Re: [jose] Binary JSON Signing and Encryption

Carsten Bormann <cabo@tzi.org> Sat, 05 July 2014 08:28 UTC

Return-Path: <cabo@tzi.org>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D26AA1A039D for <jose@ietfa.amsl.com>; Sat, 5 Jul 2014 01:28:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level:
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rE2TT9i_F8_G for <jose@ietfa.amsl.com>; Sat, 5 Jul 2014 01:28:10 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 66CF51A0154 for <jose@ietf.org>; Sat, 5 Jul 2014 01:28:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s658S0nd029755; Sat, 5 Jul 2014 10:28:00 +0200 (CEST)
Received: from [192.168.217.145] (p548928EB.dip0.t-ipconnect.de [84.137.40.235]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id E5F288F6; Sat, 5 Jul 2014 10:27:59 +0200 (CEST)
Content-Type: text/plain; charset="windows-1252"
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <CFDD04E6.1B0C3%john.mattsson@ericsson.com>
Date: Sat, 05 Jul 2014 10:27:58 +0200
X-Mao-Original-Outgoing-Id: 426241678.087535-962f070d62de1d10b04d76644496176a
Content-Transfer-Encoding: quoted-printable
Message-Id: <0EB9429D-EE4F-4326-BBE8-021C6CD40373@tzi.org>
References: <CFDD04E6.1B0C3%john.mattsson@ericsson.com>
To: John Mattsson <john.mattsson@ericsson.com>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/jose/oTI67LkhvEJlA3yauGOu5vFrikU
Cc: "jose@ietf.org" <jose@ietf.org>
Subject: Re: [jose] Binary JSON Signing and Encryption
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 05 Jul 2014 08:28:12 -0000

On 05 Jul 2014, at 01:26, John Mattsson <john.mattsson@ericsson.com> wrote:

> Is anyone aware of any work on securing binary JSON?

CBOR certainly was designed with the knowledge that JOSE was going to be available.
Preliminary analysis indicated that an adaptation of JOSE to CBOR should be possible with a limited amount of work.
So our plan here at TZI is to contribute to that work as soon as the work on JOSE is completed.

Maybe we can have a short hallway meeting in Toronto between people interested in this space.

Grüße, Carsten

(I’m not particularly fond of calling CBOR a “binary JSON”, but I read this usage here as a shorthand for “a binary-capable representation format in the spirit of the JSON data model”, which CBOR is.)