[Rats] draft-aegisfs-secdispatch-rats-01 — RATS EAT Integration in AegisFS Secure File Runtime

sripad karthik <sripadkarthik@gmail.com> Mon, 31 August 2026 02:11 UTC

Return-Path: <sripadkarthik@gmail.com>
X-Original-To: rats@mail2.ietf.org
Delivered-To: rats@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id DD902131FA40E for <rats@mail2.ietf.org>; Sun, 30 Aug 2026 19:11:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788142310; bh=RMej37962dmNvNbDyDWAgfzc9cfVAenaRMSK/M4YaAg=; h=From:Date:Subject:To; b=aNgjBaWy1WxGmOpE6/JfMsCScoZUwwfo23d6yrafPGdkewc4vb9pA+zhMyctx2vSp wPdiNaMPZeoc5aF+BNG1QFnhDmYRF1mJ2ZHHZuLeD0p18L4qte+/nFYyajdKR2vgf8 ob3vOzSBG/DXTH9mj4kS39aj8YkVHDq/+jyChfXA=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pnt9_r-h5TRc for <rats@mail2.ietf.org>; Sun, 30 Aug 2026 19:11:50 -0700 (PDT)
Received: from mail-lf1-x136.google.com (mail-lf1-x136.google.com [IPv6:2a00:1450:4864:20::136]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5876E131FA407 for <rats@ietf.org>; Sun, 30 Aug 2026 19:11:50 -0700 (PDT)
Received: by mail-lf1-x136.google.com with SMTP id 2adb3069b0e04-5b5607bd3b5so2564864e87.3 for <rats@ietf.org>; Sun, 30 Aug 2026 19:11:50 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788142309; cv=none; d=google.com; s=arc-20260327; b=DtTFRnctyn+HbdSGDuL2nF4SQe1cWG+91h+2qy0KFmPYMG5mUKrlt4zRFdKIcALBmh WKltVK3lDDcuvqQJLgJX+B5K0XmUwfqC+W2C6AVtZGzJT/JFCfc1WhDwKcyZDExKe8JA FbcEBoxzGFXO4NKxoLsSWQaRdxFxmRr9/BEHONuDSXqQ7gixls3Vo0Fh2Kw3PLYgMBc9 zi7wdQzcV/BOFDq63sVLjp5GNiQifvo0o1U86+LQ9kbmyN8s+dV45sOkXPgJzhOpQ3Qa gfHTDLtLdVeC7/mlAoF3EWqNvsXa0bEyWyNs0SQAimK+z94NDRQzDTh/coiX134UQij2 VN0Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=QtdlbRdzJyZImt77eOYd0f65RXYOfhRYAY6k9cHoMW8=; fh=QnncXh5Js8lSjNXKJeZij0rDGq8OM5k7dH31IzJ9QYw=; b=GMla8pCr5SiqSm2fSM6TzCsOkO/vNOBFQ1ca+Mg7nhKTpzNMxI5Gpb/jW3cK97G7Ph qAKGvw1ZIgJZe9wqCGhy4UL5N+7jfjUSz4d6wBnDioZdL+aPv6AYnygpmPZ4EnfGrYcK c8Qr0MbO9m+NyccagEbvGTvfyN0lwHsF9e8KrvWDxuDkAxq2gvW3Z+DijK/34sh5TYpO IIVkaDifm2AUZI9ARjEVGhsGwePsh8XwY+cE9hhr8Bkd+M+9hPsEBF8eg5QU1BMDmsCz XxhGLqQCa8vfXokhAroikBYWf9/WvXcDIZu5JG+epEY4ACB0uh30HvT9GE3Idh37K3oF ZeTg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788142309; x=1788747109; darn=ietf.org; h=content-type:to:subject:message-id:date:from:mime-version:from:to :cc:subject:date:message-id:reply-to:content-type; bh=QtdlbRdzJyZImt77eOYd0f65RXYOfhRYAY6k9cHoMW8=; b=CMo3DgiOUDrg835XS333GcxKRMmm6SANsDyFdlL2mD/AnhS8YxghmG1N9U6Jt/iEdX fPib/tGOavH43C1mCY3lGhbbo5BH458JKETOvab+yuL47bG4Im+QSFD9fzHcvemoPTlH m298/9PNc7k5xwb9nbxBxBllcGiI4g5LXLZCcdtl3s37I4oTbwIZrGMMfh0QkOjPml2f xhx+O1MqWpU3WE/GKOFzcVUC8LVFqm9ZtMCLLmr4JgQmZAdwATug4bRWulfbBb3IdVAS oIXBu6SirJdc4RarP+RBn4JD1j3tzVe9UJqZGU5XTBfz7T33i1lWAy5/fGzvG930MfaR E/Pw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788142309; x=1788747109; h=content-type:to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=QtdlbRdzJyZImt77eOYd0f65RXYOfhRYAY6k9cHoMW8=; b=tSVK56DgGHL6RQcHM9CDkIx3Q10ZTSNWcYfpr9mn6UvLLgGILZnW3wSqDF9w4cv17K /U3IzfO7xUc/9POeI5n6EBOhdaLCF31ytDR2nCiBczxxgTvmkFqdekI3zJlslartz728 RmGSZUuME1vgo8mdGxYldFir9q0m8QdKbK6yvWI6392jqT42duHT2/y0O8gthI+38sJS 4Tvd9S4FFM65sbiZR0DNLqKIhYA6oScMwLsEip0XTetvPyfI+3JPRMZSFkd7lXdDlbaz m1Bi5biOslD+FaBE6Km5wIbXGoWNT/npE8rzSB0pu5A9BWFGFe2nBjaWcjXUE4UOnRjG ZxbQ==
X-Gm-Message-State: AFuF++lQlfn50Fmq37Us5btvg3HCRmTWr9NN0hmjGrB0sLHp56iDvUYf n42J7dLaMnEaQ0l6llDwCsPPjl8k/7v4O1Hq8C/MdQvuHgMnPymFUhbzy97BoO54M4KDddKQ+nZ yDeHTw3kM+B02krdUhgCoME/N+bkHFPyrmRZD
X-Gm-Gg: AYBFou3JjBYE9nhrFnPijxaw2sCXV22LaUkuY+FSOBaQah++oYcnvokRSfL349Sa2F3 i4otTg1aE3TFPB6t0ev7GVLFdrkuJpYCYv7/wjKoCHubbIYAFHZwy1aROro/2Naw3lgCZKP2Lsr CpEIOXofp4dYzUV+PN4W8uJ7tbXS92j1ReokOlTKIsRDWKj531nob2QczrCjZC50b9fVvDYlvjw 3UqS7/11nMTnMKyhbXwCAoIqQ2ZvakdeNqIAii80TD232pZ+/FcwDwpCnlZKjyp03u+1aYkKINR QnJ70FFrl5o4yk2hhdtDgkL8OjmMmBivsj6TRptZck47f0Ld769zP92j4jXv9dY9tpyY0O3zNKt Jv7olEBQUOcGlpKJGJ+nj5nxP8y2J0xWoZLc=
X-Received: by 2002:a05:6512:3d09:b0:5b2:e947:b3de with SMTP id 2adb3069b0e04-5b5e68b1a9cmr6090345e87.7.1788142308810; Sun, 30 Aug 2026 19:11:48 -0700 (PDT)
MIME-Version: 1.0
From: sripad karthik <sripadkarthik@gmail.com>
Date: Mon, 31 Aug 2026 07:41:31 +0530
X-Gm-Features: AcwNN1UAA8mUI0P-m6v6cWH9H3FbjmoocQ6R-uDYJWU6Xa4gdXd6oaqQzQaL2nw
Message-ID: <CAC4a+jAPp-qp8UP=032DH=RpXxF970w1Wnh0AL57GhEWvBkJyA@mail.gmail.com>
To: rats@ietf.org
Content-Type: multipart/alternative; boundary="0000000000001fe415065a4e5335"
Message-ID-Hash: E74POWM24JOU6D53XRCH6AIKHKIMKI5Y
X-Message-ID-Hash: E74POWM24JOU6D53XRCH6AIKHKIMKI5Y
X-MailFrom: sripadkarthik@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-rats.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Rats] draft-aegisfs-secdispatch-rats-01 — RATS EAT Integration in AegisFS Secure File Runtime
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/7xRrmGNz5kOf0JTFLXvY90R7bdY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>

Dear RATS Chairs and Working Group,

I am writing to introduce a new Internet draft that integrates the
IETF RATS architecture (RFC 9334) as a mandatory attestation step
within a programmable secure file runtime:

Title: AegisFS: AI-Driven Programmable Secure File Runtime and
Intelligent Workspace Architecture with Octal OpCode
Processing and Policy-Driven Language Architecture

Draft: draft-aegisfs-secdispatch-rats-01

URL: https://datatracker.ietf.org/doc/draft-aegisfs-secdispatch-rats/

GitHub: https://github.com/sripad2020/AeGisFS

PyPI: https://pypi.org/project/aegisfs/


== RATS Relevance ==

AegisFS integrates RATS EAT (RFC 9334) as Step 02 of its mandatory
25-step operational lifecycle pipeline (Section 9 and Section 28).
No file operation proceeds without a valid, verifier-issued
attestation result.

The implementation follows the RATS passport model:

Attester:
- Collects platform claims: firmware version, secure boot state,
TPM/TEE presence, OS integrity hash, and runtime environment.
- Signs an EAT (Entity Attestation Token) containing a
verifier-issued nonce (for replay attack prevention).
- Returns the signed EAT to the verifier.

Verifier:
- Issues a fresh nonce per attestation session.
- Validates the EAT signature against the attester's known key.
- Checks nonce freshness to prevent replay.
- Compares platform claims against an endorsement model.
- Produces an Attestation Result with a Trust Level:
UNTRUSTED / BASIC / TRUSTED / VERIFIED_HARDWARE
- Only TRUSTED and VERIFIED_HARDWARE results allow the pipeline
progression. UNTRUSTED results immediately DENY the operation.

Relying Party (AegisFS Runtime):
- Consumes the Attestation Result.
- Enforces policy based on trust level (Section 9).
- Records the attestation result in the audit chain (Section 25).


== Alignment with RFC 9334 ==

RFC 9334 Concept | AegisFS Implementation
  --------------------------|------------------------------------------
Attester                  | aegisfs.rats.RATSAttester
Verifier                  | aegisfs.rats.RATSVerifier
Relying Party             | aegisfs.runtime (Step 02 enforcement)
EAT (Entity Att. Token) | JSON claims dict with ECDSA-P256 signature
Nonce                     | Verifier-issued per-session UUID
Endorsement               | Platform endorsement model dict
Attestation Result | TrustLevel enum + claims dict
Conveyance Channel | In-process (extensible to remote TLS)


== Open Questions for RATS WG ==

1. EAT Serialization: The current implementation uses a JSON.
representation of EAT claims. Should a future revision adopt
CBOR-encoded CWT (RFC 8392) for alignment with the RATS EAT
specification (draft-ietf-rats-eat)?

2. Remote Verifier: The current implementation is an in-process
verifier suitable for prototyping. What is the recommended
conveyance channel model for a production filesystem integration?

3. Hardware Binding: The draft describes TPM/TEE integration in
Section 9. Guidance from the RATS WG on the preferred binding
A mechanism for filesystem-layer attesters would be appreciated.


== Implementation Status ==

A reference Python implementation of the RATS integration is
available in the open-source aegisfs package (v0.2.0):

https://github.com/sripad2020/AeGisFS (see aegisfs/rats.py)
https://pypi.org/project/aegisfs/

pip install "aegisfs[all]"

The RATS engine is covered by the test suite in tests/test_upgrades. py.


I look forward to the working group's feedback on the RATS.
architecture alignment and the open questions above.

Thank you.

Best regards,
Sripad
AegisFS Project
sripadkarthik@gmail.com
https://github.com/sripad2020/AeGisFS
https://www.linkedin.com/in/sripadrh/