Re: [Rats] Review of draft-birkholz-rats-daa

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Mon, 07 June 2021 07:07 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 126AF3A39F1; Mon, 7 Jun 2021 00:07:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=nS8zeyu4; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=nS8zeyu4
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YaW8OKIFFISQ; Mon, 7 Jun 2021 00:07:44 -0700 (PDT)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-eopbgr70073.outbound.protection.outlook.com [40.107.7.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7731D3A39F8; Mon, 7 Jun 2021 00:07:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=O/izt/+8FYnBVjDf6yGojXqt50d02MNBZE4iFflYPEc=; b=nS8zeyu4kAxQDFp5gvsmBeYLwebsUE0FAXRJO/LF088jVoEHmVOP0YNDSwX8ujLnZEBCmCHfmTLfYexahsa1vg/ao3tldnn9RVZNUMNa09bFIoFk5fLGN4KXpA+1Bl18znRcRTp/GRGUdHzq7eHlal9d2wy7qnroeYfSVhifndY=
Received: from AM7PR04CA0014.eurprd04.prod.outlook.com (2603:10a6:20b:110::24) by DB9PR08MB6890.eurprd08.prod.outlook.com (2603:10a6:10:2a8::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4195.23; Mon, 7 Jun 2021 07:07:40 +0000
Received: from AM5EUR03FT007.eop-EUR03.prod.protection.outlook.com (2603:10a6:20b:110:cafe::76) by AM7PR04CA0014.outlook.office365.com (2603:10a6:20b:110::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4195.22 via Frontend Transport; Mon, 7 Jun 2021 07:07:40 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT007.mail.protection.outlook.com (10.152.16.145) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4195.21 via Frontend Transport; Mon, 7 Jun 2021 07:07:39 +0000
Received: ("Tessian outbound 6d1d235c0b46:v93"); Mon, 07 Jun 2021 07:07:38 +0000
X-CR-MTA-TID: 64aa7808
Received: from 902e492d21c7.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id C82D2314-627D-4F5B-8874-46211E5C732A.1; Mon, 07 Jun 2021 07:07:28 +0000
Received: from EUR04-DB3-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 902e492d21c7.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Mon, 07 Jun 2021 07:07:28 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=h97Lu3JqDxJMRwH5+ErDFrQSCqnB6TAmyFEKXzA2JcmmmjcAITl/EVnzcDofi9O7+wnRU7UEnrswR2wB191AP7fFpB/LnojS1inQ6vQvzGnMusejb6IOpcmjv4alDx9fNqBZ8AWcPRkJ8UpuzaPMUPuQ2G+kQ8p5pzgJqB5MxMShp0aNwLdZW6RFI6iPEYnkyHdmusjVHOsUOI/179OODSCtqMpNoFz7DINHYWsAXZjycKqZeaTy5mS9q5rvixD30JTEKLNqdosPD82vhI0J5FuRs75Whjz7zXBYqO3f1Gaf13rCxWlT1UgKSvFQpxAqFOgf4vLSCjRIi6BdEXDmOw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=O/izt/+8FYnBVjDf6yGojXqt50d02MNBZE4iFflYPEc=; b=YvaUuZFUCazb5Y+RLMZOfkJsj2gUiel7EbVEuIa9QxTlQeV/5uXiqD2murA1/lEZHW5mLxv7BXzeDQdA/wfJR/0RCp6rupC+Ie2SdRMOxoj11+anyDfG2uJIZpK+98zRGOSE4p2jMfQQpjJyhgEPy3gjRyv6l6C+YBzppr0l2+VWrIqCuoZO1LHs7BdeOd5/C9Aj7xUcw+Gak8+RIwNIxkSw36DsKW7sQd7CScUo0zpb9yeYOFAmirU2ScfIeWylrWEnH1J4za7iOTa4JbJZhTAFcg7iI6JeNW1QFj07F7+Ri4ljdjWzgDWKU98i3tWaObFZtLUL9ed8B3ZOtYdb7w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=O/izt/+8FYnBVjDf6yGojXqt50d02MNBZE4iFflYPEc=; b=nS8zeyu4kAxQDFp5gvsmBeYLwebsUE0FAXRJO/LF088jVoEHmVOP0YNDSwX8ujLnZEBCmCHfmTLfYexahsa1vg/ao3tldnn9RVZNUMNa09bFIoFk5fLGN4KXpA+1Bl18znRcRTp/GRGUdHzq7eHlal9d2wy7qnroeYfSVhifndY=
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com (2603:10a6:10:20d::17) by DB8PR08MB5020.eurprd08.prod.outlook.com (2603:10a6:10:e3::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4195.23; Mon, 7 Jun 2021 07:07:27 +0000
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::3405:8699:991d:b2e9]) by DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::3405:8699:991d:b2e9%7]) with mapi id 15.20.4195.030; Mon, 7 Jun 2021 07:07:27 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: Christopher Newton <c.newton@surrey.ac.uk>, "draft-birkholz-rats-daa@ietf.org" <draft-birkholz-rats-daa@ietf.org>
CC: "rats@ietf.org" <rats@ietf.org>, Thomas Fossati <Thomas.Fossati@arm.com>, Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, Liqun Chen <liqun.chen@surrey.ac.uk>
Thread-Topic: Review of draft-birkholz-rats-daa
Thread-Index: AQHXUicvJq5JZhB/2Euw8worVT3R7qr1uvdAgBHBg7CAALXiQA==
Date: Mon, 07 Jun 2021 07:07:27 +0000
Message-ID: <DBBPR08MB5915525A6AC4D64B8FA7968FFA389@DBBPR08MB5915.eurprd08.prod.outlook.com>
References: <2AC24A3A-C295-4BAC-8007-4D0B75C6C60B@arm.com> <DBBPR08MB59152A44396C2E7EF9ED79CAFA249@DBBPR08MB5915.eurprd08.prod.outlook.com> <AM8PR06MB7441DE5E10DFCAF237468A4EB8399@AM8PR06MB7441.eurprd06.prod.outlook.com>
In-Reply-To: <AM8PR06MB7441DE5E10DFCAF237468A4EB8399@AM8PR06MB7441.eurprd06.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 0F8B7B70062BDB4483841FF3A81E45FF.0
x-checkrecipientchecked: true
Authentication-Results-Original: surrey.ac.uk; dkim=none (message not signed) header.d=none; surrey.ac.uk; dmarc=none action=none header.from=arm.com;
x-originating-ip: [80.92.119.239]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: 4050de57-9890-4715-15a7-08d92982efcb
x-ms-traffictypediagnostic: DB8PR08MB5020:|DB9PR08MB6890:
x-ms-exchange-transport-forked: True
X-Microsoft-Antispam-PRVS: <DB9PR08MB6890AE36CD431D0DC56D3341FA389@DB9PR08MB6890.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:10000;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: tM7LFcsh8siH2Ww0UxHfvw8SYNJGs9gZYqXBtMb/V8LKc5fcwilEmdTee4LM8cFoKYIE/+/gZUeUKQMoauSEkQjIEHkqZ7kCeqgoEsPL2psRZH0438Dgkh4fdM8spclQUmQ90pevb3UjCGAGxjGY5uZeSfM1PewBzOQDgi/3IgGaJRrKfzvBKCFKFpdyIWAmRlNk6Qv1vSURXTKJnI+VnY0eHV0eodszPinlPdqEXmHoTXfEveABdkLVfK/F9Go53OFc7DWMEVge5aJB3kZK0vgkqELWHC9Xz/JMyuSoE8uhjjtl13xhVgj3dAe4YdvK9QjADYQYwZK0wPd8LeNIM1JYjZ/wPxKEGd5kGnWaBSLK5eWBW5u5ryRwCAg6HMKnmlvLpcCupZOeWTrs9CCgQgJcNnSXCRTJbvt2z9jVwhxx5rjYFDGPqhuY8wpA1nUnYRR7QdWLaNwdDg+VqnULR1PaUeB0mH9PMuSGj0OY3CXzzoIIdWUzt79HZLUXcVEZJEzM4dXBnbTW2vtl/Sk7tezx1k+EhJYoH9WdJPT6AEbDE8EOY+kocBrwK31qoknQoTULe3Qxztqd5wq4pWIHVJ9DTdUd3vtl7DPKAGLmnDV/c0fGdTRpA20fBdE+irSChCQ+h29fsoWE276jC5l0JY9mMjslV85ifnQG6UAlvgls7NiA9fU0jThGZ/ptGXtkHEUZwOBLx0eATYG5fVcELA==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBBPR08MB5915.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(396003)(346002)(376002)(39860400002)(366004)(136003)(8676002)(8936002)(83380400001)(478600001)(4326008)(55016002)(966005)(9686003)(5660300002)(71200400001)(38100700002)(122000001)(26005)(186003)(86362001)(316002)(66446008)(64756008)(66476007)(7696005)(33656002)(76116006)(53546011)(6506007)(66946007)(54906003)(110136005)(2906002)(52536014)(66556008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: FWSW4WjQCFoUUKpB8JUzhHUA0MCQuFgkJ7c39tpg5eEh/fLjFfx6T416tmFNp0vgalKLe3xuwhAQ6fKwObywhBYN3XaxYcNp/hYcvkEN8fofuGy+bvhnClVt3o1wSE+GTPaFZP8/fStEVZKDYHm32n64KD84Ir+Ky5CL9Vasw8ZvVJBkJ9o92cZR8DHTh0fbmrJpIb9TLrv/Z7kemdsJ1Ex4dmo26lJKAPVpCHznRVUFi8B0GYwlgGYm+Wf1wjmHPk8YZ6VMGh3r0XpW86C449Krb5yR/UlVn+blVpOyC9rcoxOL5iVxchBG//9GzqLGEnjZ64akOF9xfQa+9Ubrc8mFu/hWAwPBXH7O5mby+PJvDMMTaN2yPDoJLLTnYzCIBQQvaMpGCvOS2jzScnTauWaABL7JrKH1S2HghVy1M2akTeXNnMgx6pbA1G3uwxFpJ9PqxGB3gfZAQhpkxQ+QYPR91xXhMDTJTq/IDWaOQNCH4J0ZG9GJ2IJcwXXfob3GSVVb0lOunvKeY/AF4OvCS8eR4xzS44cEV8IPjRc0rwXTFolGYTF/bwdxiaMp2cQqPMzmraNQglXOvGld+4IcN8UB2IsOy5VzCbK6FiE6gZBUNalS0oo4duOxJ8ZiJOr2+mfrdjvhdF+jZBSPIGsQ3jBqCpjbTN2OAli8480UEOfHRz6RhMXrG8VvxDIgE9EaobZ4/d/VVW38Lc4wAFFJD9OsT6u3MJYm2V1x+xbeKvSbzdTHBloYJ08K4coIhHclfZNfl2Do8cljgQPt6ipgqWuJn1rhC9UXel2+6LVh1EA+AtSuuMCNx41xSCsIkLwzl+pciTTMRSSwXqNn6NMV1b8MscUh3mG08kwqn//IgJeJfm5p1T5s1h5a49m98u18u2EiC7RseznPv6Ww9QzzilncuhU2ce+Amuzx1G5vTQsucNcqNNfN36VM0NNM5TEtcQYPv6k/hFDyJwDTO/4Pm+DolL8MgrhKUnaUd+KJ3+e22rV7Onq0BR/tnpXOtaGyFY8AjLglch33iSNncgzcD8Qls55msYotJLyHUfxx3mWQIYImFcIoTB9he73oy5B4eK4qLSLNTf8h+mGy54LT/7aOJs/+6kfTwgPlnYA+SD4xH3b8R1RTDeJ2rC9/dWismygGQp5UC5xfGyyqO6TADKucJDz34qrRq9ts38piL9m7E8QfUb7whLxrsbQGxoR4ULLEJTPakRMWuFhspvd/oryvAACWzwV1q99xdA1OCZo/HHjJu7rwm4WOn8ogwtd9qIQBDARyoBltxul2hJJGTMIxClphftJYxaRGuFzXuZXZreqOtiudHE1CMuRW6qfs
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB8PR08MB5020
Original-Authentication-Results: surrey.ac.uk; dkim=none (message not signed) header.d=none; surrey.ac.uk; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT007.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: c2baad46-9be1-43cc-6344-08d92982e89e
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: OVPfTKh0oK7ND+GlNnWp3lwG018rrerxQAmCV8B7PV9BziMfBv3NObCuWAdAKwwp+RSibGeK0SG5MFlRzAecZuZHcslYZlyIQmjUjIUkSMF2iR0WwhjEQt5lYTg2T8FPNQlry3oVqETAgS1QzeWfnxTMfYZwXJIjr0peMHe6Er3+FliiiSXVFHD5Msde21FVWmF3IVzIHLjPuyKdbCNVRpFxqQ6UhP+NuWNvGHPzWwdcLvjMBQucGgpVr0VECKbG5KnUCEj6sWSH4laUWOTN1+MeisVgQzDicyIhhIqYH/9ve0YCCf7c0uR6NeuMzqjlLycU66c3s+OjxBTAyRisWKuQh3cnuGXP8sKp0QDoUi0dQqJtEGbJ6ZWrAn4yvBb85Jpvg6sozktZCDiveKz4yl/4XjtHAHnduwlZ0AQ+V1VopNJR9euOhLDJk5RnWsE79cUu3zJ1DoU6fYhaJcX3kgtJf15L5wsUQhMLZLJDV6V6a8BlXZ1HpJ+Bxa/tiRkAIH6wpwuRMI+hRWVaqa9tIycgcyjQ1QvRsSudbWW+XTxAAd+Bslrno03QMbHZvNaRJeykNCxgbbJf09eYldS9vdgzcF56IjwRijb/P2yBT3HKWb+pKSZyqp272U9p64eLDGO8CawTFT8Uvhqc1r8Yr2AcYx79xaxy378odo8hBlOF/OWDPmbfG81s+ArMUd01G6Zbpawptg2GsYRWQusjA1hgrU+gjAJO75laY+CqlkeYKBxjqsbGJVWaU7vtB/qvOiUK9WvvdBIcfBwQ9fJ4Dw==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(36840700001)(46966006)(8936002)(336012)(82310400003)(7696005)(498600001)(966005)(52536014)(110136005)(47076005)(54906003)(55016002)(53546011)(6506007)(356005)(81166007)(186003)(9686003)(2906002)(450100002)(107886003)(26005)(4326008)(70206006)(5660300002)(70586007)(36860700001)(33656002)(86362001)(8676002)(83380400001); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 Jun 2021 07:07:39.4418 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 4050de57-9890-4715-15a7-08d92982efcb
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: AM5EUR03FT007.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR08MB6890
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/MZIaV471_phJSREwCAG0fpYGKTI>
Subject: Re: [Rats] Review of draft-birkholz-rats-daa
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jun 2021 07:07:58 -0000

Hi Christopher,

I think it would be worthwhile to note in the security considerations section that you are making certain assumptions about the content of the token. It is easy to imagine that those using the token get this wrong.
There is also good privacy terminology you can rely on, see https://datatracker.ietf.org/doc/html/rfc6973

Ciao
Hannes



-----Original Message-----
From: Christopher Newton <c.newton@surrey.ac.uk>
Sent: Sunday, June 6, 2021 10:20 PM
To: Hannes Tschofenig <Hannes.Tschofenig@arm.com>; draft-birkholz-rats-daa@ietf.org
Cc: rats@ietf.org; Thomas Fossati <Thomas.Fossati@arm.com>; Henk Birkholz <henk.birkholz@sit.fraunhofer.de>; Liqun Chen <liqun.chen@surrey.ac.uk>; Christopher Newton <c.newton@surrey.ac.uk>
Subject: RE: Review of draft-birkholz-rats-daa

Hi Hannes,

Thank you for your interest and comments.

> In any case, [DAA] has to be a normative reference.
Yes.

> I would also like to see the privacy properties articulated in more detail, particularly when DAA is used with an attestation token that potentially contains a lot of claims.

For DAA itself, we assume that the attestation token does not reveal the identity of the signer. However, if this is the case there is research into property based attestation that will anonymise the attestation token.

Regards,

Liqun and Chris.

--
Dr Christopher Newton
Surrey Centre for Cyber Security
Department of Computer Science
University of Surrey
Guildford, Surrey, GU2 7XH, UK
--

-----Original Message-----
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
Sent: 26 May 2021 14:59
To: draft-birkholz-rats-daa@ietf.org
Cc: rats@ietf.org; Thomas Fossati <Thomas.Fossati@arm.com>
Subject: RE: Review of draft-birkholz-rats-daa

Hi Henk,

I have not been following the RATS work closely and hence I was wondering whether this document is supposed to become part of the architecture document?
In any case, [DAA] has to be a normative reference. I would also like to see the privacy properties articulated in more detail, particularly when DAA is used with an attestation token that potentially contains a lot of claims
IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.