+ All Categories
Home > Documents > Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February...

Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February...

Date post: 22-Jan-2016
Category:
Upload: ethan-hensley
View: 217 times
Download: 0 times
Share this document with a friend
Popular Tags:
39
Using Levels of Using Levels of Assurance Assurance Renee Shuey Renee Shuey nmi-edit CAMP: Charting Your nmi-edit CAMP: Charting Your Authentication Roadmap Authentication Roadmap February 8, 2007 February 8, 2007
Transcript
Page 1: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Using Levels of Using Levels of AssuranceAssurance

Renee ShueyRenee Shueynmi-edit CAMP: Charting Your nmi-edit CAMP: Charting Your

Authentication RoadmapAuthentication RoadmapFebruary 8, 2007February 8, 2007

Page 2: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

AgendaAgenda

DisclaimerDisclaimer About Penn StateAbout Penn State Level Set on Levels of AssuranceLevel Set on Levels of Assurance

– Delivering of the packageDelivering of the package Uses for LOA Uses for LOA

– Both Internal and External to the Both Internal and External to the universityuniversity

Points to PonderPoints to Ponder Discussion, Q&ADiscussion, Q&A

Page 3: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Penn StatePenn State

Page 4: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Penn StatePenn State

Established 1855, Established 1855, PA’s Land GrantPA’s Land Grant

24 campus 24 campus locationslocations

80K students, 10K 80K students, 10K faculty, 10K stafffaculty, 10K staff

$640M annual $640M annual research research expenditureexpenditure

Page 5: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Penn State IAM - TechnologyPenn State IAM - Technology Kerberos, DCE, Active Kerberos, DCE, Active

DirectoryDirectory

LDAP (eduPerson)LDAP (eduPerson)

Cosign (WebAccess)Cosign (WebAccess)

ShibbolethShibboleth

Member of InCommonMember of InCommon

22ndnd Factor Factor AuthenticationAuthentication

““Access Account” - Access Account” - branding for Penn branding for Penn State identity ~120KState identity ~120K

““Short Term Access Short Term Access Accounts” Accounts”

““Friends of Penn Friends of Penn State” - branding for State” - branding for external identity, external identity, ~450K~450K

Page 6: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Level Set - Delivering Level Set - Delivering of the Package….of the Package….

Page 7: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

It’s all about how It’s all about how certain you are…certain you are…

Page 8: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

And how Certain you And how Certain you need to be…need to be…

Page 9: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Scenario 1…

deleted image of favorite web site here…

Page 10: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

deleted photo of well known delivery vehicle.

Page 11: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

deleted photo of individual from well known delivery service

Page 12: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

deleted image of nicely wrapped gift here….

Page 13: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Scenario 2…

deleted image of favorite website

Page 14: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.
Page 15: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.
Page 16: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.
Page 17: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.
Page 18: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Risk

Identity Proofing

Logical & Physical Control

Indemnification

Liability

Laws & Regulations

Data

Intellectual Property

Transaction

Identifying and Mitigating Risk

Page 19: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Uses for Uses for Levels of AssuranceLevels of Assurance

Page 20: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.
Page 21: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

eCommerce ComplianceeCommerce Compliance

Payment Card Industry Questionnaire Payment Card Industry Questionnaire 8.118.11– Is there an account-lockout mechanism Is there an account-lockout mechanism

that blocks a malicious user from that blocks a malicious user from obtaining access to an account by obtaining access to an account by multiple password retries or brute force? multiple password retries or brute force? Yes No Yes No

Card Industry following bank industry Card Industry following bank industry requirement for 2requirement for 2ndnd Factor Factor AuthenticationAuthentication

Page 22: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Business Transactions

Electronic Signatures

Promissory Notes

Page 23: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

W-2 Information OnlineW-2 Information Online

Page 24: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

“THE” Demo

(at least the boss’s part)

Internet2 FastLane Demo

Page 25: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Points to PonderPoints to PonderDecreasing of LOADecreasing of LOAPassword ResetsPassword Resets

Page 26: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

In Person Proofing

Page 27: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

It’s a big, big worldNot all university affiliates are located on the campus

In fact, there are some we never see

Page 28: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Remote ProofingNotary

Forms of Id

Page 29: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Self Service - Ask Self Service - Ask Questions?Questions?

? ??

?

?

? ?? ?

Mother’s Maiden Name

Favorite Color

Favorite Pet’s Name

Create own Q & ASpouse’s Nickname

First Concert Attended

Page 30: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

www.londonstimes.us

DistributionAt times snail mail is still preferred and more trusted…

Page 31: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Points to PonderPoints to PonderMultiple Registration Multiple Registration

AuthoritiesAuthorities

Page 32: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Multiple Registration Authorities World Campus

Registrar

Admissions

Human Resources

Accounts Office

Hershey Medical

Page 33: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Multiple Registration Multiple Registration AuthoritiesAuthorities

Registration Authority’s need to change Registration Authority’s need to change their requirements to meet identity their requirements to meet identity provider requirements.provider requirements.

Understand processes tied to business Understand processes tied to business such as the activation of accounts, such as the activation of accounts, resetting of passwords, etcresetting of passwords, etc

Applications relying on these processes Applications relying on these processes – Applications need to changeApplications need to change– Processes for proofing, notification, etc all need Processes for proofing, notification, etc all need

to be changedto be changed– Activation of accounts and resetting of Activation of accounts and resetting of

passwords needs to changepasswords needs to change

Page 34: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Multiple Registration Multiple Registration Authorities Multi-factor Authorities Multi-factor

AuthenticationAuthentication multi-factor remote network

authentication. identity proofing procedures require

verification of identifying materials and information.

based on proof of possession of a key or a one-time password through a cryptographic protocol.

Page 35: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Points to PonderPoints to PonderChanging the CultureChanging the Culture

Page 36: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Changing the CultureChanging the Culture

Identifying & Adding new applications Identifying & Adding new applications and servicesand services

Risk AssessmentRisk Assessment– OwnershipOwnership– Data, Transaction, FunctionData, Transaction, Function

Access control = authentication + LoA Access control = authentication + LoA + attributes+ attributes

Page 37: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

To Summarize:

It’s All about how certain you are…

And How Certain you need to be…

Page 38: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Questions/CommentsQuestions/Comments

Contact InformationContact Information

Renee ShueyRenee Shuey

ITS Emerging Technologies GroupITS Emerging Technologies Group

Pennsylvania State UniversityPennsylvania State University

[email protected]@PSU.EDU

Page 39: Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.

Copyright Renee Shuey 2007. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.


Recommended