[Rats] Organizing IETF attestation work

Laurence Lundblade <lgl@island-resort.com> Sun, 02 September 2018 19:02 UTC

Return-Path: <lgl@island-resort.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 133CF130DEE for <rats@ietfa.amsl.com>; Sun, 2 Sep 2018 12:02:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.495
X-Spam-Level:
X-Spam-Status: No, score=-0.495 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RbJmure8FSXl for <rats@ietfa.amsl.com>; Sun, 2 Sep 2018 12:02:14 -0700 (PDT)
Received: from p3plsmtpa09-01.prod.phx3.secureserver.net (p3plsmtpa09-01.prod.phx3.secureserver.net [173.201.193.230]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CE811130DF3 for <rats@ietf.org>; Sun, 2 Sep 2018 12:02:13 -0700 (PDT)
Received: from [192.168.1.82] ([76.192.164.238]) by :SMTPAUTH: with ESMTPSA id wXdTfdaU388dPwXdTfwGhV; Sun, 02 Sep 2018 12:02:13 -0700
From: Laurence Lundblade <lgl@island-resort.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_936DD48C-0081-4249-90ED-E23B61034700"
Mime-Version: 1.0 (Mac OS X Mail 11.4 \(3445.8.2\))
Message-Id: <F6917D3A-901F-474B-8E4C-A7F23C626045@island-resort.com>
Date: Sun, 02 Sep 2018 12:02:10 -0700
To: eat@ietf.org, rats@ietf.org
X-Mailer: Apple Mail (2.3445.8.2)
X-CMAE-Envelope: MS4wfJXCcLrzS75ecUkX0plwwwuyAvl0Suc/AKdJzbsEGYKe0LGwAXu2lHh6heiB2NeEeYQE70sEQbCdZp7Gutq9SuD438IIKYpGVTpPRyu7fdVVWmKo9rwp YgMg4zmptvbSH2d8Gzd9ug2yrU/u8x6TCjYkzVWewiLig/LN72/MfcOWQZmar4C/IBgIoU7JZydXYQ==
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/AFz_aSRdRBrTtED2pdzdP7GVaS8>
Subject: [Rats] Organizing IETF attestation work
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Remote Attestation Procedures <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 02 Sep 2018 19:02:17 -0000

Hi folks, here is a straw man proposal for organizing the IETF attestation work.

I proposed we combine eat and rats and call this the Remote Attestation or RA working group. 

Example in-scope use cases include:
TPM/TCG based attestations that are sent to remote entities, relying parties and such (non-local attestations)
Attestations used by protocols like FIDO that provide secured claims about a particular subsystem on a device to relying parties
Platform/system attestation schemes like Android O attestation
Reporting of device/system security characteristics by subsystems like TEEs and secure elements
Securing of risk signals (e.g., SW version, geographic location, device types) sent to relying parties
For IoT device on-boarding, proof of device provenance
The documents produced would probably be:
An overall model and terminology document (we have a start with the RATS <https://tools.ietf.org/html/draft-birkholz-attestation-terminology-02> document)
A claims definition document (we have a start with the EAT <https://tools.ietf.org/html/draft-mandyam-eat-00> document)
A protocol definition for transmitting attestations when they are not being carried in other protocols as extensions or such (not started)
Possibly the token binding attestation work (Giri has completed a lot of work on this <https://tools.ietf.org/html/draft-mandyam-tokbind-attest-04>)

We get to reference Ra, the Egyptian sun god and use hieroglyphics.

LL