home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Security
S N E A K   P R E V I E W  
CoreStreet's Real Time Credentials Validation Authority

  July 10, 2003
  By Mike Fratto


TOC Issue TOC
Printer Print full article
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author

In the world of authentication, the underlying assumption is our account is active; it is valid. But that's not always the case. When digital certificates are used for authentication or secure e-mail, for example, we typically don't have a way to determine if the certificate has been revoked. CoreStreet RTVCA (Real Time Credentials Validation Authority) can be used to validate digital certificates and update other user permissions.

Digital Certificates

At the heart of RTCVA is an OCSP (Online Certificate Status Protocol) VA (validation authority). The VA takes certificate status information from certificate authorities, generates OCSP responses and/or CoreStreet Vtokens and publishes them to OCSP responders. The responders function as middlemen, sending the prepared responses to network-attached equipment when asked. Clients that support OCSP, such as Netscape Communicator, or third-party OCSP plug-ins query the OCSP responders rather than the VA directly to validate digital certificates. This provides an extra barrier between potential abusers and the VA. The responders don't sign any data, so they can handle more concurrent client requests than the VA can.


A proof--in CoreStreet parlance, an OCSP response or Vtoken--is a digitally signed statement regarding the status of a digital certificate or user account. These proofs contain unique information about the user, including certificate serial number or user name; status of the user account (active, revoked or suspended); a time stamp that gives the period for which the proof is valid; any attached attributes; and a digital signature showing the VA's private key. Because the proof is signed using public key cryptography--RSA or DSA--any changes, such as a status or validity-period change, to the contents of the proof will cause the signature validation to fail. As long as the signing VA, in this case RTCVA, is protected from attack, only it can create statements of validity using its private key.



RTCVA OCSP Response Process

click to enlarge

I set up RTCVA in our Syracuse University Real-World Labs using a Microsoft Certificate Server as our CA (Certificate Authority), although RTCVA works with all directories via LDAP. RTCVA runs on an Apache Tomcat application server and uses a relational database to store data. I used the included Mckoi Java database server. Installation using command line went smoothly. Once RTCVA was installed, I defined the signing CAs by importing the signed CA digital certificate.

Physical Validation

Corestreet, working with hardware lock vendors, can provide a robust validation system for both connected and unconnected card-based door locks and solves the problem of having to manually update non-networked card door readers. The card reader still authenticates the user, but by using CoreSteet's SDK Real Time Credentials Foundation, the reader can also validate the credentials. Lock vendor's sell CoreStreet-enabled products as a package, complete with RTCVA.

On the reader, two items are needed: a policy that defines access controls for users or user groups and the signing RTCVA public certificate. On the user's card, a proof is written that is valid for a specific time period. After the user authenticates, the reader validates that the user is an authorized user and that the user has access rights. If both checks are OK, the user is granted access. If the proof is out of date, doesn't validate or doesn't match the policy in the reader, the user is denied access. The proofs can be read from an OCSP responder if the reader is network-attached or from the user's card if the reader is standalone.

Good
• Better performance
• Better ability to protect the VA from attack
• Use of attributes in OCSP responses let's administrators assign roles to users.

Bad
• Integration with existing CAs/directories could be more developed.
• Group- or role-based definition for user attributes could be easier.
• RTCVA has to be launched manually through a command prompt. It should be a self-starting service.

Real Time Credentials Validation Authority (RTCVA) starts at under $35,000/ Real Time Credentials Foundation (RTCF) pricing is via custom quote. CoreStreet Ltd. 617-718-0082 www.corestreet.com

The reader can also write proofs to users' cards. So when users first enter the building, they should have to pass through a network-attached reader, which will automatically update users' cards with a current proof. Then they can pass through any non-networked reader. More importantly, the revocation proofs, or reader policies, of other users can be written to any user's card for automatic redistribution to any non-network-attached reader because the revocation proof can be read off the card and stored for later use. Likewise, reader log files can be collected from non-network-attached readers. The obvious weakness in this system is that users need to swipe their cards through a connected reader to get their updated proofs. You should take extra care when deciding where to place network-attached card readers--often used, easily accessed readers are critical for a successful system.

RTCVA is a useful product for certificate validation, and the performance gains of pre-generating OCSP responses and the decreased exposure of the signing RTCVA being off-line are compelling to any organization using digital certificates. The physical security validation is a practical and unique use of validation that augments existing physical security measures.

Mike Fratto is a senior technology editor based in Network Computing's Syracuse University Real-World Labs®; he covers all security-related topics. Prior to joining this magazine, Mike worked as an independent consultant in central New York. Write to him at mfratto@nwc.com.

Post a comment or question on this story.









Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights