Re: [Rats] Call for adoption of draft-birkholz-rats-reference-interaction-model

Henk Birkholz <henk.birkholz@sit.fraunhofer.de> Tue, 18 August 2020 12:40 UTC

Return-Path: <henk.birkholz@sit.fraunhofer.de>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A3B813A09A0 for <rats@ietfa.amsl.com>; Tue, 18 Aug 2020 05:40:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.848
X-Spam-Level:
X-Spam-Status: No, score=-2.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.949, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WpydmBLRrmXo for <rats@ietfa.amsl.com>; Tue, 18 Aug 2020 05:40:44 -0700 (PDT)
Received: from mail-edgeKA27.fraunhofer.de (mail-edgeka27.fraunhofer.de [153.96.1.27]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8FE793A098E for <rats@ietf.org>; Tue, 18 Aug 2020 05:40:41 -0700 (PDT)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A2FcBQBMyztf/xmnZsBfgQmDRYEfgTMKhC2RIporgWAJCwEBAQEBAQEBAQYBARgNCAIEAQEChEoCgiEBJDgTAhABAQYBAQEBAQYEAgKGRQyDU4EDAQEBAQEBAQEBAQEBAQEBAQEBARYCQ1USAR8BAQEDAQEbBg8BBTYLEAkCDgoCAiMDAgInHwEQBg0BBQIBAReDCwGCfAQLlCibeoEyhE9BQoNVgToGgQ4qhUVLQ4ZMD4FNP4ERJw+BXH4+glwBAQIBAYEmARECAYM3gmAEkn+iKF4qB4FbgQqBCgQLh0uRMQUKHoMAiVyFBAYojhWcf5BVhCcCBAIJAhWBaoELcE0kT4JpUBcCDY4rF4ECAQiHV4VEcgI1AgYBCQEBAwl8jwgBgRABAQ
X-IPAS-Result: A2FcBQBMyztf/xmnZsBfgQmDRYEfgTMKhC2RIporgWAJCwEBAQEBAQEBAQYBARgNCAIEAQEChEoCgiEBJDgTAhABAQYBAQEBAQYEAgKGRQyDU4EDAQEBAQEBAQEBAQEBAQEBAQEBARYCQ1USAR8BAQEDAQEbBg8BBTYLEAkCDgoCAiMDAgInHwEQBg0BBQIBAReDCwGCfAQLlCibeoEyhE9BQoNVgToGgQ4qhUVLQ4ZMD4FNP4ERJw+BXH4+glwBAQIBAYEmARECAYM3gmAEkn+iKF4qB4FbgQqBCgQLh0uRMQUKHoMAiVyFBAYojhWcf5BVhCcCBAIJAhWBaoELcE0kT4JpUBcCDY4rF4ECAQiHV4VEcgI1AgYBCQEBAwl8jwgBgRABAQ
X-IronPort-AV: E=Sophos;i="5.76,327,1592863200"; d="scan'208";a="23738886"
Received: from mail-mtadd25.fraunhofer.de ([192.102.167.25]) by mail-edgeKA27.fraunhofer.de with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 18 Aug 2020 14:40:39 +0200
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BkBgCJyztf/1lIDI1fHgEBCxIMQINFL3ADVDAsCoQtkSOaK4FpCwEDAQEBAQEGAQEYDQgCBAEBhEwCgh8CJDgTAhABAQUBAQECAQYEbYVcDIVyAQEEAQEbBg8BBTYLEAkCDgoCAiMDAgInHwEQBg0BBQIBAReDCwGDAAuUKZt6gTKET0FCg1WBOgaBDiqFRUtDhkwPgU0/gREnD4Fcfj6CXAEBAgEBgSYBEQIBgzeCYASSf6IoXioHgVuBCoEKBAuHS5ExBQoegwCJXIUEBiiOFZx/kFWEJwIEAgkCFYFqI2dwTSRPgmlQFwINjisXgQIBCIdXhURBMQI1AgYBCQEBAwl8jwgBgRABAQ
X-IronPort-AV: E=Sophos;i="5.76,327,1592863200"; d="scan'208";a="88437754"
Received: from mailext.sit.fraunhofer.de ([141.12.72.89]) by mail-mtaDD25.fraunhofer.de with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 18 Aug 2020 14:40:36 +0200
Received: from mail.sit.fraunhofer.de (mail.sit.fraunhofer.de [141.12.84.171]) by mailext.sit.fraunhofer.de (8.15.2/8.15.2/Debian-10) with ESMTPS id 07ICeX8L003782 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-SHA256 bits=128 verify=NOT); Tue, 18 Aug 2020 14:40:33 +0200
Received: from [192.168.16.50] (79.206.156.41) by mail.sit.fraunhofer.de (141.12.84.171) with Microsoft SMTP Server (TLS) id 14.3.487.0; Tue, 18 Aug 2020 14:40:28 +0200
To: Laurence Lundblade <lgl@island-resort.com>, "Nancy Cam-Winget (ncamwing)" <ncamwing=40cisco.com@dmarc.ietf.org>
CC: "rats@ietf.org" <rats@ietf.org>
References: <DBDAA23E-74BC-45C7-AA87-C303963131CE@cisco.com> <D4B37433-E0DF-4FE4-84E1-A8880359190B@island-resort.com>
From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Message-ID: <19311dcf-cfe7-a2c0-c8cb-c0ec8aeca634@sit.fraunhofer.de>
Date: Tue, 18 Aug 2020 14:40:27 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.10.0
MIME-Version: 1.0
In-Reply-To: <D4B37433-E0DF-4FE4-84E1-A8880359190B@island-resort.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Originating-IP: [79.206.156.41]
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/_Sflu4ucPI_dRLYqwczzc4bQIII>
Subject: Re: [Rats] Call for adoption of draft-birkholz-rats-reference-interaction-model
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Aug 2020 12:40:47 -0000

Hi Laurence,

there is a slight difference between 'generic' and 'reference' (at least 
from my PoV).

Yes, 'these' are THE *reference* interaction models for all of RATS - 
that hopefully also accommodate all FIDOs (at least that was the intent).

Meanwhile, each reference interaction model is probably always specific 
to a subset of RATS use cases - which is intentional.

If a use case - or better: solution I-D - uses a specialization or 
derivate of a reference interaction model (because it describes 
something new) that can be easily elaborated on by using the reference 
models as... well a reference.

More generalization or more abstraction of course makes the models fit 
"better" to bigger sets of use cases, but it also removes the value they 
add. For example, if a solution does not require an Authentication 
Secret ID to be conveyed, then it can now simply refer to the concept 
and highlight why the contribution does not need that baggage.

As a result, I think I would neither call them "THE models" nor would I 
attempt to generalize them more. They are simply "THE reference models" 
that help with placing emerging solutions in the landscape of the 
exiting ecosystem (which is notoriously hard to do, typically).

I am not sure, if my reply was helpful or not, though :-)

Viele Grüße,

Henk

On 14.08.20 20:32, Laurence Lundblade wrote:
> Henk and others, can you comment on how this relates to FIDO, Android 
> Attestation, ARM PSA Token and such?
> 
> It seems that a decision has to be taken as to whether this is:
> - THE generic interaction model for all of RATS in which case FIDO, 
> Android and such have to fit into it
> - One interaction model specific to a subset of RATS use cases
> 
> I did a quick read and it seems like FIDO, Android and such could fit. 
> But it seems a commitment one way or the other is needed up front. If it 
> is THE model, then the work to make sure it is fully generic needs to be 
> done. People (not just me) will have to review it to see if it fits all 
> attestation use cases. If it doesn’t there will be writing to do.
> 
> Right now it seems framed as THE interaction mode (abstract, 
> introduction sections). Are the authors committing to this as THE Rats 
> interaction model?
> 
> I think this needs to be clear before the document is adopted.
> 
> LL
> 
> 
>> On Aug 12, 2020, at 1:25 PM, Nancy Cam-Winget (ncamwing) 
>> <ncamwing=40cisco.com@dmarc.ietf.org 
>> <mailto:ncamwing=40cisco.com@dmarc.ietf.org>> wrote:
>>
>> Hello RATs members,
>> At our IETF 108 session we discussed the draft:
>> https://datatracker.ietf.org/doc/draft-birkholz-rats-reference-interaction-model/
>> There was interest in the discussion on the adoption of the topic, but 
>> ran out of time to get consensus on “where” these interaction models 
>> should be documented.  Further, Henk started an email thread prior to 
>> our session to get a sense of interest and where these models would 
>> best be described.
>> Given those results, there seemed to be a preference to keep the 
>> document as a standalone draft that describes all models.
>> Thus, this is a Call for Adoption of the 
>> draft-birkholz-rats-reference-interaction-model to serve as the 
>> starting point for a standalone draft that describes all models.  If 
>> you have reservations for documenting interaction models, or for such 
>> a document to be a standalone draft to describe all of them please 
>> respond to the mail list and provide rationale for your concerns.
>> The call for adoption will end on Aug 28.
>> Best, Nancy (on behalf of the RATs chairs)
>> _______________________________________________
>> RATS mailing list
>> RATS@ietf.org <mailto:RATS@ietf.org>
>> https://www.ietf.org/mailman/listinfo/rats
> 
> 
> _______________________________________________
> RATS mailing list
> RATS@ietf.org
> https://www.ietf.org/mailman/listinfo/rats
>