Probably the best PKI in the world

Similar documents
NIS Standardisation ENISA view

A Tale of Two Open Source Cryptography Projects. Bouncy Castle EJBCA

einfrastructures Concertation Event

Taking Back Control of Your Network With SD-LAN

VdTÜV Statement on the Communication from the EU Commission A Digital Single Market Strategy for Europe

esignature Infrastructure Marketing Model

Business and R&D needs strengthening / needing eachother

GLOBAL PKI TRENDS STUDY

Conformity and Interoperability Key Prerequisites for Security of eid documents. Holger Funke, 27 th April 2017, ID4Africa Windhoek

EU Cloud Computing Policy. Luis C. Busquets Pérez 26 September 2017

ITU Workshop on Security Aspects of Blockchain (Geneva, Switzerland, 21 March 2017) Blockchains risk or mitigation?

Whitepaper CLOUDSCAPE SWEDEN. Pim Bilderbeek Partner and Principal Analyst

The emerging EU certification framework: A role for ENISA Dr. Andreas Mitrakas Head of Unit EU Certification Framework Conference Brussels 01/03/18

TOOP Introducing The Once-Only Principle project

We are also organizational home of the Internet Engineering Task Force (IETF), the premier Internet standards-setting body.

«SINGLE MARKET MONITOR SURVEY»

Single Secure Credential to Access Facilities and IT Resources

open.org Case study of XML based PKI management protocols. Tomas Gustavsson PrimeKey Solutions AB

Pernilla Baralt. EU kommissionen i Sverige

CLOUD-BASED DDOS PROTECTION FOR HOSTING PROVIDERS

NETWORK DDOS PROTECTION STANDBY OR PERMANENT INFRASTRUCTURE PROTECTION VIA BGP ROUTING

Security Aspects of Trust Services Providers

VISION Virtualized Storage Services Foundation for the Future Internet

IN THE FRAME. Computacenter Public Sector Frameworks FRAMEWORK

E X E C U T I V E B R I E F

Security for Wireless Handhelds

New cybersecurity landscape in the EU Sławek Górniak 9. CA-Day, Berlin, 28th November 2017

Executive brief Create a Better Way to Work: OpenText Release 16

NDIX & Relined: we complement and augment each other

hidglobal.com HID ActivOne USER FRIENDLY STRONG AUTHENTICATION

DMR Interoperability Process DMR Association

EU Innovation Investments: The Challenges met by Innovation Infrastructures Today in Europe

EN CEPA CERTIFIED: HERE IS HOW IT WORKS DQS - COMPETENCE FOR SUSTAINABILITY

IPv6 Deployment Survey. Based on responses from the RIPE community during June 2009 Maarten Botterman RIPE 59, Lisbon, 6 October 2009

PKI (digital ID security services) extension of RESPONSE ON CONSULTATION DOCUMENT ON THE FINAL REPORT OF THE EXPERT GROUP ON E-INVOICING

e-sens Electronic Simple European Networked Services Klaus Vilstrup Pedersen WP6 Manager DIFI, Norway

With K5 you can. Do incredible things with Fujitsu Cloud Service K5

Business White Paper IDENTITY AND SECURITY. Access Manager. Novell. Comprehensive Access Management for the Enterprise

Say Goodbye to Enterprise IT: Welcome to the Mobile First World. Sean Ginevan, Senior Director, Strategy Infosecurity Europe

Cloud Computing: A European Perspective. Rolf von Roessing CISA, CGEIT, CISM International Vice President, ISACA

The State of the Linux Desktop An OSDL Perspective. John Cherry OSDL Desktop Linux (DTL) September 23, 2006

Putting security first for critical online brand assets. cscdigitalbrand.services

Current status of WP3: smart meters

APNIC input to the Vietnam Ministry of Information and Communications ICT Journal on IPv6

Vademecum of Speakers

1. Publishable Summary

Certificate Enrollment for the Atlas Platform

ENISA And Standards Adri án Belmonte ETSI Security Week Event Sophia Antipolis (France) 22th June

BROADBAND TAKE-UP DRAMATICALLY SLOWS ACROSS EUROPE. ECTA blames rise in monopolies

DCOS Workshop: The Intersection of Open ICT Standards, Development, and Public Policy

Secure VPNs for Enterprise Networks

Data Center Cooling Market Research Report Forecast to 2023

ENUM: Country Experiences

Swedish bank overcomes regulatory hurdles and embraces the cloud to foster innovation

Digital Signatures: How Close Is Europe to Truly Interoperable Solutions?

GOV Framework. Transport Infrastructure Transport Infrastructure Agreement (TIA) Framework. Version: 1.10 Status: In use

EU policy and the way forward for smart meters and smart grids

eidas Regulation in the context of Cybersecurity: Electronic seals and website certificates: Two sides of a (gold) medal?

Cloud28+ Compliance in Cross Border Business

DIGITIZING INDUSTRY, ICT STANDARDS TO

Call for Expressions of Interest

GDPR: A QUICK OVERVIEW

eidas Interoperability Architecture Version November 2015

Introduction to Danfoss

Get your business Skype d up. Lessons learned from Skype for Business adoption

e SENS Pilots of eid, esignatures and Trusted Services

Trusted Identities That Drive Global Commerce

WEB DDOS PROTECTION APPLICATION PROTECTION VIA DNS FORWARDING

Building an Assurance Foundation for 21 st Century Information Systems and Networks

European Union Agency for Network and Information Security

iotrust Security Solutions

UK-led international standards for BIM

IT S TIME TO UNIFY AIR TRANSPORT COMMUNICATIONS

ETSI FOUNDATION OF A STANDARD BASED ECOSYSTEM. The views expressed are personal to the speaker and do not necessarily represent those of ETSI

Get Connected: Building your Digital Workplace

A PURCHASER NETWORK FOR INCREASED ENERGY EFFICIENCY IN SUPERMARKETS

Sándor Szőke, Dr. Microsec Ltd. Migration of national PKI Services to eidas conformant Trust Services case study in Hungary

IT Monitoring Tool Gaps are Impacting the Business A survey of IT Professionals and Executives

ICT support for Primary Schools. Helping primary schools to apply a successful ICT strategy for teaching and digital learning.

ETSI and GRID Standardisation. Mike Fisher, BT ETSI TC GRID Chair. 23 October 2006 ITU-T/OGF Workshop on Next Generation Networks and Grids

Interoperability Challenge of Certified Communication Systems via Internet

Campus IT Modernization OPERATIONAL CONTINUITY FLEXIBLE TECHNOLOGY MODERNIZED SYSTEMS

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information

BDI The Voice of German Industry. Mittelstand companies in the German economy

Harmonisation of Digital Markets in the EaP. Vassilis Kopanas European Commission, DG CONNECT

Arabian Cloud Computing Project

Mobile App Development Market Research Report- Global Forecast to 2022

Alcatel-Lucent 1357 ULIS

CEF Telecom policy background. DG CONNECT, 12 September 2017

northeast group, llc Smart Meter Refresh: Market Forecast ( ) October Northeast Group, LLC

Shaping the Cyber Security R&D Agenda in Europe, Horizon 2020

Move Up to an OpenStack Private Cloud and Lose the Vendor Lock-in

Verizon Software Defined Perimeter (SDP).

Public consultation on the revision of the Recommendation on relevant markets

THE VALUE OF STANDARDIZATION IN ICT

Background Brief. The need to foster the IXPs ecosystem in the Arab region

Analysys Mason Research Key Themes for 2013

Big data and data centers

The current status of Esi TC and the future of electronic signatures

Towards a European Cloud Computing Strategy

Transcription:

Probably the best PKI in the world

PrimeKey At A Glance Solutions and Professional Services within Applied PrimeKey Group Cryptography with focus on PKI (what's PKI?) PrimeKey Solutions AB Main customers are Governments & Large Enterprises Number of employees: 22 Date of incorporation: May 2002 Headquarters in Stockholm, with offices in Sweden and Germany PrimeKey Labs GmbH Number of employees: 7 Developers and commercial force behind open source Date of incorporation: June 2012 projects EJBCA.org and SignServer.org

100 years of PKI More than 100 years of collective experience in deploying real world, production, PKI systems. World-wide deployments. Europe, Asia, USA, Africa and Middle East. eid, epassport, Government and Enterprise.

How We Started PKI is based on an ISO standard, X.509, complemented by multiple standards from IETF, Oasis, ETSI and other standardization organizations. Although there have been, and are some, patents around cryptography there are few barriers since the RSA patent expired in September 2000 (before this the US market was complicated). Many basic features of the standards were already available as open source software in 2001, when I started the EJBCA project. The rest could be implemented and contributed back.

How We Started Implementing open standards in open source software, and contributing to other projects made it possible to implement the same functionality as expensive proprietary software as an open source project in 2001. In 2002 PrimeKey was started as a company to change the world of PKI. Today > 2000 downloads per month and thousands of deployments world-wide (one large partner made a survey claiming that 70% of governments operate EJBCA somewhere). EJBCA is now EJBCA Enterprise and EJBCA Community, trusted by governments and corporations for mission critical applications.

Who else? Security industry is largely dominated by large companies like RSA, Entrust-Datacard. In the PKI niche specifically there are several smaller companies in various countries in Europe (Sweden, Denmark, Germany, France, Spain, ) This competition is possible with solutions based on open standards.

Implementing open standards Implementing open standards is low barrier. Download standard documents. Search for existing open source projects, with a suitable license. Implement solution. Interoperability test against open reference implementations. Short turn around Low cost Low barrier of entry

Implementing non-open standards Implementing non-open standards is high barrier. If available, purchase standard document. Implement from scratch. Interoperability test against competitors or customers. Long turn around High cost High barrier of entry Government customers ask us if we have non open standardization documents they can borrow, because the process is too heavy.

Result Governments and Enterprises have access to cost effective security solutions. PKI is nowadays underlying infrastructure of almost every secure communication technology. Secure Web VPN Telco,mobile networks ebanking einvoicing IoT No closed standards (except.doc) gets such ubiquitous presence.

What is EU doing good (1)? ETSI standards are open. Profiling PKI for use in EU with Trust Service Providers, eidas, etc. Allows competition between vendors in different countries. Possible to fulfill requirements based on ETSI standards across the world consistently. Repetition lowers cost.

What is EU doing bad (1)? Enforcement takes a long time. Countries have been allowed to addon national standards, making it very expensive to compete. Allow(ed) local protection of markets. In our field the eidas regulation tries to relieve this, but it will take several years. epassports...

epassports In 2007 PrimeKey developed a second open source project, based on open standards, in order to deliver an epassport solution to the Swedish Police. Implemented in record time, achieving an almost impossible time line where vendors of proprietary technology could not do it. For epassports there are two different standardization organizations, ICAO and EU, both unfortunately half-open/half-closed. (does not fulfill requirements for an open standard according to the definition in EIF v1.0)

epassports ICAO (works partly together with ISO). Open standards documents. Closed standardization process. No/limited possibility for small companies to participate, except implementing the result. EU had a group called BIG, responsible for the first standard. BIG group was terminated, BSI handles the standardization. Open standards documents. Close standardization process. No/limited possibility for small companies to participate, except implementing the result.

epassports BIG created a standard called SPOC. No maintenance, still v1.0 although there are interoperability issues. EU requires member countries to implement the standard, threatening with fines. But there is no maintenance of the standard. Implementation is very expensive and interoperability is very hard (the standard would benefit from a v2). Leads to unnecessary high expenses for member countries, for little gain. The standard is practically abandoned, but still enforced.

How could we do this? PrimKey is a supplier to the Swedish Police. As such we were close to the standardization, and could participate early on in the implementation. Swedish police even contributed open source library implementing important parts of the semi-closed standard. Cert-cvc library, used in EJBCA, was born. Separate open source software, used by others across EU as well. Basically, we were lucky.

Drawbacks Hard for independent vendors, without government connections to enter this market. Suppliers in different countries with good connections had/have an advantage. Follow the biggest/most active country syndrome, hope they do the right thing for us as well?

Conclusions Open standards allow new disruptive companies to enter the market. Improving technology Lowering cost Creating jobs Does not threaten anything (except monopolies). EU can use the good standardization organs it has. Don't let important projects bypass proper standardization. Don't allow local additions for protecting local suppliers. Require open standards for procurement.

Examples Contracting authorities in Sweden may require ICT standards as mandatory if these meet the requirement of the European Union s Interoperability Framework (EIF v 1.0). (https://joinup.ec.europa.eu/community/osor/news/sweden-refinesspecifications-open-standards) CSV (IETF), DNS (IETF), HTTP/S (IETF), IP (IETF), TCP (IETF), Date and time (ISO), PDF/A-1 (ISO), PNG (ISO), Genericode (Oasis), HTML (W3C), HTML5 (W3C), RDF (W3C), RDFa (W3C)

In our context... If procurement is performed requiring closed, or semi-closed, or regional, standards. Implementation will be costly and we will likely not be able to participate. If procurement is performed with open standards, we are likely to have implemented it already, and can deliver cost effective solutions. In competition with other vendors EU-wide. Extends to certifications required, not only technical standards. In our niche we are at least partly lucky, other areas may not be. Requiring open standards (and avoiding region specific lock-in) in procurement can give large effects for SMEs.

PrimeKey & The ORIOS project important for PrimeKey to be at the forefront of thinking concerning development and use of open standards in software partner in a collaborative research project ORIOS (2012-2015) financially supported by the Knowledge Foundation ORIOS: Overarching goal: What are the necessary and desirable features of an Open Standard, and how can Open Standards and their implementations be utilised by small companies in different usage contexts?