e-PASTA - A Kung
-
Upload
mfrancis -
Category
Technology
-
view
44 -
download
0
Transcript of e-PASTA - A Kung
![Page 1: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/1.jpg)
OSGI World Congress - 26 September 2002 page 1
e-PASTAe-Protection of Appliances through Secure and Trusted Access
Antonio Kung - TrialogMario Cipriani - Merloni Elettrodomestici
![Page 2: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/2.jpg)
OSGI World Congress - 26 September 2002 page 2
e-PASTA
uConsortium– Trialog
– T-Systems
– Trusted Logic
– Merloni Elettrodomestici
– Wrap
uwww.e-pasta.org
![Page 3: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/3.jpg)
OSGI World Congress - 26 September 2002 page 3
Presentation
uContext of Home ConnectivityuSituation on SecurityuTrust Value Chains
– Example of Service on Demand Application (Pay-per-use)
uTrust through Evaluation and Certification– Common Criteria
ue-PASTA workuNext steps
Presentation also applies tovehicle connectivity
![Page 4: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/4.jpg)
OSGI World Congress - 26 September 2002 page 4
Smart Homes will be Connected
HomeAppliances
InformationAppliances
Audio-VideoAppliances
u Home control– Lighting/shutters– Heating Ventilating Air
Conditioning (HVAC)– Applications for Domestic
Appliances– Safety and Security– Energy and Resource
Management
u Communication– Messaging– Chats and Bulletin
Broadcast– PDA
u Infotainment– Information– Entertainment
![Page 5: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/5.jpg)
OSGI World Congress - 26 September 2002 page 5
Several Types of Access
uLocal– owner access is direct– owner access is through home network
uRemote– owner access is through other network (e.g. ISDN)– owner uses “virtual interface” (PDA, PC, etc.)
uDelegated– third party access through other network
![Page 6: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/6.jpg)
OSGI World Congress - 26 September 2002 page 6
Typical Connectivity Infrastructure
u Remote Accessu Point of Presenceu Access Network
u Gatewayu Home Networku Appliancesu Local / Home Access
Home
PublicNetwork
GatewayRemoteAccess
Point of Presence
PublicNetwork
HomeNetwork
HomeAccess
Appliances
![Page 7: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/7.jpg)
OSGI World Congress - 26 September 2002 page 7
Typical Home Access
uDial-Up– PSTN– ISDN– GSM
uPermanent– xDSL– Cable
A B
Wireless, Broadcast
Satellite, RF,TV, GSM, UMTS
Cable
PSTN, ISDN,Power Line, Cable TV
![Page 8: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/8.jpg)
OSGI World Congress - 26 September 2002 page 8
Situation on Security of Access
uConnectivity systems are complexuNo real approach for security of access
– not enough experience on this– lack of awareness– not all or few networks provide cryptographic mechanisms
uWe need a trusted value chainuWhich garantees that the right level of security is
deployed
![Page 9: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/9.jpg)
OSGI World Congress - 26 September 2002 page 9
Trust Value Chains
Example of Merloni Pay-Per-Use Application
![Page 10: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/10.jpg)
OSGI World Congress - 26 September 2002 page 10
![Page 11: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/11.jpg)
OSGI World Congress - 26 September 2002 page 11
From the washing machine to the washingFrom the washing machine to the washing
Electric energy
+
Washingcycle
Maintenance
From
To
=
Washing machineI buy thewashing machine
I buy thewashing
°C= +
![Page 12: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/12.jpg)
OSGI World Congress - 26 September 2002 page 12
From the product to the use of the productFrom the product to the use of the product
timetime timetime
valu
eva
lue
valu
eva
lue
Value of using the productValue of using the productValueValue of the of the productproduct
ProductProduct ProductProductMaintenanceMaintenance
EnergyEnergy
The traditional logic of purchasing a new washing machineis replaced by a modern and smart appliance rental thatenables the consumer to pay for each use, i.e. per eachwashing load.
![Page 13: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/13.jpg)
OSGI World Congress - 26 September 2002 page 13
Tele-diagnosis and Tele-allarm
5 years full warranty all included
News letter with washing cycles and better use advices
Installation and full testing
Front door delivery
Recovery of the old appliance
48 hours technical assistance
Phone assistance 7 on 7 days
The offer
![Page 14: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/14.jpg)
OSGI World Congress - 26 September 2002 page 14
Capable toCapable to generate and generate andmemorizememorize data: data:
èDiagnostics
è Consumption
è Historic
è Statistic
And … rAnd … readyeady to tocommunicate with thecommunicate with theoutside worldoutside world
First of First of allall:: a new generation of smart a new generation of smart appliancesappliances
![Page 15: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/15.jpg)
OSGI World Congress - 26 September 2002 page 15
A multifunction display allows access to the PXU functions:
•Residual credit
•Cost of the last washing
•Access to promotion
•Date of the last recharge
•Messages
After each washing cycle the appliance display will inform the consumer aboutthe amount of credit left. When the credit is finished, the appliance willconnect automatically to the toll-free number for re-charge. The energyconsumed for each load will be automatically deducted from the energy bill.
The interface man - machine
![Page 16: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/16.jpg)
OSGI World Congress - 26 September 2002 page 16
TLITLI
Powerline
PSTN
Indoor system
à Standard model: Ariston Dialogic AD 1600
à Node for power line communication assembled at the installationtransform the WM in a PayXUse version
à Telelink: modem power-line / telephone-line
ContactCenter
![Page 17: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/17.jpg)
OSGI World Congress - 26 September 2002 page 17
PUBLIC SWITCHTELEPHONE
NETWORKTLIPower Line
Communication Manager
Server
PBX
Application Server
CommunicationEquipment
Call desk
Contact CenterContact Center
PXU
Outdoor system
àRecharge management
à Promotion management
à Tele-diagnosis
à Tele-alarm
à SMS messages
à Statistical datarecovery
![Page 18: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/18.jpg)
OSGI World Congress - 26 September 2002 page 18
Merloni PPU Configuration
PaymentServer
PaymentClient
Application
Call Center Gateway Washing Machine
S Security component
S S
![Page 19: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/19.jpg)
OSGI World Congress - 26 September 2002 page 19
Trust Value Chain
Consumer
BrandGarantee
Owner
PaymentServer
PaymentClient App
Merloni
S S
S Security component
![Page 20: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/20.jpg)
OSGI World Congress - 26 September 2002 page 20
Future Service-on-demand Applications
PaymentServer
PaymentClient
App 1
Call Center OSGI Gateway Appliance 1
S Security component
S SApp 2
Appliance 2
S
S
![Page 21: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/21.jpg)
OSGI World Congress - 26 September 2002 page 21
Trust Value Chain
Consumer
BrandGarantee
Owner
App 1
ManufactAppliance1
S
ManufactAppliance2
Owner
App 2S
Supplier1
Owner
PaymentServer
S
Supplier2
Owner
PaymentClient
S
CertificationGarantee
S Security component
![Page 22: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/22.jpg)
OSGI World Congress - 26 September 2002 page 22
Trust through Evaluation/Certification
uUse Common Criteria– ISO standard (ISO 15408)– Standard for security evaluation
• Used for an increasing number of products (e.g. smart cards, terminals,firewalls, …)
– Evaluation Assurance Level• EAL1: functionally tested• EAL2: structurally tested• EAL3: methodically tested and checked• EAL4: methodically designed, tested and reviewed• EAL5: semiformally designed and tested• EAL6: semiformally verified design and tested• EAL7: formally verified design and tested
![Page 23: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/23.jpg)
OSGI World Congress - 26 September 2002 page 23
Common Criteria Implies an Analysis Methodology
Security objectivesmaterial (PP/ST)
Security requirements material (PP/ST)
Security Spec. material (ST)
Security environment material (PP/ST)
Assumptions
TOE environment
CC requirementscatalogues
Functional requirements
TOE purpose
Organisational securitypolicies
Requirements for theenvironment
Assets requiringprotection
Threats
Security objectives
Assurance requirements
TOE summaryspecification
Establish securityenvironment
Establish TOE summaryspecification
Establish securityobjectives
Establish securityrequirements
TOE purpose
![Page 24: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/24.jpg)
OSGI World Congress - 26 September 2002 page 24
Common Criteria Imply Templates
uNotion of Protection ProfileuReuse of Security Analysis
![Page 25: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/25.jpg)
OSGI World Congress - 26 September 2002 page 25
e-PASTA Work
uValidate approachuWork on 3 generic configuration
– local operations• e.g. start the washing machine in the home
– remote operations• e.g. remote diagnosis
– service on demand• e.g. pay per use
uDemonstration of security components. Technologyused– ISO15408 for security analysis– Simple gateways and OSGi gateway– EHS home networking
![Page 26: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/26.jpg)
OSGI World Congress - 26 September 2002 page 26
Example of Conclusions on Local Operation
u Impact on underlying home network– Authentication needed– Encryption not needed (but could serve as authentication)– Denial of service protection not needed– Non replay needed– Secure initialization of keys needed
![Page 27: e-PASTA - A Kung](https://reader038.fdocuments.us/reader038/viewer/2022110203/55d2c3ffbb61ebc3678b4644/html5/thumbnails/27.jpg)
OSGI World Congress - 26 September 2002 page 27
Conclusions
uAnalyse Security Needs– e.g. using Common Criteria
uDefine Security ArchitecturesuStandardise Security Components when NeededuCreate Trust Value Chains
Conclusions apply for vehicle connectivity