[saag] 回复: FW: Interests on Initiating the standardization work related to "Zero Trust"?

Xueting Li <lixt2@foxmail.com> Wed, 31 December 2025 02:58 UTC

Return-Path: <lixt2@foxmail.com>
X-Original-To: saag@mail2.ietf.org
Delivered-To: saag@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8A1BBA0EDC3F for <saag@mail2.ietf.org>; Tue, 30 Dec 2025 18:58:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: 3.8
X-Spam-Level: ***
X-Spam-Status: No, score=3.8 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HELO_DYNAMIC_IPADDR=1.951, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RDNS_DYNAMIC=0.982, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=foxmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ESiN1PcUsr3d for <saag@mail2.ietf.org>; Tue, 30 Dec 2025 18:58:33 -0800 (PST)
Received: from out162-62-58-211.mail.qq.com (out162-62-58-211.mail.qq.com [162.62.58.211]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 01386A0EDC3A for <saag@ietf.org>; Tue, 30 Dec 2025 18:58:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=foxmail.com; s=s201512; t=1767149899; bh=7UPszhdeuHvBcfrEoadzCzVfMYKiB0qqklHqvssDomg=; h=Date:From:To:Cc:Subject:References; b=wEt4+sNItjo/kkU73yZWH1Ymmm3/MPmEMZjAgyxW6DWvakCo2uoxvuNY9ceQVH2r7 a8Xh+cjhBkqSEPDRPD4iqLGifz3paKmWCLxCKjvdQGdtCX94eropNQn4AlWWsWgtyH 9XFcxp6nNK3oDWm7k0FyWxwgQwJ+YoBsZMJN+8h0=
Received: from DESKTOP-690SC9I ([219.142.69.76]) by newxmesmtplogicsvrszc50-0.qq.com (NewEsmtp) with SMTP id E921C65E; Wed, 31 Dec 2025 10:58:18 +0800
X-QQ-mid: xmsmtpt1767149898tmyravijv
Message-ID: <tencent_A209D88864464D5B53B4C5A9F540B6C8910A@qq.com>
X-QQ-XMAILINFO: NWz9UcDegcjfpGTMf2XSZ599EgeM5mElOEE44NpcGxArwlu0HbYV2COpkzeE3c 7TNNrGBZ6hM+bQpYrCzymePwGWvPDnTl6x1LNK11adks+tiwUN9ugyhzIeRDzCLY2/VAIujhKOGh p58EST0VTHR7iMKmMLwh7sLjpf655bZLVaeVFmH45fh7sriBI3Aj3k/b4yzKbsNLoLVrYAbHEy+n +FdsblGmlDaCuO5ZhIbedmB+EX0lUpgqZ7UrnnH3Y9ylssJdxhF3NCK+z3wye5Iwg6B0eNju5WRL UqW/auHmVwtekXWa+k4Fd1ywXwWc1lU+Ssrxx7i/F3Nu+ApZ3iIW4uyFtNidGu8NEkkQLdijYf+v M0cr37INR7VKsnQ15AOOdz3BxdfcUoGBxX1kHunWsnmKTLflEvhrX5amzwe5Mp9OszFZkLg+9Yhf 8Q8Hg2Q7WF9YioZyc3Kv9uf3nXSVPOR4ZgarX7GWJMfUOZYeS1CSDjlPxmn541cH4qFZjVo1Ov1G iZxn6YjKgvcZBV2mU2b7FS+vtA+xfv2h4GZZKQT3utAYNjJRDl5GQeyMh87Iiv9mpICBdiN4MgIj y6UWeXqmhMgPQM5xG7VK3J7nJl593aij7RgjP9ai2AVk7lfIGclSsEBA/nnTeO57P4biv1xmhRhu 3S9TBHNWjXXedWSeq+GkX24CQJFeuVe+wMR6gaIa2WKJCZGRg2k/LS4wSkTSAJPf8wKDSqMANwXu zjfbaLyw4rGif5Net6sIuuG8TZczpjvd9FKcP7nELNC0l+Qe0HTnYhng1YfQhPRZ6TPX/Bd++8+V u0BD084pgLhIm7UHpmzOr3nZW0eldDwYmnQaUCXTVmOvQmBwc6rCgAZmyGIxxewPWK0aPYeDhJeE bKFTUgKWnqtGR7sCGUz4lf+lUAgNvNJSTt62cF54w0d2LDPo+1E09dFsn9EmBTBIkg6envEdOWbW R5/QQgMfKIUevGww76WcdX+ctzUCF/feECipcebk/L4z2imc718KgMTyiA8GABvZh5wZwMEjbBu3 DZIKaQEu8ezuysK84gLV/wjCM614cPW9b5ycqwL6PThYolG7DPv8KCao6WDhRPWVJlafHxdRBf1I Nlv9GB+ujKqqWhpVsLdKY3HAyaZgbnKESQOGQU
X-QQ-XMRINFO: NS+P29fieYNwiF4r4Bkjuh/SawjEXnXBOA==
Date: Wed, 31 Dec 2025 10:58:18 +0800
From: Xueting Li <lixt2@foxmail.com>
To: saag <saag@ietf.org>
References: <000001dc6ef7$8a09d570$9e1d8050$@tsinghua.org.cn>, <000c01dc79f8$f2788ff0$d769afd0$@tsinghua.org.cn>
X-Priority: 3
X-GUID: 7CE1423D-BD90-4ECC-8FF4-D3CF5AA28D90
X-Has-Attach: no
X-Mailer: Foxmail 7.2.25.213[cn]
Mime-Version: 1.0
X-OQ-MSGID: <2025123110581792291813@foxmail.com>
Content-Type: multipart/alternative; boundary="----=_001_NextPart831356515557_=----"
Message-ID-Hash: VYNTLWZWJ6GMCWXHVXGVVGO7XXHF2YEX
X-Message-ID-Hash: VYNTLWZWJ6GMCWXHVXGVVGO7XXHF2YEX
X-MailFrom: lixt2@foxmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-saag.ietf.org-0; header-match-saag.ietf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: wangaijun <wangaijun@tsinghua.org.cn>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [saag] 回复: FW: Interests on Initiating the standardization work related to "Zero Trust"?
List-Id: Security Area Advisory Group <saag.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/hpQ__wy9MoFbVgX0ny-9m1zMToY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Owner: <mailto:saag-owner@ietf.org>
List-Post: <mailto:saag@ietf.org>
List-Subscribe: <mailto:saag-join@ietf.org>
List-Unsubscribe: <mailto:saag-leave@ietf.org>

Hi, all,
We have submitted an initial draft: draft-li-zt-consideration-00.
This document serves as a starting point to gather use cases, requirements, and challenges related to applying Zero Trust philosophy in network infrastructure―specifically addressing the limitations of perimeter-centric models and the need for in-network ZT deployment to mitigate internal threats.

We warmly welcome your comments, suggestions, and involvement. Please feel free to share your feedback.

Name:     draft-li-zt-consideration
Revision: 00
Title:    Consideration of Applying Zero Trust Philosophy in Network Infrastructure
Date:     2025-12-31
Group:    Individual Submission
Pages:    7
URL: https://www.ietf.org/archive/id/draft-li-zt-consideration-00.txt
Status: https://datatracker.ietf.org/doc/draft-li-zt-consideration/
HTMLized: https://datatracker.ietf.org/doc/html/draft-li-zt-consideration


Abstract:

   Network security has traditionally relied on a perimeter-centric
   model, assuming that traffic originating within the network can be
   implicitly trusted.  This model is fundamentally challenged by
   modern, highly distributed, and software-driven network environments
   where internal compromise is a realistic and high-impact threat
   scenario.  This document examines the critical limitations of edge-
   only network protection and the systemic risks that arise from
   insufficient internal validation.  Once the network perimeter is
   bypassed, the absence of internal protection mechanisms facilitates
   rapid lateral movement, impersonation of network entities, and
   interference with critical control and management functions.  The
   document argues that Zero Trust (ZT) principles, which mandate
   continuous, dynamic verification of all entities and communications
   regardless of network location, are necessary to address contemporary
   threat models.  Deploying ZT-aligned network protection mechanisms
   beyond the network edge is essential to build resilient,
   controllable, and trustworthy networks.


Best regards
Xueting 


lixt2@foxmail.com
 
发件人: Aijun Wang
发送时间: 2025-12-31 09:58
收件人: 'Xueting Li'
主题: FW: [saag] Interests on Initiating the standardization work related to "Zero Trust"?
 
 
From: forwardingalgorithm@ietf.org [mailto:forwardingalgorithm@ietf.org] On Behalf Of Aijun Wang
Sent: Wednesday, December 17, 2025 9:51 AM
To: saag@ietf.org
Cc: 'Benfeng Chen' <benfeng@gmail.com>; 'Erik Johnson' <ejohnson@cloudsecurityalliance.org>; uri@ll.mit.edu; six1@chinatelecom.cn; liux15@pcl.ac.cn; 'Hillary Baron' <hbaron@cloudsecurityalliance.org>; 'Aijun Wang' <wangaj3@chinatelecom.cn>
Subject: [saag] Interests on Initiating the standardization work related to "Zero Trust"?
 
Hi, All:
 
As someone may be aware, that we have held two side meetings regards to the topics about “zero trust” in the past IETF 123 and 124 meetings
In these side meetings, we discussed mainly the problem statements regarding to the “zero trust” and some potential solutions.
 
Now, we want to seek more feedbacks, or interests on this topic, and plan to organize another side meeting, or if possible, one non-wg forming BoF in the coming IETF 125 meetings.
 
Then, if you have interests on this topic, and would like to contribute your thoughts, please feel free to express your supports.
If you have any question on this direction, you can comment also along this threads.
 
We will ask our ADs to build one dedicated mail list for further/deeper discussions, if there are enough interests on this topic.(After the coming Christmas Holiday)
 
Now, we are collaborate with the “Zero Trust” working group (Zero Trust Working Group | CSA - Cloud Security Alliance) in CSA to forward this activities. 
 
Best Regards
 
Aijun Wang
China Telecom