low Value X High Value X X X X Complex (Workflow) X X X X Document Signing –X.509 • Low Risk documents - Time Cards / Standard Reports • High Risk documents – Contracts / Financial Transactions • Complex documents - HR Performance Reviews • Document Management – Work Flow / Document Control Spans all of Industry Domains Example – Access to patient record information for research including “Patient Release Authorization”
Application Govt. Health Care Financial Other Industries Secure Messaging Email X X X X Instant Messaging (IM) X X X Secure Messaging – X.509 • S/MIME • Instant Messaging – IMing Email touches all Industry Domains, Instant Messaging is getting there? Example – The Financial Industry in particular is leveraging “Secure IM” across multiple enterprises.
Application Govt. Health Care Financial Other Industries Authentication Network authentication X X X X Authentication – X.509 • Network Authentication – Signal Sign On etc Spans all of the industry domains Examples - Authenticating to corporate and partner networks is and obvious area where trust is across the enterprises. Note – Several areas that would certainly benefit from any of the PKI solutions • Online Banking Access • Retirement Management Access • Brokerage Accounts
Application Govt. Health Care Financial Other Industries Transport Security Web Server Security X X X X Virtual Private Network X X X X EDI X X X X Transport Security – X.509 • Web server Security - SSL/ TLS • VPNs and IPSEC • Secured EDI - Over HTTPS or SFTP Spans all of the Industry Domains Example – Secure transfer of medical information via HTTPS based EDI.
Contact Information Russel F Weiser Betrusted US Inc. Managing Consultant Rweiser@betrusted.com Office 801-942-6480 Cell 801-631-1685