Re: [Rats] Endorsement ID and verification key (was Processing Endorsements and Evidence into Results)

Thomas Fossati <Thomas.Fossati@arm.com> Thu, 09 April 2020 11:54 UTC

Return-Path: <Thomas.Fossati@arm.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E28F13A0943 for <rats@ietfa.amsl.com>; Thu, 9 Apr 2020 04:54:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=0abEIzQL; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=0abEIzQL
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QEu8dUUASXm4 for <rats@ietfa.amsl.com>; Thu, 9 Apr 2020 04:54:24 -0700 (PDT)
Received: from EUR02-VE1-obe.outbound.protection.outlook.com (mail-ve1eur02on062b.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe06::62b]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C35DF3A0940 for <rats@ietf.org>; Thu, 9 Apr 2020 04:54:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8kt6nnc2epl+NaY7kRULLKPEs4B8yJQr3NMeK5cf/BU=; b=0abEIzQLVGX4D0lazT5QurIH39Fd/AyQXxUFpLWdNRE9NZ/Pn5bHls6u6xhkF48+L7GGwdKElwkCPjDXAdXfeZTpl2qM21JcJ/qjWJ3mvmeBC/qcRCqMS/qsPnqSOIDUlbcGxw6ED7WAkYtp191Vw3dv3zRG5EoG43VlGS0ymZ0=
Received: from AM5PR0202CA0003.eurprd02.prod.outlook.com (2603:10a6:203:69::13) by DB8PR08MB5129.eurprd08.prod.outlook.com (2603:10a6:10:ec::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2878.19; Thu, 9 Apr 2020 11:54:17 +0000
Received: from AM5EUR03FT032.eop-EUR03.prod.protection.outlook.com (2603:10a6:203:69:cafe::77) by AM5PR0202CA0003.outlook.office365.com (2603:10a6:203:69::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2900.17 via Frontend Transport; Thu, 9 Apr 2020 11:54:17 +0000
Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=bestguesspass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT032.mail.protection.outlook.com (10.152.16.84) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2900.18 via Frontend Transport; Thu, 9 Apr 2020 11:54:17 +0000
Received: ("Tessian outbound e2c88df8bbbe:v50"); Thu, 09 Apr 2020 11:54:16 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: 133e6a776694a2a7
X-CR-MTA-TID: 64aa7808
Received: from 1436b12724f7.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 8DED1BC5-6834-4C24-B874-0888C7CAD900.1; Thu, 09 Apr 2020 11:54:11 +0000
Received: from EUR04-HE1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 1436b12724f7.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Thu, 09 Apr 2020 11:54:11 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ndX8oCoFWms1TTPsc73R0D5Oh72pty+xSWM7kyVHiQwVEPttq5B4DTn8DOcCe8yAswi2BsEZbbSp0Qs/UD5gaXsfuc8njD1FUwYFFegOBSiHj3kwOUEMwak+xk7cDWNZ07frhrUE4fSWdFatU9/ywiMu2nyU20pA/0d3JNOUiKeJhtHt+3P3sOU2nzTBcDzqk0DI+yRvYidvMKSeBLvuWrOSorRI0Ao6Bdzeirhnl+bdPnuqG6d45VxE7yd/l6feiSjUk+YdjySJZj+/eRsLVZheE46qWOlFLkbG2jSVE1OvWb0K6uJdbP86QcSLV6ZUASxpxZio28ggFjquNAJZPA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8kt6nnc2epl+NaY7kRULLKPEs4B8yJQr3NMeK5cf/BU=; b=E/JNepg7Gn9nQSeTJ+ZpKKug6sm1RXf3zm8uuoekTKk54Y85HaaSgXrrBif2/jSzDv9tl4TRHSxM9FtQ44CEvfWD+iR6FVnK5nnCd6e2EFkgm7TuYKYq347Bp+RocrKztqMNM9I+FXF2hoxkCDgQkRv6iaMw+P+fNDibnREDGNqn61oJr9+hIuDmRM4Hamm6MJ7sR1q8oRUgTVb8VqGaoh4rW3EcwkU6+BwPYN3EDLccuzuaVsBw232uUcACOoKnH+7cy3OKaeYqC29acPFIRje9MiwptME8YBEY/wBRHyMqNdGsfrglTwkIrzloeJSLTXxyDOUTwRHvr9+kbMgG2Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8kt6nnc2epl+NaY7kRULLKPEs4B8yJQr3NMeK5cf/BU=; b=0abEIzQLVGX4D0lazT5QurIH39Fd/AyQXxUFpLWdNRE9NZ/Pn5bHls6u6xhkF48+L7GGwdKElwkCPjDXAdXfeZTpl2qM21JcJ/qjWJ3mvmeBC/qcRCqMS/qsPnqSOIDUlbcGxw6ED7WAkYtp191Vw3dv3zRG5EoG43VlGS0ymZ0=
Received: from AM6PR08MB4231.eurprd08.prod.outlook.com (2603:10a6:20b:73::23) by AM6PR08MB5079.eurprd08.prod.outlook.com (2603:10a6:20b:e8::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2900.17; Thu, 9 Apr 2020 11:54:09 +0000
Received: from AM6PR08MB4231.eurprd08.prod.outlook.com ([fe80::b08c:a849:e63d:6150]) by AM6PR08MB4231.eurprd08.prod.outlook.com ([fe80::b08c:a849:e63d:6150%7]) with mapi id 15.20.2900.015; Thu, 9 Apr 2020 11:54:09 +0000
From: Thomas Fossati <Thomas.Fossati@arm.com>
To: Laurence Lundblade <lgl@island-resort.com>
CC: "rats@ietf.org" <rats@ietf.org>, Ned Smith <ned.smith@intel.com>, Thomas Fossati <Thomas.Fossati@arm.com>
Thread-Topic: [Rats] Endorsement ID and verification key (was Processing Endorsements and Evidence into Results)
Thread-Index: AQHWCe9bvbcLEp+Zjk2vMtbuW9TMtqht0JyAgAA8hgCAArrqgA==
Date: Thu, 09 Apr 2020 11:54:09 +0000
Message-ID: <327A2536-0657-45B2-AD34-9DC97A83A429@arm.com>
References: <C3BC4E14-8BF8-4CD5-882B-F7AAF4B9155F@island-resort.com> <BB724659-3075-4ED2-8745-BACBD0D17C2B@island-resort.com> <7FF8F147-968E-40B4-8E46-A8E86094DD4D@island-resort.com> <71AEA046-BF2C-4ACD-AD1F-43E11648127E@arm.com> <E57F3041-A8DD-41B7-8D4A-73BDD5156893@island-resort.com>
In-Reply-To: <E57F3041-A8DD-41B7-8D4A-73BDD5156893@island-resort.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.35.20030802
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=Thomas.Fossati@arm.com;
x-originating-ip: [82.11.185.80]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: f616f19e-524a-4437-3a67-08d7dc7cbb37
x-ms-traffictypediagnostic: AM6PR08MB5079:|AM6PR08MB5079:|DB8PR08MB5129:
x-ms-exchange-transport-forked: True
X-Microsoft-Antispam-PRVS: <DB8PR08MB5129C8A51F590EED3645FD219CC10@DB8PR08MB5129.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:6430;OLM:8273;
x-forefront-prvs: 0368E78B5B
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM6PR08MB4231.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(10009020)(4636009)(376002)(346002)(396003)(136003)(366004)(39860400002)(6512007)(8936002)(5660300002)(81156014)(8676002)(6486002)(6506007)(71200400001)(186003)(2616005)(53546011)(2906002)(478600001)(26005)(36756003)(66476007)(33656002)(76116006)(6916009)(54906003)(15650500001)(66446008)(81166007)(316002)(64756008)(91956017)(66556008)(86362001)(66946007)(4326008); DIR:OUT; SFP:1101;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: 434zvcRFk26AcdQlBccLsQ9E7e0sJuzbDc+85NYsPSaPJLT+c2iJhEuDNScYj9OrQ3KoBPa9QknRparI60lMT8Fr7MBwrqvuzj4SrZIzD35mJdxqhDf2cGVYKVr5I/diD9pe7tGIXxhopo4OzfgjaMsJb0k0BC87JWXrycEETIfPP8BTk5Zi1K3MEDhKKiRpgY/plYAL9GPzxBAJ+Ompb4knSegcdIhno4c42oB/k922Quhj//WxjY9d2wWJQNJviHj578lsnA+ZBxQ1PBIh6LBRQmS0K2+leBhVBQSFFxD4g3ichYe1WTRHmhdU9dZnQ+JUSfesy8VbS88WoI6uUaxlaZLYZZ8VO1y+vwUi3Esdc1VQGeZbioaTiRuu5oHHXjQciNCc2c0u19vn1Ab6HurcaIAf04vMt8vt0ngjFq5GM4ZPhmmhqFSVOIU7BRK4
x-ms-exchange-antispam-messagedata: krWON6OKJiu86Ol75NCSgD+dnelopx26DzlZXVMWkXDV9FgEmWBjynypv9pyQs4cbsk+PSMcDUVi6OQkm+S7EBdcar8Pqqp7ywViZ6wAzi8JZEW3ha4IGDWakWiAGDJc+yBOMUMm4GlvUT5HROG/sg==
Content-Type: text/plain; charset="utf-8"
Content-ID: <9086B952C948A840ACF878BCD68B65F5@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR08MB5079
Original-Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Fossati@arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT032.eop-EUR03.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFTY:; SFS:(10009020)(4636009)(376002)(346002)(136003)(396003)(39860400002)(46966005)(26826003)(8936002)(186003)(53546011)(478600001)(2906002)(336012)(4326008)(86362001)(33656002)(36756003)(5660300002)(8676002)(81156014)(6506007)(6486002)(15650500001)(6512007)(70206006)(36906005)(82740400003)(6862004)(47076004)(2616005)(70586007)(316002)(81166007)(356004)(26005)(54906003); DIR:OUT; SFP:1101;
X-MS-Office365-Filtering-Correlation-Id-Prvs: 5420016c-85a5-4a07-d7a5-08d7dc7cb6ae
X-Forefront-PRVS: 0368E78B5B
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: r4yST5lyR+hvClltaxsFBCCyrTsanOr1aUrjzrDwKS/LHLyZHf7XnaLRVJ/OCDlZygvJWPX35IDEtKEW1PD7zvbl3TcVCSeVuWjeeVnYXz2SqdYxOvE+oOHSmpCHJOOttDd+EtEuIwvAXr7vPHJsMCzM1UG1mhn9MLBk9OAm8UnYk5jvGZArl7eZDSM6l95e3aCn8B4F+CBDfEXqVzM6AFAiOJM3WDMu3JTVs/MQxXTpKZujJx2cQ4/zDleMmJK0UQKaqvZa570MIC/GjSZREDo+j31g2/bnWuIF68pmGqqXPSyNxg6aJEFbQw2fY307fCxVRKLJJ14sUTfRO2a+LpYgemRp+5jWO3zOm2DNM/ItG8NLWRURJ6FqhFjBj0qIUfAliqQaPpYmbgmkLgDnPlCBUCwI6MpMwOMOfg+WVeKPA96B4OSGWfCeEBLuKhkPHEglk2N80RXmxn49G/mUco5g4L/yQlHaITwsBZBs1sTJLjB/65zmQhE1sCSmqdYM8WcS7Cjgs8AC9YoyLaHJLw==
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Apr 2020 11:54:17.0628 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: f616f19e-524a-4437-3a67-08d7dc7cbb37
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB8PR08MB5129
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/AKdOiaLIIWmtTd4ZewKJzeWrgu4>
Subject: Re: [Rats] Endorsement ID and verification key (was Processing Endorsements and Evidence into Results)
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Apr 2020 11:54:26 -0000

Hi Laurence,

On 07/04/2020, 20:12, "Laurence Lundblade" <lgl@island-resort.com> wrote:
> On one extreme is a separate endorsement for every device ("micro
> endorsement"?), which is what I think Thomas and ARM PSA are tending
> towards. The other extreme is one endorsement for a product line
> (macro endorsement"?), say a product line of TPMs. Then it's more
> like the data sheet for the product.
>
> Then there's different ways to fan this out to the different key /
> signing schemes (per-device key, group key, ECDAA, X.509). For example
> a macro-endorsement could include the root of an X.509 hierarchy and
> the individual devices (or groups of devices) would have individual
> keys that chain up.  With a micro-endorsement the per-device public
> key could be per endorsement.

One tiny clarification.  While it's true that the current PSA
attestation format gravitates towards micro-endorsements, that is not a
necessary outcome of the underlying security architecture.  The baseline
requirement is for a raw public key, but nothing prevents it being a
certified key instead.

There is both already shipped and in-progress work that would help
moving in the direction, specifically:
- have the attestation key associated with a profiled [1] and compressed
  [2] cert;
- have EAT / PSA tokens carry cert material instead of just key
  identifiers [3].

cheers!

[1] RFC7925
[2] draft-mattsson-tls-cbor-cert-compress
[3] draft-ietf-cose-x509

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.