InCommon Operations Assurance Requirements

InCommon Operations is planning to deploy a two-factor login interface to the InCommon Federation Manager by the end of Q2 2012. At the same time, InCommon and Comodo are considering the feasibility of deploying a two-factor login interface to the InCommon Certificate Manager. This document enumerates the assurance requirements of these two, high-profile services.

Executive Summary

The InCommon Federation Manager and the InCommon Certificate Manager are high-security applications that must know their users in advance. Since these applications do not require strong identity-proofing, it follows that Silver is not required for access to the FM or the CM. On the other hand, the applications do require strong authentication, stronger than password alone. Consequently, the FM and the CM implicitly depend on an assurance profile that rationalizes Bronze requirements in the presence of two-factor authentication. Such a profile, dubbed Bronze + 2FA, is the logical conclusion of this requirements analysis of the FM and the CM.

Terminology

Assurance Requirements Analysis

Federation Manager Requirements

The following requirements are the actual requirements of the InCommon Federation Manager, to be deployed by the end of Q2 2012.

  1. InC Ops requires 2FA for all FM users except when the user’s physical location is inside the Internet2 security domain.
  2. The InC Ops IdP issues Bronze passwords and 2FA credentials to all FM users.
  3. The InC Ops IdP accepts a federated Bronze password in lieu of a locally issued Bronze password for any FM user (but remains authoritative for the 2FA credential).
  4. The FM accepts assertions from the InC Ops IdP only.

Certificate Manager Requirements

The following requirements are under discussion and for illustration only. Actual requirements will be jointly determined by Comodo and InCommon.

  1. InC Ops requires 2FA for all CM users except when the user’s physical location is inside the Internet2 security domain.
  2. The InC Ops IdP issues Bronze passwords and 2FA credentials to any CM user that needs them.
  3. The InC Ops IdP accepts a federated Bronze password in lieu of a locally issued Bronze password for any CM user.
  4. The CM accepts assertions from any InCommon IdP that is certified Bronze + 2FA.

Conclusions

Open Questions