|
Does View500 support Military applications ?
Yes View500 is one of the very few vendors worldwide to have implemented the ACP 133 Edition C and Edition C supplement (Allied Communications Protocol). View500 in fact is in use today in both the Australian & Singapore Defence Forces and is also deployed in a number of test bed facilities in NATO and in the United Kingdom. It is also used by Clearswift UK to support its Common Criteria EAL4 Deep Secure & Directory Bastion High Assurance Guard technology and its ACP 145 Gateway environments. In the United States a number of Defence Systems Integrators have integrated View500 with their technology and indeed eB2Bcom partners with Commpower a US Defence software company.
What sort of Military & Intelligence Applications can View500 be used for:
View500 can be used in:
a) Tactical Messaging
In modern military messaging either the CCEB standard military messaging standard - ACP 123 or the European STANAG 4406 standard protocols are used to deliver military messaging between defence forces. As part of the requirement to support military messaging, there is requirement to provide Directory Services in accordance with the CCEB ACP 133 standard. In addition with the emergence of joint coalition task forces to conduct operations, there is a need to deploy common gateways to link nations.
This has led to the establishment of another CCEB protocol called ACP 145.
View500 is fully compliant with the CCEB ACP (Allied Communications
Protocol) 133 Edition C Directory schema standard and the CCEB ACP 145 standard. In Defence Messaging there is also the need to provide support for any combination of signing and encryption on a desk top to desktop basis. This means that at network gateways between units and networks, there is a need to deploy a High Assurance Guard such as Clearswift EAL4 Deep Secure product. View500 is fully tested and deployed with the Clearswift Deep Secure EAL4 High Assurance Messaging Guard which requires 2 x ACP 133 compliant Directory servers. In this deployment, as well as directory message addressing information, the Directory stores information such as Security policies and Anti virus index files and uses Strong authentication together with component matching to access digital certificates for authentication and encryption.. View500 can also be used for the support of Tactical Military Message environments
b)Defence white & yellow pages and as repository for defence role based access control
The Australian Department of Defence had a challenge: how to keep track of its people and how to use its central identity management infrastructure as a basis for online services. Historically, internal divisions had 'gone their own way', and developed a wide variety of corporate directories.
These were constantly in need of update, wouldn't 'talk to each other', and offered very poor performance, which discouraged their use. Defence Headquarters took steps to overcome the problem by acquiring a single, easy to maintain corporate directory, capable of integrating with a diverse collection of legacy and new systems, able to be accessed via the Web as well as from Microsoft desktop platforms and mobile devices and offering significant performance improvement in a cost-effective manner.
eB2Bcom's View500 was selected since it was a highly compliant implementation of the ISO OSI Directory Standard, and offering both DAP and LDAP interfaces as well as full support for the new IETF XML enabled Directory standard as well as SOAP, LDIF, XLDIF and a variety of other standards. eB2Bcom View500 easily interfaced to the Defence Department's wide variety of disparate legacy systems, which included email, a proprietary HR system, other more standard HR systems and a telephone database as well as a variety of systems on both the Australian Defence Secret and restricted networks . Existing legacy systems remain and are dynamically linked to eB2Bcom View500, allowing either for periodic update or live linkage (i.e. when a change is made in eB2Bcom View500, it is reflected in the legacy system, or visa versa depending upon the specified relationship).
The new Australian Department of Defence Identity Management infrastructure Directory is accessed through a specially configured eB2Bcom View500 Web Directory User Agent (DUA), offering simple but powerful search capabilities, including phonetic and intelligent sub-string matching. Users can search for a particular person, or browse through the entire directory. The system administrator, using either a Web based or Windows DUA, performs administration. This allows full maintenance of all data records, the ability to move entire branches by a simple drag and drop operation, system backup and report generation (including production of a paper based directory when required). An SNMP interface links eB2Bcom View500 to the Department's on-line systems monitor, providing real-time systems performance monitoring. Australian Defence with its requirements for mission critical performance has multiple View500 licences and requires 24x7x365 operation with 99.99% availability.
c) Defence Tactical deployment
In most Defence CONOPS (Concept of Operations), as part of the ORBAT (Order of Battle) a Defence Task Group will typically have one or more tactical headquarters. Each of these installations will have sophisticated computing and communications infrastructures. In most cases a number of tactical directories will be used to support messaging and other infrastructure in each of these Tactical Headquarters (HQs). As Defence organisations move to more NCW (Network centric Warfare) this requirement will only grow and normally Tactical HQs will be at least duplicated with one HQ echelon always on the move in nul emission control situations whilst the other is up and running operationally. This infrastructure for a tactical HQ will typically be put together over a few days before an operation. In these cases , setting up the directory, and tearing it down must be achievable and straightforward and fast as well as easily repeatable to support multiple sets of infrastructure and partial or total destruction of this infrastructure. The key for this situation is View500 support of X.500 DISP where each Directory can receive just the amount of information it needs to function without the need to hold unnecessary amounts of information. View500 is also very easy to use and provides a variety of functions designed to make it ideal in the Tactical deployment scenario.
d) Hub Coalition Border Directory
One of the requirements needed by most Defence Forces worldwide is the need to support coalition operations and inter coalition communications.
Part of that requirement to support Network Centric Warfare (NCW) especially between the Partner for Peace nations is the deployment of an ACP 145 Coalition Gateway and a Coalition Border Directory. This Directory needs to hold key addressing information and security policies to allow communications between Allied Forces. View500 has been fully tested and deployed in this scenario as Australia’s Border directory and in communication with Border Directories used by a number of other countries including the United Kingdom. With its support for X.525 Directory synchronisation protocol, View500 has also been deployed in the Allied Border Directory scenario and has been used by Australia in a number of JWID and CWID programs. View500 has undergone extensive testing with the Nexor Military Messaging system and the ISODE Directory Servers in this Border role.
e) Proxy Directory Guard
View500 can be used as a Proxy X.525 Directory server when deployed in the Directory Guard scenario. In this scenario 2xView500 licences are deployed with the Clearswift EAL 4 evaluated Directory Bastion Guard solution. The Clearswift Directory Bastion role is to provide assured network separation supporting only the DISP ITU-T Rec. X.525 protocol between explicitly identified Directory servers deployed in a Red Black network configuration where data is required to be synchronised between directory servers on two otherwise disjointed networks.. That is two networks operating at different classification levels or similar levels, but where classified network separation is required. In this View500 is deployed on both sides of the Directory Bastion as a Directory Bastion and supports strong authentication for all server to server operations. Because DISP is the standard protocol to synchronise directory data between View500 DSAs, a Directory Bastion can be inserted between two View500 DSAs without requiring anything other than normal shadowing agreement configuration on the View500 DSAs. Apart from network level addressing, the Directory Bastion is entirely transparent to the View500 DSAs
f) Public Key Infrastructure (PKI) and Trusted Third Party deployments
Identity Management solutions provide the foundation of the digital certificate identity verification services Trusted Third Parties (TTPs) provide a range of PKI and Timestamping services on behalf of industry associations, corporate organizations, government and citizens. By deploying Identity Management solutions, TTPs will: need to support rapidly growing user population to cover initial cost commitments and enabling cost containment in provision of secure authentication services.
View500 is designed to provide a 24x7 Provide 99.99% availability of service to conform with SLA’s. View500 also has a number of unique features designed to support deployments support the use of PKI. In this scenario, View500 support for Password encryption, strong authentication using X.509 PKI certificates and more importantly Component matching can rapidly assist in the speed of processing and retrieval of information such as Certificate status.
| |