Officer Data Card (Odc) Dissemination Policy, Model, and Blockchain-Based Accountability Mechanism
Total Page:16
File Type:pdf, Size:1020Kb
Calhoun: The NPS Institutional Archive DSpace Repository Theses and Dissertations 1. Thesis and Dissertation Collection, all items 2018-06 OFFICER DATA CARD (ODC) DISSEMINATION POLICY, MODEL, AND BLOCKCHAIN-BASED ACCOUNTABILITY MECHANISM Gentile, Brett Monterey, CA; Naval Postgraduate School http://hdl.handle.net/10945/59665 Downloaded from NPS Archive: Calhoun NAVAL POSTGRADUATE SCHOOL MONTEREY, CALIFORNIA THESIS OFFICER DATA CARD (ODC) DISSEMINATION POLICY, MODEL, AND BLOCKCHAIN-BASED ACCOUNTABILITY MECHANISM by Brett Gentile June 2018 Thesis Advisor: Cynthia E. Irvine Second Reader: Theodore D. Huffmire Approved for public release. Distribution is unlimited. THIS PAGE INTENTIONALLY LEFT BLANK Form Approved OMB REPORT DOCUMENTATION PAGE No. 0704-0188 Public reporting burden for this collection of information is estimated to average 1 hour per response, including the time for reviewing instruction, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing this burden, to Washington headquarters Services, Directorate for Information Operations and Reports, 1215 Jefferson Davis Highway, Suite 1204, Arlington, VA 22202-4302, and to the Office of Management and Budget, Paperwork Reduction Project (0704-0188) Washington, DC 20503. 1. AGENCY USE ONLY 2. REPORT DATE 3. REPORT TYPE AND DATES COVERED (Leave blank) June 2018 Master's thesis 4. TITLE AND SUBTITLE 5. FUNDING NUMBERS OFFICER DATA CARD (ODC) DISSEMINATION POLICY, MODEL, AND BLOCKCHAIN-BASED ACCOUNTABILITY MECHANISM 6. AUTHOR(S) Brett Gentile 7. PERFORMING ORGANIZATION NAME(S) AND ADDRESS(ES) 8. PERFORMING Naval Postgraduate School ORGANIZATION REPORT Monterey, CA 93943-5000 NUMBER 9. SPONSORING / MONITORING AGENCY NAME(S) AND 10. SPONSORING / ADDRESS(ES) MONITORING AGENCY N/A REPORT NUMBER 11. SUPPLEMENTARY NOTES The views expressed in this thesis are those of the author and do not reflect the official policy or position of the Department of Defense or the U.S. Government. 12a. DISTRIBUTION / AVAILABILITY STATEMENT 12b. DISTRIBUTION CODE Approved for public release. Distribution is unlimited. A 13. ABSTRACT (maximum 200 words) The Officer Data Card (ODC) is an automated record that provides up-to-date data about U.S. Navy officers for use in detailing and promotion boards. Policy regarding ODCs requires controlled access and dissemination of ODC information. A better understanding of the policies associated with ODCs could allow current technologies to be employed to support their use and management. This work builds a model for ODC dissemination based on current policies and practices. A process model is built to describe controlled dissemination of ODCs during specific promotion board processes. It is found that the dissemination policies and model for ODCs have a strong similarity to those applied to ORCON-labeled information handled by the intelligence community. With the threat of unauthorized dissemination of ODCs in mind, a blockchain solution is proposed for auditing the access to and modification of ODCs. The proposed solution is a distributed auditing mechanism that does not rely on a central auditing server. The proposed blockchain solution is analyzed and determined to be able to provide accountability for record handling processes and ODC dissemination but does not provide enough new functionality or efficiency beyond that possible through intensive central audit logging. 14. SUBJECT TERMS 15. NUMBER OF personnel records, ODC, originator control, ORCON, dissemination control, access control, PAGES 91 integrity, accountability, audit, OMPF, blockchain, distributed ledger 16. PRICE CODE 17. SECURITY 18. SECURITY 19. SECURITY 20. LIMITATION OF CLASSIFICATION OF CLASSIFICATION OF THIS CLASSIFICATION OF ABSTRACT REPORT PAGE ABSTRACT Unclassified Unclassified Unclassified UU NSN 7540-01-280-5500 Standard Form 298 (Rev. 2-89) Prescribed by ANSI Std. 239-18 i THIS PAGE INTENTIONALLY LEFT BLANK ii Approved for public release. Distribution is unlimited. OFFICER DATA CARD (ODC) DISSEMINATION POLICY, MODEL, AND BLOCKCHAIN-BASED ACCOUNTABILITY MECHANISM Brett Gentile Ensign, United States Navy BS, United States Naval Academy, 2017 Submitted in partial fulfillment of the requirements for the degree of MASTER OF SCIENCE IN COMPUTER SCIENCE from the NAVAL POSTGRADUATE SCHOOL June 2018 Approved by: Cynthia E. Irvine Advisor Theodore D. Huffmire Second Reader Peter J. Denning Chair, Department of Computer Science iii THIS PAGE INTENTIONALLY LEFT BLANK iv ABSTRACT The Officer Data Card (ODC) is an automated record that provides up-to-date data about U.S. Navy officers for use in detailing and promotion boards. Policy regarding ODCs requires controlled access and dissemination of ODC information. A better understanding of the policies associated with ODCs could allow current technologies to be employed to support their use and management. This work builds a model for ODC dissemination based on current policies and practices. A process model is built to describe controlled dissemination of ODCs during specific promotion board processes. It is found that the dissemination policies and model for ODCs have a strong similarity to those applied to ORCON-labeled information handled by the intelligence community. With the threat of unauthorized dissemination of ODCs in mind, a blockchain solution is proposed for auditing the access to and modification of ODCs. The proposed solution is a distributed auditing mechanism that does not rely on a central auditing server. The proposed blockchain solution is analyzed and determined to be able to provide accountability for record handling processes and ODC dissemination but does not provide enough new functionality or efficiency beyond that possible through intensive central audit logging. v THIS PAGE INTENTIONALLY LEFT BLANK vi TABLE OF CONTENTS I. INTRODUCTION..................................................................................................1 A. OBJECTIVES ............................................................................................1 B. RELEVANCE TO THE DEPARTMENT OF DEFENSE .....................2 C. THESIS ORGANIZATION ......................................................................2 II. BACKGROUND AND EXISTING WORK ........................................................5 A. NAVY PERSONNEL RECORDS ............................................................5 1. Record Types ..................................................................................5 2. Construction of Underlying Database ..........................................6 3. Digital Record Storage ..................................................................7 4. Record Access and Maintenance ..................................................7 5. Record Usage ..................................................................................7 6. Record Privacy ...............................................................................8 B. ORIGINATOR CONTROLLED INFORMATION DISSEMINATION .....................................................................................8 1. History of ORCON Models ...........................................................9 2. ORCON Usage Example .............................................................10 C. BLOCKCHAIN TECHNOLOGY ..........................................................11 1. History and Origin .......................................................................12 2. Blockchain Characteristics and Features ..................................14 D. SUMMARY ..............................................................................................18 III. PERSONNEL RECORD MANAGEMENT SCENARIOS .............................19 A. OVERVIEW OF PROMOTION BOARD PROCESS .........................19 B. RECORD HANDLING IN STATUTORY PROMOTION BOARDS ...................................................................................................22 C. STEPS FOR CORRECTING ODC INFORMATION .........................25 1. Determination ...............................................................................25 2. Request ..........................................................................................25 3. Admittance....................................................................................26 4. Resolution .....................................................................................26 D. CONSTRUCTING THE SCENARIOS .................................................27 1. Scenarios .......................................................................................27 2. Variables .......................................................................................27 3. Desired Outcomes ........................................................................28 E. SUMMARY ..............................................................................................28 vii IV. THREAT MODEL...............................................................................................31 A. ASSET EVALUATION ...........................................................................31 1. Confidentiality ..............................................................................31 2. Integrity ........................................................................................32 3. Availability....................................................................................32