[Ace] Fwd: New Version Notification for draft-tiloca-ace-group-oscore-profile-03.txt

Marco Tiloca <marco.tiloca@ri.se> Tue, 14 July 2020 10:49 UTC

Return-Path: <marco.tiloca@ri.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA6853A09A3 for <ace@ietfa.amsl.com>; Tue, 14 Jul 2020 03:49:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, MSGID_FROM_MTA_HEADER=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ri.se
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tWZ8s47JT0pe for <ace@ietfa.amsl.com>; Tue, 14 Jul 2020 03:49:35 -0700 (PDT)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-eopbgr150057.outbound.protection.outlook.com [40.107.15.57]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 94AB13A099B for <ace@ietf.org>; Tue, 14 Jul 2020 03:49:34 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=KikZEGAl6pS6vs49PtvJRVX2dwLk8uyVpx/KFFQZP/x3flSXuffzE4H4Z/+yMcAKY01R6Z6A213Xfx5qyciOhDgEikF+SgxL9n8Djy8t/9/ANA+yCbgSNvLTjk+n+P0BV9VF/IfFRdoUK/uv7VzCNAahoO8SjWB1N3fyzjR1Dfen/qikc3m2wFBoe+R/zzahqy/ASo1Y6Nqx3uS3kkD14tPNDZ+dMgEFEtvSS+E98frQP15KEyLcfofMvP+Agye2OPXBwgMXyrT01njdQnUgGkpRsD0032fG1j8haIpkA9K62CTFp1XLTsPjuSfInwjEF98pNyR0QPL/TRNYsPOLrQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cffnkIqykWi/dbxHBlWzQt9HnQn6CANbVLEt31M2gxo=; b=Igl5r5MQZAbxmT6483FWM1QgiEYmaywphccOJiaZ9w0p5sGCbMu/Wl+mcK4MnvnO8UjacAfttO+PU9Dz0to3v/wUZJuDk82RuiYMaos1e02qVc3GqRM21PgVvKwSNyz+s8kmtAgsF5TfwEPoLT7IG0YmW8pNr9RbDMI/r+VTbsv7o/La5aMnD47SmCGFp5m0RQIaQQQZ4+FrDrKyAJ8CgTnTLJuovB61wwCgtvfhWtUpwaaI8Js2zh1FXCb0agYvyX7wmUpUZeGu9EYTI8gO74Smhb11jriVJuKj0vPuwyqMzS71z4tnImhURVbqsxCVTB6ITNh28nWQAUQ9+JzLyA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ri.se; dmarc=pass action=none header.from=ri.se; dkim=pass header.d=ri.se; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ri.se; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cffnkIqykWi/dbxHBlWzQt9HnQn6CANbVLEt31M2gxo=; b=Ex/0J5/FqoqhyDDf9+dpY9SBPhXmrHeW20PSsZjs45bnto3h9JFSOxL2Dj+WT+E3ZWPaaT9ELphDOODVrriJyhYvVBqYplzPNw7bWbKGIyTVHzWtHvSQupFGfWLRTmJpBHIOovIN+QgnEfnB7b9HsHmPToB+Vr9ESYrGN2oKb2A=
Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=ri.se;
Received: from VI1P189MB0398.EURP189.PROD.OUTLOOK.COM (2603:10a6:802:35::31) by VI1P18901MB0093.EURP189.PROD.OUTLOOK.COM (2603:10a6:801:e::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3174.22; Tue, 14 Jul 2020 10:49:32 +0000
Received: from VI1P189MB0398.EURP189.PROD.OUTLOOK.COM ([fe80::2124:eed3:60cd:95a2]) by VI1P189MB0398.EURP189.PROD.OUTLOOK.COM ([fe80::2124:eed3:60cd:95a2%6]) with mapi id 15.20.3174.025; Tue, 14 Jul 2020 10:49:32 +0000
References: <159466103225.28477.14586704329355377501@ietfa.amsl.com>
To: Ace Wg <ace@ietf.org>
From: Marco Tiloca <marco.tiloca@ri.se>
Autocrypt: addr=marco.tiloca@ri.se; prefer-encrypt=mutual; keydata= mQENBFSNeRUBCAC44iazWzj/PE3TiAlBsaWna0JbdIAJFHB8PLrqthI0ZG7GnCLNR8ZhDz6Z aRDPC4FR3UcMhPgZpJIqa6Zi8yWYCqF7A7QhT7E1WdQR1G0+6xUEd0ZD+QBdf29pQadrVZAt 0G4CkUnq5H+Sm05aw2Cpv3JfsATVaemWmujnMTvZ3dFudCGNdsY6kPSVzMRyedX7ArLXyF+0 Kh1T4WUW6NHfEWltnzkcqRhn2NcZtADsxWrMBgZXkLE/dP67SnyFjWYpz7aNpxxA+mb5WBT+ NrSetJlljT0QOXrXMGh98GLfNnLAl6gJryE6MZazN5oxkJgkAep8SevFXzglj7CAsh4PABEB AAG0Nk1hcmNvIFRpbG9jYSAobWFyY28udGlsb2NhQHJpLnNlKSA8bWFyY28udGlsb2NhQHJp LnNlPokBNwQTAQgAIQUCWkAnkAIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgAAKCRDuJmS0 DljaQwEvCACJKPJIPGH0oGnLJY4G1I2DgNiyVKt1H4kkc/eT8Bz9OSbAxgZo3Jky382e4Dba ayWrQRFen0aLSFuzbU4BX4O/YRSaIqUO3KwUNO1iTC65OHz0XirGohPUOsc0SEMtpm+4zfYG 7G8p35MK0h9gpwgGMG0j0mZX4RDjuywC88i1VxCwMWGaZRlUrPXkC3nqDDRcPtuEGpncWhAV Qt2ZqeyITv9KCUmDntmXLPe6vEXtOfI9Z3HeqeI8OkGwXpotVobgLa/mVmFj6EALDzj7HC2u tfgxECBJddmcDInrvGgTkZtXEVbyLQuiK20lJmYnmPWN8DXaVVaQ4XP/lXUrzoEzuQENBFSN eRUBCACWmp+k6LkY4/ey7eA7umYVc22iyVqAEXmywDYzEjewYwRcjTrH/Nx1EqwjIDuW+BBE oMLRZOHCgmjo6HRmWIutcYVCt9ieokultkor9BBoQVPiI+Tp51Op02ifkGcrEQNZi7q3fmOt hFZwZ6NJnUbA2bycaKZ8oClvDCQj6AjEydBPnS73UaEoDsqsGVjZwChfOMg5OyFm90QjpIw8 m0uDVcCzKKfxq3T/z7tyRgucIUe84EzBuuJBESEjK/hF0nR2LDh1ShD29FWrFZSNVVCVu1UY ZLAayf8oKKHHpM+whfjEYO4XsDpV4zQ15A+D15HRiHR6Adf4PDtPM1DCwggjABEBAAGJAR8E GAECAAkFAlSNeRUCGwwACgkQ7iZktA5Y2kPGEwf/WNjTy3z74vLmHycVsFXXoQ8W1+858mRy Ad0a8JYzY3xB7CVtqI3Hy894Qcw4H6G799A1OL9B1EeA8Yj3aOz0NbUyf5GW+iotr3h8+KIC OYZ34/BQaOLzdvDNmRoGHn+NeTzhF7eSeiPKi2jex+NVodhjOVGXw8EhYGkeZLvynHEboiLM 4TbyPbVR9HsdVqKGVTDxKSE3namo3kvtY6syRFIiUz5WzJfYAuqbt6m3TxDEb8sA9pzaLuhm fnJRc12H5NVZEZmE/EkJFTlkP4wnZyOSf/r2/Vd0iHauBwv57cpY6HFFMe7rvK4s7ME5zctO Ely5C6NCu1ZaNtdUuqDSPA==
X-Forwarded-Message-Id: <159466103225.28477.14586704329355377501@ietfa.amsl.com>
Message-ID: <ae5d74d6-e9e0-f07a-0af7-849e8037b3f2@ri.se>
Date: Tue, 14 Jul 2020 12:49:30 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.10.0
In-Reply-To: <159466103225.28477.14586704329355377501@ietfa.amsl.com>
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="lqXzBYoGqGatvcHALZhEKEOWKJDU8VD7T"
X-ClientProxiedBy: HE1PR0902CA0024.eurprd09.prod.outlook.com (2603:10a6:3:e5::34) To VI1P189MB0398.EURP189.PROD.OUTLOOK.COM (2603:10a6:802:35::31)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
Received: from [10.8.3.9] (31.13.191.152) by HE1PR0902CA0024.eurprd09.prod.outlook.com (2603:10a6:3:e5::34) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3174.22 via Frontend Transport; Tue, 14 Jul 2020 10:49:31 +0000
X-Forwarded-Message-Id: <159466103225.28477.14586704329355377501@ietfa.amsl.com>
X-Originating-IP: [31.13.191.152]
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 9c372f79-b78e-4bf3-14e7-08d827e39717
X-MS-TrafficTypeDiagnostic: VI1P18901MB0093:
X-Microsoft-Antispam-PRVS: <VI1P18901MB009341E15132548F13F72E7D99610@VI1P18901MB0093.EURP189.PROD.OUTLOOK.COM>
X-MS-Oob-TLC-OOBClassifiers: OLM:2733;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: IC9Ch7P84RJ9jV8EMLv68m3HY4vsz0iJ17bxT+oojV0TgQjdg/nQUVf4ksIX5nVrtGL+FixH48oTwNK54vCL3QdMB7Alvuyg5MdeBUrdmCSgvHYs5KiCD5j4y4K/mXoza/RRArhJr8BE1oyHucIE051OSIpDWI6xiuRuHyDzvRR7Oj7VQRGtsS0jyfrmy78Wr7CelCqBVx4RnND1/2HEa8hmLGDe7VdxNVGH3bSMBVLnqx88/b4zRBrnilQqsefr0vERBMr80XX71V0+U7bkag4+Itqbpf+vicGkZSpQSCfGTA213sLAtgkgC/XcMb6skeIbAWGlKmeNAr5eiJV2aoYY1taYJGpdeD6HxxFytR18u6bcA5gKrrjcwGz1E8hp8IUV+FH31AYN8uxRrC4mY/3rA5T46K/xWBQSNj5HBqucnNROFkFJ/GRF/RLBlyWM8AdDj/eucuPDPjrDHf5QGQ==
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:VI1P189MB0398.EURP189.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(396003)(39850400004)(366004)(346002)(376002)(136003)(52116002)(6486002)(2906002)(33964004)(316002)(21480400003)(86362001)(66574015)(2616005)(44832011)(31696002)(956004)(83380400001)(66556008)(15650500001)(186003)(66476007)(166002)(8676002)(16526019)(16576012)(966005)(66946007)(36756003)(235185007)(6916009)(31686004)(26005)(478600001)(8936002)(5660300002)(43740500002); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData: /GOxUv5fbFcr7WxmYfLztg9ynlXohRbS9l1ZAAPk/HDvSUNnA2ROZpELv7L0j+jDQ5Xm/o8hc2QDTPd/9fTYAtJldUUEZO9NWted2o0AADRHGD/breIFbkErutO+NvnQRGgQeLV5T2i4WDfZvr0tbmp9rJG1IiPtpW+vImLzFNIR4f9O7eTK9BNZsOQC1DNxCw6Yo41K3sxNGnakeH467OzVLuQ61bMYgo6rsLAohXzXYpP9Mjd/ZXWEA5VSjoPGVoWmuvDAuD/LMLkTEgHUffJbm0CcoYOJQVyXF+eTFtKWwyYHEJfk85pXNAO2E7hA2/6ciid0v7CyYcoX3JmB9A5t0a4pbVaGTipPJdb2HUTIPehPJ93zoXpKPYy4DKOMgo+57pZgpXJafp5qyqRvVctzsCB3KE2bZlZS10gZiz0hnqcUEC7kb7o0fxNQp0ziEJiTvDIftrKCJCFnY9VcbtOGgo3WPF4gxUad+4jN6SY=
X-OriginatorOrg: ri.se
X-MS-Exchange-CrossTenant-Network-Message-Id: 9c372f79-b78e-4bf3-14e7-08d827e39717
X-MS-Exchange-CrossTenant-AuthSource: VI1P189MB0398.EURP189.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Jul 2020 10:49:32.0815 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 5a9809cf-0bcb-413a-838a-09ecc40cc9e8
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: RDh3CcC9H8gpPsa6K3SrieLvxvL6qgJ6m0PcKkeHWP2AvtOuORP3E7pGUuVbNCOUalJt+TMzgMGMlAZz5AcyjQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1P18901MB0093
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/ZAwOX7X4unwE6BjxtOYu8KA9kfE>
Subject: [Ace] Fwd: New Version Notification for draft-tiloca-ace-group-oscore-profile-03.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2020 10:49:39 -0000

Hello ACE,

We have submitted an updated version of
draft-tiloca-ace-group-oscore-profile

https://tools.ietf.org/html/draft-tiloca-ace-group-oscore-profile-03

The document describes a profile of ACE where client and server
communicate with Group OSCORE. This supports fine-grained access control
in group communication environments, where different group members have
different access rights to the resources of the servers in the group.

This version builds on the major update of v -02, with the profile now
focused on Group OSCORE as only security protocol, and further adds:

1) Clearer motivation in the introduction, with access control to the
secure group communication channel (addressed in [1]) separated from
access control to the resources of the servers in the group (addressed
in this document).

2) Achievement of proof-of-possession discussed for both the group mode
and the pairwise mode of Group OSCORE.

Comments are very welcome!

Best,
/Marco

[1] https://tools.ietf.org/html/draft-ietf-ace-key-groupcomm-oscore


-------- Forwarded Message --------
Subject: 	New Version Notification for
draft-tiloca-ace-group-oscore-profile-03.txt
Date: 	Mon, 13 Jul 2020 10:23:52 -0700
From: 	internet-drafts@ietf.org
To: 	Ludwig Seitz <ludwig.seitz@combitech.se>, Rikard Hoeglund
<rikard.hoglund@ri.se>, Francesca Palombini
<francesca.palombini@ericsson.com>, Marco Tiloca <marco.tiloca@ri.se>




A new version of I-D, draft-tiloca-ace-group-oscore-profile-03.txt
has been successfully submitted by Marco Tiloca and posted to the
IETF repository.

Name: draft-tiloca-ace-group-oscore-profile
Revision: 03
Title: Group OSCORE Profile of the Authentication and Authorization for
Constrained Environments Framework
Document date: 2020-07-13
Group: Individual Submission
Pages: 53
URL:
https://www.ietf.org/internet-drafts/draft-tiloca-ace-group-oscore-profile-03.txt
Status:
https://datatracker.ietf.org/doc/draft-tiloca-ace-group-oscore-profile/
Htmlized:
https://tools.ietf.org/html/draft-tiloca-ace-group-oscore-profile-03
Htmlized:
https://datatracker.ietf.org/doc/html/draft-tiloca-ace-group-oscore-profile
Diff:
https://www.ietf.org/rfcdiff?url2=draft-tiloca-ace-group-oscore-profile-03

Abstract:
This document specifies a profile for the Authentication and
Authorization for Constrained Environments (ACE) framework. The
profile uses Group OSCORE to provide communication security between a
Client and a (set of) Resource Server(s) as members of an OSCORE
Group. The profile securely binds an OAuth 2.0 Access Token with the
public key of the Client associated to the signing private key used
in the OSCORE group. The profile uses Group OSCORE to achieve server
authentication, as well as proof-of-possession for the Client public
key. Also, it provides proof of Client's membership to the correct
OSCORE group, by binding the Access Token to information from the
Group OSCORE Security Context, thus allowing the Resource Server(s)
to verify the Client's membership upon receiving a message protected
with Group OSCORE from the Client.



Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat