Re: [Ideas] Your Input requested: Charter Proposal New Version

Lan Gao <langao@cdi.cn> Thu, 10 August 2017 01:31 UTC

Return-Path: <langao@cdi.cn>
X-Original-To: ideas@ietfa.amsl.com
Delivered-To: ideas@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 18FBD1324F9 for <ideas@ietfa.amsl.com>; Wed, 9 Aug 2017 18:31:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.399
X-Spam-Level:
X-Spam-Status: No, score=-1.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QZcRMjSXrkkY for <ideas@ietfa.amsl.com>; Wed, 9 Aug 2017 18:31:47 -0700 (PDT)
Received: from regular1.263xmail.com (regular1.263xmail.com [211.150.99.132]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7BBB1324FD for <ideas@ietf.org>; Wed, 9 Aug 2017 18:31:46 -0700 (PDT)
Received: from langao?cdi.cn (unknown [192.168.165.252]) by regular1.263xmail.com (Postfix) with ESMTP id 265F594B3 for <ideas@ietf.org>; Thu, 10 Aug 2017 09:31:43 +0800 (CST)
X-263anti-spam: KSV:0;bpcheck:1;
X-MAIL-GRAY: 0
X-MAIL-DELIVERY: 1
X-KSVirus-check: 0
X-ADDR-CHECKED: 0
X-ABS-CHECKED: 1
X-ANTISPAM-LEVEL: 2
Received: from smtp.263.net (va-smtp01.263.net [54.88.144.211]) by smtp.263.net (Postfix) with ESMTP id D70EF3F1 for <ideas@ietf.org>; Thu, 10 Aug 2017 09:31:41 +0800 (CST)
Received: from mail-pf0-f181.google.com (localhost.localdomain [127.0.0.1]) by smtp.263.net (Postfix) with ESMTP id E09909F6E9 for <ideas@ietf.org>; Thu, 10 Aug 2017 09:31:26 +0800 (CST)
X-RL-SENDER: langao@cdi.cn
X-FST-TO: ideas@ietf.org
X-SENDER-IP: 209.85.192.181
X-LOGIN-NAME: langao@cdi.cn
X-UNIQUE-TAG: <917750cdeedcf0cc4a3331456eeb5b9e>
X-ATTACHMENT-NUM: 0
X-SENDER: langao@cdi.cn
X-DNS-TYPE: 0
Received: from mail-pf0-f181.google.com (unknown [209.85.192.181]) by smtp.263.net (Postfix) whith ESMTP id 113876RQFKY; Thu, 10 Aug 2017 09:31:27 +0800 (CST)
Received: by mail-pf0-f181.google.com with SMTP id o86so34748651pfj.1 for <ideas@ietf.org>; Wed, 09 Aug 2017 18:31:26 -0700 (PDT)
X-Gm-Message-State: AHYfb5iktfCo1wifAPZzM9MfXrMPZbGt/fLM8BiYeXbU0+fYNbR6cEik x/HNqTUYoEkvEj57ihWZg1I4c27veA==
X-Received: by 10.84.231.131 with SMTP id g3mr11031771plk.283.1502328683373; Wed, 09 Aug 2017 18:31:23 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.100.160.76 with HTTP; Wed, 9 Aug 2017 18:31:22 -0700 (PDT)
In-Reply-To: <25B4902B1192E84696414485F572685401A3A265@SJCEML703-CHM.china.huawei.com>
References: <CAG-CQxpxDXxLXdu0a2GdBRfTFLM_C+jqCz58HoNim52C7Yzr8g@mail.gmail.com> <CALx6S34hbV5D84RZQ1+V3zFz+VNeJsDn0rsr-PN6Wg4b1gdSpA@mail.gmail.com> <83622B5F-A2D0-40A4-BD75-BC6222754059@telefonica.com> <25B4902B1192E84696414485F572685401A3A234@SJCEML703-CHM.china.huawei.com> <16A0829F-78E9-4E8C-B719-B25431603939@telefonica.com> <25B4902B1192E84696414485F572685401A3A265@SJCEML703-CHM.china.huawei.com>
From: Lan Gao <langao@cdi.cn>
Date: Thu, 10 Aug 2017 09:31:22 +0800
X-Gmail-Original-Message-ID: <CAOB5waKBVxT7d5vFpnttDRWjDe8VJLoL144ezaMdenPR+sMJaw@mail.gmail.com>
Message-ID: <CAOB5waKBVxT7d5vFpnttDRWjDe8VJLoL144ezaMdenPR+sMJaw@mail.gmail.com>
To: "ideas@ietf.org" <ideas@ietf.org>
Content-Type: multipart/alternative; boundary="f403045fdf9a822a5f05565c27f5"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ideas/hOB3NAfwq2TYeo08pBziKMXoJnc>
Subject: Re: [Ideas] Your Input requested: Charter Proposal New Version
X-BeenThere: ideas@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Discussions relating to the development, clarification, and implementation of control-plane infrastructures and functionalities in ID enabled networks." <ideas.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ideas>, <mailto:ideas-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ideas/>
List-Post: <mailto:ideas@ietf.org>
List-Help: <mailto:ideas-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ideas>, <mailto:ideas-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Aug 2017 01:31:50 -0000

I agree with Sam. Specific chartered tasks or a statement referencing the
chartered tasks should be added to the Deliverables as the current document
only implies that they will be met by the Generic Identity Services
Framework.

Regards,

Lan Gao

On Thu, Aug 10, 2017 at 7:26 AM, Uma Chunduri <uma.chunduri@huawei.com>
wrote:

> Hi Diego,
>
> In-line [Uma1]:
>
> -----Original Message-----
> From: Diego R. Lopez [mailto:diego.r.lopez@telefonica.com]
> Sent: Wednesday, August 09, 2017 3:58 PM
> To: Uma Chunduri <uma.chunduri@huawei.com>; Tom Herbert <
> tom@herbertland.com>; Padma Pillay-Esnault <padma.ietf@gmail.com>
> Cc: ideas@ietf.org
> Subject: Re: [Ideas] Your Input requested: Charter Proposal New Version
>
> Hi Uma,
>
> On 10/8/2017, 24:30 , "Uma Chunduri" <uma.chunduri@huawei.com> wrote:
>
>         > - in addition, introduce the concept of identity-identifier
> split and new
>         > mechanisms that let endpoints dynamically change identifiers.
> These new
>         > functionalities may, for example, facilitate anonymity through
> obscurity
>         > while preventing security issues that might result from abuse,
> ensuring that
>         > information about actual endpoints and their location is
> revealed only on a
>         > need-to-know basis.
>         >
>         Padma,
>
>         I don't think this goes far enough in terms of protections for
> users
>         against the potential abuse of something that might be able to
>         individually and persistently identify them on the Internet. First,
>         it's not clear what network layer identity means in this context. I
>         hope it refers to an ad hoc collection of identifiers as opposed to
>         the identity of individual users or devices. In any case maybe a
>         definition of identity might be in order here. Secondly, I think it
>         should be stated up front that identity cannot in any way be used
> to
>         identify individual users, it cannot be used to create a global
>         database of Internet users, in no way can it be used by networks or
>         governments to track or block individuals, nor can it ever be
> required
>         for communications. That implies network layer identities cannot
>         contain PII (personally identifiable information) and cannot be
>         permanently assigned to users or devices (in the same spirit that
>         Ethernet addresses were removed from IIDs because of privacy
>         concerns).
>
>         Thanks,
>         Tom
>
>     When it comes to these concerns I’d strongly recommend to have a look
> at how identity attributes were exchanged and trust established within the
> ABFAB framework (https://tools.ietf.org/wg/abfab/)
>
>     [Uma]: Though  this is not about SSOs or application stuff, thanks for
> the pointer.
>                     I always believed EAP has a role to play for IDy auth
> procedures and lot of concerns brought out here (especially related to
> Identity-privacy) are effectively taken care with existing mechanisms.
>
> ABFAB was not about SSO, but about using user identities to allow their
> access to network services while protecting user privacy. And among those
> services you could consider any kind of application or connectivity service…
>
> [Uma1]: Thanks for the correction.  Yes, what is needed for IDEAS is to
> access AUTH to GRIDS by entity and also simple policy  at Identity
> (referring Identity through Identifier in the packet regardless of which
> Identifier of the entity is used).
>                   Sure, we ought to re-use any existing and well defined
> mechanisms for this purpose.
> _______________________________________________
> Ideas mailing list
> Ideas@ietf.org
> https://www.ietf.org/mailman/listinfo/ideas
>