RFP_DOC52PAPT1300015_IDEAI2_Unrestricted.pdf
PDF 534 KB Posted
- Attached to
- Infrastructure, Design, Engineering, Architecture, and Integration, (IDEAI-2) Full and Open Federal contract opportunity
- Solicitation number
- DOC52PAPT1300015
About this file
Request for Proposals Full and Open
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP_DOC52PAPT1300015_Amendment_1.pdf | ||
| Attachment_05_(GD17).doc | DOC document | |
| Attachment_12_(Termination_Worksheet).doc | DOC document | |
| Attachment_13_(Experience_Reference_Worksheet).doc | DOC document | |
| Attachment_04_(PN01).doc | DOC document | |
| Attachment_01_(FN01).doc | DOC document | |
| Attachment_06_(TM02).doc | DOC document | |
| Attachment_03_(GD16).doc | DOC document | |
| Attachment_10_Contract_Actuals_Templates.xls | XLS spreadsheet | |
| Attachment_02_(FN07).doc | DOC document | |
| Attachment_11_(Labor_Categories)_full_and_open.xls | XLS spreadsheet | |
| Attachment_07_(Document_Receipt).doc | DOC document | |
| Attachment_09_(Invoices).xls | XLS spreadsheet | |
| Attachment_08_(Weekly_Funding_Analysis).doc | DOC document |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DOC52PAPT1300015
PART I - THE SCHEDULE
Section B – Supplies or Services and Prices/Costs
The Government expects to award at least one contract as a result of this competition, but reserves the right to make multiple awards. Should more than one contract be awarded, the Government will allocate the work through managed competition between the Contractors, in accordance with Section G.
B.1 Period of Performance
Base Period March 1, 2014 – February 28, 2015
Option 1 March 1, 2015 – February 28, 2016
Option 2 March 1, 2016 – February 28, 2017
Option 3 March 1, 2017 – February 28, 2018
Option 4 March 1, 2018 – February 28, 2019
B.2 Maximum Contract Limitation
The maximum cumulative ceiling value of all contracts awarded under this procurement is established at $TBD.
B.3 Labor Hour Estimate
The Contractor shall provide all labor required to support the tasks awarded under this contract, utilizing the labor categories and rates specified in Attachment 11, Labor Categories and Rates.
The following tables specify the maximum obligation of the Government.
(a) CLIN 001
Period of Performance
Total Number Labor Hours
Hourly Labor Rate, Off-Site (Contractor
Site)
Hourly Labor Rate, On-Site (Government
Site)
Base Year See See March 1, 2014 – February 28, 2015 65,600 Attachment 11 Attachment 11 Option Year 1 See See March 1, 2015 – February 28, 2016 65,600 Attachment 11 Attachment 11 Option Year 2 See See March 1, 2016 – February 28, 2017 65,600 Attachment 11 Attachment 11 Option Year 3 See See March 1, 2017 – February 28, 2018 65,600 Attachment 11 Attachment 11 Option Year 4 See See March 1, 2018 – February 28, 2019 65,600 Attachment 11 Attachment 11
TOTAL Labor Hours: 328,000
TOTAL Estimated Price $ $ $
(b) Optional Quantities
(1) CLIN 002A
Period of Performance
Total Number Labor Hours
Hourly Labor Rate, Off-Site (Contractor
Site)
Hourly Labor Rate, On-Site (Government
Site)
Base Year See See March 1, 2014 – February 28, 2015 25,000 Attachment 11 Attachment 11 Option Year 1 See See March 1, 2015 – February 28, 2016 25,000 Attachment 11 Attachment 11 Option Year 2 See See March 1, 2016 – February 28, 2017 25,000 Attachment 11 Attachment 11 Option Year 3 See See March 1, 2017 – February 28, 2018 25,000 Attachment 11 Attachment 11
March 1, 2018 – February 28, 2019 25,000 Attachment 11 Attachment 11
TOTAL Labor Hours: 125,000
(2) CLIN 002B (Optional Quantities)
Period of Performance
Total Number Labor Hours
Hourly Labor Rate, Off-Site (Contractor
Site)
Hourly Labor Rate, On-Site (Government
Site)
Base Year See See March 1, 2014 – February 28, 2015 25,000 Attachment 11 Attachment 11 Option Year 1 See See March 1, 2015 – February 28, 2016 25,000 Attachment 11 Attachment 11 Option Year 2 See See March 1, 2016 – February 28, 2017 25,000 Attachment 11 Attachment 11 Option Year 3 See See March 1, 2017 – February 28, 2018 25,000 Attachment 11 Attachment 11
(3) CLIN 002.C (Optional Quantities)
Period of Performance
Total Number Labor Hours
Hourly Labor Rate, Off-Site (Contractor
Site)
Hourly Labor Rate, On-Site (Government
Site)
Base Year See See March 1, 2014 – February 28, 2015 25,000 Attachment 11 Attachment 11 Option Year 1 See See March 1, 2015 – February 28, 2016 25,000 Attachment 11 Attachment 11 Option Year 2 See See March 1, 2016 – February 28, 2017 25,000 Attachment 11 Attachment 11 Option Year 3 See See March 1, 2017 – February 28, 2018 25,000 Attachment 11 Attachment 11
B.4 Contract Type
The Government contemplates awarding at least one Labor Hour contract resulting from this solicitation. The contract award will consist of a base period (effective date of award for one year) and four (4) one-year options.
B.5 Task Order Structure
(a) The Contractor shall have the capacity and capability to perform all aspects of the work identified in Section C, Description/Specifications/Work Statement. Work to be performed under the terms of this contract will be awarded to Contractors by issuance of task orders.
(b) Task orders may be discrete task orders for engineering or design efforts, or level-of-effort task orders for infrastructure, design, engineering, architecture or integration efforts. All task orders will be issued on a Labor Hour basis.
(c) Task orders will be performance-based and will include the performance metrics when issued.
B.5.1 Level of Effort Tasks
The Contractor shall perform all work and provide all required task order deliverables within the level of effort specified in Section B.3. The Government intends to order up to 65,600 direct labor hours during the contract base year and during each option period, an amount which represents the Government’s best estimate of the level of effort required to fulfill its requirements. Should there be multiple awards under this effort, these labor hours are the cumulative level of effort planned in each base and option year periods (total of all labor hours on all awards resulting from this solicitation).
B.5.2 Labor Hour Contract Completion Tasks
Task orders issued for design and engineering efforts, which may be referred to as discrete task orders, are completion tasks. The Contractor is expected to provide all labor required to complete each awarded task.
B.5.3 Labor Hour Pricing Rates
(a) All task orders will be priced in accordance with the labor categories and rates set forth in Attachment 11, Labor Categories and Rates, which represents fully-loaded hourly rates for each skill classification. Fully-burdened labor rates include all direct, indirect, general and administrative costs and profit associated with providing the required skill. The fully-burdened labor rates include all labor and labor-related costs, such as, but not limited to, the following list of representative labor-related costs: salaries, wages, bonuses to include stock bonuses, incentive awards, employee stock options, stock appreciation rights, employee stock ownership plans, employee insurance, fringe benefits, contributions to pension, other post-retirement benefits, annuity, employee incentive compensation plans, incentive pay, shift differentials, overtime, vacation time, sick pay, holidays, and all other allowances based upon a comprehensive employee compensation plan. The use of uncompensated overtime is not encouraged. All hourly rates are based on a 40-hour work-week (ex. 2,000 hours per year or in accordance with the Contractor’s Cost Accounting Standards (CAS) Disclosure Statement), if available. The loaded hourly rates are ceiling price rates and the Contractor may, at its discretion, elect to propose lower hourly rates on a task by task basis.
(1) Government Site Rates. When performing at Government sites, the Contractor shall furnish fully-burdened labor rates. The Government will provide only office space, furniture, office equipment, and supplies as specified in each individual Task Order.
Office equipment would include the use of personal computers and office automation software, to the extent that the Contractor personnel have been granted access to USPTO IT systems. For pricing purposes, Offerors should assume Government provision of personal computers.
(2) Contractor Site Rates. When performing at a Contractor site, the Contractor shall furnish fully-burdened labor rates which include loads for office space and all normal supplies and services required to support the work. This includes, but is not limited to, telephones, faxes, copiers, personal computers, postage (to include courier services such as Federal Express), ordinary business software (e.g., word processing, spreadsheets, graphics, etc.), normal copying and reproduction costs.
(b) Program Management Support Costs. Contract-level program management support costs are deemed indirect costs, and are therefore included in the total hourly labor rates for each task order, and encompass support for contract-level management, reporting requirements (See Section F) and related travel and meeting attendance costs associated with the Contractor’s program management staff, as it relates to overall management of the IDEAI-2 program. These “program management” support costs are differentiated from individual task order “Task Order Manager” or “Project Manager” support costs, which are billed as direct costs against individual task orders for direct support to the effort performed under those task orders. This will result in direct billings at the task order level for labor hours in the “Task Order Manager” or “Project Manager” categories, to specifically support project management for the task order.
B.5.4 Rate Refreshment
(a) The labor rates are fixed for all contract year periods, however, the Contractor may submit a proposal reducing the fixed labor rates at any time during the life of this contract. The proposed labor rates for the out years for Option 1 – Option 4 should be all inclusive of any escalations.
The Government will review these proposals and determine if the revised rates are realistic and in the best interest of the Government. If the rates are accepted, the Government will modify the contract by incorporating the new rates into the contract.
(b) At any time and throughout the life of the contract, at the request of either the Contractor or the Government, the Contractor may propose additional labor categories, rates and descriptions in addition to the Government labor categories. These additional labor categories, rates and descriptions will be negotiated on a case-by-case basis (See Section G. for process). The additional categories, rates and descriptions proposed, upon determination by the Government that they are fair and reasonable, will be incorporated by modification into the contract.
B.5.5 Indirect Labor
Contractor employees who do not provide direct services to the Government under the IDEAI-2 contract, but who instead provide support or contribute to the overall operation of the Contractor’s company, such as company management, accountants, attorneys, and other company-wide staff not specifically supporting the IDEAI-2 program, are termed “indirect labor”. Indirect labor costs shall be included in the Contractor’s indirect pool. Task orders for any indirect labor shall not be issued under the IDEAI-2 contract.
B.5.6 Other Direct Costs (ODCs)
All authorized ODCs associated with this contract will be included in task orders and shall be approved by the Contracting Officer (CO). Other direct costs include all direct costs required in the performance of a task order that are not attributable to labor costs. ODCs shall be reimbursed on a time and material basis, unless otherwise negotiated prior to issuance of a task order. Parking at the USPTO for Contractors who are located on the government’s site are considered “commuter expenses” and are not reimbursable costs. Any travel cost authorized under this contract shall be accomplished and billed in accordance with current Federal Travel Regulations and rates.
B.6 Task Orders
(a) The Contractor shall perform work under this contract as specified in awarded task orders issued by the Contracting Officer and as specified in the Task Management Plan (TM02) (refer to Section J.2, Attachment 6).
(b) The USPTO will provide each Contractor with a Task Order Statement of Work (TOS) for each task order required. Contractors are required to submit a Resource Estimate (FN07) for each TOS provided. Resource Estimates shall follow the format specified in Section J.2, Attachment 2. The USPTO will make an award selection based upon the resource estimates.
(c) A Task Management Plan (TM02) is required for every task order. Each Task Order will include:
(1) A numerical designation
(2) The estimate of required labor hours and cost ceiling
(3) The period of performance and schedule of deliverables
(4) The description of the work (consisting of clearly defined task objectives, scope, methodology, resource requirements, and milestones)
(5) Identification of the period (base, option period 1, etc.) to which the Task Order is to be charged if the contract includes overlapping periods.
(d) The Contractor shall acknowledge receipt of each task order by returning to the Contracting Officer a signed copy of the task order within five (5) calendar days after its award and receipt.
The Contractor shall begin work on the Task Order in accordance with the effective date indicated on the Task Order.
(e) Task orders shall not change any terms or conditions of the contract. Where any language in the work assignment may suggest a change to the terms or conditions, the Contractor shall notify the Contracting Officer within five (5) calendar days after receipt of a task order. In the event of a discrepancy between the terms and conditions of the contract and the terms and conditions of a task order issued under the contract, the terms and conditions of the contract shall take precedence until a clarification is made, in writing, by the Contracting Officer.
B.7 Task Order Implementation
(a) A Task Management Plan with detailed descriptions of tasks to be performed, work or deliverables to be produced and task due dates, is required for all discrete and level-of-effort task orders. In addition, all discrete task orders must have a baselined project plan before the task order will be negotiated and approved. Level-of-effort type task orders will not require a project plan. Task Order modifications shall be documented by a Task Management Plan revision (CDRL TM02) (refer to Section J.2, Attachment 6 of this solicitation).
(b) Following execution of the Task Order, technical clarifications may be issued in writing at any time by the COR to amplify or provide additional guidance to the Contractor regarding the performance of the Task Order.
(c) Pursuant to the FAR Clause 52.243-3, Changes-Time-And-Materials or Labor-Hours (Sept 2000) as contained in Section I.6 of this solicitation, the Contractor shall notify the Contracting Officer immediately of any instructions or guidance the Contractor considers to be a change to the Task Order which will impact the cost, schedule or deliverable content of the baseline work plan. In cases where technical instructions or other events may dictate a change from the baseline, task orders may be formally amended to reflect modifications to tasking. The Contractor is responsible for revising the work plan to reflect task order amendments within 5 working days following negotiation or issuance of a modification of the task order.
SECTION C - DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
C.1 Descriptions
The Contractor shall furnish the necessary personnel, material, equipment, services and facilities (except as otherwise specified), in performance of the following Statement of Work/Specifications.
C.1.1 Background
(a) The mission of the United States Patent and Trademark Office (USPTO) is to administer the laws and regulations related to patents and trademarks in order to promote industrial and technical progress in the United States and strengthen the national economy. The USPTO carries out its mission by examining patent and trademark applications, issuing patents and registering trademarks, disseminating patent and trademark information to the public and by encouraging a domestic and international climate in which intellectual property can flourish.
(b) Consistent with the President's Management Agenda, the USPTO is committed to improving transparency in its operations to enhance quality and public confidence. This means reporting information that is more meaningful about workloads and performance. It also means the information shall present a real basis for measuring improvements. The USPTO estimates that by the year 2017 over 692,000 patent applications and more than 517,000 trademark applications will be submitted annually. An estimated 1,200 additional patent examiners are to be hired each year for the next five years in an attempt to reduce patent pendency, which will substantially increase system workloads, and require establishment of remote sites throughout the country.
(c) To support this significant increase in workloads, the USPTO is aggressively pursuing the design and development of new automated information systems and the refinement of existing information systems that will provide automated support to the patent and trademark application processing and examination functions, and dissemination of patent and trademark information to the public through the year 2017 and beyond. For the USPTO to be ready to meet the challenges brought on by the aforementioned increases in application filings, it must meet tight deadlines for its system planning, design and engineering activities, which underscores the importance of prescribing sound foundational designs.
C.1.2 Purpose
(a) The USPTO has a continuing requirement for Infrastructure, Design, Engineering, Architecture, and Integration, (IDEAI-2) contractor(s) to provide independent, objective, and expert technical advice and assistance for ongoing and future information technology initiatives.
(b) The requirement is to provide Network Engineering, Security Engineering, Public Key infrastructure (PKI), Unified Communications Engineering (Voice, Collaboration) and Video Engineering services.
(c) Examples of technical efforts include, but are not limited to, the planning, design, and implementation of office automation capabilities linked together through a USPTO-wide and wide area or remote (Telework) communications network.
C.1.3 Technology and Infrastructure Descriptions
(a) The Communication Services Branch (CSB) staff is responsible for all of the USPTO’s data network, Public Key Infrastructure, security, unified Communications (voice/collaboration) and video communication infrastructure requirements, including telecommunications architecture, collaboration architecture, network design, network cabling, network engineering, wireless communications, and telephony. The CSB manages the Voice over IP systems (VOIP), voicemail systems, call accounting systems, and video teleconferencing capabilities, secure remote access capabilities, monitoring, reporting on activities and performance, capacity planning of network resources, and advising the IEO Director on recommended actions. The CSB manages vendors that provide telecommunications services to the USPTO and is responsible for ordering telecommunications products and services.
(b) The staff is responsible for the engineering, operations and maintenance, the network technology hardware and software, and telecommunications capabilities deployed in support of the USPTO business processes. As the USPTO’s telecommunications provider, the staff is responsible for providing network and telecommunications services to effectively deliver voice, video, collaboration, data and security communications among the USPTO’s users. To accomplish this, the CSB must be able to:
(1) Provide network and telecommunications services to meet all customer requirements of availability, response times, and problem resolution,
(2) Monitor network traffic and security events and take effective and timely corrective measures to address vulnerabilities, and
(3) Manage capacity planning effectively to optimize current and projected network utilization.
(c) CSB staff manages and provides 24/7 engineering, operation and maintenance with on-site and on-call engineering support of the following:
(1) Patent and Trademark Network (PTONet: LAN/WAN) infrastructure; network security infrastructure; Enterprise Management System (EMS); Public Key Infrastructure (PKI);
Enterprise Contact Center System (ECC); Remote access/Tele-work systems (ERA, SEAS, EAIS, CAS); OFDnet; OHRnet; TRInet, UPWS, Wireless, DR Site.
(2) VOIP, Collaboration tools and VTC.
(d) The staff has two objectives. First is to improve the services provided so that customers have timely, reliable, innovative, and cost-effective access to USPTO information technology when and where they need it. The second objective is to manage costs so that the increasing number of customer information technology requirements may be met. The achievement of these objectives will enable the staff to better meet and exceed customer commitments and established service level agreements.
(e) The CSB functions and responsibilities break down into the infrastructure capabilities of Voice Networks, Public Key Infrastructure, Collaboration Services, Video Conferencing Services, Data Networks and Security Networks for Engineering, Operation and Maintenance and Development, Modernization and Enhancement.
C.1.3.1 Voice Systems & Support
C.1.3.1.1 Voice Systems (PBX)
(a) The Voice System provides VOIP voice communications capabilities for the Carlyle campus in Alexandria, Virginia the Randolph Square Building in Shirlington, Virginia, the Nationwide Work Force (NWF) Facilities (Detroit, Dallas, Denver and Silicon Valley), and ERA users. Support for the USPTO’s phone system is geographically dispersed across a ten HQ building campus in addition to the NWF locations.
(b) The CSB/Voice Services Group is responsible for all of the USPTO’s telephony and wireless communications requirements. These responsibilities include support of the VOIP system, voice circuits located on the USPTO’s OC192, voicemail system, call accounting system, and video teleconferencing capabilities within USPTO. The primary goal of the Voice System is to provide voice communication to all USPTO employees and contractor support personnel no matter where they are located.
(c) The current system consists of the Cisco infrastructure that has provided USPTO voice communications integrated with collaboration tools and WebEx. The current system provides local, long distance, and international calls to users, voicemail, and processes 750k number of calls per month to the PSTN and the Enterprise Call Center (ECC).
(d) The Cisco VoIP solution also supports a very large Work-at-Home (W@H) Patent and Trademark workforce numbering ~5000 employees. The Cisco VoIP solution provides enhanced telephony capabilities as well as provides an improved solution for remote users either at home or at a remote office location. The user will also have increased flexibility of 'personalizing' their phone and voicemail through the use of web pages.
(e) CISCO Voice Systems VoIP architecture is in production:
(1) operating on approximately 26 appliances;
(2) using 3 versions of the CISCO IOS operating system;
(3) supported by 5 COTS software products;
(4) requiring 3 interfaces to other AIS; and
(5) CISCO Voice Systems VoIP consumes data from voice communications and supplies data to PSTN and ECC.
(f) The VoIP system provides key customer, performance, and support services for a customer base of 12000 subscribers. The USPTO’s PBX system currently has over 15000 active ports providing voice communications. The goal of the VoIP system is to provide effective, efficient, and highly available voice communications for all USPTO’s business units and work at home personnel.
C.1.3.1.2 Unified Business Collaboration System
A unified communication and collaboration system provides a geographically dispersed/remote workforce with the tools to communicate effectively. A unified communication and collaboration system provides employees with presence information, unified messaging, and conferencing capabilities. Presence combines calendar data with desktop activity to provide an indication of a user’s availability. Unified messaging enables users to manage their voicemail, email, calendar events, and instant messaging in one inbox. With conferencing capabilities, a user can escalate a voice call or install message into a conference call with a single mouse click. Conferencing provides users with the ability to share their desktop, conduct interactive presentations, and run online meetings from their desktop.
C.1.3.1.3 Public and Enterprise Wireless 802.11n LAN
(a) Wireless LAN (WLAN) is a productivity enhancer for USPTO staff, guests, and contractors. A smoothly-implemented WLAN facilitates secure network connectivity from anywhere within USPTO’s space. It also provides simple flexibility for cube-sharing, hoteling, and other situations where staff move around and the number of network connections varies over time.
(b) WLAN supports document sharing and remaining connected during meetings. Instead of making a paper note and emailing a document at the end of the day, a meeting attendee can make it happen immediately. Similarly, immediate web or document storage access provides answers as needed, instead of going away, doing some quick research, and then continuing the discussion at another meeting. WLAN also supports the use of 802.11 phones that are integrated with the USPTO Cisco VOIP system.
(c) WLAN supports wireless useful for connectivity while doing work in IT East Data Center, IT West Lab, or the Remsen IITF. Desktop Field Support can obtain new assignments without having to return to their offices.
(d) Certain hybrid cell phones can now use 802.11n within a building for voice as well as data, meaning that a cell phone could serve as a desk phone while onsite, with access to many of the same functions.
C.1.3.2 Network Systems and Engineering Support
C.1.3.2.1 Network Engineering Services
(a) The Network Engineering Team provides support for the network infrastructure for all USPTO data/voice/video communications efforts; provides final engineering designs for the network infrastructure, including security; engineers voice, video and data integration for all data communications including the USPTO campus (PTONet), and wide area network requirements;
provides support in resolving second and third tier network problems; upgrade, replace, or augment network hardware and software; leverages internet technologies to support USPTO business functions; and establishes remote access capabilities.
(b) The staff provides a full range of infrastructure engineering design, enterprise architecture standards, prototyping, integration, including, but not limited to, concept development, planning, requirements definition and analysis, systems design, integration, and deployment. The following areas are managed and supported by the staff:
(1) Provide Application and System Development Leader (SDL) Project network and security engineering support to the various AISs and SDL development efforts.
(2) Manage on-call, third-level engineering support for the PTONet.
(3) Perform engineering lab testing on major release code upgrades for infrastructure systems, install new code upgrades, and troubleshoot production-related problems on USPTO production Firewall infrastructure devices.
(4) Develop engineering recommendations for improvements to USPTO production network and firewall systems.
(5) Define engineering rule-based change requests (CRs), and provide ad hoc security engineering trouble shooting to USPTO network operations and USPTO C&A teams.
(6) Evaluate network and security products and technologies, as required, such as the following:
a. Oversee vendor discussions and perform hardware/software evaluation testing required to recommend and procure new infrastructure products.
b. Review industry, trade, and vendor documentation to narrow the number of products to be evaluated.
(7) Provide network and security engineering expertise in all of the market- and technology leading network and Firewall products, including Cisco, CheckPoint, and Juniper.
(8) Provide ongoing engineering support for PTONet (both production and development).
This includes more than 11,500 PTONet users and thousands of network devices located throughout multiple buildings in the Alexandria, Virginia campus and the Arlington Randolph Square building.
(9) Provide ongoing support to USPTO for network analysis and isolation of PTONet communication problems and the evaluation of network performance.
(10) Plan, design, deploy, test, document and support the transition of the network equipment to support additional employees and applications in existing and new campus buildings as required.
(11) Plan, design, deploy, test, document and support the transition to Network Operations of the network equipment to support new servers and applications as required.
(12) Provide engineering support for design, testing, configuration, and installation of telecommunications equipment.
(13) Integrate collaboration applications into the network infrastructure including Cisco, Juniper, F5, Bluecoat, Riverbed, Microsoft Sharepoint, Cisco Telepresence, WebEx and Adobe Connect. Engineer QoS and security solutions.
(c) Network Engineering Services provides 24x7 on-site/on-call Tier 2 assistance and Tier 3 network support to resolve networking problems and CPNs involving USPTO switches, routers, firewalls, IDS sensors, Web content filters, enterprise logging and provides Network Engineering solutions for new infrastructure requirements. This includes analyzing, designing, and coordinating deployment solutions for C&A findings, performing evaluations of new network and security hardware and software, provide guidance and support to USPTO SDLs as they implement and upgrade their applications, and performing Enterprise-wide Login engineering in support of the USPTO business areas. In addition, there are several key milestones for specific projects that are listed below:
C.1.3.2.2 Public Key Infrastructure (PKI) Services
(a) The USPTO Public Key Infrastructures (PKI) provides digital credentials for the IT security enhancements of USPTO employees, contractors, and customers to conduct business in a digitally secure manner. The USPTO PKI is used for strong, two-factor based authentication to the USPTO networks and for virtual private network (VPN) access by the employees and contractors. In addition, the USPTO PKI provides secure S/MIME communication and digital signature capabilities. The PKI infrastructure is also used to provide strong authentication of the external customers to access the sensitive patent applications, EFSWeb and Private Patent Application Information Retrieval (Private-PAIR). The PKI infrastructures are architected and deployed to provide flexibility and reliability. They position USPTO to expand its capability for authenticating, securing, and providing non-repudiation for electronic transactions.
(b) USPTO currently supports two PKI infrastructures, external PKI and internal PKI. The internal PKI infrastructure is cross-certified with the Federal Bridge Certificate Authority (FBCA) at a medium assurance level. The internal PKI system is used solely for USPTO’s internal use; i.e.
employees, contractors, and for securing internal communication. The external PKI system supports USPTO’s external customer base.
(c) Both PKI infrastructures are set up using Entrust Security Manager as the certificate authority (CA) software. The internal PKI infrastructure uses smart cards to store the user credentials. The CA keys are protected via SafeNet LunaSA hardware security modules (HSMs). Due to the medium assurance cross-certification with the FBCA, the internal PKI infrastructure is authorized to issue certificates under the provisions of Homeland Security Presidential Directive-12 (HSPD- 12).
(d) The external PKI provides the external customers with soft certificates that they can store on a device of their choice. The external users use their soft certificates and their browsers to authenticate via an Entrust TruePass authentication gateway. Once authenticated, the users can seamlessly navigate to the EFSWeb and Private-PAIR applications. To reduce USPTO administrative costs and overall provisioning delays, customers can access the USPTO Digital Certificate Management (DCM) website to self-manage their certificates. The DCM website uses the Entrust Self-Administration Service (SAS) product to allow users this functionality. A customized portion of SAS allows users to receive seven recovery codes which the users can save and use at a later date in order to recover their digital certificates as needed.
(e) The PKI infrastructure provides the following benefits and functionality to USPTO:
(1) Improved data security
(2) Support for standards-based security mechanisms for communications, authentication, non-repudiation, and security data in transit and at rest.
(3) Improved scalability to support USPTO application as it evolves.
(4) The internal PKI is fully integrated with the USPTO Enterprise Directory Service
(5) Increase in the amount of secure digital transactions performed
(6) Providing a solution to provide strong two-factor authentication
(7) Supporting the HSPD-12 mandate
(f) The PKI infrastructure is designed and configured to support the following functional commitments:
(1) Authentication: The PKI infrastructure authenticates customers, contractors and employees against the USPTO systems to determine accessibility. Due to the nature of two-factor authentication, it also deters attempts to gain unauthorized access. The PKI infrastructure will verify the identity of a user or entity to protect against unauthorized access to a system or the information it contains.
(2) High Availability: The PKI infrastructure is designed for high availability to ensure that when a machine goes down, another machine in the cluster can take over. The users should not receive a disruption in their services.
(g) The success of the PKI infrastructure will be tracked with performance measures based on infrastructure uptime and system availability for end users and AISs. The external PKI system can also be tracked by the continued use of EFSWeb and Private-PAIR applications by the external customers.
C.1.3.2.3 Firewall infrastructure Services
(a) The USPTO Enterprise and Departmental firewall infrastructure represents a technical application of the organization's written network security policies. USPTO Enterprise and departmental firewalls are used to provide security infrastructure to protect USPTO’s internal networks and resources. The firewall components include capabilities that allow for the centralized monitoring and management of data traffic coming in or out of USPTO, permit network-based intrusion prevention, enable user authentication, and allow secured data exchange. The firewall infrastructure provides the flexibility to support and secure USPTO applications/systems as they develop and expand.
(b) The Enterprise firewall Infrastructure consolidates Virtual Private Networks (VPN) termination points, segregates data sensitivity zones, and performs network address translation (NAT) while providing high availability, scalability, and flexibility in the agency. These capabilities result in an improved overall level of security provided to USPTO internal networks.
(c) The existing Enterprise firewall infrastructure consists of: 1) the Juniper EFC, a two-tier firewall in which, all external access is inspected by the Tier 1 firewalls and re-inspected (for both internal and external access); for the sensitive and Highly Sensitive zones by the Tier 2. This firewall currently inspects inbound public web traffic and outbound USPTO web traffic. 2) The Enterprise Trusted User (ETU) firewall (or teleworker/contractor access) firewall. The ETU firewall acts as a USPTO gateway for USPTO trusted users who need access to USPTO resources. The ETU firewall provides (security) functionality and protection between PTONet and trusted user networks. These users can include: a) Enterprise Remote Access (ERA) teleworkers (work from home users) that connect via Virtual Private Networks (VPN) across the Internet and,
b) Contractors with dedicated network connections via the Contractor Access Zone (CAZ). 3) USPTO departmental firewalls such as the Universal Public Workstation System (UPWS) firewall, the RTIS Horsham firewall, RTIS Mill Road firewall used to isolated public and contractor computers from the USPTO network.
(d) In addition, the enterprise firewall systems provide intrusion detection/prevention capabilities along with logging and alerting functions where deep packet inspection is performed by in box and standalone Intrusion prevention devices that are integrated with the firewall systems.
(e) The firewall infrastructure provides the following benefits and functionality to USPTO:
(1) Improved data security
(2) Increased performance and throughput
(3) Improved auditing, alerting, logging and reporting
(4) Reduction in complexity for the firewall subsystems security infrastructure
(5) Improved centralized administration of all firewalls
(6) Increased flexibility for emerging security technologies
(7) Improved scalability to support USPTO application as it evolves.
(8) Increased application security as new capabilities are added
(9) Increased application security performance by providing web caching and SSL acceleration
(10) Continued and improved user authentication via active directory LDAP services to be used to authenticate users and web-based traffic.
(f) The firewall infrastructure is designed and configured to support the following functional commitments:
(1) Access Control: The firewall infrastructure determines, before permitting access, whether a user or entity is authorized to use a USPTO system, network, or resource. It also deters attempts to gain unauthorized access.
(2) Authentication: The firewall infrastructure will verify the identity of a user or entity to protect against unauthorized access to a system or the information it contains.
(3) Confidentiality: the firewall infrastructure works to prevent unauthorized entities or processes may inadvertently access USPTO-sensitive information
(4) High Availability: The firewall infrastructure is designed for high availability to ensure that when a machine goes down, another machine in the cluster can toke over existing connections. These sessions are kept alive and the failover should go unnoticed by the users.
C.1.3.2.4 Enterprise Remote Access - VPN
(a) ERA – VPN enables authorized USPTO personnel to telecommute via secure remote access specifically using Secure Sockets Layer (SSL) Virtual Private Network (VPN) over a broadband Internet connection to the Patent and Trademark Office network (PTONet).
(b) Once a user establishes a VPN session, the user can securely connect to the user’s applications on PTONet using either Microsoft Remote Desktop Protocol (RDP) or Citrix thin client, as if the user was using a workstation in a Carlyle office. Employees with Government Furnished Equipment (GFE) can establish a VPN session using the standard USPTO Universal Laptop (UL). When using employee furnished equipment, a user would execute Microsoft Remote Desktop Protocol (RDP) to the backend resource such as a Universal Laptop. When using the UL platform, all USPTO applications are ported and run locally on the UL’s Windows 7 laptop. To accommodate the additional network load and increase application performance, USPTO has installed the Riverbed WAN Acceleration devices and increased the internet bandwidth. Employees with non-managed clients will be accessing the resources provided on Citrix servers or by the SSLVPN proxy for greater security control.
(c) All clients are subject to anti-virus policy upon login.
C.1.3.3 External Access Systems and Support
C.1.3.3.1 Contractor Access System (CAS)
(a) The Contractor Access System (CAS) is Contractor Access Zone (CAZ) network that provides remote sites (governments and contractors) with access to the USPTO network (PTONet) through the Enterprise Trusted User (ETU) Firewall architecture. These government and contractor remote sites include (a) Government: the Alexandria Warehouse, Boyers EDT, Lorton Warehouse, Springfield Warehouse; (b) Contractors: CSC, 2034 Eisenhower Avenue (Evolver, Avaya, EIS, and ASCR), RTIS Horsham PA, RTIS Eisenhower Center III, GDIT, PPC, ManTech, SRA, and DTSV.
(b) The ETU Firewall filters and monitors all CAZ traffic. Only USPTO-approved remote sites (contractors and government), scanners, workstations and printers are connected to the CAZ network. Server installation is subject to approval by SDL, and Security Office, and Firewall installation is required. CAS users are allowed to access the Internet through the CAZ Internet proxy server. The purpose of CAS is to provide off-site contractors and selected government sites with limited, monitored, and secure access to PTONet applications, resources, and services.
(c) Over the next 5 years, CAS will continue to upgrade the CAZ infrastructure and existing sites to meet the new PTONet III standards. Furthermore, CAS will add new sites for new contractors for realignment. Support of upgrading and/or adding new contractor/government sites, infrastructure and overall health of the CAS will be provided through the below goals and objectives.
(d) The current CAS architecture in production is the CAZ network, which provides contractors with access to the USPTO network (PTONet) through the Enterprise Trusted User (ETU) Firewall architecture. This SOP addresses the Alexandria Warehouse, Boyers, CSC, Eisenhower Avenue, Horsham, Eisenhower Center III, Lorton, and Springfield Warehouse CAZ sites, all of which are located in Virginia and Pennsylvania. The sites change as existing support contracts end and new support contracts start.
C.1.3.3.2 Enterprise Access Infrastructure System (EAIS)
(a) EAIS is designated as an Information Technology Infrastructure system. EAIS is based upon the Axway SecureTransport (formerly named Tumbleweed) products. These products provide an enterprise solution that allows the HTTPS and AS2 protocols to have secure access to USPTO, over the Single Socket Layer (SSL) protocol. In this environment, USPTO uses the Axway Edge Appliance and the Axway Server products. Both products allow USPTO to design a dual-server (two-tier) environment. The Axway Edge Appliance product acts as a proxy for the Axway server, and is located in the Demilitarized Zone (DMZ). The Internet Axway server is located in the Sensitive Zone for security. The Appliance device talks only to the Axway server, which is Active Directory compliant.
(b) Interface to/Integration with other AIS Projects: EAIS provides an opportunity to automate secure file transfers within USPTO production servers and external customers nationally and worldwide. This activity can be performed through the Axway software with minimal effort and support through our servers.
(c) EAIS Internal/External Servers: EAIS consists of four secure file transport servers that transport files between internal and external sites/accounts. Under normal operations, internal users/accounts logon to the internal Axway servers via HTTPS, SSH, and upload/download their files. However, upon customer request, Axway can be configured to monitor specified folders on a network drive and automatically transport any files that may have been sent to those folders.
The Data Management Branch (DMB) has requested this for the SI-International (SI-INT) and RTIS (RTIS-Omaha) sites. Customers are RAMProd for Axway Certificate, New York law school, Google, PTDL, Library of Congress, EPO/JPO, CSS, Patent Peer Review Pilot, Boyers EDT, RTIS Horsham PA, Production Services Branch with 10 production servers writing 24x7 large files data transfer, average 3GB - 50GB per transfer.
(d) External users/accounts: connected to USPTO external File Transport Proxy Appliances located in DMZ sensitive zone, which communicate to the external File Transport Servers.
C.1.3.3.3 Secure External Access Systems (SEAS)
(a) SEAS provide a means for remote users to access USPTO applications and services in a secure manner while mitigating the associated security risks to USPTO. SEAS use a Citrix Farm environment with the remote users gaining access through a virtual private network (VPN) using SSL through the ERA-VPN SSL accelerators. This method limits access for contractor and government users to USPTO infrastructure and to minimize the risk of unauthorized access to that infrastructure.
(b) The primary goal of SEAS is to enable authorized remote users to access USPTO applications and services. The secondary goal is to provide the infrastructure for future secure remote access to USPTO services and applications for both remote USPTO and contractor employees. USPTO personnel and contractors will use their existing broadband Internet connections and equipment to gain access to USPTO applications and services. Encryption and strong two-factor authentication mechanisms for remote users will be included as an integral part of the system. The system is configured to support USPTO personnel and contractor employees who require access to the USPTO network (PTONet) worldwide.
C.1.3.4 External Network Systems and Support
C.1.3.4.1 OHRnet/OFDnet System
(a) The current OHRNET/OFDNET is the extranet infrastructure that provides secure connectivity for all US Department of Agriculture – National Finance Center (NFC) and US Treasury – Financial Management System (FMS) applications and network access from Offices of Finance and Human Resources employees and contractors.
(b) The DMZ based equipment includes:
(1) Servers including domain controllers, file and print servers;
(2) Cisco switches;
(3) Cisco routers;
(4) Cisco Adaptive Security Appliances;
(5) Cisco Security Management appliance;
(6) Advanced Inspection and Prevention Security Services;
C.1.3.4.2 Trilateral Information Network (TriNet) System
(a) TriNet is a Virtual Private Network (VPN) that was initially set up among the Trilateral Offices as directed by the Kyoto Action Plan of November 1997. The TRINet connects the three original partner sites: European Patent Office (EPO), Japan Patent Office (JPO), and the United States Patent and Trademark Office (USPTO). TriNet has been extended to include four additional members: World Intellectual Property Office (WIPO), Korea Intellectual Property Office (KIPO), Canadian Intellectual Property Office (CIPO), Chinese Intellectual Property Office (SIPO) and the Intellectual Property Australia (IPAU). The network is used to exchange sensitive patent information between the corresponding Intellectual Property Organizations (IPOs).
(b) A VPN is functionally a private network overlaid on public networks by the use of end-to-end encryption technology to protect sensitive information. In the case of TriNet, the public network is currently an Internet based service with each international IPO using their existing Internet Service Provider (ISP) for exchanging data between the partners. Data sent over TriNet is encrypted by secure network devices at the network gateway access points. USPTO with EPO and JPO’s agreement selected and deployed the encryption mechanism on TriNet and operates a Network Management System (NMS) that controls the encryption network devices.
(c) TriNet architecture includes (1) operating on 24 appliances, 15 of which are in containment or are standard. The TriNet network provides secure network connectivity for electronic exchange and dissemination of sensitive patent data between authenticated access points at the International Trilateral Offices and TRINet members. The Trilateral Offices consist of the United States Patent and Trademark Office (USPTO), the European Patent Office (EPO), and the Japanese Patent Office (JPO). Other TRINet members include the World Intellectual Property Office (WIPO), the Canadian Intellectual Property Office (CIPO), the Korean Intellectual Property Office (KIPO), Chinese Intellectual Property Office (SIPO) and the Intellectual Property Office of Australia (IPAU).
C.1.3.5 Network, Security and Unified Communication Infrastructure Manufacturers, Devices and Software:
The contractor shall provide staff that has extensive experiencing designing, deploying and troubleshooting the following network and security infrastructure products, including but not limited to:
(a) Cisco
(1) Cisco switches ( Catalyst 6500, Nexus 5000 and Catalyst 3750)
(2) Cisco routers (881W, 3900,V224, 7600)
(3) Cisco Managed Express Virtual Office (MEVO)
(4) Cisco Network Compliance Manager (NCM)
(5) Cisco 3500 servies Wireless Access Points
(6) Cisco 5500 services Wireless LAN Controllers
(7) Cisco Network Control System (NCS)
(8) Cisco Secure ACS RADIUS/TACACS+
(9) Cisco type MCS and UCS servers
(b) Juniper
(1) Juniper switches (4200, 4500)
(2) Juniper Firewalls (Netscreen and JunOS), IDS/IPS, Network and Security
Manager (NSM) and SPACE
(c) Riverbed
(1) Riverbed Steelhead, Interceptor, CMC and Steelhead Mobile Controller
(2) Riverbed Cascade Profiler, Gateway, Sensor and Shark appliance
(d) F5 BigIP LTM, ASM, ACA, WBA, GTM
(e) Infoblox
(f) Bluecoat
(g) Layer 7
(h) VBrick
(i) WebEx
(j) Entrust
(k) RSA
(l) IXIA
(m) Snort
(n) Q-Radar
(o) Connexon
(p) Unimax
(q) Avotus
(r) Microsoft Lync
(s) Network Time Protocol servers including, Symmetricom, Endrun and Spectacom
(t) Bridgewave
(u) Canon
(v) Axway
(w) Citrix
(x) AVTECH
(y) AirMagnet
(z) Splunk
(aa) VMWare
(bb) Cacti
(cc) OPNET IT Guru and ACE Plantronics
C.2 Scope of Work
(a) The Contractor shall provide technical support for all phases of system planning and design through deployment to ensure that USPTO Office of the Chief Information Officer (OCIO) information technology (IT) solutions enable its internal and external users to meet their mission, goals, and objectives. These efforts include the full range of infrastructure engineering design, enterprise architecture standards, prototyping and integration, which may also include but are not limited to, concept development, planning, requirements definition and analysis, systems design, integration, and deployment.
(b) The services under development are complex in scope and far-reaching in application, both within and outside the USPTO. Successful development is largely dependent upon the collective efforts of a staff of diverse technical specialists able to respond quickly to the many variables and conditions that accompany a design and deployment effort of this proportion. There is a need for specialized areas of expertise especially in rapidly changing or evolving technologies.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .