NIH Interfederation Activities and Status: Federal PKI

12
NIH Interfederation NIH Interfederation Activities and Status: Activities and Status: Federal PKI Federal PKI Peter Alterman, Ph.D. Peter Alterman, Ph.D. Asst. CIO for E-Authentication, NIH and Asst. CIO for E-Authentication, NIH and Chair, Federal PKI Policy Authority Chair, Federal PKI Policy Authority

description

NIH Interfederation Activities and Status: Federal PKI. Peter Alterman, Ph.D. Asst. CIO for E-Authentication, NIH and Chair, Federal PKI Policy Authority. NIH E-Authentication Initiative Goals. - PowerPoint PPT Presentation

Transcript of NIH Interfederation Activities and Status: Federal PKI

Page 1: NIH Interfederation Activities and Status: Federal PKI

NIH Interfederation Activities NIH Interfederation Activities and Status: Federal PKIand Status: Federal PKI

Peter Alterman, Ph.D.Peter Alterman, Ph.D.Asst. CIO for E-Authentication, NIH and Asst. CIO for E-Authentication, NIH and

Chair, Federal PKI Policy AuthorityChair, Federal PKI Policy Authority

Page 2: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 2

NIH E-Authentication Initiative GoalsNIH E-Authentication Initiative Goals

• Researchers use their institutional identity credentials to authenticate to NIH online applications and services

• Build a reliablereliable, securesecure, trustedtrusted IT infrastructure that supports e-authentication

Page 3: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 3

NIH E-Authentication Initiative GoalsNIH E-Authentication Initiative Goals

• Researchers use their institutional identity credentials to authenticate to NIH online applications and services

• Build a reliablereliable, securesecure, trustedtrusted IT infrastructure that supports e-authentication

Page 4: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 4

Current NIH InitiativesCurrent NIH Initiatives

• Interfederated with InCommon higher education Identity Management Federation at OMB LOA 1: low/no risk applications put online and consume identity credentials issued by universities that are members of InCommon;

• Extend interfederation agreement to OMB LOA 2 applications for universities that issue higher-assurance credentials under the InCommon Federation Silver program – for moderate risk applications (ETA 1/08);

• Direct trust relationship with University of Texas System Public Key Infrastructure

Page 5: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 5

NIH Pilot LOA 1 ApplicationsNIH Pilot LOA 1 Applications

• NLM Proxy Redirector (initial application )

• Good Clinical Practice (GCP)

• Community for Advanced Graduate Training (CAGT)

• NIH Login/ADFS/MOSS integration (general collaboration)

• More to follow

Page 6: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 6

NIH Pilot LOA 2 ApplicationsNIH Pilot LOA 2 Applications

• Electronic Research Administration (eRA)

• caBIG data (via Grid interoperability?)

• Firebird (FDA, SAFE, NIAID involvement)

• More to follow

Page 7: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 7

End State for NIHEnd State for NIH

• All NIH outward-facing, online apps risk assessed and credential LOA requirements determined

• Credential validation infrastructure and/or linkages at production operational level

• All NIH outward-facing, online apps connected to NIH Login front end with validation service enabling infrastructure (e.g., Shibboleth, etc.)

• End State achieved… ???

Page 8: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 8

Federal PKI Update

Page 9: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 9

Fed PKI: View from 20,000 kmFed PKI: View from 20,000 km

FBCA

C4

eGCA (3)

Common Policy CA (HSPD-12)

CertiPath

SSPs

Industry PKIs

CertiPath SSP(HSPD-12-comparable)

SAFE

Industry PKIs

Serving all otherAgencies

Page 10: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 10

Fed PKI: View from 20,000 kmFed PKI: View from 20,000 km

FBCA

C4

eGCA (3)

Common Policy CA (HSPD-12)

CertiPath

SSPs

Industry PKIs

CertiPath “SSP”

DOD DHSNASA CommerceUSPS USPTOHHS DOE IL DOJ State DOD/ECAGPO DOD/Interop TreasuryWells FargoMIT LLUTexasSxCommercial “SSP-like”

Serving all otherAgencies

BoeingRaytheonLockheed Martin

VeriSignCybertrustORCTreasuryGPOExostarEntrust/CygnacomIdenTrusT?

Total: 15 – 20Musers

EAF member CSPsTLS certs

SAFE

Industry PKIsJohnson & JohnsonMerckPfizerProcter & GambleSanofi-AventisTAP Pharmaceuticals

Abbott Labs AstraZenecaBristol-Myers SquibbGenzymeGlaxoSmithKlineINC Research

(HSPD-12-comparable)State of VA first responders

~ 500k users!

Page 11: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 11

Interoperability InitiativesInteroperability Initiatives

• CertiPathCertiPath – Federal Bridge cross-certification complete

• SAFESAFE PKI Bridge and services – supporting digitally-signed electronic forms and document management

• inCommoninCommon –assertion-based technology, LOA 1 & 2 – demonstration projects with NSF – interfederation with NIH NOWNOW

Page 12: NIH Interfederation Activities and Status: Federal PKI

EDUCAUSE 2007 12

ResourcesResources

[email protected]

• http://csrc.nist.gov/pki

• www.cio.gov/fpkipa

• www.cio.gov/ficc

• www.cio.gov/eauthentication

• www.smartcardalliance.org