Security Plugins
Part 1: Welcome to Security Plugins
- 1. Overview
- 1.1. Description of DDS System Threats
- 1.2. Applying DDS Protection
- 1.3. Introduction to the Security Plugins
- 1.4. Choosing the Right Approach to Protect Your Data
- 2. Using Security Plugins
- 3. Quick Start: Primary Security Configurations
Part 2: Core Concepts
- 4. Elements of a Security Plugins System
- 4.1. Security Plugins Properties
- 4.1.1. Simplified Artifacts Configuration
- 4.1.2. Security Plugins Global Properties
- 4.2. Public Key Infrastructure (PKI)
- 4.3. Governance Document
- 4.4. Permissions Document
- 4.5. Security Builtin Topics
- 4.1. Security Plugins Properties
- 5. Authentication
- 5.1. Handshake
- 5.2. Authentication Builtin Topic (ParticipantStatelessMessage)
- 5.3. Related Governance Rules
- 5.4. Cryptographic Algorithms
- 5.5. Advanced Authentication Concepts
- 5.5.1. Protecting Participant Discovery
- 5.5.2. Identity Certificate Chaining
- 5.5.3. Re-Authentication
- 5.5.4. Guidelines for Minimizing Authentication Negotiation Times
- 5.5.5. Dynamic Certificate Revalidation
- 5.5.6. Dynamic Certificate Revocation of Remote DomainParticipants through Whitelisting
- 5.5.7. CRL Expiration
- 5.5.8. Dynamic Certificate Renewal of a DomainParticipant
- 5.5.9. Online Certificate Status Protocol
- 5.6. Properties for Configuring Authentication
- 6. Access Control
- 6.1. Governance Document
- 6.2. Permissions Document
- 6.3. Related Governance Rules
- 6.4. Advanced Access-Control Concepts
- 6.5. Properties for Configuring Access Control
- 7. Cryptography
- 7.1. Introduction
- 7.2. Cryptographic Algorithms
- 7.3. Secure Entities
- 7.4. Secure Key Exchange Channel (ParticipantVolatileMessageSecure Topic)
- 7.5. Securing DDS Messages on The Wire
- 7.6. Security Protections Applied by DDS Entities
- 7.7. Related Governance Rules
- 7.7.1. Understanding ProtectionKinds
- 7.7.2. Domain-Level Rules
- 7.7.2.1. rtps_protection_kind (domain_rule)
- 7.7.2.2. rtps_psk_protection_kind (domain_rule)
- 7.7.2.3. discovery_protection_kind (domain_rule)
- 7.7.2.4. liveliness_protection_kind (domain_rule)
- 7.7.2.5. monitoring_metrics_protection_kind (domain_rule)
- 7.7.2.6. monitoring_logging_protection_kind (domain_rule)
- 7.7.2.7. service_request_protection_kind (domain_rule)
- 7.7.2.8. instance_state_consistency_protection_kind (domain_rule)
- 7.7.2.9. type_lookup_protection_kind (domain_rule)
- 7.7.2.10. allowed_security_algorithms (domain_rule)
- 7.7.2.11. enable_key_revision (domain_rule)
- 7.7.3. Topic-Level Rules
- 7.8. Advanced Cryptography Concepts
- 7.8.1. Reliability Behavior When MAC Verification Fails
- 7.8.2. Configuring Reliability Protocol Settings of the Secure Key Exchange Topic
- 7.8.3. Securing Application-Level Acknowledgments
- 7.8.4. Origin Authentication Protection Implications
- 7.8.5. Reencoding Protected Data when Regenerating Keys
- 7.8.6. Interactions with Persistence Service
- 7.8.7. Interactions with FlatData and Zero Copy
- 7.8.8. Lightweight Security Pre-Shared Key RTPS Protection
- 7.8.9. Interactions with Instance State Consistency
- 7.8.10. Interactions with TypeLookup Service
- 7.9. Properties for Configuring Cryptography
- 8. Security Events and Logging
- 9. Data Tagging
- 10. Building and Running Security Plugins-Based Applications
- 10.1. Linking Applications with the Security Plugins
- 10.2. Mixing Libraries Not Supported
- 10.3. Properties for Enabling Security
- 10.4. Advanced Concepts
- 10.5. Platform-Specific Notes
- 10.6. Libraries Required for Using the Builtin Security Plugins
- 10.7. Libraries Required for Using the Lightweight Builtin Security Plugins
Part 3: Advanced Concepts
- 11. Using STRIDE Threat Modeling to Analyze Security Risks in DDS Systems
- 11.1. Introduction to Threat Modeling
- 11.2. Simplified DDS Security Threat Model
- 11.3. Introduction to STRIDE
- 11.4. Detailed DDS Security Threat Model
- 11.5. Configuration Examples for Common Threat Scenarios
- 12. Design Considerations
- 12.1. Time Requirements for Security Plugins
- 12.2. Security Considerations for Expiration and Banishment
- 12.3. Factors Affecting Performance and Scalability in General
- 12.4. Security Plugins’ Impact on Scalability at Startup
- 12.5. Security Plugins Impact on Scalability and Performance During Steady State
- 12.5.1. Overhead of the Different Protection Kinds
- 12.5.2. Factors Impacting Performance and Scalability During Steady State
- 12.5.2.1. Performance Impact of Different Protection Kinds
- 12.5.2.2. Interaction Between the Security Plugins and Batching QoS
- 12.5.2.3. Interaction Between the Security Plugins and Multicast
- 12.5.2.4. Interaction with Reliability
- 12.5.2.5. Scalability Considerations for Origin Authentication Protection
- 12.5.2.6. Interaction with Content Filtered Topics
- 12.5.2.7. Interaction with Topic Queries
- 12.5.2.8. Interaction with Asynchronous Publishing
- 12.5.2.9. Interaction with Compression
- 12.5.2.10. Interaction with CRC
- 12.5.2.11. Interaction with Transport UDPv4_WAN
- 12.6. Recommendations for Usage with Observability Framework
- 12.7. Security Considerations when Enabling Compression
- 12.8. Considerations when Enabling OCSP
- 12.9. GUID consistency enforcement
- 12.10. Recommendations When Enabling ROS 2 Interoperability
- 13. Best Practices
- 13.1. Choosing the Granularity of Your Permissions Documents for DomainParticipants
- 13.2. Using Serialized Data Protection Along with Submessage/RTPS Protection
- 13.3. Using Separate Domains for Secure and Unsecure Participants
- 13.4. Keeping Governance and Permissions Compatibility Across Different Security Plugins Versions
- 14. Support for OpenSSL Providers
- 15. What’s Different Between the Security Plugins and the OMG Security Specification
- 15.1. Differences Affecting Builtin Plugins to be Addressed by Next DDS Security Specification
- 15.2. Differences Affecting Builtin Plugins
- 15.3. Differences Affecting Custom Plugins
- 15.3.1. Authentication
- 15.3.2. Access Control
- 15.3.2.1. check_remote_topic
- 15.3.2.2. check_local_datawriter_register_instance
- 15.3.2.3. check_local_datawriter_dispose_instance
- 15.3.2.4. check_remote_datawriter_register_instance
- 15.3.2.5. check_remote_datawriter_dispose_instance
- 15.3.2.6. check_local_datawriter_match / check_local_datareader_match
- 15.3.2.7. Revocation
- 15.3.2.8. PermissionsToken
- 15.3.3. Cryptography
- 16. Pre-Shared Key Protection
- 17. The Lightweight Builtin Security Plugins
- 18. Relevant Connext APIs
Part 4: Integration with other RTI Connext Products
- 19. DDS Security Data Visualization with RTI Administration Console
- 20. Support for RTI Infrastructure Services
- 21. Support for RTI Real-Time WAN Transport
- 22. Support for RTI Observability Framework
- 22.1. Security for Telemetry Data
- 22.1.1. Securing Telemetry Data with Security Plugins
- 22.1.1.1. Creating a Governance Document for Observability Framework
- 22.1.1.2. Creating a Permissions Document for Collector Service
- 22.1.1.3. Creating a Permissions Document for Monitoring Library 2.0
- 22.1.1.4. Enabling Security Plugins in Collector Service
- 22.1.1.5. Enabling Security Plugins in Monitoring Library 2.0
- 22.1.2. Securing Telemetry Data with Lightweight Builtin Security Plugins
- 22.1.1. Securing Telemetry Data with Security Plugins
- 22.1. Security for Telemetry Data