### Re: [Rats] Age Claim in EAT

"Oliver, Ian (Nokia - FI/Espoo)" <ian.oliver@nokia-bell-labs.com> Thu, 30 July 2020 10:01 UTC

Interesting.

We've implemented something similar (or at least tried to be compliant with the spec as much as we can)

For each claim we have at minimum the time of the claim request (R) by the attestating authority, the time of claim creation (C) by the reporting authority and the time of receipt (T) by the attesting authority.

One of the attestation rules is thus: R < C < T

Another would then deal with timliness of the obtaining of the claim, eg:   T -R < \epsilon

I agree that some idea of the latches/stage-transitions would help.

Ian

From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
Sent: 30 July 2020 11:28
To: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>de>; rats@ietf.org <rats@ietf.org>
Subject: Re: [Rats] Age Claim in EAT

Thanks for the clarification, Henk.

Since I don't know what information consumers of Entity Attestation Tokens really need to make decisions I am not sure whether the current functionality is sufficient already or not. To me as a reader it appears underspecified.  At a minimum a reference to Appendix A of the RATS architecture document in the EAT spec would be useful.

Ciao
Hannes

-----Original Message-----
From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Sent: Wednesday, July 29, 2020 11:11 AM
To: Hannes Tschofenig <Hannes.Tschofenig@arm.com>om>; rats@ietf.org
Subject: Re: [Rats] Age Claim in EAT

Hi Hannes,

in the scope of Evidence:

Signing a CWT structure is creating an EAT. This event is defined as
time(EG) here:
https://tools.ietf.org/html/draft-ietf-rats-architecture-05#appendix-A

"Creating a token" would mean "Evidence Generation", for example.

Age also is a time interval based on a time unit (units that apply to Henk are years, I claim that Henk's age is 21, of course. Trust in Henk's Claims can be established via Endorsements). Age is a time interval expressed as a duration. That means that the beginning of that time interval is set as zero (an epoch) and then counts the time units.

The semantics of age in EAT are:

the epoch is time(EG) and the unit is seconds.
This only works, if time sources for relative time-counters are available, of course.

Collection of Claims - time(CC) was proposed to the architecture, but did not find consensus yet (we are working on time(AA), though, the time at which the Attester becomes aware of a changes value in the Target Environment right now).

But! there is time(VG), the Value Generation. This time can often only be inferred or approximated (in contrast to time(AA)), but it is the best we have defined right now in the context of:

> If that's the case, I wonder whether it would also make sense to take into account that different information may be collected at a different point in time and hence the age indication would better go (somehow) with specific claims where the time difference between the collection of the data and the signature generation matters.

As a note: We have not talked at all before about the common concept of "latches" or stage transitions... this is an important concept that does capture the "this event has happened" (before/after a defined event) and represents strong security implications that are not included in the RATS architecture today. Would that maybe help in your context?

Viele Grüße,

Henk

On 29.07.20 10:37, Hannes Tschofenig wrote:
> Hi Laurence, Hi all,
>
> How does the age claim work?
>
> The spec says "represents the number of seconds that have elapsed since the token was created".
>
> By creating a token you also protect the claims with a signature and hence you cannot change the content of the claims anymore (without breaking the signature).
>
> Hence, here "creating a token" must mean something different. I suspect it means when certain values have been collected from the device and before the token with the signature was put together. Correct?
>
> If that's the case, I wonder whether it would also make sense to take into account that different information may be collected at a different point in time and hence the age indication would better go (somehow) with specific claims where the time difference between the collection of the data and the signature generation matters. I also wonder whether the number of seconds matter and whether you really want to communicate something more abstract, such as "I created a hash over the firmware during boot time" rather than "I created the hash over the firmware in real-time when I was asked".
>
> Ciao
> Hannes
>
>
