Public Key Directory: What is the PKD and How to Make Best Use of It

Similar documents
ICAO Public Key Directory (PKD)

ICAO Public Key Directory (PKD) How to join

ICAO Public Key Directory (PKD)

ICAO PUBLIC KEY DIRECTORY (PKD) Christiane DerMarkar ICAO PKD Officer

ICAO Public Key Directory (PKD)

ICAO PUBLIC KEY DIRECTORY (PKD)

Christiane DerMarkar Programme Officer PKD

Christiane DerMarkar Programme Officer - PKD Secretary of the PKD Board

MINISTERIAL CONFERENCE ON AVIATION SECURITY AND FACILITATION IN AFRICA. WINDHOEK, NAMIBIA, 4-8 April 2016

MEMORANDUM OF UNDERSTANDING (MOU)

Roman Vanek PKD Board Chairman

epassport PKI Validation & the ICAO PKD

Implementation of the Public Key Directory

ICAO PUBLIC KEY DIRECTORY (ICAO PKD) 2007 ANNUAL REPORT TO PARTICIPANTS

ICAO Public Key Directory ICAO PKD Key Ceremony Procedures

Introduction ICAO PKD Higher Travel Security. ICAO TRIP Seminar 9 to 11th May 2016

Overview of the OIE PVS Pathway

International movement of pet animals

Better Training for Safer Food

GUIDELINE 1: MICROCHIP TECHNOLOGY FOR RADIO FREQUENCY IDENTIFICATION OF ANIMALS

The Scottish Government SHEEP AND GOAT IDENTIFICATION AND TRACEABILITY GUIDANCE FOR KEEPERS IN SCOTLAND

COMMISSION OF THE EUROPEAN COMMUNITIES. Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Recognition of Export Controls and Certification Systems for Animals and Animal Products. Guidance for Competent Authorities of Exporting Countries

Current Regulations and Emerging Issues in the US

Transmitted by Co-Chairs of the Informal Working Party On Periodical Technical Inspections. WP (08-11 March 2016, agenda item 7.

FREQUENTLY ASKED QUESTIONS. General. 1. How can I provide feedback on the stop puppy farming provisions?

The PVS Tool. Part 4. Introduction to the concept of Fundamental Components and Critical Competencies

GOOD GOVERNANCE OF VETERINARY SERVICES AND THE OIE PVS PATHWAY

EUROPEAN COMMISSION DIRECTORATE-GENERAL FOR HEALTH AND FOOD SAFETY

A Bill Regular Session, 2017 HOUSE BILL 1717

OIE SUB-REGIONAL TRAINING SEMINAR ON VETERINARY LEGISLATION FOR OIE FOCAL POINTS

Import Health Standard

Import Health Standard

international news RECOMMENDATIONS

Analogous application of the GDP Guidelines 2013/C 343/01 for veterinary medicinal products

GLOSSARY. Annex Text deleted.

Sanitary and Phytosanitary (SPS) issues in exports from the EU to Russia What will Russia s accession to the WTO change?

Lessons learned from implementing EVM on a large scale IT portfolio at the Department of State

Risk of rabies introduction by noncommercial

COMMISSION. (Text with EEA relevance) (2009/712/EC)

PORTUGUESE WATER DOG CLUB OF AMERICA, INC. BREEDER REFERRAL PROGRAM & LITTER LISTING AGREEMENT Introduction

SENATE BILL No AN ACT enacting the Kansas retail pet shop act; establishing the Kansas retail pet shop act fee fund.

EU Programmes for Animal Welfare in the European region

The OIE-PVS: a tool for good Governance of Veterinary Services

SOUTH AFRICAN NATIONAL STANDARD

General Directorate of Animal Health and EpizooticDiseases Control. Dr.Sabah Hassan Abdelgadir Sudan Focal Point for Veterinary products

in food safety Jean-Luc ANGOT CVO France

Subject: Public safety; welfare of animals; sale of dogs and cats. Statement of purpose of bill as introduced: This bill proposes to amend 6

Resolution adopted by the General Assembly on 5 October [without reference to a Main Committee (A/71/L.2)]

Texas 4-H/FFA Heifer Validation Program

GUIDELINES. Ordering, Performing and Interpreting Laboratory Tests in Veterinary Clinical Practice

ANNEXES. to the Proposal. for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

New York State Animal Population Control Program (APCP)

Responsible Antimicrobial Use

OIE standards on the Quality of Veterinary Services

Dogs and Cats Online All of our Puppies in One Basket

PO Box 1036 Antioch, TN Litter Registration

Owner Information: Please list only one primary owner. Last Name: Country (if outside USA):

Annex III : Programme for the control and eradication of Transmissible Spongiform Encephalopathies submitted for obtaining EU cofinancing

OIE Regional Commission for Europe Regional Work Plan Framework Version adopted during the 85 th OIE General Session (Paris, May 2017)

The Animal Control Perspective

The impact of Good Veterinary Services Governance (GVSG) on the control over Veterinary Medicinal Products (VMP s)

Ohio State Board of Pharmacy Compliance in Veterinary Practice

VICH GL30 on pharmacovigilance of veterinary medicinal products: controlled list of terms

COMMISSION DELEGATED REGULATION (EU)

Questions and Answers: Retail Pet Store Final Rule

Import Health Standard

Guidelines to Reduce Sea Turtle Mortality in Fishing Operations

Ministry of Health. Transport of animals Pratical Experience Member Country perspective

Introduction SEAVDRAC. 23 October Prof G E Swan. Southern and Eastern African Veterinary Drug Regulatory Affairs conference

ANNEX. to the COMMISSION IMPLEMENTING DECISION

CROATIA State of play Food safety- legislation Establishments upgrading

DEPARTMENT 6 GOATS. ENTRY FEE - $4.00 per animal Entries not limited to Westmoreland County HEALTH RULES FOR GOATS

Dr A T Sigobodhla. Regional Workshop for OIE National Focal Points for Veterinary Products (Cycle V): Ezulwini, Swaziland, 6-8 December 2017

OIE global strategy for rabies control, including regional vaccine banks

Dr. Gérard Moulin AFSSA/ANMV OIE Collaborating Centre on Veterinary medicinal products BP FOUGERES CEDEX, FRANCE

3. records of distribution for proteins and feeds are being kept to facilitate tracing throughout the animal feed and animal production chain.

Session 1: An introduction to the new requirements under the Food and Drug Regulations affecting industry and health care practitioners who compound

Bearabella Golden Retriever s Stud Dog Contract Helena B. Lamont 7868 Highway 54 Sharpsburg, GA (cell) (home)

Domestic Animals Amendment (Puppy Farms and Pet Shops) Bill 2016

PARTIAL LISTING OF RULES FOR 2018 PA JR. DAIRY SHOW (COMPLETE RULES CAN BE FOUND IN PA JDS RULES AND REG. BOOKLET)

SENATE, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED MAY 26, 2016

Technical assistance for the Animal Health Department of the KVFA and the Food and Veterinary Laboratory (Kosovo) - Deliverable 1.

Hobby Breeder Permit Application

and suitability aspects of food control. CAC and the OIE have Food safety is an issue of increasing concern world wide and

The OIE Relevant Standards and Guidelines for Vaccines

Surveillance. Mariano Ramos Chargé de Mission OIE Programmes Department

The OIE Relevant Standards and Guidelines for Veterinary Medicinal Products

THE ENERGY IDENTIFICATION CODING SCHEME (EIC) REFERENCE MANUAL

L 39/12 Official Journal of the European Union

Better Training for Safer Food

Convention on the Conservation of Migratory Species of Wild Animals

Venue : Exhibition Hall 1, Viva Home Shopping Mall, 85, Jalan Loke Yew, Kuala Lumpur

State system for animal identification and registration in Ukraine

VICH:Organization,Guidelines and Global Outreach

Support for OIE Member Countries OIE PVS / Gap Analysis, Reference Laboratories and twinning programmes

American Association of Equine Practitioners White Paper on Telehealth July 2018

1.1. Project Number: Project 02 of the 2002 National Pre-accession Programme for Malta Title: Veterinary Controls Animal Health / Public Health

1.3. Initial training shall include sufficient obedience training to perform an effective and controlled search.

CHAPTER Committee Substitute for Senate Bill No. 1540

Transcription:

Public Key Directory: What is the PKD and How to Make Best Use of It Christiane DerMarkar ICAO Programme Officer Public Key Directory 1

ICAO PKD: one of the 3 interrelated pillars of Facilitation Annex 9 Chapter 3:main SARPs related to the TRIP ICAO TRIP Strategy Doc 9303 Part 12: PKI specs ICAO PKD Mean to enhance security in crossborder movement. Inspection Tool for epassports verification, validation and authentication of the digital signatures and content of the chip Amendment 25 to Annex 9: RP 3.9.1: Contracting States issuing, or intending to issue emrtds should join the ICAO Public Key Directory (PKD) and upload their information to the PKD. RP 3.9.2: Contracting States implementing checks on emrtds at border controls should join the ICAO Public Key Directory (PKD) and use the information available from the PKD to validate emrtds at border controls.

MRP Connection between PKD and epassports epassport 0111001001010 Machine Readable Passport (MRP) CHIP RFID 14443 IMAGE FACE Logical Data Structure (LDS) PKI DIGITAL SIGNATURE Public Key Directory (PKD) 3

What is the PKD & What does it do? A central storage location, highly secure where States and other entities can input and retrieve the security information to validate the electronic information on the passport. It allows Border control authorities to confirm that the epassport: Was issued by the right authority Has not been altered Is not a copy or cloned document 4

The Role of The PKD Minimizing the volume of certificate exchange: Document Signer Certificates (DSCs) Certificate Revocation Lists (CRLs) Country Signing Certificate Authority (CSCA) Master List Ensuring timely uploads Managing adherence to technical standards Facilitating the validation process 5

Central Broker Distribution of Certificates and CRLs via bilateral Exchange via ICAO PKD Conformity validated certificates Country A Country B Country A Country B Country H Country C Country H ICAO PKD Country C Country G Country D Country G Country D Country F Country E Country F Country E This example shows 8 States/non-States requiring 56 bilateral exchanges (left ) or 2 exchanges with the PKD (right) to be up to date with DSCs and CRLs. In case of 191 ICAO States 36,290 bilateral exchanges would be necessary while there are still 2 exchanges with the PKD. This example shows 8 states requiring 56 bilateral exchanges (left) or 2 exchanges with the PKD (right) to be up to date with certificates and CRLs. In case of 188 ICAO States 35,156 bilateral exchanges would be necessary while there are still 2 exchanges necessary with the PKD. 6

Current Services of the PKD Validated DSCs and CRLs of Participants CSCA Master List List of CSCAs used by Participants Country Signing Certificate Authority (CSCA) Registry Yellow Pages for the Passport Issuance Agency of the Participant A reference for compliance to Doc 9303 for DSCs and CRLs Contains lists on non-compliant certificates 7

8 51 Participants New Participants: Romania Finland Benin Botswana Kuwait

ANNEX 9: Recommended Practice 3.9.1 & 3.9.2 The Standards and Recommended Practice of Annex 9 recommend the following: 3.9.1: Contracting States issuing, or intending to issue emrtds should join the ICAO Public Key Directory (PKD) and upload their information to the PKD. 3.9.2: Contracting States implementing checks on emrtds at border controls should join the ICAO Public Key Directory (PKD) and use the information available from the PKD to validate emrtds at border controls. 9

Some Arguments repeated over and over. It s too expensive Bilateral exchange works good enough It s not necessary DSCs are (mostly) on the chip It s too complicated we must first introduce epassports As of 01.01.2016 Fee reduction cumbersome, time consuming and possible security risk A DSC on the epassport but not on the PKD could mean a compromised private signing key. & CRLS are only distributed via PKD 1. Participation in the PKD should go hand in hand with introduction of epassports 2. PKD participation is key for setting up any successful epassport based border control. 10

Reasons to Participate The need to exchange certificates is the logical step forward from the well known specimen exchange (you must know what you're looking for, when inspecting a travel document). Without the ability of validating the digital signature in a epassport at the border, the travel document must be treated exactly as a simple MRP not an epassport Using the PKD in epassport validation is essential to capitalize on the investment made by States in developing epassports to improve Border Security 11

Value of PKD for epassports - Use of the PKD enhances the security of the epassport validation process - Facilitates fast and secure cross-border movement by the frontline entities - PKD can be used with Automated Border Controls (ABC)or with a manual e-reader - Maintain compliance with ICAO specifications - Assure smooth and continuous epassport validation (less than 10 seconds per pax) at control points - Fees for PKD membership are low compared to investment required for a multiple bilateral infrastructure - Over 120 States claim that they are currently issuing epassports (nearly half a billion of epassports in circulation world wide) - States still need to do significant work to ensure that the data chip in epassports is fully compliant with ICAO Doc 9303 specifications - ICAO and the International Organization for Standardization (ISO) have implemented a mechanism to make error codes available at each border to detect security issues when reading a non-compliant epassport data chip

It s not complicated : All you have to do is. Find out who is responsible Check legislation and budget Different organizations in different states (try to make it as simple as possible) Contact ICAO or any PKD Board Member or PKD Participant if you have questions 13

Formalities: The steps to join the PKD 1. Deposit a Notice of Participation with the Secretary General of ICAO 2. Deposit a Notice of Registration with the Secretary General of ICAO 3. Effect payment of the Registration Fee and Annual Fee to ICAO a) 1.1.2016 Registration Fees : US $ 15,900 b) Annual Fees: +/- US $40,000 4. Securely submit to ICAO and all Participants, the CSCA certificate 5. Use the PKD : upload/download certificates 6. http://www.icao.int/security/mrtd/pages/pkd-howtopartici.aspx 14

2016 a year that will bring changes New Fees New Services + CSCA = ICAO Master List (new) 15

01.01.2016 : Fees reduction A. For new Participants - Registration Fee: US $15,900 B. Annual Fees based on 49 Participants: 1. Operator: US $ 29,900 2. ICAO: US $ 9,262 3. Total: US $ 39,162 C. More Participants = reduction in Operators and ICAO Annual Fees 50 Participants 27,000.00 US$ 55 Participants 24,500.00 US$ 60 Participants 22,500.00 US$ 65 Participants 20,900.00 US$ 16

New Service ICAO Global Master List A fact: e-mrtds capabilities are not used at their full extend Border Agencies need the tools (certificates) necessary, bilateral exchange doesn t meet the requirements + CSCA = ICAO Master List One-Stop Shop For epassport Validation K L I + A M B H PKD G F D E C + DSCs + + CRLs CSCA (new) = currently in the PKD = currently in the PKD 17

Contact Details Name: Christiane DerMarkar Email: cdermarkar@icao.int PKD website: http://www.icao.int/security/mrtd/pages/icaopkd.aspx 18