Re: [Ace] Agenda

Ludwig Seitz <ludwig@sics.se> Mon, 14 July 2014 12:42 UTC

Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 028C11A03C8 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:42:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, J_BACKHAIR_22=1, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z8A66Hmb9bfQ for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:41:56 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 8F6141A03C7 for <ace@ietf.org>; Mon, 14 Jul 2014 05:41:56 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 87DA711AA for <ace@ietf.org>; Mon, 14 Jul 2014 14:41:55 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6ECftru026542 for <ace@ietf.org>; Mon, 14 Jul 2014 14:41:55 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 64A3C40116 for <ace@ietf.org>; Mon, 14 Jul 2014 14:41:55 +0200 (CEST)
Message-ID: <53C3D013.6030006@sics.se>
Date: Mon, 14 Jul 2014 14:41:55 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <53C398ED.3030302@gmx.net>
In-Reply-To: <53C398ED.3030302@gmx.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha1"; boundary="------------ms040704010608030504030404"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: ip=85.235.11.178; country=SE; region=Skåne; city=Lund; latitude=55.7000; longitude=13.1833; http://maps.google.com/maps?q=55.7000,13.1833&z=6
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MqcFTUQ - a734b9698ebc - 20140714
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MqcFTUQ&m=a734b9698ebc&t=20140714&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MqcFTUQ&m=a734b9698ebc&t=20140714&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MqcFTUQ&m=a734b9698ebc&t=20140714&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/2K60bzbsxmiBRrsbsR64uMZZcrY
Subject: Re: [Ace] Agenda
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 12:42:00 -0000

Hi Hannes,

just some requests for clarification. See inline.

/Ludwig

On 07/14/2014 10:46 AM, Hannes Tschofenig wrote:
[...]
> Authentication and Authorization for Constrained Environments (ACE)
>
> WEDNESDAY, July 23, 2014
>
> 0900-1130 EDT
> Tudor 7/8 (MM)
>
> - Welcome & Agenda Bashing (Chairs, 10 mins)
>
> - ACE Introduction (Chairs, 10 mins)
>
> Since this is the first meeting of the working group we would like to
> give a brief description the high level goal of the group. This part of
> the agenda should also help you to become familiar with the terminology.
>
> - Design Directions
>
> We want to spend the main meeting time to answer a couple of challenging
> questions.
> Our hope is it to get answers to some of these questions during the
> meeting or in preparation of the meeting.
>
> 1) Problem Description
>
> 1a) Client <-> RS Communication: What transport should be used?
> 1b) What degree of flexibility should we aim for? DTLS or application
> layer security?

What do you mean with "What transport should be used?" Is that the DTLS 
vs Object Security discussion?

>
> [[Relevant document: draft-seitz-ace-problem-description-01]]
>
> Discussion Leader: Ludwig (to-be-confirmed)
>
> 2) Design Patterns
>
> 2a) Is the OAuth/Kerberos design pattern sufficient?
> (does it cover all the use cases)
> 2b) Is the OAUTH/Kerberos design pattern necessary?
> (can we throw something away?)
>
> [[Relevant document: draft-seitz-ace-usecases-01]]
>
> Discussion Leader: Ludwig (to-be-confirmed)
>

What do you mean with the "OAuth/Kerberos design pattern"? Is that the 
Client, RS, AS architecture? Does it include the authorization push 
sequence or could it be any other (pull or agent)?


> 3) Design Considerations
>
> 3a) What design components could we re-use?
> 3b) What areas need to be explored in more detail?
>
> Example topics:
>
>    * RS<->AS Communication: In scope / out of scope?
>    * Protocol re-use: what's good and what's not?
>    * Message encoding: Base64, JSON, ASN.1, CBOR
>
> 3c) Should the design be based on symmetric or asymmetric crypto?
>    (or both?)

I think this question (3c) is too generic. If we ask like that, we will 
just reiterate the discussions currently ongoing on the DICE list (see 
the "Tyranny of the Lightswitch" thread).

We should really try to get input on what is likely to be supported by 
manufacturers of mass market IoT hardware.


/Ludwig



-- 
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelevägen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se