Re: [Anima-bootstrap] [6tisch-security] goals for this 6tisch design team -- zero-touch vs one-touch

Michael Richardson <> Wed, 08 June 2016 12:47 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 38DC112D1EA; Wed, 8 Jun 2016 05:47:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -3.327
X-Spam-Status: No, score=-3.327 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-1.426, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id p3i2o5bp2MdC; Wed, 8 Jun 2016 05:47:52 -0700 (PDT)
Received: from ( [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id D2EC812D09F; Wed, 8 Jun 2016 05:47:52 -0700 (PDT)
Received: from ( [IPv6:2607:f0b0:f:2::247]) by (Postfix) with ESMTP id CD6492009E; Wed, 8 Jun 2016 08:55:00 -0400 (EDT)
Received: from (localhost [IPv6:::1]) by (Postfix) with ESMTP id E4423638BF; Wed, 8 Jun 2016 08:47:51 -0400 (EDT)
From: Michael Richardson <>
To: Randy Turner <>
In-Reply-To: <>
References: <> <>
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 08 Jun 2016 08:47:51 -0400
Message-ID: <>
Archived-At: <>
Subject: Re: [Anima-bootstrap] [6tisch-security] goals for this 6tisch design team -- zero-touch vs one-touch
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Mailing list for the bootstrap design team of the ANIMA WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 08 Jun 2016 12:47:54 -0000

Randy Turner <> wrote:
    > The only ANIMA document I can find with “bootstrap” in the title specifically
    > precludes its’ application in constrained environments…

Well, you might have noticed that I'm one of the authors.
And while the *protocol* we intend to use in ANIMA bootstrap is inappropriate
for *6tisch* for a number of subtle reasons, we think:
    a) it will work for "class 3" devices with no UI in non-constrained networks.
    b) the certificate, MIC, TPM, 802.1AR, MASA and registar are designed to
       be useable in both environments.

    > So I’m assuming we can “borrow” ideas from ANIMA but reuse it …

Entire non-edge subsystems, just not the code at the edge.

Back to the question though.  Do you have one-touch process, and if so, would
you want to describe it's capabilities?

    > It seems that there are an innumerable number of ways that the "touch"
    > for a one-touch system could be done, and if there is real desire to accomodate
    > such a process, we need to state some assumptions about the touch
    > process.
    > As such, a document is surely needed. Some questions I have:
    > 1) is it physical? (vs radio. vs a BNC/etc cable plugged instead of
    > antenna)
    > 2) is it encrypted?
    > 3) does it run IP?
    > 4) how many bits can be transmitted/received?
    > 5) is the target CPU alive, or is this JTAG or JTAG-like?

Michael Richardson <>ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-