Re: [Rats] About (E)UID's

Simon Frost <Simon.Frost@arm.com> Wed, 12 February 2020 14:08 UTC

Return-Path: <Simon.Frost@arm.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 605A712001E for <rats@ietfa.amsl.com>; Wed, 12 Feb 2020 06:08:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=ZDn0PADX; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=ZDn0PADX
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Pz8BWrHatW8L for <rats@ietfa.amsl.com>; Wed, 12 Feb 2020 06:08:32 -0800 (PST)
Received: from EUR05-VI1-obe.outbound.protection.outlook.com (mail-vi1eur05on2060a.outbound.protection.outlook.com [IPv6:2a01:111:f400:7d00::60a]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C1BBF12001A for <rats@ietf.org>; Wed, 12 Feb 2020 06:08:31 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NVLJwtlt0lOviAqzo3mlCzPcvVCchBXm2bGN3NzTsAo=; b=ZDn0PADXUTRum8kX+oCD+8XoAbRzHbuK6w/fSkYFzF6X5ipAebR199m/kk6oGGzzcrbnNmWqkJfwIXY4t3OKW0Z3AM6Sur3CwwY006iIYGFNZnhe0bsHxaOl1Gwucg8sT7VDJgv/CVzuiQENKc/wj4jYCcqjVOIxVG2A9UO6OrE=
Received: from VI1PR08CA0141.eurprd08.prod.outlook.com (2603:10a6:800:d5::19) by DB6PR0801MB1623.eurprd08.prod.outlook.com (2603:10a6:4:3b::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2707.25; Wed, 12 Feb 2020 14:08:27 +0000
Received: from DB5EUR03FT017.eop-EUR03.prod.protection.outlook.com (2a01:111:f400:7e0a::207) by VI1PR08CA0141.outlook.office365.com (2603:10a6:800:d5::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2729.23 via Frontend Transport; Wed, 12 Feb 2020 14:08:27 +0000
Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=bestguesspass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by DB5EUR03FT017.mail.protection.outlook.com (10.152.20.114) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2665.18 via Frontend Transport; Wed, 12 Feb 2020 14:08:27 +0000
Received: ("Tessian outbound 0420f1404d58:v42"); Wed, 12 Feb 2020 14:08:27 +0000
X-CR-MTA-TID: 64aa7808
Received: from 937ddb245f09.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id B4121A7F-E79D-4021-BD30-A660AE0ADBAE.1; Wed, 12 Feb 2020 14:08:22 +0000
Received: from EUR02-AM5-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 937ddb245f09.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 12 Feb 2020 14:08:22 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=aH6TzAOwga7VfeHI+EXn579nEonaGQglTgwxs9+zAkZwQ1KjM4zWNqCgAvTJ3cidmQFsztKG8G4eLksuSQPjsB79GxGfI7O8qHF2Ah5tdc/ZDCrDy8oDVXiVibjpsV/XMv8OVoGlCd3AAjbOmMlvutUFcmdYM5jnoYDK7LmhVh0hyC8wQ/X87qA2Gmw/JXF+WBEN+OqfFT8Px63eaKOmJJL2iWAyh1lA5EgorVs7y2TeJf0OIwskIkCDAuJRl3/boBeKhtCjcjx6qygLhFK18ikNGuAOPXhJoWRjQO0OTpFXlRB0XJr4nNVXS9P28pAD2KOVHWMqiutOrriPvXHNqQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NVLJwtlt0lOviAqzo3mlCzPcvVCchBXm2bGN3NzTsAo=; b=oegRVFpf/Yrcm5l4mwq6Yo7IZpaSDhmfzeV+GQEnYg0sE6TjXKthl+7F/o1N20gZQR1D6itGCF6rdIL8XN+bKy0xokvc4F8RjASVq1X/qa/rgqGUoY5sRhpl/5pbSoOzRUJcz4xRkewtGYTB5qNQlTjntvq7N8WDIr2PfWayaYL/9iOkNB1zjfh5VtjkgjHtQeK/lVPP3OOSrs9L19k23bR14VYPdZ1RkGrDX3dxIPJCLaGQ+UGd3cJFGt0f1V1ULKkku3LvlVhwj/ZM+AEmkl1fpf1IwLyUFxnNf6cyx8HI/S4OIh89O9KZ3u4zMUFm4ZVDSHdAPplvUDzoUBUrKA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NVLJwtlt0lOviAqzo3mlCzPcvVCchBXm2bGN3NzTsAo=; b=ZDn0PADXUTRum8kX+oCD+8XoAbRzHbuK6w/fSkYFzF6X5ipAebR199m/kk6oGGzzcrbnNmWqkJfwIXY4t3OKW0Z3AM6Sur3CwwY006iIYGFNZnhe0bsHxaOl1Gwucg8sT7VDJgv/CVzuiQENKc/wj4jYCcqjVOIxVG2A9UO6OrE=
Received: from DBBPR08MB4903.eurprd08.prod.outlook.com (10.255.78.17) by DBBPR08MB4265.eurprd08.prod.outlook.com (20.179.43.205) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2707.26; Wed, 12 Feb 2020 14:08:20 +0000
Received: from DBBPR08MB4903.eurprd08.prod.outlook.com ([fe80::880d:db9f:7e7c:a934]) by DBBPR08MB4903.eurprd08.prod.outlook.com ([fe80::880d:db9f:7e7c:a934%7]) with mapi id 15.20.2729.021; Wed, 12 Feb 2020 14:08:20 +0000
From: Simon Frost <Simon.Frost@arm.com>
To: Laurence Lundblade <lgl@island-resort.com>
CC: "Smith, Ned" <ned.smith@intel.com>, "Salz, Rich" <rsalz@akamai.com>, "rats@ietf.org" <rats@ietf.org>
Thread-Topic: [Rats] About (E)UID's
Thread-Index: AQHV3bXmW6h++AX9GUeMvr4rBHsANKgP5Z2AgABgOICAAayuAIAEFkMQgAF83wCAABkjIA==
Date: Wed, 12 Feb 2020 14:08:20 +0000
Message-ID: <DBBPR08MB4903840E6D30A59083F8B119EF1B0@DBBPR08MB4903.eurprd08.prod.outlook.com>
References: <8BDAAE2E-9803-4048-AD5B-59233708E6FB@akamai.com> <1C16DAA0-D03B-417C-894A-30C4015AEED7@island-resort.com> <DBBPR08MB49031E717F69E4CF58CF67A1EF1C0@DBBPR08MB4903.eurprd08.prod.outlook.com> <509C8229-20DC-4888-BE1D-9109733A9E2D@intel.com> <5B9516E6-1441-462E-86D2-B630B32CE1C7@island-resort.com> <DBBPR08MB4903356ED09601AA7A6006FAEF180@DBBPR08MB4903.eurprd08.prod.outlook.com> <07A3E092-068F-4E35-8C39-D290FDB8CFDC@island-resort.com>
In-Reply-To: <07A3E092-068F-4E35-8C39-D290FDB8CFDC@island-resort.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: cb82af3a-2360-4e1c-9171-c9e69d7fb462.0
x-checkrecipientchecked: true
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=Simon.Frost@arm.com;
x-originating-ip: [217.140.106.50]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: 8b8f4ef6-62d8-4413-4f73-08d7afc50819
X-MS-TrafficTypeDiagnostic: DBBPR08MB4265:|DB6PR0801MB1623:
X-Microsoft-Antispam-PRVS: <DB6PR0801MB16235434660D0639CACB2DC5EF1B0@DB6PR0801MB1623.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:9508;OLM:10000;
x-forefront-prvs: 0311124FA9
X-Forefront-Antispam-Report-Untrusted: SFV:NSPM; SFS:(10009020)(4636009)(376002)(366004)(396003)(346002)(39860400002)(136003)(199004)(189003)(478600001)(8936002)(8676002)(52536014)(5660300002)(81156014)(81166006)(6916009)(4326008)(9686003)(316002)(33656002)(86362001)(54906003)(66556008)(71200400001)(55016002)(66946007)(66476007)(64756008)(76116006)(66446008)(53546011)(186003)(26005)(6506007)(7696005)(2906002); DIR:OUT; SFP:1101; SCL:1; SRVR:DBBPR08MB4265; H:DBBPR08MB4903.eurprd08.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: KH4Mki6ZHf0yJLa0vfEKtBaGXM+jgaVU0sjBx7SsB2as+vpxiFCgn6V9ZZgjXobm27vny13mrFT8Te7IvpJOQvx6mjTm6Yptlr0EEdUYutzVdM92k5R4JuSZbU4dvFOCqc5W1QyuA7giM691jGhDdoMKbC/S39oS+Al26kn+BlFZ18M5ocdEWJNqy9j5Q8dpCik15NBTpDANb6GXH5F/nbjwt3kHAjJO5R6kXPlkCoaRsNZeiCWA6Xhz2nu8EGc1EVP6YGNA1wD8GtSMAZdg9iKlRuLe2yH/bnr9TZBujJdVnkfK7yEYAXmAvHQ0el1Lpyw+Wc/2Qx5igbrqU3DdfRwOV75eR/ByJrxzDvZDFjY6hMf8I/5165Cnte0b1pppGl5k8XU3c6juPsRTYunRqcqdVtAt75N2oU5NLkbWsPrVHv6ZeVL28XQo5QUWjnMN
x-ms-exchange-antispam-messagedata: UUyVqv30SWdVwX0bpYkY6Yahb/4eJux2zKl5nfD1FhKnidiN3oCxOgNNjNxx8hOvgbe20lZb8XOKeaZhNGBClzlyXJg9sOBLOd/wW/PjCFOdWNy8LZ22ecKwniiJWHZD8rXxVqS0QE3VW6h+IqVoug==
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_DBBPR08MB4903840E6D30A59083F8B119EF1B0DBBPR08MB4903eurp_"
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBBPR08MB4265
Original-Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Simon.Frost@arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: DB5EUR03FT017.eop-EUR03.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:63.35.35.123; IPV:CAL; SCL:-1; CTRY:IE; EFV:NLI; SFV:NSPM; SFS:(10009020)(4636009)(39860400002)(396003)(136003)(376002)(346002)(199004)(189003)(33656002)(53546011)(7696005)(70586007)(81166006)(26005)(70206006)(8676002)(6506007)(81156014)(26826003)(8936002)(33964004)(54906003)(478600001)(52536014)(336012)(86362001)(55016002)(186003)(5660300002)(9686003)(2906002)(356004)(4326008)(6862004)(316002); DIR:OUT; SFP:1101; SCL:1; SRVR:DB6PR0801MB1623; H:64aa7808-outbound-1.mta.getcheckrecipient.com; FPR:; SPF:Pass; LANG:en; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; A:1; MX:1;
X-MS-Office365-Filtering-Correlation-Id-Prvs: 163d654e-c03d-46b2-12db-08d7afc5041e
X-Forefront-PRVS: 0311124FA9
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: F4Y/ksbzJgLZQ00ki/NsYcVYj6ChsDj1tMsJgbpwbXUGkhJvSuajjr9+BAbdSEJ5ytNZBCq+CnelYJiqeuWYbpYdUkm63WN98vilt2DafTsiwhOXm9Lvr4xPSYL0qD68OyKQGlzivFUqpQmFojyCCEGkf7Q74Ts9dCRyDUFVNvIARrRpYKqILHSOCWJ4hSSXIvxAHkpjqqVKYqUEkyk1v5n65farFC9EHVhZnnqQEG9UT2wWKMXMg+W8cqu/yAN/NfJV9ksV9MkbLs+WARN9BqzJkfq6U6qkJbBpJd0dw3tZAB7q08T+HAsvS0YIXkqJ5gvgHpKYQND4x1HJ7bC8aYzaj4AosEshr6HgV0Ootqt4cXzmlOIP2dOMyRijRM63KbzRzDXruNIfkzX0jq/7+ZP93wraqa1rdTLLwEXSKLRQMFu2s1INGWCMSAhs9OK7
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 12 Feb 2020 14:08:27.4788 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 8b8f4ef6-62d8-4413-4f73-08d7afc50819
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB6PR0801MB1623
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/L-ZQ5JRPdJGsLX4g8ydQUc3lWQc>
Subject: Re: [Rats] About (E)UID's
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote Attestation Procedures <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 Feb 2020 14:08:36 -0000

Sorry, missed this while replying to Michael – see my just posted response which should enlarge on my original comment.

I don’t think probabilistic uniqueness can be relied upon globally. However it should be reliable where other information, either implicit from the use case or explicit by the use of other information establishes a more reliable locus.

I agree no one will want to pay fees to, or take liability for, a registry for global uniqueness on an instance level.


From: Laurence Lundblade <lgl@island-resort.com>
Sent: 12 February 2020 12:33
To: Simon Frost <Simon.Frost@arm.com>
Cc: Smith, Ned <ned.smith@intel.com>; Salz, Rich <rsalz@akamai.com>; rats@ietf.org
Subject: Re: [Rats] About (E)UID's


On Feb 11, 2020, at 3:39 PM, Simon Frost <Simon.Frost@arm.com<mailto:Simon.Frost@arm.com>> wrote:

I suggest we should change the description of the UEID claim to allow the standard to support more interpretations of what the locus of uniqueness might be to an implementation.

Hi Simon,

Can you say more and / or give an example?

The design goal of UEID is global / universal uniqueness — the locus is everything. It offers the vendor two paths to achieving this.

1) Probabilistically unique large random values that need to central authority and involve no money.

2) Global values assigned and managed by a central authority like IEEE or GSMA. This usually involves money.

1) is flexible in that it allows creation of the value by hashing together enough random bits from sources ready-to-hand (which Thomas points out, PSA is using).

We can add other global registries if needed (and they truly are global).

LL


IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.