Document-based message-centric security using XML authentication and encryption for coalition and interagency operations

Approved for public release, distribution unlimited === Approved for public release, distribution unlimited === Different agencies and different nations are not able to securely communicate and share structured information due to differences in security policies and data formats. The current evolu...

Full description

Bibliographic Details
Main Author: Williams, Jeffrey Scott
Other Authors: Brutzman, Don
Published: Monterey, California. Naval Postgraduate School 2012
Online Access:http://hdl.handle.net/10945/4610
id ndltd-nps.edu-oai-calhoun.nps.edu-10945-4610
record_format oai_dc
spelling ndltd-nps.edu-oai-calhoun.nps.edu-10945-46102014-12-04T04:08:47Z Document-based message-centric security using XML authentication and encryption for coalition and interagency operations Williams, Jeffrey Scott Brutzman, Don McGregor, Don Naval Postgraduate School Modeling, Virtual Environment and Simulation (MOVES) Approved for public release, distribution unlimited Approved for public release, distribution unlimited Different agencies and different nations are not able to securely communicate and share structured information due to differences in security policies and data formats. The current evolution of security and data policies is not solving this fundamental problem. Document-based message-centric XML security can provide satisfactory security within a diversified communications framework between traditional and nontraditional partners by utilizing existing Web standards for XML canonicalization, XML digital signature, XML compression and XML encryption. Vulnerabilities related to the exchange of cryptographic technologies are minimized by strictly adhering to open-standards technology. This approach thus resolves multi-partner trust challenges in regards to using another entity's equipment, software, or policy requirements through the proper adoption of standards-based structured data and alternative cryptographic algorithms. Exemplar results demonstrated in this thesis show that XML Security is a feasible approach for operations that include multiple agencies and coalition partners. Alternative solutions are also available using proprietary technologies, but such approaches lock participants into commercial contracts, prohibit distribution and provide suspect capabilities. Therefore, they cannot attain interagency or international acceptance. Such methods involve the use of unique or proprietary message formats with customized encryption and compression algorithms that are not available for broad scrutiny by open source communities. Closed approaches cannot gain group trust. This thesis specifically investigates XML standardization methods for various categories of unclassified data to provide secure information exchange among a wide audience, e.g. multi-agency task force or multinational coalition partners. Using an XML document-centric approach is a helpful organizing principle for this problem that provides levels of security consistent with common business practices achieved, within the constraints of the respective organizational security policies of each participant. The resulting design patterns for XML document development enhance confidentiality, integrity, and authentication commensurate with the nature of the unclassified document generated, while maintaining information objects at an appropriate level of security and acceptable level of risk. 2012-03-14T17:42:26Z 2012-03-14T17:42:26Z 2009-09 Thesis http://hdl.handle.net/10945/4610 463643441 This publication is a work of the U.S. Government as defined
in Title 17, United States Code, Section 101. As such, it is in the
public domain, and under the provisions of Title 17, United States
Code, Section 105, is not copyrighted in the U.S. Monterey, California. Naval Postgraduate School
collection NDLTD
sources NDLTD
description Approved for public release, distribution unlimited === Approved for public release, distribution unlimited === Different agencies and different nations are not able to securely communicate and share structured information due to differences in security policies and data formats. The current evolution of security and data policies is not solving this fundamental problem. Document-based message-centric XML security can provide satisfactory security within a diversified communications framework between traditional and nontraditional partners by utilizing existing Web standards for XML canonicalization, XML digital signature, XML compression and XML encryption. Vulnerabilities related to the exchange of cryptographic technologies are minimized by strictly adhering to open-standards technology. This approach thus resolves multi-partner trust challenges in regards to using another entity's equipment, software, or policy requirements through the proper adoption of standards-based structured data and alternative cryptographic algorithms. Exemplar results demonstrated in this thesis show that XML Security is a feasible approach for operations that include multiple agencies and coalition partners. Alternative solutions are also available using proprietary technologies, but such approaches lock participants into commercial contracts, prohibit distribution and provide suspect capabilities. Therefore, they cannot attain interagency or international acceptance. Such methods involve the use of unique or proprietary message formats with customized encryption and compression algorithms that are not available for broad scrutiny by open source communities. Closed approaches cannot gain group trust. This thesis specifically investigates XML standardization methods for various categories of unclassified data to provide secure information exchange among a wide audience, e.g. multi-agency task force or multinational coalition partners. Using an XML document-centric approach is a helpful organizing principle for this problem that provides levels of security consistent with common business practices achieved, within the constraints of the respective organizational security policies of each participant. The resulting design patterns for XML document development enhance confidentiality, integrity, and authentication commensurate with the nature of the unclassified document generated, while maintaining information objects at an appropriate level of security and acceptable level of risk.
author2 Brutzman, Don
author_facet Brutzman, Don
Williams, Jeffrey Scott
author Williams, Jeffrey Scott
spellingShingle Williams, Jeffrey Scott
Document-based message-centric security using XML authentication and encryption for coalition and interagency operations
author_sort Williams, Jeffrey Scott
title Document-based message-centric security using XML authentication and encryption for coalition and interagency operations
title_short Document-based message-centric security using XML authentication and encryption for coalition and interagency operations
title_full Document-based message-centric security using XML authentication and encryption for coalition and interagency operations
title_fullStr Document-based message-centric security using XML authentication and encryption for coalition and interagency operations
title_full_unstemmed Document-based message-centric security using XML authentication and encryption for coalition and interagency operations
title_sort document-based message-centric security using xml authentication and encryption for coalition and interagency operations
publisher Monterey, California. Naval Postgraduate School
publishDate 2012
url http://hdl.handle.net/10945/4610
work_keys_str_mv AT williamsjeffreyscott documentbasedmessagecentricsecurityusingxmlauthenticationandencryptionforcoalitionandinteragencyoperations
_version_ 1716726300086894592