SBIR-STTR Award

Security for Open Architecture Web-Centric Systems
Award last edited on: 5/28/2008

Sponsored Program
SBIR
Awarding Agency
DOD : Army
Total Award Amount
$810,019
Award Phase
2
Solicitation Topic Code
A02-235
Principal Investigator
Vadim Antonov

Company Information

MAK Solutions Inc

PO Box 1862 Converse Building
Irmo, SC 29063
   (803) 213-1077
   info@maksolutions.biz
   www.makconsulting.com
Location: Single
Congr. District: 02
County: Richland

Phase I

Contract Number: ----------
Start Date: ----    Completed: ----
Phase I year
2003
Phase I Amount
$96,275
MAK Consulting will conduct detailed security analysis of existing solutions, specifically the PTC Windchill and Hyperwave eInfrastructure, and will define the architecture for the middleware layer that satisfies the requirements outlined in this proposal. While PTC suite of CAD tools, document management system and PDM, PLM (Windchill, proEngineer, proDesktop) delivers a very strong functionality required by TARDEC/NAC applications, it has significant security holes and vulnerabilities. MAK Consulting proposes to: ú Offer the design for secure middleware layer and front-end for web-centric, multi-channel (web, wireless, CTI) environment. ú Analyze the suite of PTC products and identify the security gaps. ú Analyze the system integration approach of the PTC products and identify APIs and other ways to extend and intertwine these products with secure middleware. ú Adhere to open architecture principle to facilitate an objective review of the resulting secure portal infrastructure. The work will result in creation of the secure portal infrastructure. Since security is the major drawback for current web-centric and especially wireless applications, offering an open architecture, which has sound security will foster and justify development of various web-centric applications cutting the cost of operation and opening new business opportunities

Phase II

Contract Number: ----------
Start Date: ----    Completed: ----
Phase II year
2003
Phase II Amount
$713,744
The existing tools for collaborative Web-centric engineering design and engineering document management - such as PTC Windchill - provide only rudimentary security features, which are often inconvenient to end users, require significant efforts to manage, and only offer a token protection from attacks by a resourceful adversary. This Phase II project will yield the integrated security infrastructure designed to improve both usability and resistance to various attacks of a range of existing collaborative and engineering applications; and is positioned to be used as a unified platform for future secure application development. The key areas of the proposed development are: universal user identity management, integration of strong cryptography and key management into transport protocol, hardening of higher-level protocol implementations and the application layer, user session management and red-flag alarms, and secure management and distribution of sensitive information such as access control policies. Such integrated security infrastructure may subsequently be used in both government/military and private sectors, particularly in context of increasing integration of commercial off-the-shelf products (such as PTC Windchill) and the resulting necessity to facilitate limited and well-regulated access to the sensitive information by the outside users. The proposed solution can also be used to mitigate known problems - weak authentication protocols, secure user sessions over intermittent connections in the wireless networks.

Keywords:
Integrated Security Infrastructure, Web-Centric, Single Sign-On, Identity Management, Pki, Open Architecture, Access Control, Authentication