Public Key Directory: What is the PKD and How to Make Best Use of It



Similar documents
Introduction ICAO PKD

Deputy Chief Executive Netrust Pte Ltd

PKD Board ICAO PKD unclassified B-Tec/37. Procedures for the ICAO Public Key Directory

Electronic machine-readable travel documents (emrtds) The importance of digital certificates

PKD Board ICAO PKD unclassified B-Tec/36. Regulations for the ICAO Public Key Directory

Case Studies. National Identity Management Commission (NIMC), Nigeria eid Consulting for national ID system

Establishing and Managing the Schengen Masterlist of CSCAs

Security by Politics - Why it will never work. Lukas Grunwald DN-Systems GmbH Germany DefCon 15 Las Vegas USA

Sub- Regional Workshop and Consulta;ons on Capacity- Building in Travel Document Security: Colombia, 2013

Operational and Technical security of Electronic Passports

Implementation of biometrics, issues to be solved

MACHINE READABLE TRAVEL DOCUMENTS

Best Solutions for Biometrics and eid

COMMON CERTIFICATE POLICY FOR THE EXTENDED ACCESS CONTROL INFRASTRUCTURE FOR PASSPORTS AND TRAVEL DOCUMENTS ISSUED BY EU MEMBER STATES

International Civil Aviation Organization ASSEMBLY 38TH SESSION EXECUTIVE COMMITTEE

FAQs Electronic residence permit

Preventing fraud in epassports and eids

Biometrics for Public Sector Applications

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke

PRIME IDENTITY MANAGEMENT CORE

Concept of Electronic Approvals

SSLPost Electronic Document Signing


Progress by Partnership. State Wide E-Procurement Implementation

Common Criteria Protection Profile for Inspection Systems (IS) BSI-CC-PP Version 1.01 (15 th April 2010)

Veridos Protects Identities. The expert for worldwide government solutions

Certificate Policies and Certification Practice Statements

MACHINE READABLE TRAVEL DOCUMENTS

Mobile Driver s License Solution

Electronic Signatures: A New Opportunity for Growth. May 10, 2005

White Paper. Cloud Signing vs. Smartcard Signing

Brocade Engineering. PKI Tutorial. Jim Kleinsteiber. February 6, Page 1

sign-me Bundesdruckerei's solution for online signatures using the new German ID card

TeleTrusT European Bridge CA Status and Outlook

CS 356 Lecture 28 Internet Authentication. Spring 2013

esign FAQ 1. What is the online esign Electronic Signature Service? 2. Where the esign Online Electronic Signature Service can be used?

Combatting Counterfeit Identities: The Power of Pairing Physical & Digital IDs

The Costs of Managed PKI:

Certificate Management. PAN-OS Administrator s Guide. Version 7.0

Guide to Using DoD PKI Certificates in Outlook

fulfils all requirements defined in the technical specification The appendix to the certificate is part of the certificate and consists of 6 pages.

ELECTRONIC SIGNATURES AND ASSOCIATED LEGISLATION

ICP BRASIL The Brazilian PKI

Best Practices for the Use of RF-Enabled Technology in Identity Management. January Developed by: Smart Card Alliance Identity Council

Certification Practice Statement

E-Visas Verification Schemes Based on Public-Key Infrastructure and Identity Based Encryption

Technical Guideline eid-server. Part 2: Security Framework

Modular biometric architecture with secunet biomiddle

Course Outline: 6436 _ Designing a Windows Server 2008 Active Directory Infrastructure and Services Learning Method: Instructor-led Classroom Learning

Merchants and Trade - Act No 28/2001 on electronic signatures

Understanding Digital Signature And Public Key Infrastructure

MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE

TeleTrusT IT Security Association Germany. TeleTrusT IT Security Association Germany. Overview

FAQs - New German ID Card. General

GNB RSA Token Standards and Procedures

TELSTRA RSS CA Subscriber Agreement (SA)

I N F O R M A T I O N S E C U R I T Y

Card Management System Integration Made Easy: Tools for Enrollment and Management of Certificates. September 2006

Designing a Windows Server 2008 Active Directory Infrastructure and Services

THE LEADING EDGE OF BORDER SECURITY

Common Criteria Protection Profile

Certificate Policy for. SSL Client & S/MIME Certificates

TPM Key Backup and Recovery. For Trusted Platforms

Electronic Document Imaging Solution for Births, Marriages & Death Certificates Digitization & Issuance Colombo, Sri Lanka

6436: Designing a Windows Server 2008 Active Directory Infrastructure and Services (5 Days)

EPASSPORT WITH BASIC ACCESS CONTROL AND ACTIVE AUTHENTICATION

DNSSEC - Tanzania

Securing the Service Desk in the Cloud

Facts about the new identity card

A B U N D E S D R U C K E R E I P O C K E T G U I D E T O B O R D E R C O N T R O L

Land Registry. Version /09/2009. Certificate Policy

Compliance Response Edition 07/2009. SIMATIC WinCC V7.0 Compliance Response Electronic Records / Electronic Signatures. simatic wincc DOKUMENTATION

FIVE-MINUTES-TO-CONTRACT The DESKO over-all concept for digital contract management and ID verification.

e-authentication guidelines for esign- Online Electronic Signature Service

DNSSEC Policy and Practice Statement.amsterdam

Class 3 Registration Authority Charter

Security Digital Certificate Manager

Public Key Infrastructure. A Brief Overview by Tim Sigmon

Statewatch Briefing ID Cards in the EU: Current state of play

Adobe Digital Publishing Security FAQ

Online Voting Project. New Developments in the Voting System an Consequently Implemented Improvements in the Representation of Legal Principles.

An introduction to EJBCA and SignServer

Counter-Terrorism Global Strategy Civil Aviation Sector ICAO s Contribution. Counter-Terrorism Committee Meeting UN Security Council

Danske Bank Group Certificate Policy

Global eid Developments. Detlef Eckert Chief Security Advisor Microsoft Europe, Middle East, and Africa

ID Security Made in Germany Holistic Solutions for Biometric Systems and Identity Documents

New Attacks against RFID-Systems. Lukas Grunwald DN-Systems GmbH Germany

I N F O R M A T I O N S E C U R I T Y

Executable Integrity Verification

Meeting the FDA s Requirements for Electronic Records and Electronic Signatures (21 CFR Part 11)

Designing a Windows Server 2008 Active Directory Infrastructure and Services

Certification Practice Statement (ANZ PKI)

Security Services and Solutions. Full security, from planning through implementation to operation.

An identity management solution. TELUS AD Sync

Information Security Basic Concepts

Lot 4 Specialist Cloud Service Questmark Ltd. Video Conferencing Small Meeting Room Service

Breeder documents closing the gap in the identity management chain. Christian Wagner VP SDM Government Washington, March 23, 2015

POSITION PAPER. The Application of Biometrics at Airports PUBLISHED BY ACI WORLD HEADQUARTERS GENEVA SWITZERLAND

Citizen s Charter (Services of the Embassy)

Control and management of privileged users

Transcription:

Public Key Directory: What is the PKD and How to Make Best Use of It Christiane DerMarkar ICAO Programme Officer Public Key Directory ICAO TRIP: Building Trust in Travel Document Security 19/10/2015 Footer 1

PKD and TRIP Strategy For the efficient and secure reading and verification of MRTDs, including the use of PKD 2

MRP Connection between PKD and epassports epassport 0111001001010 Machine Readable Passport (MRP) CHIP RFID 14443 IMAGE FACE Logical Data Structure (LDS) PKI DIGITAL SIGNATURE Public Key Directory (PKD) 3

What is the PKD & What does it do? A central storage location, highly secure where States and other entities can input and retrieve the security information to validate the electronic information on the passport. It allows Border control authorities to confirm that the epassport: Was issued by the right authority Has not been altered Is not a copy or cloned document 4

The Role of The PKD Minimizing the volume of certificate exchange: Document Signer Certificates (DSCs) Certificate Revocation Lists (CRLs) Country Signing Certificate Authority (CSCA) Master List Ensuring timely uploads Managing adherence to technical standards Facilitating the validation process 5

Central Broker Distribution of Certificates and CRLs via bilateral Exchange via ICAO PKD Conformity validated certificates Country A Country B Country A Country B Country H Country C Country H ICAO PKD Country C Country G Country D Country G Country D Country F Country E Country F Country E This example shows 8 States/non-States requiring 56 bilateral exchanges (left ) or 2 exchanges with the PKD (right) to be up to date with DSCs and CRLs. In case of 191 ICAO States 36,290 bilateral exchanges would be necessary while there are still 2 exchanges with the PKD. This example shows 8 states requiring 56 bilateral exchanges (left) or 2 exchanges with the PKD (right) to be up to date with certificates and CRLs. In case of 188 ICAO States 35,156 bilateral exchanges would be necessary while there are still 2 exchanges necessary with the PKD. 6

Current Services of the PKD Validated DSCs and CRLs of Participants CSCA Master List List of CSCAs used by Participants Country Signing Certificate Authority (CSCA) Registry Yellow Pages for the Passport Issuance Agency of the Participant A reference for compliance to Doc 9303 for DSCs and CRLs Contains lists on non-compliant certificates 7

8 46 Participants New Participant COLOMBIA

ANNEX 9: Recommended Practice 3.9.1 & 3.9.2 The Standards and Recommended Practice of Annex 9 recommend the following: 3.9.1: Contracting States issuing, or intending to issue emrtds should join the ICAO Public Key Directory (PKD) and upload their information to the PKD. 3.9.2: Contracting States implementing checks on emrtds at border controls should join the ICAO Public Key Directory (PKD) and use the information available from the PKD to validate emrtds at border controls. 9

Some Arguments repeated over and over. It s too expensive Bilateral exchange works good enough It s not necessary DSCs are (mostly) on the chip It s too complicated we must first introduce epassports As of 01.01.2016 Fee reduction cumbersome, time consuming and possible security risk A DSC on the epassport but not on the PKD could mean a compromised private signing key. & CRLS are only distributed via PKD 1. Participation in the PKD should go hand in hand with introduction of epassports 2. PKD participation is key for setting up any successful epassport based border control. 10

Reasons to Participate The need to exchange certificates is the logical step forward from the well known specimen exchange (you must know what you're looking for, when inspecting a travel document). Without the ability of validating the digital signature in a epassport at the border, the travel document must be treated exactly as a simple MRP not an epassport Using the PKD in epassport validation is essential to capitalize on the investment made by States in developing epassports to improve Border Security 11

It s not complicated : All you have to do is. Find out who is responsible Check legislation and budget Different organizations in different states (try to make it as simple as possible) Contact ICAO or any PKD Board Member or PKD Participant if you have questions 12

Formalities: The steps to join the PKD 1. Deposit a Notice of Participation with the Secretary General of ICAO 2. Deposit a Notice of Registration with the Secretary General of ICAO 3. Effect payment of the Registration Fee and Annual Fee to ICAO a) 1.1.2016 Registration Fees : US $ 15,900 b) Annual Fees: +/- US $40,000 4. Securely submit to ICAO and all Participants, the CSCA certificate 5. Use the PKD : upload/download certificates 6. http://www.icao.int/security/mrtd/pages/pkd-howtopartici.aspx 13

2016 a year that will bring changes New Fees New Services New service provider 14

01.01.2016 : Fees reduction A. For new Participants - Registration Fee: US $15,900 B. Annual Fees based on 45 Participants: 1. Operator: US $ 29,900 2. ICAO: US $10,000 3. Total: US $39,900 C. More Participants = reduction in Operators and ICAO Annual Fees 50 Participants 27,000.00 US$ 55 Participants 24,500.00 US$ 60 Participants 22,500.00 US$ 65 Participants 20,900.00 US$ 15

New Service ICAO Global Master List A fact: heir full extend Border Agencies need the tools (certificates) necessary, bilateral exchange doesn t meet the requirements One-Stop Shop For epassport Validation K L I + A M B D H PKD G F E C + CSCA + DSCs + + CRLs CSCA = ICAO Master List (new) = currently in the PKD = currently in the PKD 16

01.01.2016 : New Service Provider Bundesdruckerei - Germany Operations at ICAO HQ Montreal Site BDr Berlin Site MOI UAE, Abu Dhabi 17

Technology and Security ICAO HQ Montreal 1 2 1 2 Site A: D-Trust Berlin (Germany) Fully redundant system at each location Outer Firewall Inner Firewall incl. Intrusion Detection & Prevention System High Security VPN Network 1 2 Disaster Scenario: Geo-redundant, TLS encrypted and load-balanced up- and Even certificate with one download based access site completely d download sites own, additional failures at the remaining s ites the system is still fully functional with Trust Center without service interruption Security Level, Min. 99.8% availability Site B: Abu Dhabi Police (UAE) ICAO PKD October 2015 18

ICAO PKD - how does it work? D S New generation of DS certificates in DS issued passports Access to ICAO PKD Service CSCA Official key ceremony by diplomatic means cryptographic check ICAO PKD D S Access to ICAO PKD Service e.g.national PKD system ICAO PKD October 2015 19 D S Border Control

ICAO PKD - Advantages for participants Unique chain of trust: Supervision by ICAO as supra-national institution Transparent and reliable processes (initial key ceremony at ICAO HQ) High security and high availability of ICAO PKD system, available end of 2015 Additional advantages: A combination with National PKD systems (npkd) allows for secure and automated distribution of certificates to border control stations nation-wide Live support via phone and ticket system ICAO PKD October 2015 20

Support for ICAO PKD by Veridos/BDr Site A: D-Trust, Berlin (Germany) Site B: MoI, Abu Dhabi (UAE) ICAO HQ Montreal Local Technical support downlaod sites Berlin & Abu Dhabi 46 ICAO PKD Participants Local technical support ICAO HQ Montreal Monthly reports on system usage and performance for ICAO Participant support - Live Phone support - Online Support System - 2h reaction time (Monday- Friday) High Security High Availability min. 99.8% 24/7 ICAO PKD October 2015 21

Schedule & Transition to new ICAO PKD Pilot Testing (AUS, Sweden, UK) Beg. August 2015 Testing period Test Environment New PKD system Bundesdruckerei Current Structure Switch-Over Date Beg. Dec 2015 PKD Pre-Production System Bundesdruckerei (new structure) Current Structure All participants can perform Implementation migration and tests Testing for of 4 month Implementation prior to the and switch-over Testing of day New Structure New Structure The test environment provides identical interface and functions as the production system Testing Current Structure PKD Production System Bundesdruckerei (new structure) Current Structure Step 1: Testing and migration to current structure guarantee business continuity on switch-over day Step 2: Testing and migration to new structure gain more time even until after the switch-over day ICAO PKD October 2015 22

Project Setup involved companies ICAO Customer and ICAO PKD system principal Bundesdruckerei Prime Contractor Bundesdruckerei GmbH D-Trust Abu Dhabi Police GHQ EGSP Veridos IT operations ICAP PKD Housing the ICAO PKD System Site Berlin Local service Berlin Housing the ICAO PKD System - Site Abu Dhabi Local service Abu Dhabi Service Management ICAP PKD System Local service Montreal ICAO PKD October 2015 23

Contact Details Name: Christiane DerMarkar Email: cdermarkar@icao.int PKD website: http://www.icao.int/security/mrtd/pages/icaopkd.aspx 19/10/2015 24