Re: [5gangip] Network tokens draft

Yiannis Yiakoumis <yiannis@selfienetworks.com> Fri, 10 July 2020 16:35 UTC

Return-Path: <yiannis@selfienetworks.com>
X-Original-To: 5gangip@ietfa.amsl.com
Delivered-To: 5gangip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6BF43A102A for <5gangip@ietfa.amsl.com>; Fri, 10 Jul 2020 09:35:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=selfienetworks-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JoOrHTppyTBX for <5gangip@ietfa.amsl.com>; Fri, 10 Jul 2020 09:35:32 -0700 (PDT)
Received: from mail-vk1-xa2f.google.com (mail-vk1-xa2f.google.com [IPv6:2607:f8b0:4864:20::a2f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B53EA3A108B for <5gangip@ietf.org>; Fri, 10 Jul 2020 09:35:13 -0700 (PDT)
Received: by mail-vk1-xa2f.google.com with SMTP id h190so1368923vkh.6 for <5gangip@ietf.org>; Fri, 10 Jul 2020 09:35:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=selfienetworks-com.20150623.gappssmtp.com; s=20150623; h=mime-version:message-id:subject:in-reply-to:references:date:cc:from :to; bh=ZqIyPWyOBpUSJbe2y/rT0xqOUe4Cms0uJ8UFJdYbv+E=; b=Xcb1vcQ3s/yuRPsP9pUBSiseAL9xY9CpiHJYEhbnkE90m0iCVlZty97BbAmN4GK/SL EJp2GhMyHvESYQxapgwhuKrdom5RkqOrdTUaN8DmAt8OMeyFm27Ktk45wB2Bd7AQixpx O96OCb/Ew+u1yqo+5vpjWjZzw4Z+LOFBkBTqKQuvoVHmiwwUR07k2hphyBbWIJY0XbXx O2Yg+mdStFDrluCtIKc0zssKSlN8gfYLzeZ5H/gR96PJQGP1Vg1o0h+GnJnWSkDMuWVb vehukokpCnq8JEyB4ocPL8g/KCf4wkUW3ELWOymWBHobTGhcn/q3zrrWA5cofuYruiVg Xs6Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:message-id:subject:in-reply-to :references:date:cc:from:to; bh=ZqIyPWyOBpUSJbe2y/rT0xqOUe4Cms0uJ8UFJdYbv+E=; b=Ag4ZcAxXXeX+l2d7PZs6FQa/PnAJGF/nUSMVXd9/T2PGr3sEfT/Av7no4W4zbQ3rlu HVBpO1AJBNsCMqqmSrDgHWHiivR0XSdy6+3CdRVvd3XYOZOc/88GLnVwJu7cfaOtQqhm boiPCMq1e9vsAcIwEFkXFQgEyE2LPn1K7VXdNMjrzZBMqaezdt8ntm+uXbXnz+67F8Ih MsyAjM4sp4VRzBh5KvMkk0YyqL3q0lo2+o3PD5SgTo7zawg3Frj0DSrz2VEu3ddQQkta JHOtCZ5hrnE3VUGO8IpK0EegUArtjkgM5PQi9bWiM6XshBDPVmu9zx+H+sfX0FPqGZTt +Tng==
X-Gm-Message-State: AOAM5316hWwB2VMdopD92sToms+lafSkllpOJ+lwLL4nGT/X+IJN4kGl l0iTsdu9yGun20SBxMH0CjdODr6cdkE=
X-Google-Smtp-Source: ABdhPJx/jgUGUvWYVbSl73nKOxuSpduBN3knX3zlXUGZY72q0HJTM3obiStr+7WbLHK3ERO3d81WRQ==
X-Received: by 2002:a1f:add1:: with SMTP id w200mr45370586vke.22.1594398912193; Fri, 10 Jul 2020 09:35:12 -0700 (PDT)
Received: from localhost (0.92.231.35.bc.googleusercontent.com. [35.231.92.0]) by smtp.gmail.com with ESMTPSA id 73sm890293vkw.13.2020.07.10.09.35.12 for <5gangip@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 10 Jul 2020 09:35:12 -0700 (PDT)
Mime-Version: 1.0
Message-ID: <kcgfqrcm.279044f8-05de-4fa2-961b-667288c328c4@we.are.superhuman.com>
X-Mailer: Superhuman Desktop (2020-07-09T22:06:01Z)
In-Reply-To: <CALx6S37Qu_Gj166u5mS4=EDrGr-xSpjYhsFOopGrWcNRSHY7jA@mail.gmail.com>
References: <CALx6S37Qu_Gj166u5mS4=EDrGr-xSpjYhsFOopGrWcNRSHY7jA@mail.gmail.com>
Date: Fri, 10 Jul 2020 16:35:10 +0000
Cc: 5GANGIP <5gangip@ietf.org>
X-Superhuman-ID: kcgfxlah.4758aed2-3bcf-4334-8eda-8397f909dcb0
X-Superhuman-Draft-ID: draft00d4ed432df3e657
From: Yiannis Yiakoumis <yiannis@selfienetworks.com>
To: Tom Herbert <tom@herbertland.com>
Content-Type: multipart/alternative; boundary="05ca2e5b18e7571a4797f39c3d0f965d5761d409a602ed4a8991646f8d4b"
Archived-At: <https://mailarchive.ietf.org/arch/msg/5gangip/bIMzF7Myrl4ERaOfTi6yn62jkao>
Subject: Re: [5gangip] Network tokens draft
X-BeenThere: 5gangip@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discussion of implications of the upcoming 5th Generation \(fixed and\) Mobile communication systems on IP protocols." <5gangip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/5gangip>, <mailto:5gangip-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/5gangip/>
List-Post: <mailto:5gangip@ietf.org>
List-Help: <mailto:5gangip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/5gangip>, <mailto:5gangip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 10 Jul 2020 16:35:43 -0000

subscribed late and can't reply inline to follow-up comments. Short response to Ca By's point on whether the network trusts the UE.

"A fundamental principle of mobile qos is that you do not trust the UE, as
it can be compromised to make all traffic high priority. Only the network
can reliably and securely allocate resources based on policy."
The basic architecture for network tokens is agnostic on the trust relationships between UE, app provider, network and server. It provides mechanisms to encrypt/sign a token, and metadata to prevent replay and spoofing attacks so that operators can adjust it to the appropriate trust model. It borrows a lot from the ideas implemented in JWT, CWT and OAUTH2.

Yiannis

=====================
Yiannis Yiakoumis
Co-Founder & CEO
https://selfienetworks.com | +1-650-644-7857

On Thu, Jul 09, 2020 at 10:00 AM, Tom Herbert < tom@herbertland.com > wrote:

> 
> 
> 
> This is a draft on "Network Tokens" which is of relevance to facilitate
> fine grained QoS in 5G networks.
> 
> 
> 
> https:/ / tools. ietf. org/ html/ draft-yiakoumis-network-tokens-01 (
> https://tools.ietf.org/html/draft-yiakoumis-network-tokens-01 )
> 
> 
> 
> There is also a mailing list in
> https:/ / www. ietf. org/ mailman/ listinfo/ network-tokens (
> https://www.ietf.org/mailman/listinfo/network-tokens )
> 
> 
> 
> We are planning to present in tsvwg and app aware networking and possibly
> have a side meeting on this topic in IETF108.
> 
> 
> 
> Thanks,
> Tom
> 
> 
>