[Iotsi] Sticky Policy: Attaching privacy policies to data

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Mon, 21 March 2016 08:58 UTC

Return-Path: <hannes.tschofenig@arm.com>
X-Original-To: iotsi@ietfa.amsl.com
Delivered-To: iotsi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4F6B912D664 for <iotsi@ietfa.amsl.com>; Mon, 21 Mar 2016 01:58:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.101
X-Spam-Level:
X-Spam-Status: No, score=-5.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H5=-1, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, T_DKIM_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (1024-bit key) reason="fail (message has been altered)" header.d=armh.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JFPjIUHXT9Sd for <iotsi@ietfa.amsl.com>; Mon, 21 Mar 2016 01:58:04 -0700 (PDT)
Received: from eu-smtp-delivery-143.mimecast.com (eu-smtp-delivery-143.mimecast.com [146.101.78.143]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8845D12D53C for <iotsi@iab.org>; Mon, 21 Mar 2016 01:58:04 -0700 (PDT)
Received: from emea01-db3-obe.outbound.protection.outlook.com (mail-db3lrp0075.outbound.protection.outlook.com [213.199.154.75]) (Using TLS) by eu-smtp-1.mimecast.com with ESMTP id uk-mta-7-SXG-WT1eRSe2vyajdRUGKw-1; Mon, 21 Mar 2016 08:58:02 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector1-arm-com; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=NXJjuXxEjR4RVgIRLCHTWGUa8Qm/6SNWKy1GuuziW84=; b=DV62gasgU2XcTIXgVq0Pzn+s+Yob1AljQlTjxbmKsNVYoekyW/zjT0V8Zo03OFs9S5GRmpgdWILP9KRUNX+6Em2PdgP4ZTUl3gTC5zrgoLaoQBLNF+cOUZjhxtOHbKxGxeKAtvSIkp0XFIYNA7ijm8o0afL8D0lY3OBpLWLeyD0=
Received: from AM4PR08MB1090.eurprd08.prod.outlook.com (10.167.91.144) by AM4PR08MB1091.eurprd08.prod.outlook.com (10.167.91.145) with Microsoft SMTP Server (TLS) id 15.1.434.16; Mon, 21 Mar 2016 08:58:01 +0000
Received: from AM4PR08MB1090.eurprd08.prod.outlook.com ([10.167.91.144]) by AM4PR08MB1090.eurprd08.prod.outlook.com ([10.167.91.144]) with mapi id 15.01.0434.021; Mon, 21 Mar 2016 08:58:01 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "iotsi@iab.org" <iotsi@iab.org>
Thread-Topic: Sticky Policy: Attaching privacy policies to data
Thread-Index: AdGDT8aYezw41O5yR1CFEqx4Eukxjg==
Date: Mon, 21 Mar 2016 08:58:00 +0000
Message-ID: <AM4PR08MB10906C866EB907945F67A035FA8F0@AM4PR08MB1090.eurprd08.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [193.171.77.3]
x-ms-office365-filtering-correlation-id: 454cbd29-2d3d-47f1-50bd-08d35166e7fd
x-microsoft-exchange-diagnostics: 1; AM4PR08MB1091; 5:zcLkTgYPjfyLjgni7jTn7PcOUg85FCbph8I5LDQ9TWCAil4A3gtHPqI43hgXZ2z6/dOkNW9MWh8u53nLp/sxlC4qJpZcDlz0bGeeOCmnQfPlTli5nJNFhvamwRoFuKxFWCN1ghNwLulbfNePgceRbw==; 24:PxtUt5R2ewB21980vkfkJG3WBUfVjFSTwV7GUofbp3OgIW7hWvoymahInXGKt7+PNi+qgXu07Z9IuHi1c75tqTmAOt+zMThNtPECe4PD4Y4=; 20:xZXhtMEb12rixfqx6NRT3ZtXyz4XsobeAqTFFQ5vtr7V4RPE/kY7tnSCMRdtAEwGgJt5Q23e7UBXtUkPHWJjZ0serXa0bxBwBNXrC5TzaFK0i+RUnB6pDuXCxr9d0NaTd8nuqMCddxO0dIqp8dbFEU1VIY95QsSaQfZDsNBA3Ho=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:AM4PR08MB1091;
x-microsoft-antispam-prvs: <AM4PR08MB109172A64705C58393929F77FA8F0@AM4PR08MB1091.eurprd08.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(5005006)(8121501046)(10201501046)(3002001); SRVR:AM4PR08MB1091; BCL:0; PCL:0; RULEID:; SRVR:AM4PR08MB1091;
x-forefront-prvs: 0888B1D284
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(40434004)(53754006)(3846002)(102836003)(1720100001)(6116002)(1096002)(1220700001)(2906002)(2501003)(5003600100002)(77096005)(15975445007)(5890100001)(81166005)(74316001)(450100001)(122556002)(76576001)(54356999)(2900100001)(107886002)(92566002)(5640700001)(19580395003)(189998001)(3280700002)(11100500001)(5004730100002)(3660700001)(586003)(110136002)(5008740100001)(5002640100001)(87936001)(10400500002)(66066001)(229853001)(2351001)(50986999)(86362001)(33656002); DIR:OUT; SFP:1101; SCL:1; SRVR:AM4PR08MB1091; H:AM4PR08MB1090.eurprd08.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
MIME-Version: 1.0
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Mar 2016 08:58:00.8774 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR08MB1091
X-MC-Unique: SXG-WT1eRSe2vyajdRUGKw-1
Content-Type: text/plain; charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable
Archived-At: <http://mailarchive.ietf.org/arch/msg/iotsi/lR5hDEOR-1Qh5-dKZpsk8KfU2kU>
Subject: [Iotsi] Sticky Policy: Attaching privacy policies to data
X-BeenThere: iotsi@iab.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Internet of Things Semantic Interoperability Workshop <iotsi.iab.org>
List-Unsubscribe: <https://www.iab.org/mailman/options/iotsi>, <mailto:iotsi-request@iab.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/iotsi/>
List-Post: <mailto:iotsi@iab.org>
List-Help: <mailto:iotsi-request@iab.org?subject=help>
List-Subscribe: <https://www.iab.org/mailman/listinfo/iotsi>, <mailto:iotsi-request@iab.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Mar 2016 08:58:06 -0000

Hi all,

During the security discussion the idea of attaching privacy policies to data was mentioned and I noted that there has been work in the IETF on that topic.

Here are the relevant pointers: RFC 4119 (see https://www.ietf.org/rfc/rfc4119.txt) specified a way to convey usage-rules along with location data. These usage-rules contain four pieces of information:
- retransmission-allowed
- retention-expires
- ruleset-reference
- note-well

The ruleset-reference contains richer information about what a recipient of location information is allowed to do with that information. RFC 4745 (see http://tools.ietf.org/html/rfc4745) defines the format of those policies and they have been extended for use with application specific domains, such as presence information and geolocation information. The former can be found in https://tools.ietf.org/html/rfc5025 and the latter in http://tools.ietf.org/html/rfc6772

Ciao
Hannes

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.