[Lwip] draft-urien-lwig-security-classes-00.txt

Pascal Urien <pascal.urien@gmail.com> Thu, 22 November 2018 18:01 UTC

Return-Path: <pascal.urien@gmail.com>
X-Original-To: lwip@ietfa.amsl.com
Delivered-To: lwip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 46B97130E13 for <lwip@ietfa.amsl.com>; Thu, 22 Nov 2018 10:01:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kDqZg4SQblOL for <lwip@ietfa.amsl.com>; Thu, 22 Nov 2018 10:01:07 -0800 (PST)
Received: from mail-ua1-x92d.google.com (mail-ua1-x92d.google.com [IPv6:2607:f8b0:4864:20::92d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 24352129C6A for <lwip@ietf.org>; Thu, 22 Nov 2018 10:01:07 -0800 (PST)
Received: by mail-ua1-x92d.google.com with SMTP id d21so3349428uap.9 for <lwip@ietf.org>; Thu, 22 Nov 2018 10:01:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=H/FuuJ4ZeWj4izFI6LQBSiV+V8bpgWb8DWpLZGbFb1s=; b=WqHdqEHpfkcyLtVPaZc0JI2lkaQsLb3kyEVj4yTsNgPnpEw7V09Xrw5tz2mIBRjGoW /pRt5OeDvst2j9uDPAVt459aYdzoEgRHXrTpVxpsQmpM5RI6m/VWzapU43+yIjVhELxT fFjc54eazvNc9YGMujRjsKDVsWHvSG1hFbXEaWQYVWp9/AiG3ae6wWE3UtRKvO8AQqcX XTUMUbjrwxvaUGRblatTFhUW6viqwqErgYrM8+2DY9h0JdwW/5MoY5zI3LZoIfEW08No L3FFAtIyiXL3/gNI4CH1bGIlvCtnvceYL4DIsmdauTBuzsJIFdn36HBF1oP4j2YHq3Z0 j7tQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=H/FuuJ4ZeWj4izFI6LQBSiV+V8bpgWb8DWpLZGbFb1s=; b=OCBv5iAp29ZU6aSeoy9FoMYpno6It7Oovchg6JoH5stK0CwlODOTKzjIaUP1j/6FZl oSCtf7e6wtWr1qjVt/KZ1TSk0hL82hLVnzb2Cl+ADOKf7TTcFcaiSSAs9Z/u/HJRM6hY VZlvP+Tntp1viqah5yQt36thw2A2CXQR5rXD5gt6Epbj5MzvnA+iQF+jFiE0cEDI/86w bb/lK76O6ojqUG8BULooZDY6pBW6M/QA8B4bzsZcUsX8yFHuR+X87QrczG5UIDbMgsVn havZ5AQ/vp2/F8lqoZG9pyVsRmEfazoSBVZOx6LBFlxmpY5/SpQ/PjXjtnS3vdXfUT+y /41g==
X-Gm-Message-State: AA+aEWbHgRZz9PC2vHKFeRGUJ/9nBD3l89AaXf/+zaNL4HaEoYZ/ubZy Z/34MKYYVBZ9uvTKKF2vHnTKcWxned/wtVytDRrMmTdL
X-Google-Smtp-Source: AFSGD/VleETmfDFqcFDLF77RWzhm0Z23INPJrJ1SnrGNK8vJnKe2JPDIwDejw6a4XbU1NkAr/ShMcFdW0YFcr6F3gMI=
X-Received: by 2002:ab0:7544:: with SMTP id k4mr534526uaq.66.1542909665820; Thu, 22 Nov 2018 10:01:05 -0800 (PST)
MIME-Version: 1.0
From: Pascal Urien <pascal.urien@gmail.com>
Date: Thu, 22 Nov 2018 19:00:52 +0100
Message-ID: <CAEQGKXTm=oLS27R4b+tH7090BtLfXeuPfN4HvWH=Sqa+hLOV8g@mail.gmail.com>
To: lwip@ietf.org
Content-Type: multipart/alternative; boundary="0000000000008d43a6057b44a6d8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/lwip/vFIbodjm0DRiGlhqwhhVmDOu924>
Subject: [Lwip] draft-urien-lwig-security-classes-00.txt
X-BeenThere: lwip@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Lightweight IP stack. Official mailing list for IETF LWIG Working Group." <lwip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lwip>, <mailto:lwip-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lwip/>
List-Post: <mailto:lwip@ietf.org>
List-Help: <mailto:lwip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lwip>, <mailto:lwip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Nov 2018 18:01:09 -0000

Hi All

I have posted the draft,
https://www.ietf.org/id/draft-urien-lwig-security-classes-00.txt

Which is an enhanced/modified version of
https://tools.ietf.org/html/draft-urien-suit-security-classes-00

This draft attempts to define security classes for constraint IoT devices.
A device security is characterized by five Boolean security attributes: one
time programmable memory (OTP), firmware loader (FLD), secure firmware
loader (FLD-SEC), tamper resistant key (TRT-KEY) and diversified key
(DIV-KEY).
This leads to the definition of 6 classes of devices, embedding or not OTP
resource, whose security increases with the class number (0 to 5). The
suffix + indicates OTP availability

I reduced the number of security classes a tried to clarify the rationnal

Regards

Pascal