[irtf-discuss] Secure Elements in the cloud...

Pascal Urien <pascal.urien@gmail.com> Wed, 16 July 2014 08:26 UTC

Return-Path: <pascal.urien@gmail.com>
X-Original-To: irtf-discuss@ietfa.amsl.com
Delivered-To: irtf-discuss@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 89B641B29E4 for <irtf-discuss@ietfa.amsl.com>; Wed, 16 Jul 2014 01:26:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fHuuUmKnECOQ for <irtf-discuss@ietfa.amsl.com>; Wed, 16 Jul 2014 01:26:02 -0700 (PDT)
Received: from mail-qc0-x232.google.com (mail-qc0-x232.google.com [IPv6:2607:f8b0:400d:c01::232]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7F021A0322 for <irtf-discuss@irtf.org>; Wed, 16 Jul 2014 01:26:01 -0700 (PDT)
Received: by mail-qc0-f178.google.com with SMTP id x3so467557qcv.9 for <irtf-discuss@irtf.org>; Wed, 16 Jul 2014 01:26:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:cc:content-type; bh=OZp4KB6R86tp90n4Pdxx9PcfyT++aL7ZWMRxsCCAN4w=; b=Og1mKLuWp4dBj0UXLcAEfWSFX/7LC9n72Im6ZFEffRsoz+MStxGOmPRPxlUB8NJVZk woWS9Fqr9FG2ohVoVH+VFFn2+DreyaoUpWdsFA8LkgWwWp9WWxYC7o4eD9TYkOEv/w0v Hq0wTADvSZuqSrg/wB8klX+tfbmkSmlfpLiEaOz779mKMTxOwTgF5uhYfE1/8ucA4Ojp C1YDXXrgxZg6niV8/nS5u2PxVil9gxZn+k5KLTNPRgXvy98GvGdJnzjJtPrw4pBESy9m qXDBUrLorq1TNZfZEc3i4dAK+hvrV70Rkq2+TjDqeYTaywuwAVDEfQq88Xu0om3oTkF8 c/Cw==
MIME-Version: 1.0
X-Received: by 10.224.115.3 with SMTP id g3mr43758956qaq.9.1405499160981; Wed, 16 Jul 2014 01:26:00 -0700 (PDT)
Received: by 10.96.194.225 with HTTP; Wed, 16 Jul 2014 01:26:00 -0700 (PDT)
Date: Wed, 16 Jul 2014 10:26:00 +0200
Message-ID: <CAEQGKXSM3DQdMisB=y=qVG2QjSML2cHYrESaAzL_xxDy_kv6wA@mail.gmail.com>
From: Pascal Urien <pascal.urien@gmail.com>
To: irtf-discuss@irtf.org
Content-Type: multipart/alternative; boundary="047d7bdc96b038f7ae04fe4b46af"
Archived-At: http://mailarchive.ietf.org/arch/msg/irtf-discuss/3JF7YIRIQhVf0W8neHO0ZJBNmsc
Cc: Pascal Urien <pascal.urien@telecom-paristech.fr>
Subject: [irtf-discuss] Secure Elements in the cloud...
X-BeenThere: irtf-discuss@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IRTF general and new-work discussion list <irtf-discuss.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/irtf-discuss>, <mailto:irtf-discuss-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/irtf-discuss/>
List-Post: <mailto:irtf-discuss@irtf.org>
List-Help: <mailto:irtf-discuss-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/irtf-discuss>, <mailto:irtf-discuss-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Jul 2014 08:26:03 -0000

Dear All

During the IRTF open meeting, (IETF 90, Tuesday 22 july), i would like to
introduce the idea of trust for internet applications and internet users,
based on secure elements hosted in the cloud

This concept is illustrated by the draft
http://tools.ietf.org/html/draft-urien-cfrg-cose-00.

The main idea is to deploy over the internet secure elements, hosted by
Trusted Secure Element Servers (TSES), which could be used and managed by
human or software entities. This functional granularity is a key feature
for the proposed paradigm called CoSE (Cloud of Secure Elements).

 The CoSE is a kind of WEB for secure elements, able to deliver secure
storage or cryptographic services. Secure element are identified by a
server (TSES) name, a port and a unique identifier (SEID, the secure
element identifier), i.e Server:Port/SEID

 To be practical we work today with ISO7816 tamper resistant chips, which
are manufactured per billions and used for payments, access control and
various cryptographic purposes. These chips generally include a Java
Virtual Machine (JVM) and therefore can run various applications.
Furthermore open standards are available to manage their contents.

A first protocol named RACS see
http://tools.ietf.org/html/draft-urien-core-racs-03 is under definition and
is already tested by several implementations, which are online and can be
demonstrated

The URI associated to a secure element hosted is the cloud is consequently
RACS://Server:Port/SEID

 It should be great to share this vision with people caring with internet
trust for both users and applications.
What about a working group ?
Regards
Pascal Urien