Notes
Outline
Technical Approach

Chris Louden
Enspier
Technical Approach
Lower Assurance Approach
Overview
Management
SAML as an adopted Scheme
Higher Assurance Approach
Overview
Certificate Validation
Relationship to Bridge Architecture
Where we are today
Today
Near Term
Slide 3
Slide 4
Slide 5
Slide 6
Slide 7
Slide 8
SAML as an Adopted Scheme
SAML 1.0 Artifact Profile
Proven interoperability
Slide 10
Slide 11
Slide 12
Lower Assurance Approach
SAML Assertion Contents
Name
User ID
CS ID
AA Responsabilities
Authorization / Entitlements
Mapping asserted identity to known identity
May map multiple credentials to a known identity
CS Responsabilities
Identity Management
Credential Assessment Framework (CAF) requirements
Higher Assurance Levels
Certificate Based Authentication
“All sensitive data transfers shall be cryptographically authenticated using keys bound to the authentication process”  NIST SP800-63
Does not require shared secrets
Certificate Path Discovery and Validation
Certificates at lower assurance AAs
Slide 15
Slide 16
Higher Assurance Approach
Certificate Validation is not enough
Certificate Path Discovery and Validation
One Minute PKI
Public & Private Key Pair
Mathematically bound numbers
Encrypt with one,  Decrypt with the other
Digital Signatures
Hashes encrypted with a private key
Validate source and integrity
Certificate Authorities (CAs) and Certificates
Certificates bind a public key to an identity
CAs issue certificates based on their policies
Certificates are digitally signed by CAs
Trust Anchors
A CAs self-signed certificate
Typical PKI
Hierarchical PKI
Mesh PKI
Mesh PKI
Slide 23
Slide 24
Higher Assurance Approach
Certificate Usability at lower assurance AAs
Avoid multiple interfaces at AAs
Avoid PKI complexities at lower assurance AAs
Slide 26
High Assurance Approach
Relation to Federal PKI Architecture
Slide 28
Slide 29
Slide 30
Slide 31
Slide 32
Where we are today
Proof of Concept
SAML 1.0 Artifact Profile
Interoperability Lab
Architecture Working Group
Pilots
References
eAuthentication Documents
http://www.cio.gov/eauthentication
NIST Documents
http://csrc.nist.gov/pki/testing/x509paths.html
http://csrc.nist.gov/publications/drafts.html
Coming Soon
FOC
Forms
Web Services
Composite Apps
New Schemes