Industry Prototyping Practices
Smart Card Alliance
Increasing Adoption of Smart Card Technology
IAB
24 July 2013
Interagency Advisory Board Smart Card
Alliance IDmachines 24 April 2013
Fail Fast
• Things are not going to work
• Need an ability to simulate as a test enterprise
use cases
• Walk the chain from credential to services to
infrastructure and back the other way
Interagency Advisory Board Smart Card
Alliance IDmachines 24 April 2013
Management/ Use/Risk/Administration/Analytics
Access/ Policy/Audit
Access/Attributes/Roles/Groups/Rules
Credential/ PKIX, SAML,
OAuth, JOSE, OATH, e.g.
tokens
Id(entity)/
Directory/Identifier
Frequency
of Use
Frequency
of Change
Copyright © IDmachines LLC
all rights reserved 2010-2013
Risk
Policy
Rules
Administration
Audit
Analytics
Use
Interagency Advisory Board Smart Card
Alliance IDmachines 24 April 2013
Testing = Rapid Prototyping
• Component Testing (for industry doesn’t have to
be on the APL)
– Cards
– Keys
– Applets
– Certificates
• Profiles
• Extensions
– Middleware
– Readers
– Applications/Use in context
Interagency Advisory Board Smart Card
Alliance IDmachines 24 April 2013
Prototyping and Test Infrastructure
• Mimic enterprise (federation) sorry for the
acronyms..
– PKI
• Person
• NPE
– DNS
– NTP
– DHCP, HTTP, OSDP
– TFTP
– Directories
– SNMP
Interagency Advisory Board Smart Card
Alliance IDmachines 24 April 2013
Open Source Tools
• Significant and growing set of open source
tools
– Debian Linux
– Open SSL
– Open SC
– Open LDAP
• Map to normative standards and set controls
• Work to propagate these throughout the
supply chain
Interagency Advisory Board Smart Card
Alliance IDmachines 24 April 2013

Industry best prototyping practices iab 24 april 2013

  • 1.
    Industry Prototyping Practices SmartCard Alliance Increasing Adoption of Smart Card Technology IAB 24 July 2013 Interagency Advisory Board Smart Card Alliance IDmachines 24 April 2013
  • 2.
    Fail Fast • Thingsare not going to work • Need an ability to simulate as a test enterprise use cases • Walk the chain from credential to services to infrastructure and back the other way Interagency Advisory Board Smart Card Alliance IDmachines 24 April 2013
  • 3.
    Management/ Use/Risk/Administration/Analytics Access/ Policy/Audit Access/Attributes/Roles/Groups/Rules Credential/PKIX, SAML, OAuth, JOSE, OATH, e.g. tokens Id(entity)/ Directory/Identifier Frequency of Use Frequency of Change Copyright © IDmachines LLC all rights reserved 2010-2013 Risk Policy Rules Administration Audit Analytics Use Interagency Advisory Board Smart Card Alliance IDmachines 24 April 2013
  • 4.
    Testing = RapidPrototyping • Component Testing (for industry doesn’t have to be on the APL) – Cards – Keys – Applets – Certificates • Profiles • Extensions – Middleware – Readers – Applications/Use in context Interagency Advisory Board Smart Card Alliance IDmachines 24 April 2013
  • 5.
    Prototyping and TestInfrastructure • Mimic enterprise (federation) sorry for the acronyms.. – PKI • Person • NPE – DNS – NTP – DHCP, HTTP, OSDP – TFTP – Directories – SNMP Interagency Advisory Board Smart Card Alliance IDmachines 24 April 2013
  • 6.
    Open Source Tools •Significant and growing set of open source tools – Debian Linux – Open SSL – Open SC – Open LDAP • Map to normative standards and set controls • Work to propagate these throughout the supply chain Interagency Advisory Board Smart Card Alliance IDmachines 24 April 2013