Re: [Cbor] CDDL for COSE + EAT/CWT + SUIT + CoSIWD

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Wed, 08 December 2021 16:08 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: cbor@ietfa.amsl.com
Delivered-To: cbor@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 51BDC3A0AD4; Wed, 8 Dec 2021 08:08:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=Ax3+wSsv; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=Ax3+wSsv
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1UT2moTOIwsW; Wed, 8 Dec 2021 08:08:32 -0800 (PST)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2048.outbound.protection.outlook.com [40.107.20.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D21533A0AD3; Wed, 8 Dec 2021 08:08:31 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+apfa82kcWJ8WjucTW/ZzUCxqlZfLeppsqtmbWPtbe0=; b=Ax3+wSsvmaZfido2vLgmKyMuHcHW433jwVe1K+iaQPAC5tN1wS57WR71JFFg+/sZu3G9K/UcwNGC77psHfkws5+013FgKDNPnS74oRWN4FNB2/1C8XaOkgVQUI/wL0wm6T/Pfh6UAAb1OO9+i/3DGtyHmNZvRvyhZ4ihBscoZVM=
Received: from AS9PR06CA0028.eurprd06.prod.outlook.com (2603:10a6:20b:462::16) by AM0PR08MB3716.eurprd08.prod.outlook.com (2603:10a6:208:106::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4755.11; Wed, 8 Dec 2021 16:08:28 +0000
Received: from VE1EUR03FT047.eop-EUR03.prod.protection.outlook.com (2603:10a6:20b:462:cafe::ad) by AS9PR06CA0028.outlook.office365.com (2603:10a6:20b:462::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4778.11 via Frontend Transport; Wed, 8 Dec 2021 16:08:27 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT047.mail.protection.outlook.com (10.152.19.218) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4755.13 via Frontend Transport; Wed, 8 Dec 2021 16:08:26 +0000
Received: ("Tessian outbound 9a8c656e7c94:v110"); Wed, 08 Dec 2021 16:08:26 +0000
X-CR-MTA-TID: 64aa7808
Received: from 929b31dfe03d.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 5B10758F-C5CE-4453-9DD8-D87F69F36259.1; Wed, 08 Dec 2021 16:08:19 +0000
Received: from EUR05-AM6-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 929b31dfe03d.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 08 Dec 2021 16:08:19 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=QrGBfl1KPpL5mKgWFEYjA3RFlQNPGQ9Qq18Z62z6X0AOD245+q4pflQSYHi7JQMPviH7ZOEAlQrshXVno6XUNZqOyuVbnxDEEbar3QEPTeK7LIlQJ19AfkF6E5tTQvUttaKSdeaUfPbjz/YmlVWMPSDoyBtayMtpGyEpuvXC9TWxMDHyCk2Undc0i2kKEjeKXwnThPO4R+9GtHEYdFOUyVOBV7crWnYPhWPo+gcrcNzQYIwYJ9pevMPuj8naCySlFv5Dt4LFkLNyKMSauP5+zvG0GAWaUtfKMAYJDrGYlCSpBKffk3VLl2HesBpDu0c3Bc6QVkDny1eJaNDtxv0qcQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=+apfa82kcWJ8WjucTW/ZzUCxqlZfLeppsqtmbWPtbe0=; b=gtN5PYl/EhpV7UgD0H3eQPKBk/W6ovXrY0ABC4ywXfT+DB2FKFup0z4UnrFcVOXXynH118FI0WFmNlzhRAStuQS/Am3V0+Xt2+Xe12BByOt/h9YuK1FHtpPLvvqIgsWkX9dew9GtEc3Dp48r3eOLMng4Whs6jO8IYubEyuNFyx/4mPpkdhxvmBtUgWzdH+jC1Kh0wocDzcPi7XV9OGWBxRIDn4+FJhuTUww8/niZjDCJhAMyHVC5+qDdV0DntqHrcDBsZ9W6vL3AfrXdE33SdSa9RMgxfO5QSUBui4lwndh4Nubm1oeY2M3uDnkN9qdHorxspvqba4NfoSzZjsnAXw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+apfa82kcWJ8WjucTW/ZzUCxqlZfLeppsqtmbWPtbe0=; b=Ax3+wSsvmaZfido2vLgmKyMuHcHW433jwVe1K+iaQPAC5tN1wS57WR71JFFg+/sZu3G9K/UcwNGC77psHfkws5+013FgKDNPnS74oRWN4FNB2/1C8XaOkgVQUI/wL0wm6T/Pfh6UAAb1OO9+i/3DGtyHmNZvRvyhZ4ihBscoZVM=
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com (2603:10a6:10:20d::17) by DB7PR08MB3898.eurprd08.prod.outlook.com (2603:10a6:10:30::27) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4755.21; Wed, 8 Dec 2021 16:08:17 +0000
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::dd96:eb7:b263:b290]) by DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::dd96:eb7:b263:b290%4]) with mapi id 15.20.4755.022; Wed, 8 Dec 2021 16:08:17 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: Carsten Bormann <cabo@tzi.org>
CC: Laurence Lundblade <lgl@island-resort.com>, cose <cose@ietf.org>, "cbor@ietf.org" <cbor@ietf.org>, Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Thread-Topic: [Cbor] CDDL for COSE + EAT/CWT + SUIT + CoSIWD
Thread-Index: AQHX67gvNbcS2jfqyUOwtKjobSbIKKwohLpQgAAEVwCAAAJZAIAAC58AgAAFYeA=
Date: Wed, 08 Dec 2021 16:08:17 +0000
Message-ID: <DBBPR08MB59159E4701598A7654E5A5A8FA6F9@DBBPR08MB5915.eurprd08.prod.outlook.com>
References: <85278E84-AD34-4F68-94DC-437BABCCD621@island-resort.com> <DBBPR08MB591541267172A49382892483FA6F9@DBBPR08MB5915.eurprd08.prod.outlook.com> <75C33F50-0C92-47B9-80DB-050499F51630@tzi.org> <DBBPR08MB5915DCAD539AD2CA4770515BFA6F9@DBBPR08MB5915.eurprd08.prod.outlook.com> <F51A9E64-D6DE-464C-8443-20009AE8E98D@tzi.org>
In-Reply-To: <F51A9E64-D6DE-464C-8443-20009AE8E98D@tzi.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: B23331E978B4024D9B6B0C15784565F9.0
x-checkrecipientchecked: true
Authentication-Results-Original: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-MS-Office365-Filtering-Correlation-Id: 36c5e96e-8b30-4964-efba-08d9ba64f7f9
x-ms-traffictypediagnostic: DB7PR08MB3898:EE_|VE1EUR03FT047:EE_|AM0PR08MB3716:EE_
X-Microsoft-Antispam-PRVS: <AM0PR08MB3716A371EB3EE92C8C606842FA6F9@AM0PR08MB3716.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:9508;OLM:9508;
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: hJkTTmNJt2eHDiWyKtODUVxGOajsVmORGqpbxFWewZS+yc3wnkrePHMMQoAmmx5bOSTK18ddeWGe/Ltv10HC7czOPmCKPcxnE9P35901h6WB6tFzee4A6zpuCLPajzEiTspzC8Y+87z0XRiDzB4kbs3nzGKDlPukEoaMN5AJ/FNTevcHkByrH/DMLnJDWtc1h60kmEcFEujW4gWQtAjFQBLzwQbQFq0/f+EmDwzcRNGsHyLkHpORJ4JveRRq3eSEXL6OSz0yIC5r3D/a+qrrk06Il/ppPcOc2bdEF4USqPSdY4Cyfg3IgbxV87VyIQWKJ7wr2LMctrZEP1/BwOO24O4pO3e+CrFWCjVkj4h+G06BkPBvw5F9Kdv/1C8woNTES/F9jqSpx46hNZhoHj7T/Yh7RFxpm2UIbuMJOB47e1GM8K65BY4yq/dhMJh6hnsSqChgTa23VaTFLSatNXZ4TSH/1/kcU1cDEng/cTQSJ30OTLaa0aLHuOJOksS84zyyMzcrdEwxDNeVTgqrYlnUafrl4PxmY8376SUYsq2thAAmErfmeeO5YAKDv5BDwODZIyxl87WPFkGz3Y9RTP/Mk+AgGCIBVglSANsYlpk+ZNUZ4FLXbTagTBoEobutLceIv7/lJ0g1z3W025byXw7nmw6+h5F+cqrWzltX1mIw9FnDbQPcWqjUfUGD/+nx2lwhHlJKTG540apCsnSf3+eCDQ==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBBPR08MB5915.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(38100700002)(66946007)(66556008)(64756008)(4326008)(66446008)(71200400001)(66476007)(9686003)(122000001)(7696005)(26005)(186003)(52536014)(33656002)(8936002)(83380400001)(2906002)(316002)(6916009)(54906003)(53546011)(508600001)(38070700005)(5660300002)(6506007)(76116006)(8676002)(86362001)(55016003); DIR:OUT; SFP:1101;
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB7PR08MB3898
Original-Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT047.eop-EUR03.prod.protection.outlook.com
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id-Prvs: 4157a532-2a4a-4960-2f7c-08d9ba64f280
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: Ut4WPJLa8eKUwy9tmSKK+ERan9DnbNZzk0nUGBtYqxyiy2oLxj9VdGIojKblMG+qcwq3aTCx8l19/y3ZAnol5J/mb2dG71LDIN63ExMA73m0kvPTRKOsMDBiQyr2mgcyoGEVauiHxonVaBN3/MDa776NBrZT7XdbaVvRX8XLpkAPtHM2wutFz2m/KSoHJctyUAjgZjjddbSbpWzwVqxo+hUz2Ait36DAd7FOuo/TfqrLhy7R+fP8I8fHzp3med0tInXlA6i9LGBZjTkkr9y/vTZsJ1JIwEhPYqBPjU+kDx+PkCusbkfze0BtjyJl5APdlhH3oY5hzXt3t72xjuBKVt4I+XaQHT0FU8R7j3fhS4IrlwI8mFctn0I+hcAbl8Was+I33pTd9GSw0mI/vJSsfZICOiEv518qesDuOgfFSk/oh85CDZ/N5PlrEGGnptM23UmcHn6AHRGzclWbMbSWQrMuQ4E/UMpbvO7rky4V2oUS6d/BKYoIVNnLCd2YRexJOfj+IFS48zBLoiSRB/NbdIvr4HEAplXEamG2gXMoJt96fRQdKD7CuEMFkwsIaTDBtZ9GKsbf48dJG432iea4TkxxGzRkQdT4LOat+WEvb4kBdeVxsT+JulRFsuDQGbO6S/eB1JAh18GXMTSOxXa2ifkB6xdbvDWZk1KK3oAyRLbah1Lk89Av5+awsfztBbIHyJNDk/PSontbXlUsGP3IXq8qc45RVDGjp+EXlIpO1V/uYW5/xrxF/r6Hy8zq7CQJ7o33kRX2ebclUCnzY8NdwQ==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(36840700001)(46966006)(40470700001)(36860700001)(450100002)(83380400001)(82310400004)(5660300002)(508600001)(40460700001)(336012)(356005)(4326008)(2906002)(55016003)(7696005)(8676002)(8936002)(81166007)(70586007)(33656002)(86362001)(316002)(6862004)(52536014)(53546011)(107886003)(9686003)(186003)(47076005)(54906003)(6506007)(26005)(70206006); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 08 Dec 2021 16:08:26.7609 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 36c5e96e-8b30-4964-efba-08d9ba64f7f9
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: VE1EUR03FT047.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR08MB3716
Archived-At: <https://mailarchive.ietf.org/arch/msg/cbor/GI1tluvxGeoKkqo99PoTFpN2HIM>
Subject: Re: [Cbor] CDDL for COSE + EAT/CWT + SUIT + CoSIWD
X-BeenThere: cbor@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Concise Binary Object Representation \(CBOR\)" <cbor.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cbor>, <mailto:cbor-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cbor/>
List-Post: <mailto:cbor@ietf.org>
List-Help: <mailto:cbor-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cbor>, <mailto:cbor-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 Dec 2021 16:08:37 -0000

Hi Carsten,

Let us ignore the current status of the EAT spec for a moment.

Laurence was saying:
"
CoSWID replicates and modifies a lot of COSE CDDL in normative text primarily so it can fully specify the COSE payload with a .cbor control.

SUIT doesn’t replicate COSE. It specifies the COSE payload in prose.
"

The statement about SUIT is only partially true. At the beginning we only referenced COSE and didn't "modify" (or profiled anything) because we thought we don't need to do it.
When we started the work on firmware encryption we suddenly realized that this is not really practical. You need to provide more rules on how to use COSE to provide implementers enough context to build interoperable specifications. That's why the firmware encryption draft modified the COSE CDDL and later it then introduced HPKE (instead of using an alternative public key encryption scheme specified in COSE itself).

It is unclear to me whether a similar approach will be needed for the SUIT manifest as well. It might be insufficient to say "use COSE_Sign, COSE_Sign1, COSE_Mac, and COSE_Mac0" alone. One could write the additional constraints into the specification text but it might be better to take the respective CDDL fragment and modify it accordingly.

Ciao
Hannes

PS: I am not sure whether the ".cbor control" is an important concept in this conversation.

-----Original Message-----
From: Carsten Bormann <cabo@tzi.org>
Sent: Wednesday, December 8, 2021 2:27 PM
To: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
Cc: Laurence Lundblade <lgl@island-resort.com>; cose <cose@ietf.org>; cbor@ietf.org; Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Subject: Re: [Cbor] CDDL for COSE + EAT/CWT + SUIT + CoSIWD

Hi Hannes,

> On 2021-12-08, at 13:46, Hannes Tschofenig <Hannes.Tschofenig@arm.com> wrote:
>
> Hi Carsten,
>
> I suspect Laurence is sending this email because of his work on EAT. I am arguing that an attempt to improve the CDDL for the mentioned specs will not lead to any improvement at all because the problem is elsewhere. I am saying that because I have just spent many hours reading the EAT spec.

Thank you for clarifying this, providing the RATS perspective that I’m missing here.

I’m glad to hear that EAT only has one problem :-) (“the problem”).

I still think that doing the work I was outlining would help us in various specifications.
And when it comes to EAT, I’m assuming that at some point we want to describe EAT claims with some statements about their structure, which would naturally use CDDL.  But that may not be needed for the initial EAT specification; I haven’t checked that.  If it is not needed, it might be too much of a distraction to apply the work I was outlining to EAT now.

Grüße, Carsten


>
> Ciao
> Hannes
>
> -----Original Message-----
> From: Carsten Bormann <cabo@tzi.org>
> Sent: Wednesday, December 8, 2021 1:37 PM
> To: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
> Cc: Laurence Lundblade <lgl@island-resort.com>; cose <cose@ietf.org>; cbor@ietf.org; Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
> Subject: Re: [Cbor] CDDL for COSE + EAT/CWT + SUIT + CoSIWD
>
> On 2021-12-08, at 13:30, Hannes Tschofenig <Hannes.Tschofenig@arm.com> wrote:
>>
>> EAT by itself is not really an interoperable spec. COSE on its own is not interoperable either.
>
> If I guess about the definition of "interoperable spec” you are using here, ASCII is not an interoperable spec either - you still have to agree on what the text means…  Still, ASCII was kind of useful as the basis for a lot of interoperability, I think.
>
> I think the point here was to shape some CDDL that makes it easier to talk about the way a more specific (interoperable?) spec uses COSE (which does have CDDL, just not in a way that usually can be integrated as-is to express the additional constraints a COSE-using specification typically makes).
>
> Grüße, Carsten
>
> IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.