27.06.2013 Views

6th European Conference - Academic Conferences

6th European Conference - Academic Conferences

6th European Conference - Academic Conferences

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Labelling<br />

Label creation<br />

Information lifecycle<br />

Management<br />

Release mechanism<br />

Labelling<br />

Verification<br />

Label translation<br />

Label creation<br />

Disseminate<br />

release information<br />

Harm Schotanus et al.<br />

PKI<br />

Labelling<br />

Trusted OS<br />

CA<br />

Smartcard auth.<br />

Certificate Valid<br />

Secure binding<br />

Label translation<br />

Label creation<br />

…<br />

Secure login<br />

HAP<br />

Integrity<br />

protection<br />

PKI<br />

Release mechanism<br />

Labelling<br />

Trusted OS<br />

CA<br />

Smartcard auth.<br />

Certificate Valid<br />

Certificate valid<br />

Authorisation<br />

Verification<br />

Secure binding<br />

Label translation<br />

Label creation<br />

…<br />

Secure login<br />

HAP<br />

Secure labelled<br />

release<br />

Figure 7: An incremental approach to introduce labelling<br />

Each functional building block can consist of several components which have to be implemented<br />

depending on the functionality we require. When these requirements increase additional functional<br />

building blocks are required and the complexity of the building blocks may increase as more<br />

components are added. As such we have established an incremental approach in which we add<br />

complexity in small steps but in the mean time we create new useful functionality.<br />

The first basic step to use labelling is to implement a system which can create labels and utilise these<br />

labels in an (existing or new) Information Management System to manage information. When all the<br />

processes and procedures are in place and people are used to work with this new form of information<br />

management it can be decided to extend the labelling with more functionality. A next step can be to<br />

implement a release mechanism which can decide to translate internal labels into external labels and<br />

share these labels with other domains. To ensure the integrity of the data-object and metadata-object<br />

PKI and Trusted OS functionality can be added. At the end all four functional building blocks are in<br />

place resulting in a “secure labelled release” application.<br />

Each step goes along with other advantages such as reduced complexity, people have time to<br />

experience and use new functionality, processes and procedures will change incremented and an<br />

better acceptance of the functionality in the organisation.<br />

4. Conclusion<br />

Labelling is an important step to provide the technical means to realise a NEC environment and<br />

implement a duty-to-share mechanism. Not only does it allow the sharing of information, it also<br />

realises a basis so that the information owner can remain in control of which information is shared.<br />

Creation of labels in itself is not a difficult process, nor is the validation of the correctness of such a<br />

label. Most of the means for these are already in place e.g. in the form of PKI. Assurance is a totally<br />

different criterion. To attain the right level it is vital to ascertain that the label is attached correctly to<br />

the right information. Hence it requires many additional controls to achieve that certainty. Crucial in<br />

that aspect is the choice of a platform as this is the basis for assurance.<br />

Implementing labelling for a high security environment is a costly and long-term development. But in<br />

the long run, it can also be a very useful technique to create a solution to exchange information<br />

across different security domains. But on the short term, obtaining results is difficult. However,<br />

encapsulating meta-data in a label can be useful for many other purposes as well. We argued that<br />

236

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!