Re: [Rats] About (E)UID's

Thomas Fossati <Thomas.Fossati@arm.com> Wed, 12 February 2020 16:07 UTC

Return-Path: <Thomas.Fossati@arm.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10E161200FB for <rats@ietfa.amsl.com>; Wed, 12 Feb 2020 08:07:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=um4x4mrM; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=um4x4mrM
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o3Ut5PUNRE4T for <rats@ietfa.amsl.com>; Wed, 12 Feb 2020 08:07:47 -0800 (PST)
Received: from EUR05-VI1-obe.outbound.protection.outlook.com (mail-vi1eur05on2062d.outbound.protection.outlook.com [IPv6:2a01:111:f400:7d00::62d]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 44CE61200E7 for <rats@ietf.org>; Wed, 12 Feb 2020 08:07:47 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=66pgbRrYbo+NWWE6q9dNIAxms3A5TN22Qi2NK/75ZPs=; b=um4x4mrM5ige9jI9dvWb5mAxf9k6YnK0XcBLeYUEVnuuzTtJCs5MlqPUtEQDbX+1JyjxEmKxK8c0CMD4fMg9wuM8Jhr2TQbxR7zxb9Jft6HEKfT7ltGsz6shZA7nQpTxFl/XrJ6SY8EMKxcdn4cRrHCFaSEIqr1yy+peI2uNEwg=
Received: from AM6PR08CA0024.eurprd08.prod.outlook.com (2603:10a6:20b:b2::36) by HE1PR0802MB2474.eurprd08.prod.outlook.com (2603:10a6:3:e2::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2729.22; Wed, 12 Feb 2020 16:07:43 +0000
Received: from VE1EUR03FT044.eop-EUR03.prod.protection.outlook.com (2a01:111:f400:7e09::201) by AM6PR08CA0024.outlook.office365.com (2603:10a6:20b:b2::36) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2707.21 via Frontend Transport; Wed, 12 Feb 2020 16:07:43 +0000
Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=bestguesspass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT044.mail.protection.outlook.com (10.152.19.106) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2665.18 via Frontend Transport; Wed, 12 Feb 2020 16:07:43 +0000
Received: ("Tessian outbound 1f9bda537fdc:v42"); Wed, 12 Feb 2020 16:07:42 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: 89d595b8f6cf454a
X-CR-MTA-TID: 64aa7808
Received: from 845e3cba1c6f.2 by 64aa7808-outbound-1.mta.getcheckrecipient.com id F424D8E4-BC57-4DAE-AB69-EE5E7D1E6885.1; Wed, 12 Feb 2020 16:07:36 +0000
Received: from EUR05-AM6-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 845e3cba1c6f.2 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 12 Feb 2020 16:07:36 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=B9p6zpzcKk1Cu0PWJWKX0VKASTKfc0e4EjGtLCVwiZYJgLleBmnEekcd+vIPVj72KbD392Ue3EhPKyaJmonwH7BJW5WucxVuwIfSWNqSU0LLiQHoBDf+0BZyB+vdpRhYB1UT0ZVmUDYbb7aaQqKUFW5s5Jy5liw9CwCZCSBsJ+W+M5OhYrBSdEGUEhH7lvKRfrIvdO5HnGIdm5+SuRLi1GnXmS8qTiR0W1ZwOLGo9VRvNKkwQfc0p336UXHR5fxDgWOk6Z91K2FirZxuVir2PfDHZqwKnifK0vdwNui6T+1OFomaH/P71XDdeHzsKQjAbcMW66id0Qv2sIreWWO4SA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=66pgbRrYbo+NWWE6q9dNIAxms3A5TN22Qi2NK/75ZPs=; b=JPFA6tWqjS9Ho/mogn2Uukw9v3l6F8qBy2LlZhiSoRyicQm8rpyVirjdEfxD2wRy9YQtF7w5/DpTJLlgXEOGu6kW0PAw2cAKBmYUIKbGfNSbfwQeQcm8gg1MEw7v5yEHlO0fr9/mi/+wDb1eM0RbvPqtmpU0oZR4MudZ/YFP6/GsQqaIQTBHhOEs5fGvGtXwWx+5TITtYARR25QA78bQ6sC5vkYRlPmZY6GeU3db/KI+np1il7NR+w1gMT18aJPa74mipdhb4Je8f3hAa2sliD/xaFnhr+9JwSuFUX2zJVJjYUeSbYab3igfM76dXORLPmy7A4dxXPdjusrC3X2+rw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=66pgbRrYbo+NWWE6q9dNIAxms3A5TN22Qi2NK/75ZPs=; b=um4x4mrM5ige9jI9dvWb5mAxf9k6YnK0XcBLeYUEVnuuzTtJCs5MlqPUtEQDbX+1JyjxEmKxK8c0CMD4fMg9wuM8Jhr2TQbxR7zxb9Jft6HEKfT7ltGsz6shZA7nQpTxFl/XrJ6SY8EMKxcdn4cRrHCFaSEIqr1yy+peI2uNEwg=
Received: from AM6PR08MB4231.eurprd08.prod.outlook.com (20.179.18.151) by AM6PR08MB3110.eurprd08.prod.outlook.com (52.135.163.159) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2707.26; Wed, 12 Feb 2020 16:07:35 +0000
Received: from AM6PR08MB4231.eurprd08.prod.outlook.com ([fe80::9989:84d6:c203:2c63]) by AM6PR08MB4231.eurprd08.prod.outlook.com ([fe80::9989:84d6:c203:2c63%7]) with mapi id 15.20.2707.030; Wed, 12 Feb 2020 16:07:35 +0000
From: Thomas Fossati <Thomas.Fossati@arm.com>
To: "Salz, Rich" <rsalz@akamai.com>, Simon Frost <Simon.Frost@arm.com>, Laurence Lundblade <lgl@island-resort.com>
CC: "rats@ietf.org" <rats@ietf.org>, "Smith, Ned" <ned.smith@intel.com>, Thomas Fossati <Thomas.Fossati@arm.com>
Thread-Topic: [Rats] About (E)UID's
Thread-Index: AQHV3QtUaUOLh4A2CU2Ls4Ypa3w676gPphyAgABDNQCAAF3ZgIABrK8AgAQ09YCAAV4sAIAAGrEAgAAcXYCAAAT1gA==
Date: Wed, 12 Feb 2020 16:07:35 +0000
Message-ID: <DE7B37F5-5675-4F3D-B279-5FB92107BED4@arm.com>
References: <8BDAAE2E-9803-4048-AD5B-59233708E6FB@akamai.com> <1C16DAA0-D03B-417C-894A-30C4015AEED7@island-resort.com> <DBBPR08MB49031E717F69E4CF58CF67A1EF1C0@DBBPR08MB4903.eurprd08.prod.outlook.com> <509C8229-20DC-4888-BE1D-9109733A9E2D@intel.com> <5B9516E6-1441-462E-86D2-B630B32CE1C7@island-resort.com> <DBBPR08MB4903356ED09601AA7A6006FAEF180@DBBPR08MB4903.eurprd08.prod.outlook.com> <07A3E092-068F-4E35-8C39-D290FDB8CFDC@island-resort.com> <DBBPR08MB4903840E6D30A59083F8B119EF1B0@DBBPR08MB4903.eurprd08.prod.outlook.com> <6CD93307-E6F2-40F9-B041-FEBF5AD226CA@akamai.com>
In-Reply-To: <6CD93307-E6F2-40F9-B041-FEBF5AD226CA@akamai.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.21.0.200113
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=Thomas.Fossati@arm.com;
x-originating-ip: [217.140.106.50]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: 3d40f733-657d-4265-b484-08d7afd5b170
X-MS-TrafficTypeDiagnostic: AM6PR08MB3110:|AM6PR08MB3110:|HE1PR0802MB2474:
x-ms-exchange-transport-forked: True
X-Microsoft-Antispam-PRVS: <HE1PR0802MB2474072D52994B256BCD03059C1B0@HE1PR0802MB2474.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:6430;OLM:8882;
x-forefront-prvs: 0311124FA9
X-Forefront-Antispam-Report-Untrusted: SFV:NSPM; SFS:(10009020)(4636009)(396003)(366004)(39860400002)(376002)(346002)(136003)(199004)(189003)(81156014)(64756008)(54906003)(81166006)(36756003)(110136005)(66556008)(76116006)(66476007)(91956017)(66946007)(8676002)(66446008)(33656002)(186003)(26005)(53546011)(8936002)(2616005)(2906002)(6486002)(316002)(4744005)(71200400001)(478600001)(6506007)(86362001)(6512007)(5660300002)(4326008); DIR:OUT; SFP:1101; SCL:1; SRVR:AM6PR08MB3110; H:AM6PR08MB4231.eurprd08.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: +c7OFQnoq/JSA021q+5knnxzZABwkgle7dakW7noPltZNcVFr4Egsn6/mhR03tBLm+fNaZMxkYfneM8sN6RM3ARvSdEOrTnD245/PejryFcDbJGa5OPMk1URlPft4ESm0MSSuWnlbVUcTd+IAPYS5RHfrYtNsASilE+F4g3nK2yPf0mfCjf/H1eYpFYHAW8v7/TO1uw3rSgYuieeKrfXw76hmhMPNecD4bNdOloKQIOR225E1bvwC0Qu+kFiDCFia3DfaEnx4BPAl1ulSS/sOxNQp/pkixyhgfoky3+FsZNEEWl00dG/6dbRrlpETdNMHhqcEhAWgsigDdn+t1f0iTQpRvWDYwARoHfKBXtpL0OCu4vRW8Dnot0zRUm6bg8ajjin3S+x+GZbqs1XaUjlkJH/bP4bOp5HLRVE/4Gxyv440lfDrV9nC2mB0kj2GOxh
x-ms-exchange-antispam-messagedata: PlaY+hXTCZsPvgvO9JK1Dspg0uOrHQg9oAdRh94KfmFgefsrN8ncMqCSFZVq7CJhPrVSt8E3k2oKl8n9wtqNx8DdBqbladRVUNnSIbo375Ot+bxMS4YXn+jP1emyb50r9+uICPlEFFDtiL55RVysug==
Content-Type: text/plain; charset="utf-8"
Content-ID: <4198DF4CA2C1EC40A70FFE7D6FAA46DC@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR08MB3110
Original-Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Fossati@arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT044.eop-EUR03.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:63.35.35.123; IPV:CAL; SCL:-1; CTRY:IE; EFV:NLI; SFV:NSPM; SFS:(10009020)(4636009)(39860400002)(376002)(136003)(396003)(346002)(189003)(199004)(2906002)(5660300002)(6512007)(4744005)(70586007)(33656002)(6486002)(356004)(4326008)(70206006)(8936002)(81166006)(81156014)(8676002)(36756003)(6506007)(26005)(53546011)(186003)(86362001)(2616005)(336012)(316002)(478600001)(110136005)(54906003)(36906005)(26826003); DIR:OUT; SFP:1101; SCL:1; SRVR:HE1PR0802MB2474; H:64aa7808-outbound-1.mta.getcheckrecipient.com; FPR:; SPF:Pass; LANG:en; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; MX:1; A:1;
X-MS-Office365-Filtering-Correlation-Id-Prvs: e5726b66-be32-4cf6-ea04-08d7afd5acbb
X-Forefront-PRVS: 0311124FA9
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: Ha73v74Mq2zG316/X5FQzAWNXkxgNUH7GUGd54kvDE2Soy4cjCzQJWPfG6YvKS9rYIWb0VpRifrhfj4IzP6wqDA2vXmRik/RQaL2rEhcn6mmzjGg4JpG1Iy+fgK78t62IWfNb9aN7sV7gbfcX4RQ6JN8PqP0cAPoGddhM8vaywaXBzXYfOFvEsV0kXPpimIPMlZNPCkMzbT0zjxvvd3dG1T/QsSRei5IWCBes3xcOqtQI/VBzd7eg8TVAc4N3aYy9rMoGzANTJd+aUTjY2TOVSpjbDKHWxfUCHgzKDQea+BzG7Mmbq883iXlrXu5zZsG3qTPSmskAh3r0ZyTNjkFUAVfS8HhihzxaxLmKtCBlYhJ9ORetd55ohG2Ttio7DWTkFlKudN3eJ8uDZGbD6K67uSiYJV7A3ioXYK77I5aNL3xGWZJQ7gvDpX+7F9UL/25
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 12 Feb 2020 16:07:43.4041 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 3d40f733-657d-4265-b484-08d7afd5b170
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0802MB2474
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/riiHvf1cMihTq4Y-B0Nxy3JDIbo>
Subject: Re: [Rats] About (E)UID's
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote Attestation Procedures <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 Feb 2020 16:07:50 -0000

On 12/02/2020, 15:50, Salz, Rich <rsalz@akamai.com> wrote:
> I am still concerned about what fails if someone re-uses an EUID,
> either by accident or maliciously.  If the security of the RATS
> architecture depends on uniqueness, this seems important.

I agree with you.

If ueid is used to locate the verification key, then verification
would fail.  (BTW, this is what we do in PSA.)

If ueid is disjoint from the verification key, then it *might* result in
impersonation -- this also depends on the verification policy.

The EAT document should warn about the latter.


IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.