[saag] 回复: FW: Interests on Initiating the standardization work related to "Zero Trust"?
Xueting Li <lixt2@foxmail.com> Wed, 31 December 2025 02:58 UTC
Return-Path: <lixt2@foxmail.com>
X-Original-To: saag@mail2.ietf.org
Delivered-To: saag@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8A1BBA0EDC3F for <saag@mail2.ietf.org>; Tue, 30 Dec 2025 18:58:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: 3.8
X-Spam-Level: ***
X-Spam-Status: No, score=3.8 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HELO_DYNAMIC_IPADDR=1.951, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RDNS_DYNAMIC=0.982, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=foxmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ESiN1PcUsr3d for <saag@mail2.ietf.org>; Tue, 30 Dec 2025 18:58:33 -0800 (PST)
Received: from out162-62-58-211.mail.qq.com (out162-62-58-211.mail.qq.com [162.62.58.211]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 01386A0EDC3A for <saag@ietf.org>; Tue, 30 Dec 2025 18:58:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=foxmail.com; s=s201512; t=1767149899; bh=7UPszhdeuHvBcfrEoadzCzVfMYKiB0qqklHqvssDomg=; h=Date:From:To:Cc:Subject:References; b=wEt4+sNItjo/kkU73yZWH1Ymmm3/MPmEMZjAgyxW6DWvakCo2uoxvuNY9ceQVH2r7 a8Xh+cjhBkqSEPDRPD4iqLGifz3paKmWCLxCKjvdQGdtCX94eropNQn4AlWWsWgtyH 9XFcxp6nNK3oDWm7k0FyWxwgQwJ+YoBsZMJN+8h0=
Received: from DESKTOP-690SC9I ([219.142.69.76]) by newxmesmtplogicsvrszc50-0.qq.com (NewEsmtp) with SMTP id E921C65E; Wed, 31 Dec 2025 10:58:18 +0800
X-QQ-mid: xmsmtpt1767149898tmyravijv
Message-ID: <tencent_A209D88864464D5B53B4C5A9F540B6C8910A@qq.com>
X-QQ-XMAILINFO: NWz9UcDegcjfpGTMf2XSZ599EgeM5mElOEE44NpcGxArwlu0HbYV2COpkzeE3c 7TNNrGBZ6hM+bQpYrCzymePwGWvPDnTl6x1LNK11adks+tiwUN9ugyhzIeRDzCLY2/VAIujhKOGh p58EST0VTHR7iMKmMLwh7sLjpf655bZLVaeVFmH45fh7sriBI3Aj3k/b4yzKbsNLoLVrYAbHEy+n +FdsblGmlDaCuO5ZhIbedmB+EX0lUpgqZ7UrnnH3Y9ylssJdxhF3NCK+z3wye5Iwg6B0eNju5WRL UqW/auHmVwtekXWa+k4Fd1ywXwWc1lU+Ssrxx7i/F3Nu+ApZ3iIW4uyFtNidGu8NEkkQLdijYf+v M0cr37INR7VKsnQ15AOOdz3BxdfcUoGBxX1kHunWsnmKTLflEvhrX5amzwe5Mp9OszFZkLg+9Yhf 8Q8Hg2Q7WF9YioZyc3Kv9uf3nXSVPOR4ZgarX7GWJMfUOZYeS1CSDjlPxmn541cH4qFZjVo1Ov1G iZxn6YjKgvcZBV2mU2b7FS+vtA+xfv2h4GZZKQT3utAYNjJRDl5GQeyMh87Iiv9mpICBdiN4MgIj y6UWeXqmhMgPQM5xG7VK3J7nJl593aij7RgjP9ai2AVk7lfIGclSsEBA/nnTeO57P4biv1xmhRhu 3S9TBHNWjXXedWSeq+GkX24CQJFeuVe+wMR6gaIa2WKJCZGRg2k/LS4wSkTSAJPf8wKDSqMANwXu zjfbaLyw4rGif5Net6sIuuG8TZczpjvd9FKcP7nELNC0l+Qe0HTnYhng1YfQhPRZ6TPX/Bd++8+V u0BD084pgLhIm7UHpmzOr3nZW0eldDwYmnQaUCXTVmOvQmBwc6rCgAZmyGIxxewPWK0aPYeDhJeE bKFTUgKWnqtGR7sCGUz4lf+lUAgNvNJSTt62cF54w0d2LDPo+1E09dFsn9EmBTBIkg6envEdOWbW R5/QQgMfKIUevGww76WcdX+ctzUCF/feECipcebk/L4z2imc718KgMTyiA8GABvZh5wZwMEjbBu3 DZIKaQEu8ezuysK84gLV/wjCM614cPW9b5ycqwL6PThYolG7DPv8KCao6WDhRPWVJlafHxdRBf1I Nlv9GB+ujKqqWhpVsLdKY3HAyaZgbnKESQOGQU
X-QQ-XMRINFO: NS+P29fieYNwiF4r4Bkjuh/SawjEXnXBOA==
Date: Wed, 31 Dec 2025 10:58:18 +0800
From: Xueting Li <lixt2@foxmail.com>
To: saag <saag@ietf.org>
References: <000001dc6ef7$8a09d570$9e1d8050$@tsinghua.org.cn>, <000c01dc79f8$f2788ff0$d769afd0$@tsinghua.org.cn>
X-Priority: 3
X-GUID: 7CE1423D-BD90-4ECC-8FF4-D3CF5AA28D90
X-Has-Attach: no
X-Mailer: Foxmail 7.2.25.213[cn]
Mime-Version: 1.0
X-OQ-MSGID: <2025123110581792291813@foxmail.com>
Content-Type: multipart/alternative; boundary="----=_001_NextPart831356515557_=----"
Message-ID-Hash: VYNTLWZWJ6GMCWXHVXGVVGO7XXHF2YEX
X-Message-ID-Hash: VYNTLWZWJ6GMCWXHVXGVVGO7XXHF2YEX
X-MailFrom: lixt2@foxmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-saag.ietf.org-0; header-match-saag.ietf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: wangaijun <wangaijun@tsinghua.org.cn>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [saag] 回复: FW: Interests on Initiating the standardization work related to "Zero Trust"?
List-Id: Security Area Advisory Group <saag.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/hpQ__wy9MoFbVgX0ny-9m1zMToY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Owner: <mailto:saag-owner@ietf.org>
List-Post: <mailto:saag@ietf.org>
List-Subscribe: <mailto:saag-join@ietf.org>
List-Unsubscribe: <mailto:saag-leave@ietf.org>
Hi, all, We have submitted an initial draft: draft-li-zt-consideration-00. This document serves as a starting point to gather use cases, requirements, and challenges related to applying Zero Trust philosophy in network infrastructure―specifically addressing the limitations of perimeter-centric models and the need for in-network ZT deployment to mitigate internal threats. We warmly welcome your comments, suggestions, and involvement. Please feel free to share your feedback. Name: draft-li-zt-consideration Revision: 00 Title: Consideration of Applying Zero Trust Philosophy in Network Infrastructure Date: 2025-12-31 Group: Individual Submission Pages: 7 URL: https://www.ietf.org/archive/id/draft-li-zt-consideration-00.txt Status: https://datatracker.ietf.org/doc/draft-li-zt-consideration/ HTMLized: https://datatracker.ietf.org/doc/html/draft-li-zt-consideration Abstract: Network security has traditionally relied on a perimeter-centric model, assuming that traffic originating within the network can be implicitly trusted. This model is fundamentally challenged by modern, highly distributed, and software-driven network environments where internal compromise is a realistic and high-impact threat scenario. This document examines the critical limitations of edge- only network protection and the systemic risks that arise from insufficient internal validation. Once the network perimeter is bypassed, the absence of internal protection mechanisms facilitates rapid lateral movement, impersonation of network entities, and interference with critical control and management functions. The document argues that Zero Trust (ZT) principles, which mandate continuous, dynamic verification of all entities and communications regardless of network location, are necessary to address contemporary threat models. Deploying ZT-aligned network protection mechanisms beyond the network edge is essential to build resilient, controllable, and trustworthy networks. Best regards Xueting lixt2@foxmail.com 发件人: Aijun Wang 发送时间: 2025-12-31 09:58 收件人: 'Xueting Li' 主题: FW: [saag] Interests on Initiating the standardization work related to "Zero Trust"? From: forwardingalgorithm@ietf.org [mailto:forwardingalgorithm@ietf.org] On Behalf Of Aijun Wang Sent: Wednesday, December 17, 2025 9:51 AM To: saag@ietf.org Cc: 'Benfeng Chen' <benfeng@gmail.com>; 'Erik Johnson' <ejohnson@cloudsecurityalliance.org>; uri@ll.mit.edu; six1@chinatelecom.cn; liux15@pcl.ac.cn; 'Hillary Baron' <hbaron@cloudsecurityalliance.org>; 'Aijun Wang' <wangaj3@chinatelecom.cn> Subject: [saag] Interests on Initiating the standardization work related to "Zero Trust"? Hi, All: As someone may be aware, that we have held two side meetings regards to the topics about “zero trust” in the past IETF 123 and 124 meetings In these side meetings, we discussed mainly the problem statements regarding to the “zero trust” and some potential solutions. Now, we want to seek more feedbacks, or interests on this topic, and plan to organize another side meeting, or if possible, one non-wg forming BoF in the coming IETF 125 meetings. Then, if you have interests on this topic, and would like to contribute your thoughts, please feel free to express your supports. If you have any question on this direction, you can comment also along this threads. We will ask our ADs to build one dedicated mail list for further/deeper discussions, if there are enough interests on this topic.(After the coming Christmas Holiday) Now, we are collaborate with the “Zero Trust” working group (Zero Trust Working Group | CSA - Cloud Security Alliance) in CSA to forward this activities. Best Regards Aijun Wang China Telecom
- [saag] Interests on Initiating the standardizatio… Aijun Wang
- [saag] Re: [EXT] Interests on Initiating the stan… Blumenthal, Uri - 0553 - MITLL
- [saag] Re: [EXT] Interests on Initiating the stan… Harry Halpin
- [saag] Re: Interests on Initiating the standardiz… six1@chinatelecom.cn
- [saag] Re: [EXT] Interests on Initiating the stan… Richard Barnes
- [saag] Re: [EXT] Interests on Initiating the stan… Paul Hoffman
- [saag] Re: [EXT] Interests on Initiating the stan… Michael Richardson
- [saag] 回复: Re: Re: [EXT] Interests on Initiating … six1@chinatelecom.cn
- [saag] Re: [EXT] Interests on Initiating the stan… Salz, Rich
- [saag] Re: [EXT] Interests on Initiating the stan… Nico Williams
- [saag] Re: [EXT] Interests on Initiating the stan… Aijun Wang
- [saag] Re: 回复: FW: Interests on Initiating the st… Muhammad Usama Sardar
- [saag] Re: [EXT] Interests on Initiating the stan… Benfeng Chen
- [saag] Re: Interests on Initiating the standardiz… Liuchunchi(Peter)
- [saag] Re: Interests on Initiating the standardiz… Eric Rescorla
- [saag] 回复: FW: Interests on Initiating the standa… Xueting Li
- [saag] Re: 回复: FW: Interests on Initiating the st… Eric Rescorla
- [saag] Re: [EXT] Interests on Initiating the stan… Muhammad Usama Sardar
- [saag] Re: [EXT] Interests on Initiating the stan… Benfeng Chen
- [saag] Re: [EXT] Interests on Initiating the stan… Muhammad Usama Sardar
- [saag] Re: [EXT] Interests on Initiating the stan… Michael P1
- [saag] Re: [EXT] Interests on Initiating the stan… Muhammad Usama Sardar
- [saag] Re: 回复: FW: Interests on Initiating the st… Xueting Li