Re: [Rats] About (E)UID's

Thomas Fossati <Thomas.Fossati@arm.com> Wed, 12 February 2020 08:54 UTC

Return-Path: <Thomas.Fossati@arm.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D56D01200A1 for <rats@ietfa.amsl.com>; Wed, 12 Feb 2020 00:54:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=EJZd7Fyt; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=EJZd7Fyt
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 46caUwNfMkrm for <rats@ietfa.amsl.com>; Wed, 12 Feb 2020 00:53:55 -0800 (PST)
Received: from EUR05-VI1-obe.outbound.protection.outlook.com (mail-vi1eur05on20622.outbound.protection.outlook.com [IPv6:2a01:111:f400:7d00::622]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 66E1A1200B1 for <rats@ietf.org>; Wed, 12 Feb 2020 00:53:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ItfcnK1qGAdifa4fo7rdMlJLqyApSXZSHfY05uisibA=; b=EJZd7FytUhLinnjersytMgE18tF9j6sBFYcN/hvaiE0dAUn4ujmurUVY3An9+aHiF3zi7UzCN88/Dj/2Irk4I9oMIbqfrH/7i5na+SNocH2a0wBiSCctti8N/DdaXzoRrvzpzxheOtcmmCMrWSbC81QzcCT2WRIBe3zge1cGDPY=
Received: from AM6PR08CA0003.eurprd08.prod.outlook.com (2603:10a6:20b:b2::15) by AM6PR08MB4582.eurprd08.prod.outlook.com (2603:10a6:20b:8f::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2707.26; Wed, 12 Feb 2020 08:53:51 +0000
Received: from VE1EUR03FT050.eop-EUR03.prod.protection.outlook.com (2a01:111:f400:7e09::206) by AM6PR08CA0003.outlook.office365.com (2603:10a6:20b:b2::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2729.22 via Frontend Transport; Wed, 12 Feb 2020 08:53:51 +0000
Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=bestguesspass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT050.mail.protection.outlook.com (10.152.19.209) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2665.18 via Frontend Transport; Wed, 12 Feb 2020 08:53:51 +0000
Received: ("Tessian outbound 3a0cbd311638:v42"); Wed, 12 Feb 2020 08:53:51 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: 91213774ac620971
X-CR-MTA-TID: 64aa7808
Received: from d09c789ac1c6.2 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 51FF083F-225B-44E2-A26E-9DAE749CF3CB.1; Wed, 12 Feb 2020 08:53:46 +0000
Received: from EUR01-HE1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id d09c789ac1c6.2 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 12 Feb 2020 08:53:46 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=QRERIQZIKgNBFJiCvQS7f60hfzB65IlzWvy31bJo+wwRlg1sGN2sKkIVIudmpertRjg5ZhIFVCdlBKNxoFoNSF2Yycs9lp74gUbLHTsLgxm+1ul4Mq9lf8+ghZO8KU8B4+4hwrM55crDm78JiMyCfJvBpjB9oolSEuUZ16nPJGTWAsNvD0IhjfYn824Gy97a6lAMi2YrhYAc2/PaVuzbzR9rkG/RuQ6fxGy2fGLj6RTar7QFZ+9VerDmD9/ohyu/HMde1chqjsdJwn1eCvFBM4U1SlVHDCkQczvabFTgvXz1z/RGkMQW2ZQiByEfLgxZ4V4efa+LbXQM1SI05E6mVg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ItfcnK1qGAdifa4fo7rdMlJLqyApSXZSHfY05uisibA=; b=PFzHGhVHBi3iHAh1JXQTYlLwzLT8esQjTVOwKe+g4hM2CwdGpaQx/0uIpgKkh385UdBpy2A1cEkXl4ccpM6BSmC3W/7qIm5rMPuH4IYlA/okSiY9G0frtGrbKXycu4gnH1KXm16RUCYAPNvlDFAtgm1FCfBlPoRY4AAuAF2M7GwBxa4U3gzzz2zaI7rvWi6k1GG15elU3O6BuUKCHDJj3mFe2hDb/WpKiF5nJ6eQdtjDJUV/L5Zh9oomGJLHecrA5TgfqCsvNwCvj4wjylXQBtMB/XI8oU+wZSTIzYU3nlV8k7c+jH5bLj3cnieXS+7yQe0JovV2G+YznyH69ruVGQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ItfcnK1qGAdifa4fo7rdMlJLqyApSXZSHfY05uisibA=; b=EJZd7FytUhLinnjersytMgE18tF9j6sBFYcN/hvaiE0dAUn4ujmurUVY3An9+aHiF3zi7UzCN88/Dj/2Irk4I9oMIbqfrH/7i5na+SNocH2a0wBiSCctti8N/DdaXzoRrvzpzxheOtcmmCMrWSbC81QzcCT2WRIBe3zge1cGDPY=
Received: from AM6PR08MB4231.eurprd08.prod.outlook.com (20.179.18.151) by AM6PR08MB3303.eurprd08.prod.outlook.com (52.135.161.30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2729.22; Wed, 12 Feb 2020 08:53:44 +0000
Received: from AM6PR08MB4231.eurprd08.prod.outlook.com ([fe80::9989:84d6:c203:2c63]) by AM6PR08MB4231.eurprd08.prod.outlook.com ([fe80::9989:84d6:c203:2c63%7]) with mapi id 15.20.2707.030; Wed, 12 Feb 2020 08:53:44 +0000
From: Thomas Fossati <Thomas.Fossati@arm.com>
To: "rats@ietf.org" <rats@ietf.org>
CC: Thomas Fossati <Thomas.Fossati@arm.com>
Thread-Topic: [Rats] About (E)UID's
Thread-Index: AQHV3QtUaUOLh4A2CU2Ls4Ypa3w676gPphyAgABDNQCAAF3ZgIABrK8AgAQ09YCAAF/fgIAAwRgA
Date: Wed, 12 Feb 2020 08:53:44 +0000
Message-ID: <B5B0DE13-9F3B-4095-9F82-C3C4962B00B0@arm.com>
References: <8BDAAE2E-9803-4048-AD5B-59233708E6FB@akamai.com> <1C16DAA0-D03B-417C-894A-30C4015AEED7@island-resort.com> <DBBPR08MB49031E717F69E4CF58CF67A1EF1C0@DBBPR08MB4903.eurprd08.prod.outlook.com> <509C8229-20DC-4888-BE1D-9109733A9E2D@intel.com> <5B9516E6-1441-462E-86D2-B630B32CE1C7@island-resort.com> <DBBPR08MB4903356ED09601AA7A6006FAEF180@DBBPR08MB4903.eurprd08.prod.outlook.com> <3503.1581456157@dooku>
In-Reply-To: <3503.1581456157@dooku>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.21.0.200113
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=Thomas.Fossati@arm.com;
x-originating-ip: [82.11.185.80]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: 7c9b64c3-6f12-4f26-9176-08d7af99151a
X-MS-TrafficTypeDiagnostic: AM6PR08MB3303:|AM6PR08MB3303:|AM6PR08MB4582:
x-ms-exchange-transport-forked: True
X-Microsoft-Antispam-PRVS: <AM6PR08MB4582B9B0F251FB082B9BEE2C9C1B0@AM6PR08MB4582.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:8273;OLM:10000;
x-forefront-prvs: 0311124FA9
X-Forefront-Antispam-Report-Untrusted: SFV:NSPM; SFS:(10009020)(4636009)(396003)(39860400002)(346002)(136003)(376002)(366004)(199004)(189003)(71200400001)(2616005)(186003)(8676002)(81166006)(81156014)(316002)(33656002)(478600001)(53546011)(6506007)(2906002)(76116006)(91956017)(86362001)(36756003)(5660300002)(6916009)(6486002)(26005)(6512007)(4326008)(8936002)(64756008)(66556008)(66946007)(66446008)(66476007); DIR:OUT; SFP:1101; SCL:1; SRVR:AM6PR08MB3303; H:AM6PR08MB4231.eurprd08.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: 7i7IV6kNZg76ER0AnVJG7WTEt7HgGdST7tOJtp3znPhb07FfwTo1lGBg7KkktNfzZ/5R0FcuzcTu74LM40pxdISLgGwg0nADPv2kefpKZh4t9nKfGQxPuxYaNiBsnzXuR6R0G+e+xmqksKntITw7BdTtG/t10sxupnfFiJYOJp3OetYrosCD+emqv/p3f5RiYMpx5V2SBdwPmxrmP3dxVchq9QMWpmHt0YVOtmCSc+OeHk857/fnX91NQ4OywhOpFx7Gd1Z2TAXm2QSmylLMJ2odGnKCbkKhsinG4cbHQum2NZar7oaGjqhgltdk2IIvES0N6TfD6FWt9gGbs7Q93yRS1Yl94LYDkZQhc92quyQh26mWNlUzTV9JNPpCC9mKTBoc0czfyuXVrMtAaOAPMEfdReePcON3GKGwXUL00G7WK5yUFyuRm4Lhko98U/zp
x-ms-exchange-antispam-messagedata: jMkhXdcDD83mrQa74/kCXjH6MFKbzdCQGa/SQ61TJAw0ZQluLz+AFIwe8zO+afkc5uSwjfwOwNsMNU7db35YX007LlMOsH0SKYbNeMTfyoLITS4bZ/2f2w2Ak0SlXB8W26YStArxB39AqVbiDF0kjw==
Content-Type: text/plain; charset="utf-8"
Content-ID: <A2CEAEA33211B645A7FE9272B3A648C4@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR08MB3303
Original-Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Fossati@arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT050.eop-EUR03.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:63.35.35.123; IPV:CAL; SCL:-1; CTRY:IE; EFV:NLI; SFV:NSPM; SFS:(10009020)(4636009)(376002)(396003)(346002)(136003)(39860400002)(199004)(189003)(336012)(186003)(53546011)(2906002)(6506007)(2616005)(4326008)(8936002)(26005)(86362001)(356004)(5660300002)(6512007)(26826003)(478600001)(36906005)(6486002)(316002)(81156014)(81166006)(6916009)(8676002)(36756003)(33656002)(70586007)(70206006); DIR:OUT; SFP:1101; SCL:1; SRVR:AM6PR08MB4582; H:64aa7808-outbound-1.mta.getcheckrecipient.com; FPR:; SPF:Pass; LANG:en; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; A:1; MX:1;
X-MS-Office365-Filtering-Correlation-Id-Prvs: 48c30701-868e-4e4f-8df1-08d7af991101
X-Forefront-PRVS: 0311124FA9
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 7Wc6JGHdGIcAEILxFcP2tj6kcyHPMFqQvxVBz0OVK1LSwLNcKBra7a7FJnA/G9iWlOMT9Mr46TyE0x8+UI3bHHTwivQT/4ioFGXRY7bT65LoZLDVzNw15IpBD+ZyJzOffR3MUw0fHv6J3E5g7fPobq9/PV6jV6AcLCTJGU2C9Wbcv3vdubXUzQ5nsowOlqdHrfMT1keP5EjvK+byZCRyoRiQ/NoTkZamVDiX1U7sLGgnyeG9vDP+rBJNT+4TOlONysePvlw4mdC43LS3Pz4OkUBSsjD8TVQ5m4+rS30aE4B5q/1NAqM0JQsfGM4xZd8uP9hLLR/4euMhOchQNy4CDU+rTpD5w6IVSPPklbESRJl5cNpXF2L/cF84NbaUkO1k/Kq8PfaXg5oMAuUzOxGfgJgV15nFq+6Okk5t688y9Y1ExxgEPYLSC4/+ftm2xfkJ
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 12 Feb 2020 08:53:51.4083 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 7c9b64c3-6f12-4f26-9176-08d7af99151a
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR08MB4582
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/c_EgR7rVwzo1kia3LHsbf9oRY_8>
Subject: Re: [Rats] About (E)UID's
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote Attestation Procedures <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 Feb 2020 08:54:03 -0000

Hi Michael,

On 11/02/2020, 21:22, Michael Richardson wrote:
> Simon Frost <Simon.Frost@arm.com> wrote:
> > I agree that there should have a UEID claim within the standard and
> > also with the proposed bitlength representations.
>
> > I suggest we should change the description of the UEID claim to
> > allow the standard to support more interpretations of what the locus
> > of uniqueness might be to an implementation.
>
> What are the implications to the Verifier and Relying Party of these
> differences?
>
> If you intend there to be code path differences based upon the locus
> of uniqueness, then I would prefer that value of the UEID claim be
> opaque, and if we need to have semantic differences, that we register
> multiple UEID key values.

This is exactly what the PSA token does: it reuses UEID RAND semantics
and encodes it with a custom arm_psa_UEID key id.

Cheers!

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.