The existing tools for collaborative Web-centric engineering design and engineering document management - such as PTC Windchill - provide only rudimentary security features, which are often inconvenient to end users, require significant efforts to manage, and only offer a token protection from attacks by a resourceful adversary. This Phase II project will yield the integrated security infrastructure designed to improve both usability and resistance to various attacks of a range of existing collaborative and engineering applications; and is positioned to be used as a unified platform for future secure application development. The key areas of the proposed development are: universal user identity management, integration of strong cryptography and key management into transport protocol, hardening of higher-level protocol implementations and the application layer, user session management and red-flag alarms, and secure management and distribution of sensitive information such as access control policies. Such integrated security infrastructure may subsequently be used in both government/military and private sectors, particularly in context of increasing integration of commercial off-the-shelf products (such as PTC Windchill) and the resulting necessity to facilitate limited and well-regulated access to the sensitive information by the outside users. The proposed solution can also be used to mitigate known problems - weak authentication protocols, secure user sessions over intermittent connections in the wireless networks.
Keywords: Integrated Security Infrastructure, Web-Centric, Single Sign-On, Identity Management, Pki, Open Architecture, Access Control, Authentication