Re: [jose] Consensus call on charter for JSON Web Proofs work

Pieter Kasselman <pieter.kasselman@microsoft.com> Tue, 18 October 2022 19:20 UTC

Return-Path: <pieter.kasselman@microsoft.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 47F33C15256F for <jose@ietfa.amsl.com>; Tue, 18 Oct 2022 12:20:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.678
X-Spam-Level:
X-Spam-Status: No, score=-2.678 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.571, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5_1bVDpIshnP for <jose@ietfa.amsl.com>; Tue, 18 Oct 2022 12:20:47 -0700 (PDT)
Received: from EUR02-AM0-obe.outbound.protection.outlook.com (mail-am0eur02on2134.outbound.protection.outlook.com [40.107.247.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 490BAC1524C1 for <jose@ietf.org>; Tue, 18 Oct 2022 12:20:46 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ZU0NHll5+q+bU/5M3q55/d64DFFNK/4da0hDJkZZTdAqW5VnSlKcQMkeN/NaHQ60hltijHTgjki6WanBO9QNB4IGV6AvA+HIcAIqPwkqb4OCzCSYNnL36v86ertluXO/fX3FJ5Bh3diQfBACWV/Q4e8a2/XUS6BXMIDuB/pU8uAirdnxKYNd/+NBCB9E4guarASX5Jfhhr4mf2NvHGAWt00fK9RUgocIyemEMHAgKricHUG9RwANaDT0E42IivJt+HGiurRNY9Ibm15lXNXiJGxiCxP8rvv/Rfktae7DbNvnuP3T+5zf4+bm4yl6jozv0RESrAOeU1s4UYN3ST/yIA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=NO4VFdX6hrdSpDnC7pevtmwZU/iPD0ukwBe9aVXs+X8=; b=fG99vTAyiiQr6uq5pplPPZPAGYnn0vJ3mCCxyuLVLhVFj2PRnh1M+yZfkU0p6L8UazFC2ZKCgjSCzjftOrIZwYoOrg13qTn5+8MQkGo6DCLl/aJS8aLzHq5TjnbeGLZmqNEbxrNN0q2ztGsKiT8HkW6bKN0g1G/GQ6Sb+smjfFi3+OcgAFiHzTt/d78j3J11psrjG9DcwPQpn6YbP7qWOp4W9Aytpdg4bB4W2xSzuDxfmYFr+MMw0mc5luXC94SmRrdZ8mYEt1JpZBjyIl6g898Yrw3oviE8Nodi3fAJBw0qpI+PTXFpHKd+kkGEbwB+sxBAHIIpv36mdrb7qnHUqQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NO4VFdX6hrdSpDnC7pevtmwZU/iPD0ukwBe9aVXs+X8=; b=bfMFTDIzhUALTWloEjwIsUH+8gVwxY7QW1EouDHY49fUvlgc10k0DbC/kNKqKr7sJX8Qb8QLiTLVX1lBzwPJ588pta3sXl+cHZ+KZz7D7nTGwXuwmRHzWz0j7FEVrGVnAvkgsMDDPILrMbqBmXSKwceDPfg5cMYMGxViV2G4hB0=
Received: from DBAPR83MB0422.EURPRD83.prod.outlook.com (2603:10a6:10:195::11) by DB9PR83MB0518.EURPRD83.prod.outlook.com (2603:10a6:10:301::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5746.6; Tue, 18 Oct 2022 19:20:41 +0000
Received: from DBAPR83MB0422.EURPRD83.prod.outlook.com ([fe80::fde5:363c:6693:da4e]) by DBAPR83MB0422.EURPRD83.prod.outlook.com ([fe80::fde5:363c:6693:da4e%3]) with mapi id 15.20.5746.017; Tue, 18 Oct 2022 19:20:41 +0000
From: Pieter Kasselman <pieter.kasselman@microsoft.com>
To: Karen O'Donoghue <odonoghue=40isoc.org@dmarc.ietf.org>, "jose@ietf.org" <jose@ietf.org>
Thread-Topic: Consensus call on charter for JSON Web Proofs work
Thread-Index: AQHY4o5yLiOS1Vx/FUSlp4yrHoQ30a4ULLtg
Date: Tue, 18 Oct 2022 19:20:41 +0000
Message-ID: <DBAPR83MB042200B7A74EDB25810E9A5D91289@DBAPR83MB0422.EURPRD83.prod.outlook.com>
References: <PH0PR06MB7061B875E484777060C5F06EC2289@PH0PR06MB7061.namprd06.prod.outlook.com>
In-Reply-To: <PH0PR06MB7061B875E484777060C5F06EC2289@PH0PR06MB7061.namprd06.prod.outlook.com>
Accept-Language: en-IE, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2022-10-18T15:38:02Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=0eaf0d67-9953-4953-8f98-91824dabdcb9; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DBAPR83MB0422:EE_|DB9PR83MB0518:EE_
x-ms-office365-filtering-correlation-id: 49c7b980-88ce-49d5-16c6-08dab13dd8b9
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: dDiHZWVRua1LQNLQYU3UJwbcPlCyynyLEtFjvV2YeCWDH8+Ko8Dhg+IAknj74jFRitsnKlVF0XctvddiBGR5QBXhtFsfqATMHP8KE4i+ARerEouTLVvnh0hLOEjO/IYuFboPgQKDDEnsV1jygtfq9UFYlpqIdhtAQYCJhi9H80GjWCb6EwXc/siAZvXnZHC2TLPzO2IvGkOk5SalCZr2yKlQ3k0SjPHrdyZYL3oi3gXU9YcOi9Wg+c7J9OVtCJbJvHzZ2+nIzxgvWbtt9jBInoAA3cFSuC+gaCShOKiVthKRdcukC6LOCAldH5lPS6Fa9RBrLmkpKOkQDXo1fzXRCpsOTLMqN45WLkYmfBh/uvpit2308KxwmKmxe02SlFw2rI2Mw0V7DjWBWXW3FOirharEvrAWiB1A9eg+OxX4T6j5Bl8MT2wqIB4PZzMi1NjawYDq1aHblsrjOTc2UkAOdASuNstkWbMYd7nWRNGd7DyTe7Aw8wvhGyBIbJLJemM/x+/eFWp3kskX5AQ3kDhDaqd+mBI1ArfiuISnwJHkHyY6QsR8DqcgdvsksqigOIAKq4svvyYQfWIiGev8EPXD+qxJDzHr7gOll6QHKdewj8SV1PtKr88sy17comsphYG/Jm721KlqoxSLib6oLPC/fZwfNUCgkcWHmyhS3QwMtxSgRu4H0f6Qfci2B8vjhXKOHz4Ayv0kcfYjZMA7mXHGs9IEiEb7AELUQ2vOpv+ETdoh5AZraADQpd+j6hPwxC3BIMDc/pV7C2D22yJqd3P8Gilzufk5yLJ6vKeaez88M5Jbsd/Kmk7YrEKw4TG08oztTXrLrO6Vy+RABmBu7kSd3H6QMC6//xlN5RpA6cFNlsmMrFRcKrtwhxvyb8Rre2Cn
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBAPR83MB0422.EURPRD83.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(366004)(396003)(346002)(376002)(136003)(39860400002)(451199015)(66946007)(2906002)(6506007)(38100700002)(7696005)(52536014)(55016003)(316002)(86362001)(53546011)(478600001)(10290500003)(166002)(33656002)(186003)(82960400001)(122000001)(8936002)(38070700005)(26005)(83380400001)(82950400001)(9686003)(44832011)(8990500004)(966005)(8676002)(66899015)(66556008)(64756008)(76116006)(66446008)(66476007)(110136005)(71200400001)(41300700001)(5660300002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: GWxsow2JaFMpJDFVHnO4+wUdr4SjyLYXJ+8jU63bQ59er8AYVL+VgU4GmclvCrqbBgIKZCusiNcynK8lBYSphbccgMx7EyFK3irBwFhrxN84qtU3AaHAKqliu88EudHyVek14HYJJD5Jtw7Ylcgld0vjpV8ZacQrj5pdXDhVKnUtAMqTqUl2glorPZaiEkfZehJh1mbvOz03Eowx8wrXGXb+qy8W0W1wb3Pn0otVWkL3yF1bdrWrVYZH0eTCLubUdgcfy9g/HHE4EtA457A7A3sJwvEotZR0Z13qgKBdGlB7dB63/WD0sqtcFNuthHnPhovLOHQ4CIvNWFXUO1sttYoNS8ZExwA5xYQgiQIFY8Q0Pm+XEPU+tPaILJr2ozHSn3LMSikzlWqy1Z73/2g8kAHIEim+zwCFJiWscaXkrHsTtqR+NmvslRNTsntQ6OC3ZeMiyJC4NX3LktCk8RCG33JfF4pk19zhY3s38ZQSnhzWq8FS7sd9A9kJUS40hMk21Vjt7XRM+J5fJvxkiqMHWU6k02iTFYODbpWmqofT23Ig8XQfts3IwdGggFD/OPnbjov0D9xdm+IpKXs8dzzkQulkk7Fau/ii329z3pKhUMQ6hyZo0XJb4r7NhZvPYaHGjRmufqy0ZhhgqjqUfawa1Rfth0TZ2fIlmjTofpLeR20MYBrbQ67XX/WjXWZagoYDeoNagTkdr9HAY49xhZpQadw4gC9aATDlkOPZGiP4sXOS8YL6wgII6HxIV/lLxeehOBVnOZp4U05ekKRHMdMKpxODcr3A5gTbD2mWi15KOFDowZtyUZ19ozal4yHEgmXxkq4WMjGzq1ad1LIAZlUR9rWnDD/Lf5Ve22yelYZFMr99fiUYbKxaY2i3DIxG0fN8bhvbpy0aZY/QlZX/wo0jxXH+2DL01wCdDVtw1QDfLVNsE6oJVdYx+MpkGUNZiraxAZqJs7jqnFAXd/WxNs1uEpf3klJb0/851WmC5cuiKMT9NJ1Jk2MeepuZTbUAQeQy8t2qTqq7qJL0njRV/QOs2mMVEfdZ03SPgAPYhbOAWcECMWGJAIYQwZluBzn9tyc4Aeb1BS9l3fBeDK035fiWjbemdpD1mQm5qroqhY3Ha3BbaTN4oSuhAMYvbeTB0L9ASKiEuWmSYn+lR6D69DK+XuCVjf9tYvq+DsRRtYNe+BlUPu9NyAYM0es5Ywg8XnLpAwiqDrz1MCYM0RYI3hQy731GgiSjkUUsPDumKNrXJzvVQkxUjqpQOCYohCWHvo87dYcYPiLJ6nahKahfRqUoCInvyLOnnxm+J536w3rGl921nJT/7FNFp2UyPQshnUhUPeIHM2KektL3l1MWwmuUZNPGy+1K90b16EG3OyThOsrIcS+8syEKoAiImP2Og4u0hbCaTOdX+VrwMOuGpEp12ceBIhp/P0Cw7kjWS/J/gfkK9NDQ8GH6463oyON9ZWaPtML/4KzC02S35LFnPg0x8Lp/9Wj/M0kfArNZZcf5/2dUa4yIbR0FAxQselTZga+j
Content-Type: multipart/alternative; boundary="_000_DBAPR83MB042200B7A74EDB25810E9A5D91289DBAPR83MB0422EURP_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DBAPR83MB0422.EURPRD83.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 49c7b980-88ce-49d5-16c6-08dab13dd8b9
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Oct 2022 19:20:41.3164 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: NIAzvSO1ApPVlB1B6C9zpW137YlqGrdq+6gQZ9mQHspIGGzYiI/7yHJ+HefOJWEw4JE/d/s5o9mvQPfy0t7Fg0vTdSJDHhwmdQv68QC7aII=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR83MB0518
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose/YLTyayrE09b9z8YkGBZjoEjRBWw>
Subject: Re: [jose] Consensus call on charter for JSON Web Proofs work
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Oct 2022 19:20:52 -0000

I support the charter text and will be willing to participate in the development and review of the standards.

From: jose <jose-bounces@ietf.org> On Behalf Of Karen O'Donoghue
Sent: Tuesday, October 18, 2022 2:45 AM
To: jose@ietf.org
Subject: [jose] Consensus call on charter for JSON Web Proofs work

Some people who received this message don't often get email from odonoghue=40isoc.org@dmarc.ietf.org<mailto:odonoghue=40isoc.org@dmarc.ietf.org>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification>
Everyone...

On 12 October 2022, we held the second BoF for JSON Web Proofs proposed work [1] as a follow-on to the BoF held at IETF 114 [2].

We had a robust discussion on problem to be solved and the proposed scope of work. A draft charter was previously circulated on the mailing list and discussed during the meeting. Polling of the BoF participants showed a strong consensus on understanding of the problem and interest to solve it in the IETF.  There was also critical mass of energy to do this work. There was some feedback on the charter along with consensus to reuse the JOSE mailing list.

The charter was updated based on the feedback from the BoF and is available here and included below:
https://github.com/json-web-proofs/json-web-proofs/blob/main/charter-ietf-jose-03.md<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fjson-web-proofs%2Fjson-web-proofs%2Fblob%2Fmain%2Fcharter-ietf-jose-03.md&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141298479%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=%2FrryNQ7PSBlZ5xO7PZsx9D5L9qA2gGljfAf0Ur3xHjw%3D&reserved=0>

Now with a revised charter available, we'd like to continue this BoF conversion with an email thread to gauge interest to forming a WG to ensure we also capture views from those who were unable to attend the BoF or those who want to reiterate their positions.  Please respond to the list:

(1) Do you support the charter text? Or do you have objections or blocking concerns (please describe what they might be)?

If you do support the charter text:
(2) Are you willing to author or participate in the developed of the WG drafts?
(3) Are you willing to review the WG drafts?
(4) Are you interested in implementing the WG drafts?

If you previously spoke of at the BoF, you are welcome to repeat yourself here.

If you have been following along on the mailing list, the charter text below is the one that was being polished in GitHub (https://github.com/json-web-proofs/json-web-proofs/blob/main/charter-ietf-jose-03.md<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fjson-web-proofs%2Fjson-web-proofs%2Fblob%2Fmain%2Fcharter-ietf-jose-03.md&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141298479%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=%2FrryNQ7PSBlZ5xO7PZsx9D5L9qA2gGljfAf0Ur3xHjw%3D&reserved=0>).

This call for feedback will end on Monday, 24 October 2022.

Thanks,
Karen and John

[1] https://datatracker.ietf.org/meeting/interim-2022-jwp-01/materials/minutes-interim-2022-jwp-01-202210121300-00<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fmeeting%2Finterim-2022-jwp-01%2Fmaterials%2Fminutes-interim-2022-jwp-01-202210121300-00&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141298479%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=9MSvfvzTZ0mBDCwdSCQLijn9WZve%2BtT8EWmhMCIVd8s%3D&reserved=0>
[2] https://notes.ietf.org/notes-ietf-114-jwp#<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnotes.ietf.org%2Fnotes-ietf-114-jwp%23&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141298479%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=xna9eRpta2otMyCle0EvQTAXthEnog1yPWHhFB4g8BU%3D&reserved=0>
[3] https://github.com/json-web-proofs/json-web-proofs/blob/main/charter-ietf-jose-03.md<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fjson-web-proofs%2Fjson-web-proofs%2Fblob%2Fmain%2Fcharter-ietf-jose-03.md&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=NLyMPmXKxhum8J9oJZhbsqWO9TiIUrNJ4QYMHa1APTY%3D&reserved=0>

Draft Charter:

The original JSON Object Signing and Encryption (JOSE) working group<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fcharter-ietf-jose%2F02%2F&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=I3r5Od6%2Fesg8EPa%2BFj9xlbX9hw8d2jdTTGysZ%2F2kkXo%3D&reserved=0> standardized JSON-based representations for:

  *   Integrity-protected objects - JSON Web Signatures (JWS) [RFC 7515<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.rfc-editor.org%2Frfc%2Frfc7515.html&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=7Pfvo%2FoQ8HWuRN7TnVIsRxr2qojjQjQwCv4S7e6DF0I%3D&reserved=0>]
  *   Encrypted objects - JSON Web Encryption (JWE) [RFC 7516<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.rfc-editor.org%2Frfc%2Frfc7516.html&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=4iO2cDNiGygcLMEngllz4yMaJAmVmEQlmj5CrZf67Jk%3D&reserved=0>]
  *   Key representations - JSON Web Key (JWK) [RFC 7517<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.rfc-editor.org%2Frfc%2Frfc7517.html&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=JyYBgsG6dTy7I1U3LaaskU3o9IqSOHPHBIIh%2Ff6WfoM%3D&reserved=0>]
  *   Algorithm definitions - JSON Web Algorithms (JWA) [RFC 7518<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.rfc-editor.org%2Frfc%2Frfc7518.html&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=8ujSGDJpWDgmYPknBef7kgiB6TWHeuPQpUCehOGVvQw%3D&reserved=0>]
  *   Test vectors for the above - Examples of Protecting Content Using JSON Object Signing and Encryption [RFC 7520<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.rfc-editor.org%2Frfc%2Frfc7520.html&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=Dur%2BttqI2X21opKQnPm132xJ2lzb6KuX1zhSFHT8NeQ%3D&reserved=0>]

These were used to define the JSON Web Token (JWT) [RFC 7519<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.rfc-editor.org%2Frfc%2Frfc7519.html&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=nexAxeBBy491rrt1GomyvFn1narciovsSFaRHixx5Rw%3D&reserved=0>], which in turn, has seen widespread deployment in areas as diverse as digital identity<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fopenid.net%2Fconnect%2F&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=rHFA%2FqqydklBCSPFiu%2FZm2Uo1VbbYPcCHXa64mComQM%3D&reserved=0> and secure telephony<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fblog%2Fstir-action%2F&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=oKaEPs93llIitOIYFhNoOVOU4wDFi4A2i6PVtojCF6U%3D&reserved=0>.

Concurrent to the growth of adoption of these standards to express and communicate sensitive data has been an increasing societal focus on privacy. Common privacy themes in identity solutions are user consent, minimal disclosure, and unlinkability.

A multi-decade research activity for a sizeable academic and applied cryptography community, often referred to as anonymous credentials, targets privacy and knowledge protection. Some of the cryptographic techniques developed in this space involve pairing-friendly curves and zero-knowledge proofs (ZKPs) (to name just a few). Some of the benefits of zero-knowledge proof algorithms include unlinkability, selective disclosure, and the ability to use predicate proofs.

The current container formats defined by JOSE and JWT are not able to represent data using zero-knowledge proof algorithms. Among the reasons are that most require an additional transform or finalize step, many are designed to operate on sets and not single messages, and the interface to ZKP algorithms has more inputs than conventional signing algorithms. The reconstituted JSON Object Signing and Encryption (JOSE) working group will address these new needs, while reusing aspects of JOSE and JWT, where applicable.

This group is chartered to work on the following deliverables:

  *   An Informational document detailing Use Cases and Requirements for new specifications enabling JSON-based selective disclosure and zero-knowledge proofs.
  *   Standards Track document(s) specifying representation(s) of independently-disclosable integrity-protected sets of data and/or proofs using JSON-based data structures, which also aims to prevent the ability to correlate by different verifiers.
  *   Standards Track document(s) specifying representation(s) of JSON-based claims and/or proofs enabling selective disclosure of these claims and/or proofs, and that also aims to prevent the ability to correlate by different verifiers.
  *   Standards Track document(s) specifying how to use existing cryptographic algorithms and defining their algorithm identifiers. The working group will not invent new cryptographic algorithms.
  *   Standards Track document(s) specifying how to represent keys for these new algorithms as JSON Web Keys (JWKs).
  *   An Informational document defining test vectors for these new specifications.
  *   Standards Track document(s) defining CBOR-based representations corresponding to all the above, building upon the COSE and CWT specifications in the same way that the above build on JOSE and JWT.

One or more of these goals may be combined into a single document, in which case the concrete milestones for these goals will be satisfied by the consolidated document(s).

An informal goal of the working group is close coordination with the rechartered W3C Verifiable Credentials WG<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.w3.org%2F2022%2F05%2Fproposed-vc-wg-charter.html&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=DYJI65HwqTMYfgXeA7kgKtC1j66QrCp%2BnKwd61CgbDk%3D&reserved=0>, which has taken a dependency on this work for the second version of its Verifiable Credentials specification. The working group will also coordinate with the Selective Disclosure JWT<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-ietf-oauth-selective-disclosure-jwt%2F&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=KCV1yy6rxWW33M2SkjRcuutsHIdS6kFxAQAMu8uHAgc%3D&reserved=0> work in the OAuth working group, the Privacy Pass<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fcharter-ietf-privacypass%2F&data=05%7C01%7Cpieter.kasselman%40microsoft.com%7C7831ac7266e844051e6608dab0aa62c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638016543141454703%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=U3JDyuNZhMdYImORuhf5ywBrYCUr0Fockp3ds%2FzUtCA%3D&reserved=0> working group, and the CFRG.