9
Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate www.oasis-open.org

Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

Embed Size (px)

Citation preview

Page 1: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

Digital Signatures to support Trust

Ronny BjonesSecurity ArchitectMicrosoft Corporate

www.oasis-open.org

Page 2: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

Digital Signatures Scenarios Code Signing Integrity/Trust on a protocol level – many time

invisible Document signing (qualified or not) Form signing Claim-based Applications

Page 3: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

Support Trust in Code Code Signing

ActiveX Kernel Drivers .Net Apps

Apps have an identity

Software Restriction Policies

Page 4: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

Support Trust in Protocols SSL/TLS Client authentication s/mime signing

IPSec (IKE) Kerberos PKINIT …

Page 5: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

Support Trust in Documents Signing contract

Office Signature XPS (XML Paper Specification) - WSIWYS

Patent requests

Page 6: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

Support Trust in Workflows XML Signatures (Embedded Signatures)

Document types don’t change in the workflow after signature XAdES

Server side

Page 7: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

Support Trust in Authentication & Authorization Claim-based Applications Identity Metasystem Authentication/Authorization become

policy-decisions

Page 8: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

QuEST

Qualified Electronic Signatures Tutorial

Demystify Qualified Electronic signatures Best practice/guidance for designing a

Qualified Electronic signature solution

http://tinyurl.com/8428q

Page 9: Digital Signatures to support Trust Ronny Bjones Security Architect Microsoft Corporate

© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be

interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.