22.01.2015 Views

Military Communications and Information Technology: A Trusted ...

Military Communications and Information Technology: A Trusted ...

Military Communications and Information Technology: A Trusted ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

372 <strong>Military</strong> <strong>Communications</strong> <strong>and</strong> <strong>Information</strong> <strong>Technology</strong>...<br />

Figure 4. Directory Services Topology in Secret Environment<br />

NEDS is not meant to interconnect with any identity store operating in a different<br />

security zone <strong>and</strong>/or governance realm. In the NEDS project, the role of directory<br />

data synchronization repository for external parties is assigned to a (not<br />

yet deployed) Alliance Replication Hub (ARH). It will be deployed in the NS<br />

demilitarized zone (DMZ).<br />

It is recommended to use the ARH as an identity data store for the federation<br />

proxy component (Figure 2) in support of SAML-token issuance processes <strong>and</strong><br />

controlling functions.<br />

An option of the NEDS project will be executed in the future, aimed to deploy<br />

the directory data synchronization mechanism at the NU/NR level.<br />

3) Data (Attribute) types:<br />

Identity data can be categorized in the following way:<br />

• Biometrics,<br />

• Personally Identifiable <strong>Information</strong>,<br />

• Qualifications,<br />

• Tokens,<br />

• Roles,<br />

• Privileges.<br />

NATO specified the Allied <strong>Communications</strong> Publications (ACP) 133 directory<br />

services st<strong>and</strong>ard. It provides foundations for NEDS directory schema definition.<br />

However, ACP 133 is not capable to support all the categories listed above. Therefore,<br />

extensions of the ACP 133 st<strong>and</strong>ard may be required.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!