Re: [Rats] Attestation Timing Definitions

"Eric Voit (evoit)" <evoit@cisco.com> Wed, 11 March 2020 12:43 UTC

Return-Path: <evoit@cisco.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 103023A1852 for <rats@ietfa.amsl.com>; Wed, 11 Mar 2020 05:43:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.6
X-Spam-Level:
X-Spam-Status: No, score=-9.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=E4dwv+T3; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=cisco.onmicrosoft.com header.b=ky80z+JX
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id plSs63whY7Qm for <rats@ietfa.amsl.com>; Wed, 11 Mar 2020 05:43:40 -0700 (PDT)
Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 222493A1849 for <rats@ietf.org>; Wed, 11 Mar 2020 05:43:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=19336; q=dns/txt; s=iport; t=1583930620; x=1585140220; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=jMsfeufEbJsLDTMNYDNkoU40E+0uympB5J0ITEBE43E=; b=E4dwv+T3robuzFe3Srq2Nh9KM0DEZfsmE/q0jHFmU/AKuWryl2CUh8I2 CWwRNZQD1BpbuYpPzEn7gcCYzGh3pPBdH5UmyNtWNq0g2iqIHVbWdtwJd ymRE41vHp3Rt0BBQpdk8eSDlwKPKzh8HPuE3QAxPy5ucq9rPSK30taWXh I=;
X-Files: smime.p7s : 3975
X-IPAS-Result: A0ACDwDw22he/5tdJa1lHgELHIMgL1AFbCstIAQLKgqEC4NFA4p0gl+TM4RiglIDVAIHAQEBCQMBAS0CBAEBhEMCggwkOBMCAwEBAQMCAwEBAQEFAQEBAgEFBG2FVgyFYwEBAQEDEhEEBhMBATcBDwIBBgISAy0CAgIwFw4BAQQODQYUgwWBfU0DHw8BjgeQZwKBOYhidX8zgn8BAQWFGhiCBQcJgTiBU4NOhnwPGoFBP4FYgk0+hE0VgnoygiyNdIJ3n0cKgjyDcoI8kFqCSphwkEqaBgIEAgQFAg4BAQWBaSKBWHAVgydQGA2OHYNzilV0gSmMNgGBDwEB
IronPort-PHdr: 9a23:Ng7A3hT86LHvGDCkJvfu9CCIy9psv++ubAcI9poqja5Pea2//pPkeVbS/uhpkESUDdfA8/wRje3QvuigQmEG7Zub+FE6OJ1XH15g640NmhA4RsuMCEn1NvnvOiEkG8VefFRk5Hq8d0NSHZW2PgeAuHC54D8MFxm6LhJ7drinPInUgoz3z/q155DYfwRPgny6fK92KxK16w7Ws5teiop5IaF3wRzM6ndPdv8ew2R0bV6ehBfz4M6s8fsBuzxdofcg69JNXe3hcqI0QKYQDDM9L3t06Q==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.70,540,1574121600"; d="p7s'?scan'208,217";a="433860691"
Received: from rcdn-core-4.cisco.com ([173.37.93.155]) by alln-iport-3.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 11 Mar 2020 12:43:38 +0000
Received: from XCH-ALN-001.cisco.com (xch-aln-001.cisco.com [173.36.7.11]) by rcdn-core-4.cisco.com (8.15.2/8.15.2) with ESMTPS id 02BChc2K025032 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 11 Mar 2020 12:43:38 GMT
Received: from xhs-rcd-001.cisco.com (173.37.227.246) by XCH-ALN-001.cisco.com (173.36.7.11) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Wed, 11 Mar 2020 07:43:38 -0500
Received: from xhs-rtp-001.cisco.com (64.101.210.228) by xhs-rcd-001.cisco.com (173.37.227.246) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Wed, 11 Mar 2020 07:43:37 -0500
Received: from NAM02-SN1-obe.outbound.protection.outlook.com (64.101.32.56) by xhs-rtp-001.cisco.com (64.101.210.228) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Wed, 11 Mar 2020 08:43:37 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=DCmyOQKVHBLcPsjkBVYfWTWXqzuOAYyzH5o1MjbfJoGVws53B1IMwtTlPxW3TSgvb9Bvru1qiHk2g3PAX8JizCry/dqv7XaTCbzs6sII7EE3bZ5jv2GhDrQrvz4KfdokN0odf46mnxPV3t+6KZnIqFH8q4wwzfb2DmwZUFtGfNRb9ALlPrFJINccrBIpBXGkcu8qUjfG7AW6ntZODQ8vEQQcYPcGniNozWmarWSzQOQF/Lglc0QmaipGjuNNs1+c94Zsh2j4quOXt0fYUKfjtaCV+y6SbUGpWAUSMZx59SMifHZUVuppWIwBI116WjKzsnVDrMuo9KLop5KBmWo+Qg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=MyUvC6hH1DVfosJmJ3Tx1WyLGZujw2CvC+IBcdq782U=; b=XZAaMfxiZLhthZ7goI10nrkdf2DNhTvDdJAMT3JjQhEkItFfwPOsb8ZEWgXoiSo3UwgAfnfM6AdRsR7co9bDwzWW92v2nbZmhtcocIe2frzVRmjPqXgWSU7stJUHnsyrDTuIhTYo4x/uvQOyOfKPPol2ScZ0PgtjpY1RowzkMaUd5K5au7GhhLr7M+gzo3bt26YCgflwCgdLTOdqP9Dcmr1in8ImVhrxhZEZ/uIikGnXTf/G2rpzqbZR/o1752Ol6+bsx/XZZ8HC3zMHX+Wk6kzD5xDna/PYHXdsNmq0g4Zpf9hhlUM8JDCgxova1cdCpwGcrSfddxtG+3d1EN7iIA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=MyUvC6hH1DVfosJmJ3Tx1WyLGZujw2CvC+IBcdq782U=; b=ky80z+JXsomghKHgOqy8Fs2nRfj4fLXAsSfCLe0Jm8eLXxXALBPyDvGI0t0ac9pQOu0L4tSnvBav8ok1DS0HFmCgjFLEsrHn/jDxqTPVlR3g0ELv/JpAO6LtaDNA6uNZuzLnYaDF7z2mWFr4rx5b4TsHEmRgMzNk+V1HcHKR5jg=
Received: from BL0PR11MB3122.namprd11.prod.outlook.com (2603:10b6:208:75::32) by BL0PR11MB3235.namprd11.prod.outlook.com (2603:10b6:208:6b::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2814.14; Wed, 11 Mar 2020 12:43:36 +0000
Received: from BL0PR11MB3122.namprd11.prod.outlook.com ([fe80::ec9a:6707:d1ba:ce30]) by BL0PR11MB3122.namprd11.prod.outlook.com ([fe80::ec9a:6707:d1ba:ce30%7]) with mapi id 15.20.2793.013; Wed, 11 Mar 2020 12:43:36 +0000
From: "Eric Voit (evoit)" <evoit@cisco.com>
To: "Panwei (William)" <william.panwei@huawei.com>
CC: "rats@ietf.org" <rats@ietf.org>
Thread-Topic: [Rats] Attestation Timing Definitions
Thread-Index: AdX3Ey664zQelNNbRnODHHrrt7v6IwAQN3YwABNeKHA=
Date: Wed, 11 Mar 2020 12:43:36 +0000
Message-ID: <BL0PR11MB31222653CAAA468988D57E87A1FC0@BL0PR11MB3122.namprd11.prod.outlook.com>
References: <BYAPR11MB31256F11BD86730AF9D21B6CA1FF0@BYAPR11MB3125.namprd11.prod.outlook.com> <92f11d0bbedc4ad6b618cd7ecdcce5da@huawei.com>
In-Reply-To: <92f11d0bbedc4ad6b618cd7ecdcce5da@huawei.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=evoit@cisco.com;
x-originating-ip: [173.38.117.92]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 9b7b8382-f9e7-4506-f3c9-08d7c5b9d14b
x-ms-traffictypediagnostic: BL0PR11MB3235:
x-microsoft-antispam-prvs: <BL0PR11MB3235FCFDF7918CC23175326FA1FC0@BL0PR11MB3235.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0339F89554
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(39860400002)(376002)(136003)(346002)(396003)(366004)(199004)(478600001)(52536014)(2906002)(71200400001)(8936002)(9326002)(81156014)(81166006)(316002)(5660300002)(7696005)(6506007)(8676002)(9686003)(55016002)(86362001)(4326008)(33656002)(76116006)(186003)(66616009)(66476007)(64756008)(66446008)(66946007)(66556008)(6916009)(26005); DIR:OUT; SFP:1101; SCL:1; SRVR:BL0PR11MB3235; H:BL0PR11MB3122.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: F8U2GfMZyqxLvkrpbUx18+FJ5P5Aqq+ZGFMMxwxs8pUiBgW2ht85RuCn5rpKsIinbm6LPQa8n2f7DHKr9OXpZkF0kS2GLhFPqFA827y8k2UyUVxt7MP56o0JZKueRsOFwRdwTknz4MH+uBlpx58To+2x5Fg8XgapYrkpdHA+iyP5y8dpVWMHPK1wKTjO1kulCtBW2lrP+Pkd1YLsv/TwCyzfvDzIO0p7axXOcnMtVGQePNLPrFtUxLDMPxM+LEab1CpCJkMlhphBGgqvz/YUeYBzM0GS6UAzKfQT0DEb/TvFFt/VjmNGMpl5yMuoRF8epgnYJNf2iyXNXlV8GXDw5H3VTDRB9d7ZmMO8sk/q11W9WCng2H4XaGWnVE3moSprMNkL/W15EcJBw1c0Dr62XA9RP/gKr9wVISlqCpqQZv6cnKCG4aGxE+z5fyvw+/sK
x-ms-exchange-antispam-messagedata: UHDWb5/M9AA+17ex3U3T7P07tQjHAdh5YUOQJ/ofUXCNlm4+Agie0X/fvFStrRQMpsh68lwB/lPWi+RoLP00XiwVmZPQQC1lmvfqC9icqIwmf0tUOsRE92SiEXxZVLk7AJn9PvM0L5i3gE1ykG+5uA==
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="SHA1"; boundary="----=_NextPart_000_020B_01D5F781.23EF8800"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 9b7b8382-f9e7-4506-f3c9-08d7c5b9d14b
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Mar 2020 12:43:36.6862 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ZzlHc886+H6EhMFd8aHS1U14SuhCoNXJylbDc5wB90rdPRPus7Q7CpatFm4Ry5p8
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL0PR11MB3235
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.11, xch-aln-001.cisco.com
X-Outbound-Node: rcdn-core-4.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/g0oTCAZm8y6IVDd-J87lg1dQ9Os>
Subject: Re: [Rats] Attestation Timing Definitions
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote Attestation Procedures <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Mar 2020 12:43:42 -0000

Hello Wei,

 

From: Panwei (William), March 10, 2020 11:30 PM



A minor update about the definition of expiry time:

 


time(h)

Time of Results expiry

Time stated by a Verifier when a specific instance of Attestation Results should no longer be accepted by a Relying Party

<eric> Agree with text tweak.

 

1.Simple Passport Model. 

This figure matches to the sequence diagram from Figure 4 of draft-ietf-rats-architecture.

 

   .----------.                     .----------.  .---------------.

   | Attester |                     | Verifier |  | Relying Party |

   '----------'                     '----------'  '---------------'

      time(a)                             |               |

      time(b)                             |               |

      time(e)                             |               |

        |------Evidence---------------->time(f)           |

        |                               time(g){@time(h)} |

        |                               time(j)           |

        |<-----Attestation Result-------time(i)           |

      time(k)--Attestation Result---------------------->time(l)

        |                                 |             time(h)

I think in this case the expiry time can also be included.

 

<eric> I agree time(h) can be supported by this case.   If these timing diagrams ever make it into a rats-draft then we will need to determine which subset of variants to present as many variants exist. 

 

Eric

 

Regards & Thanks!

潘伟 Wei Pan

华为技术有限公司 Huawei Technologies Co., Ltd.