[alto] Security/Trust aspects in ALTO

"ayoub.messous@fujitsu.com" <ayoub.messous@fujitsu.com> Tue, 06 June 2023 14:53 UTC

Return-Path: <ayoub.messous@fujitsu.com>
X-Original-To: alto@ietfa.amsl.com
Delivered-To: alto@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 72C6BC17A743 for <alto@ietfa.amsl.com>; Tue, 6 Jun 2023 07:53:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.394
X-Spam-Level:
X-Spam-Status: No, score=-4.394 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fujitsu.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dKohUBdDt0NV for <alto@ietfa.amsl.com>; Tue, 6 Jun 2023 07:53:09 -0700 (PDT)
Received: from esa11.fujitsucc.c3s2.iphmx.com (esa11.fujitsucc.c3s2.iphmx.com [216.71.156.121]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 16525C151B03 for <alto@ietf.org>; Tue, 6 Jun 2023 07:53:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=fujitsu.com; i=@fujitsu.com; q=dns/txt; s=fj1; t=1686063188; x=1717599188; h=from:to:cc:subject:date:message-id:mime-version; bh=riWYL1bFXRbGFfdLv1ajtA0/g8aI2EXuhiedmSflFBw=; b=YhDi/2jhiX04GvD0cmcFA+HjB2R3CFo7x8/9CIDmnuEVMsrkk3m4AwlN Mlo8RaJgEM9P115ppYB8CQlFei7UqJQbR7/bXwVY/iDMkPOPfVdT0BKTX ML8Y2kIfhLpwErYq6g0iQDGvi0RwXqTVAKXPCmb0+aXlZey1MvM1SJRYR UHZBfpbAUHiAntW6Ga0aipyBwXZGwt2k8DmJb7Ahc/tjmGy788ADwKMyb 3w+/1SWsGjwt9OJovFZ33yXGk4UwQXUkNnB6mqIbntDj3+0ptyGCG9KxJ UGg5Wp8Yd8NVxF4doadx2X3rSlQ0BJArPqS8/AEIrhIeM3K/ETRean2XD A==;
X-IronPort-AV: E=McAfee;i="6600,9927,10733"; a="86905614"
X-IronPort-AV: E=Sophos; i="6.00,221,1681138800"; d="scan'208,217"; a="86905614"
Received: from mail-cwlgbr01lp2058.outbound.protection.outlook.com (HELO GBR01-CWL-obe.outbound.protection.outlook.com) ([104.47.20.58]) by ob1.fujitsucc.c3s2.iphmx.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 06 Jun 2023 23:53:06 +0900
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LYob/ots3o0dlz6+X1BtOPBNt6LM1mRrI76gPjoEDrj/X1w6pkGh/ehP/TiIRR8m33GHDejajkW3W2GRLPKgNudASFMDqA0gpWLorRlRbweC6NIKGyc1+YPMGxXF8plMuptVe8RfPFKHDosBFPVvCUks/uhTnu7C7WNHOqGLwg+IQlWL4DoD/cO+Qe1tReOnZ5q/I1qM2oyg7UtAkKEXAgysxYiDWTtpT1Rp42c5fZ3Vp/DqiRMLjlvJQROqjahUODRgwHfBVtohJOFa943+07Vb0/WhTxA4qdpStK0HtJ5PIMIQRBepgwtzpip0l2EyLJE8nbFhcSsBMr5UAcwjLg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=riWYL1bFXRbGFfdLv1ajtA0/g8aI2EXuhiedmSflFBw=; b=eKoSQWtCnxoaoOvwHw7Lcq/u5U/J0wE+1DFhPbZAh12A/wiJdh+LwU9hi1sIMZy89w/Uc68xsyDpzWlFK4xtR1ggURcTA5EGV6R/uHUzUarKeS/AHyPj+yfRP/lZpjCGwAzlGVFOVzSXy8vN8P+nAOm1o8uaA2LcxAGbH44rKlDO62p8OSzsXgZ2jHIoi4jdAwLp0AZ+DZC1XIOCY5eYRkL6rNiZxuG0uhIQYaGVwyDIsXQqvQwluxP/t4Sw7zXJ+8CNVs0aFtfEb16js89T75HLQMIOBQgzFyjpTqMOfiDcMLAt2cXeSKJr8yQSQ1BVD5FoJlTkIz/e2Fhxq4zvWA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=fujitsu.com; dmarc=pass action=none header.from=fujitsu.com; dkim=pass header.d=fujitsu.com; arc=none
Received: from CWXP265MB5565.GBRP265.PROD.OUTLOOK.COM (2603:10a6:400:15b::10) by LO2P265MB5039.GBRP265.PROD.OUTLOOK.COM (2603:10a6:600:22e::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6477.18; Tue, 6 Jun 2023 14:53:05 +0000
Received: from CWXP265MB5565.GBRP265.PROD.OUTLOOK.COM ([fe80::2a78:3610:76af:2a7e]) by CWXP265MB5565.GBRP265.PROD.OUTLOOK.COM ([fe80::2a78:3610:76af:2a7e%3]) with mapi id 15.20.6477.016; Tue, 6 Jun 2023 14:53:05 +0000
From: "ayoub.messous@fujitsu.com" <ayoub.messous@fujitsu.com>
To: "Randriamasy, Sabine (Nokia - FR/Paris-Saclay)" <sabine.randriamasy@nokia-bell-labs.com>, "Motoyoshi Sekiya (Fujitsu)" <sekiya.motoyosh@fujitsu.com>, "yry@cs.yale.edu" <yry@cs.yale.edu>
CC: Jordi Ros Giralt <jros@qti.qualcomm.com>, LUIS MIGUEL CONTRERAS MURILLO <luismiguel.contrerasmurillo@telefonica.com>, Qin Wu <bill.wu@huawei.com>, "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>, "'alto@ietf.org'" <alto@ietf.org>, "Junichi Suga (Fujitsu)" <suga.junichi@fujitsu.com>
Thread-Topic: Security/Trust aspects in ALTO
Thread-Index: AdmYgB+ULTonABhLRxav7sPhn0E8ew==
Date: Tue, 06 Jun 2023 14:53:05 +0000
Message-ID: <CWXP265MB5565DF58B9CFEFDE502B6081F852A@CWXP265MB5565.GBRP265.PROD.OUTLOOK.COM>
Accept-Language: en-GB, fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=fujitsu.com;
x-ms-exchange-calendar-series-instance-id: BAAAAIIA4AB0xbcQGoLgCAAAAAAA3IqEh5jZAQAAAAAAAAAAEAAAAI65tuWU1lpNiO3TiCjX4qE=
x-ms-traffictypediagnostic: CWXP265MB5565:EE_MeetingMessage|LO2P265MB5039:EE_MeetingMessage
x-ms-office365-filtering-correlation-id: a084b186-8053-4ffa-edb6-08db669dbbe6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: xQU2RkmLwSTTbv5y5dvrBDJQqRvM0Vi2FCbjywJ3RcOx7mnZDyvjo138h0vrUGfa9mlhUbyIyrMXuJO+V3krOl4QwebtaJit+UBMIkzfCK7uJYkMagl4yNOGeugoM79KLvhmDdWRlPQcicWsrkoBejBnzNd0mwoNJV8xLfuP6+hQSV80UHTR+HtY7Gqd520uoJ7T9bzsmT5pZnGqXMpbr5NzXaFVlPvJDN9UyABJa3ppLveR952nKuL3ZyhidxlUDh58A05coYDtLT+frH1WtlaLz0xkQvcm/xwrTbP2lbehVJrJ771vp0U+4bAMZePaKK5rnKstfZmNhLkfta9yQTslKE6E0KB8jNjpJmYCU2z6g56iBiYNnVxIvio1Pd55SE0i4VOeYklsJdppzxaemSDQ820QkGGEPShUvHT/o/T8EYsT73jIeRkXBqVO8vucfgIB3c1ytbu/MLS3z2byNATwE4ZrXKNfPLobBAvxgJAhesIBFNQWPWawNMPOIHMT7Q7qfe5xB+QSlBhG2/v0BGWYggAubh6JeRHhqsoRutAhxq+j873tWu9UwMCaiNIK4q14Ijjr8rjW2Ino6dgZzTxopTAyTEDnoN+aYbXdyHg=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CWXP265MB5565.GBRP265.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230028)(4636009)(366004)(136003)(376002)(39860400002)(346002)(396003)(451199021)(66476007)(76116006)(66946007)(2906002)(66446008)(478600001)(15650500001)(45080400002)(4326008)(316002)(4744005)(8936002)(64756008)(8676002)(110136005)(41300700001)(54906003)(66556008)(52536014)(5660300002)(7696005)(71200400001)(66899021)(6506007)(26005)(107886003)(9686003)(38100700002)(82960400001)(186003)(55016003)(4743002)(83380400001)(3480700007)(38070700005)(86362001)(166002)(33656002)(122000001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: tpW6a4QnLA+OcPA6lQxvLe+jk4b08XNnogdNbwVCdRitsYch54ArHgIsCikS3sm3qqUYlNnc8XF6ELTLjY1W2+McDu102pPm2zU1y09kAOlxmJUUz/8LSZ6yE3297ZJmQhsh2+gya13uakuk1fdJKX/74YXCwPv5kdVWw6aQ5YaynOme+pPygJunX+tQ96drUyV3fxbJcX0QyXZWJ9HVBps+gmbWwzFOkSkr0ekwOTUvB3LWqVLwG4ZCOS38yzn4YArmFb5FUs7cwYQL5Mw317qkNjJDm5OrbEB2ET6MZBpHNba0tpHTB0Sd+fVugtxabbWsi7mJ2xL/6g2SNLfJJiIpIANEj4wCdDi7gp20TMfEGVNP9miDNRBTmFakPPCcFEIvSnEXIi1GKs30Vr+dZeZI7CsOX4eKCFddxGLN7Q3jgI4yccvS9u8UQe6N3isuMhXfZXOmE6GAUy6cM4Vcao5q98ctkQ2lehBtHc/UVZTVEGHeKjR9C2Tq8XxdzTVQybs7p9/gGAR9v2MSH7qOKaZU0LWX75nR0gGG+8nO/jyUVMRhPlAuQ36Ifr4cPe0x4sb5ieYkuL7Ygjeben0x+sIlVOnfytf8RuwfL3qJWcXCnHmRw/XnyMDmAEP1M1XK5f6n8vm2oxbVEEhUIpi4a1CG1kTRoc0BPN7e+v7Mr+Ds34CJ/1b099F1CXQ6McYs4mQsEDHHhYMbTrvPEHvbysabXvYKWTC5AQcu6flzsTb0xwUquQqNh7FIvwLTBd6eK6fIEBuux0ms3OyWqxx77/hs639rtF1DDLbtUp/n3anc9ik15MIXaz24PvjhD5q/vpGV6Q36t9ExoYGv0gLEGlk/GqQ20woHDhxcj2i8/N9OyiFOcgYTpGg+cgeqYOrPQ8FIkmInOKhjW3N3utgEcuOOoKJHDGbCKCnvWnr5f3v8qVejcrRp6ZcM9zAG2ZKaOOTYfEyniCe9k7WXXz9nLm8RrzqBXfFgWUAhErBbKXJnHFN6EYpg/wEv9b/wqAbzoNC2H3i2Oaijjy45+aRH5hrf6cSYK82t6WNHPMAelEiEqfAhDoaCAdSW36oJd9Q/tpFEmjZAmukHljpl2U8eboba2ww19shfjiZKWH5KPkJpvbvq/Ku7gR2/EtNX360lk3WDEyPCKzz9Vq1V4H388bSy44EkX4QcWCHb38GVBigJ3E82Q2v+KhCBpe15WAYscN2DyY8Ik/Zh6ndvW1ZO5jjZegyvLuQUdV0GWzWF1pIpXVamlJDqD1fcF5MebpFdimTnWspH/ml9abFWM5qQzgRf/0stx/OCTAMrQcoa+EUmDI5+1Y2XcIV0f5H2o71WwdjbWj3d/5u+VeiTZ6Ujp/qUtCj7XxPzHUYKmQQgUGlj2lztvVEqsgA0K2a6mx1nMowtunOIz/gXQC1/VGjocPPxjz/DnCAwty5RaM3ELtNpEE70yDq0cZnRZupw/Um+ttMU5pxCYQKOdcUxmqIHZCl2+iOg2ilyXW2N5jlbyMJaB3Ua2odxEtQK+PwMpUxrSF5vyoZIz6DSbhD2gZvLi3+1w3AjOv28IXo9RvFBfoICVJQMdbS5o43/Wg3XKjQq
Content-Type: multipart/alternative; boundary="_000_CWXP265MB5565DF58B9CFEFDE502B6081F852ACWXP265MB5565GBRP_"
MIME-Version: 1.0
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: 76sB7+rapmbBID/+0RvebuzXDZXttz9RQvLnGQreP3E814qAlqTT0IPi0zQTNDlC1lcRfAOdzokUWIGWCtt6YFngTmE9AOz1JsprjiU3TXlRE0EJMq1fAMeQAsCh9nKmtNMWnMTEAWwVOACCacnG7VbGcTv4NgWWuismOVosmL87I0NQy4qdgBQeZ+fQgkyN97i/tOkk07L6ssa1hHLl+WlAmXX60dDY/YAjbdSc5Jq2QCPSz8yBi69IQ8a+FzmfcpOLgJK6obqAfiF5oxw9zXxMvAJn/5G2fupheWr1kkA96VtXlOaS04hnckItD7ricTvW62kefsFmDrT0clfcpQaC3k48irc5uCJusaeVuAbQhaXEvjAIuPYHYVaVZ4XFLkzP7uWRnUMjOMUYkj6YxD/dDBilgE407ht9KyfCedHy2RVyifZ8u3a3gVJJkeQhj7dutpkciG02faIxy/6UlhM/r2TjqABuMGWa+KMdMGoX7HVOTSLNwWHn3VZrj4Ej3//GTVhHFKeJrdRLeWyTTnPivdMvmfjcjisL6+b7JIsypTot4IZVvl/LKUEEHgpYPByQntPpAKHti8/YbBjKkMMhcHtbay5HIustwzGmAKB53prkSp83uyTEvJiGZRzJ4mZJGx4AYgswc613z/6i4J9G4U7NsV43RzTAMjT0JRJaIYYZywxbnBkU6QOGZjjeH/TFV4sGdze+i5ZSWP1AhUZry9ceqFcOIBZl6hz5eaBjxsumREQczib4+rotusP3Spyhy/SCBwX4+l6ZAJjk3FK/gcVlEszWdO0xMdWH0asJB2HcmG07AgbhKWYVU5qVs2v6vcBBg+bVKqGvvhVXjubBf1mNsTrmC+fx1mRanwoWvH2vUL7cy4W/hUROP6YRGnIi4P4ybE1iHP8kZlScktRk1HkzvT7zcQ+dBmwVdisnu1imyP19XP6KkLHo/WglJ+8AF5WxxbULOzj4thf/AYFu7+KTHeCjlAGhRQS8zb4=
X-OriginatorOrg: fujitsu.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CWXP265MB5565.GBRP265.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: a084b186-8053-4ffa-edb6-08db669dbbe6
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Jun 2023 14:53:05.0934 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: a19f121d-81e1-4858-a9d8-736e267fd4c7
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: RQBcVJh7JLU+Iya7hnYbthGT+MWPEycNrO/pNV1/6h2dB//kh5NGM2Xnk0r/P2rLvtWMWBH6DoaJHOUa8/VzbDVJBheVsETXOxUUxNwfRWY=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LO2P265MB5039
Archived-At: <https://mailarchive.ietf.org/arch/msg/alto/HnhO5H5xy4hBGtfm3JI7-K9mq3Y>
Subject: [alto] Security/Trust aspects in ALTO
X-BeenThere: alto@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Application-Layer Traffic Optimization \(alto\) WG mailing list" <alto.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/alto>, <mailto:alto-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/alto/>
List-Post: <mailto:alto@ietf.org>
List-Help: <mailto:alto-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/alto>, <mailto:alto-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Jun 2023 14:53:13 -0000

Dear ALTOers,

Following the question from Sabine during our today’s weekly meeting,  I am suggesting this short discussion focusing on “Security/Trust aspects as part of ALTO”. The questions that we want to address revolve around:

  *   How to assess Security vulnerabilities.
  *   How to cover Security aspects (bottom-up vs top-down approaches)
  *   What are the best options to integrate security elements into ALTO.
  *   Other relevant questions.

Regards,
Ayoub


________________________________________________________________________________
Microsoft Teams meeting
Join on your computer, mobile app or room device
Click here to join the meeting<https://teams.microsoft.com/l/meetup-join/19%3ameeting_MGNkMWMwODAtYmRjMy00MGFhLWI4ZDktOGEzMDFiYzg1YTg1%40thread.v2/0?context=%7b%22Tid%22%3a%22a19f121d-81e1-4858-a9d8-736e267fd4c7%22%2c%22Oid%22%3a%22fca5f38d-5297-46aa-b455-d0973e7cb68a%22%7d>
Meeting ID: 434 067 335 84
Passcode: KLqbfi
Download Teams<https://www.microsoft.com/en-us/microsoft-teams/download-app> | Join on the web<https://www.microsoft.com/microsoft-teams/join-a-meeting>
Learn More<https://aka.ms/JoinTeamsMeeting> | Meeting options<https://teams.microsoft.com/meetingOptions/?organizerId=fca5f38d-5297-46aa-b455-d0973e7cb68a&tenantId=a19f121d-81e1-4858-a9d8-736e267fd4c7&threadId=19_meeting_MGNkMWMwODAtYmRjMy00MGFhLWI4ZDktOGEzMDFiYzg1YTg1@thread.v2&messageId=0&language=en-US> | Legal<https://www.fujitsu.com/global/about/resources/privacy/>
________________________________________________________________________________