helena sims nacha – the electronic payments association overview of the electronic authentication...

16
Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination Meeting

Upload: reynard-richard

Post on 16-Dec-2015

214 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Helena Sims

NACHA – The Electronic Payments Association

Overview ofThe Electronic Authentication

Partnership

Tenth Federal & Higher Education PKI Coordination Meeting

Page 2: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Electronic Authentication Partnership

Mission Statement

Goal:– Reliable Identity

Authentication– Convenience– Ease of use

We Propose to:– Create a voluntary partnership– Promote trust and Interoperability– Develop an evaluation process– Build on what exists– Work cooperatively with other

nations’ identity systems

Page 3: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Tasks:The EAP Will Develop

• Operating Rules Addressing

– Business requirements and processes

– Standards for Credentials

– Hierarchical assurance levels

– Criteria for evaluating credentials at each assurance level

• Evaluation, accreditation and compliance with credentialing process

• Accreditation List

Page 4: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

EAP Framework: Benefits

• Focuses on traditional problem areas for federated authentication.

• Complements and leverages existing initiatives.• Provides a framework that will:

– Enhance the utility and portability of credentials across circles of trust.

– Expand markets by promoting wider use of credentials.

– Help authentication initiatives validate their approaches to credentialing.

Page 5: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

EAP Framework

Authe

ntic

atio

n Ris

k an

d

Assur

ance

Lev

els

Cre

dent

ial r

equi

rem

ents

A

ccre

dita

tion

proc

ess

for

cred

entia

ls &

pro

vide

rs

Com

mon

bus

ines

s ru

les

Lis

t of t

rust

ed c

rede

ntia

l

pro

vide

rs w

ith E

AP

bran

d

Governance StructureA public/private governance structure to establish and maintain a federated identity

management framework

Page 6: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

EAP Framework: Development Approach

USG

Private sector

Education

Health

Etc.

Processes and Rules Sets

Credential Standards

Evaluation processes

EAP Working Groups produce EAP

Framework

EAP Framework

Reassess and update based on market

conditions and changes

Page 7: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Background

• Spring 2003 White Papers by CSIS and Johns Hopkins

• June through December 2003 - Four CSIS Work Group Meetings

• December 11, 2003 - Public Forum to Announce EAP

• 2004 – Six Meetings So Far• Active Workgroups

Page 8: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Workgroups

• Business Requirements and Processes – Linda Elliot, PingID Network, Chair– Thomas J. Greco, Betrusted, Vice Chair

• Credential Services Assessment Criteria, Levels of Assurance – R.J. Schlecht, Mortgage Bankers Association of America,

Chair – Von Harrison, GSA, Vice Chair– Subworkgroup Chairs

• Dr. Peter Alterman, NIH• Nancy Black, Consultant

Page 9: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Workgroups

• Evaluation, Accreditation and Compliance– Cornelia Chebinou, National Association of

State Auditors, Comptrollers and Treasurers, Chair

• EAP Governance– Paula Arcioni, New Jersey Office of

Information Technology, Chair– Roger Cochetti, CompTIA, Vice Chair

Page 10: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Workgroup on Business Requirements and Processes

• General Rights and Obligations– Credential Services Providers– Relying Parties

• Assessor Participation

• Agreements Process to Bind Participants to Business Rules

• Privacy and Fair Information Practices

• Enforcement and Recourse, including fines

Page 11: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Workgroup on Services Assessment Criteria, Levels of Assurance and

Technical Interoperability• Levels of Assurance• Service Assessment Criteria (SAC) for use by

Assessors– Common Organizational SAC– Identity Proofing SAC– Credential Management SAC

• Technical Interoperability– Components of interoperability – Options and recommendations for EAP adoption

Page 12: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Workgroup on Evaluation, Accreditation and Compliance

• Accreditation, Assessment and Certification– Accreditation of Assessors– Certification of Credential Service Provider

Offerings– Process for Handling Non-Compliance– Acceptable Public Statements Regarding EAP

Accreditation and Certification

Page 13: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Workgroup on EAP Governance

• Developed Charter – Approved September 2, 2004

• Developing EAP Budget

Page 14: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

Time Frames

• Remainder of 2004– Election of Board and Officers– Adoption of First Set of Operating Rules

• 2005 – Earlier Adopters Phase– Revise Rules Based on Experience

• 2006 –Production Phase - Begin Full Scale Implementation

Page 15: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination

EAP Information

• Next Meeting: February 9, 2005 in DC

– Come Join Us!

– To Register: [email protected]

• Web Site: www.eapartnership.org

Page 16: Helena Sims NACHA – The Electronic Payments Association Overview of The Electronic Authentication Partnership Tenth Federal & Higher Education PKI Coordination