Re: [Sat] WG Last Call for comments: draft-ietf-satp-architecture-02

VENKATRAMAN RAMAKRISHNA <vramakr2@in.ibm.com> Tue, 12 March 2024 17:33 UTC

Return-Path: <vramakr2@in.ibm.com>
X-Original-To: sat@ietfa.amsl.com
Delivered-To: sat@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AA8B1C14F690 for <sat@ietfa.amsl.com>; Tue, 12 Mar 2024 10:33:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.005
X-Spam-Level:
X-Spam-Status: No, score=-7.005 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ibm.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EIVcCxJ-uRJ4 for <sat@ietfa.amsl.com>; Tue, 12 Mar 2024 10:33:17 -0700 (PDT)
Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CC862C14F60B for <sat@ietf.org>; Tue, 12 Mar 2024 10:33:17 -0700 (PDT)
Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 42CH726f025295 for <sat@ietf.org>; Tue, 12 Mar 2024 17:33:17 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=from : to : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version : subject; s=pp1; bh=1lJK3Dzbe86mz0VX2PePgZo7ZJ9idJw/rxCIZCrR+HI=; b=daLms4PGIBKdPQx/6LCrxtHWnmIR9mswbl3TWxdUG/Jf0Tln40NAfCOS2hRe0rw8ergP kze3qqr8QolNfpimzcccHvjztEOWbMhlqKGGXumvE2noed8Odi/sUXaQsz55YlZC3OKa 26FxA1BPXJZaTDX6WBWrITePx0l3TtFXXCK9G2/JZCP/CFD1XDFsBKtC9plfKrscVtHl DwEERWArArRFLRXsHB3j84X1E4ViWAt4x1SI32H3eyjSA+51Ndh0325XOl9I+AK8wZHr lzIY7EPSu+5WYzl6d4BKF9xd0eTnD7LkiSfHMnEPks9vXa4NtRmEo4wSLUpBJFvNyZHB ew==
Received: from pps.reinject (localhost [127.0.0.1]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 3wtsaptvqx-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <sat@ietf.org>; Tue, 12 Mar 2024 17:33:16 +0000
Received: from m0360072.ppops.net (m0360072.ppops.net [127.0.0.1]) by pps.reinject (8.17.1.5/8.17.1.5) with ESMTP id 42CHLEsE027324 for <sat@ietf.org>; Tue, 12 Mar 2024 17:33:16 GMT
Received: from nam11-co1-obe.outbound.protection.outlook.com (mail-co1nam11lp2169.outbound.protection.outlook.com [104.47.56.169]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 3wtsaptvqp-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 12 Mar 2024 17:33:16 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Mf7f/nQFcrX04Q1EQ2u2X5HX+pizuO9T+Jm+LbqOSA0V1ox3gkKKPGpK9BuwIKVUUS93zPtdGuvmmTFwVWRj1zLQCwRDSAtJXzhuMaxC9rhGisP6UZjMwOSZM4epWucOuPH7p0GwoCKifx8LuO5hVmQzZQlAr5a+jqzZaQQCAun4XJ85bbLl3pcex9Cu0bFNrCWP9EcDK5zh4biqFNdFZWRZGR8fVKAEffEWxkwu6k0/aVZkRNvMAlldOxYptlDnA/rMHoeLD+BARwdg1xESXwBmQadB4pP4Ca/wzKjKPKS04VRocAn3FzPtKvadtjtFjFPyJq5iVL3IYy0WKYjGCQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=oLBuoBjsE3IWOixvEm9lBHH+v0fgkqKCZXoDRlbqg8A=; b=lf6nhUR3qzZO7FeWRHxz2T2VpganXx3B3nZbKp12cQKbdDa2MryBMQIGWjmeLHMtLChXTaHmZ8evCKsysBDD5XrOG1ECrXS/Lq3z5iTqCR4r4v1hTEBF51x0QaOj94SSEY5zyzIhL7jiEBGovrBWJuKJ0JFogmADGU2EgXbkNYRd6UJIqcMnjWc4WVGZ1WI4S+6mV5YOPPRBw7GNDbJnU0aTchLPiVjN/Uje/4pnpbmRRqlpjWNKCZ/uWQFqos7tGCOLXKoMJD3t36njJN9stDgMY8ZBuidEDtY6KL2lGk9hGk6mcaOQzE3YAhsKqOpvUDv4nOukPOSaMFW4PuMSNA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=in.ibm.com; dmarc=pass action=none header.from=in.ibm.com; dkim=pass header.d=in.ibm.com; arc=none
Received: from SJ0PR15MB5132.namprd15.prod.outlook.com (2603:10b6:a03:425::13) by BY1PR15MB5960.namprd15.prod.outlook.com (2603:10b6:a03:530::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7362.34; Tue, 12 Mar 2024 17:33:13 +0000
Received: from SJ0PR15MB5132.namprd15.prod.outlook.com ([fe80::22d7:203d:ce69:9c90]) by SJ0PR15MB5132.namprd15.prod.outlook.com ([fe80::22d7:203d:ce69:9c90%5]) with mapi id 15.20.7362.035; Tue, 12 Mar 2024 17:33:11 +0000
From: VENKATRAMAN RAMAKRISHNA <vramakr2@in.ibm.com>
To: "ladler2@bellatlantic.net" <ladler2@bellatlantic.net>, "sat@ietf.org" <sat@ietf.org>
Thread-Topic: [EXTERNAL] Re: [Sat] WG Last Call for comments: draft-ietf-satp-architecture-02
Thread-Index: AQHadJh0mKJYAmiAv0Ctddk0TUEVp7E0WUqA
Date: Tue, 12 Mar 2024 17:33:11 +0000
Message-ID: <SJ0PR15MB513247E0DC4DBCC3EA3AB0DAB82B2@SJ0PR15MB5132.namprd15.prod.outlook.com>
References: <yblbk7nh517.fsf@wx.hardakers.net> <017d01da7498$6c7d8f70$4578ae50$@bellatlantic.net>
In-Reply-To: <017d01da7498$6c7d8f70$4578ae50$@bellatlantic.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SJ0PR15MB5132:EE_|BY1PR15MB5960:EE_
x-ms-office365-filtering-correlation-id: bfabf006-2480-43cb-6c72-08dc42ba7d85
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: uIT1v7VrGCrGXUe/Gf9iIwT5BJGnZFxUmQnnj7olkbN9xiW6A6G/iB69LCv5+22LYDKd2AU+t/ZY4HMUsJH6lj0E9f4/FkbgS4QY7JgESSSe525QkYY5o98GF2KRgmr3xrELVh1zL8qsukasPqPTBrKd6sA1Rno/x+MUFmS4hvCHwAPgZWfStLiYvLHSWzMDRwDY/VUzQGsqKLeA5XUBnUXxCPcfWxMQVdiqAfvZf+scC3uFzXeqfNfEk58iD4sGH25kPgNO88Su6V4iM4VLnNDxuGPjoAech8ibRpOXSEFIkwbtIwVIaZ9d7Ly2E9hyNWbt5L+R65gLrVZ5+Ro7X/4e/+HIETFVr0HIj+au2imQg5Aev5/zcJNqHQyWSiCTjcCesDMfg0TI13K1As3+Sat5Cpiod+p0mJAgTW3r8TGhZPW9UGS/zP1SivbeAhBGyitrdsy2yDo64kax/aO8ifrOsuyH+nPycmgrcfkWSrx34CesIFqy8Sl5yU0+MLkL3PfsPvNme6lDikfxpNhrNiBGxZaycmCTsddiRJsFaz7gxsB/Yq1QnyU8J7l9xbRN8rbD7U3lH3DrN2YNgMPoIynMvOQnkS/403OTDPbhayVfUzCuOE3b+1wCbERdmr921zYkl7lcERoa2CAIhlZWxFnun+xx7qwMjmFHCsszAAE=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SJ0PR15MB5132.namprd15.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376005)(1800799015)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: II47m6cEE4iCePrA7YFFIU5BM3sWc6MgaDbPxr6/C3W2U+CX/VJYrZBXu+r40nFArHqO+Jv7K+SpenduHwGT1DFrJWNqqKbNJ7JJMYpyx54FnSq8tE6hvYhYxLgsQM1Q6iurrZ2SIt03qGkmRayTvva0pq4bzjs5vQlIDVFYjx7QiTSVnOAGeDG+FlviupBjDTajCO8fcGkfCQayjl4yRmD/hNrVgXah3jTP+FbjKB0OClTKhF+6XRxX54b99/ctx4Uz1WMZafvzBYFp2SxYawGWd4Hfd/m0yu471KyR5x55P/hkGbM2nemI+0aeJfoEurOcXanOekio5wMHbcUxlRYOo9FzwirMh36MAQ2MC4jjMC97H2yUir8pqbDUa/9loAZpvhk9F3MbFsxR8zN3vBZoVVwHPc7pRXFYieZ5MDgWYmwRpxRHtCT+Kia8ZCn/ddSMpWkyVpM0k2BDZVlkIOdwTcPyNf008iCUuWVNAewudGvSiqtN8OvpsUV5N/4K8KUNKs425QGoDYL5GiJAN1s57sNl1Hd3Dy7vKz1CHLywsMs3JjElee5uLiW1X9MEWq4TFQ74owfp7rqJmIz37XuFmtElOXZccdo1AfPx5S+bEuYfV7J/cfnrTKhX5A7Z+X0V2tWJKH71SR6lFStHXvWMFVM2k6784XebbGFshaomIjZndIDYiCRf3VUbUfwFGEkzw3pxJ+Y3r0JnsDC2LmzFThuNntFQgi0Qq7JbDHNUp4UfiURV8tlLQbaWOGk2ldt56244yMus2eT30/jiJmf+QhpDQJtg3+lhGJ9sTGNtwdkXwY208OXxqClHxW7Trdx3p8ZzHqFEwEQfpj1jL9hrhm3D8AhN7opbv+n7bHQ+GufAzN2dgPC2Oahcp+hAnEj66vU7xGAr49ixX8H7TWOkD5B6h9+atk+zFoY5Y9YKAIt8eoHFmj6UpAzX1J69prOvz7joBzLh8kDlBPGdg7hK1fYjteYNuaKEEjRhPGyioyo3LuROv7bVNkCtfmgvgNaZgLeejBaHDtG05LpOIPwnjr40HMuvPWd9AzuM5+ZUQrESz4+njboxH/8Bn8olQMgYdeOq1PgGwCnp5nSZVGW59gfDZG752dPb4wPGf3/RIUg+beKJl7u3Sdx4hX8M0WxaL/+oYeRe+foB+BeaKR4IE/0JzQ5N21MHlB2fdxuiC9iKEi3cLBmfrjuMXh0ZE9OtmGQloaTnifRJor/EXmVF8R+hlYrSsUyrakr1VW6OLTJCx5qi6Af//5CW45Sjee/DDVQGYOdNtgAJUiAJtOuX86Eg7FaJW76vxj4nM3hW2ltmjzvyw0J3HqcDNuZh16LTaWF089pY1Hn8rlKGpLctJiDv/4Yx9h3r4XAO/ReGXHhlaJNopP0x3fnFEMTej9X4hL9Ge9UPLgkTuij4pJyu0G9kmCATh+PahcgmdzroRqacFcK6bUagMJiC8kN7H45x999Xvyznf233Ip2w2IRCt2TqOSps2Aj3QeHTyvr0a5c1IpNY4zINO3mNSyP1fzFcZQJ6ZeOXh5ooOKiaAZhhQLXNL+BIYHA+/ROlkOC50xZvXTjWcUxmS6oQeMPc
Content-Type: text/plain; charset="us-ascii"
X-OriginatorOrg: in.ibm.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR15MB5132.namprd15.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: bfabf006-2480-43cb-6c72-08dc42ba7d85
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Mar 2024 17:33:11.6662 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: fcf67057-50c9-4ad4-98f3-ffca64add9e9
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: LgdhHzMEt0ncwCTrMvfRCY4vLQ7JUGmTnXR+/s+8SPXwsKAbiOZDVdEn2nLgjf4WfdUWu9u8zHQcqJhegiYSig==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY1PR15MB5960
X-Proofpoint-ORIG-GUID: hFNLWQf75zXIdDnKChEC0f63hgKr3RPH
X-Proofpoint-GUID: t7V0Vfd8oLv2p4_fBvuPQDnMZsr_apdQ
Content-Transfer-Encoding: quoted-printable
X-Proofpoint-UnRewURL: 2 URL's were un-rewritten
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1011,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2024-03-12_10,2024-03-12_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 mlxscore=0 lowpriorityscore=0 spamscore=0 bulkscore=0 suspectscore=0 clxscore=1011 phishscore=0 mlxlogscore=999 impostorscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2311290000 definitions=main-2403120133
Archived-At: <https://mailarchive.ietf.org/arch/msg/sat/vu7zYaG6Bb7jBWAumgPW5-asq_c>
Subject: Re: [Sat] WG Last Call for comments: draft-ietf-satp-architecture-02
X-BeenThere: sat@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "The purpose of this mailing-list is to discuss the secure asset transfer \(SAT\) protocol and related aspects." <sat.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sat>, <mailto:sat-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sat/>
List-Post: <mailto:sat@ietf.org>
List-Help: <mailto:sat-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sat>, <mailto:sat-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Mar 2024 17:33:18 -0000

David,

In my opinion, SATP doesn't require "everybody" to be honest, but just requires that each counterparty network be "collectively honest", i.e., maintain internal consistency and have the capacity to thwart insider Byzantine failures.

Further, if a gateway acts dishonestly, "honest" counterparty networks will be able to find out through an audit (which is not as satisfactory as a prevention, but it may be the best we can get in a completely decentralized setting.)

Your point about SATP coming under intense threat (and scrutiny, if it handles large-valued assets) is very well taken though. We do need to make the security assumptions and caveats crystal clear. IMO the design principle of network opacity as mentioned in Section 3.1 covers the point about collective network honesty as it tells users that, from SATP's perspective, the network is a unitary entity that has delegated asset transfer privileges to a gateway.

Rama

-----Original Message-----
From: sat <sat-bounces@ietf.org> On Behalf Of ladler2@bellatlantic.net
Sent: Tuesday, March 12, 2024 9:45 PM
To: sat@ietf.org
Subject: [EXTERNAL] Re: [Sat] WG Last Call for comments: draft-ietf-satp-architecture-02

Hi:
  I have a problem with the architecture document because it contains only small sections related to security.
The SAT process will come under intense threat from external theft and internal fraud.
The architecture document focuses on a clean asset exchange where everyone is honest and uses well tested software.

I am not an expert on blockchain or related technologies so the experts in the WG should add to the architecture document the features necessary to deal with the threats.

Question:  Do we want to revisit the architecture document when the threats to the SAT process are enumerated?

David Millman

-----Original Message-----
From: sat <sat-bounces@ietf.org> On Behalf Of Wes Hardaker
Sent: Saturday, March 9, 2024 9:08 AM
To: sat@ietf.org
Subject: [Sat] WG Last Call for comments: draft-ietf-satp-architecture-02


Greetings all,

The authors have requested that draft-ietf-satp-architecture-02 be placed into WG last call and after a review by the chairs we agree it's ready to progress forward.  I have some personal comments that I'll submit during last call, but nothing substantive or process-problematic that should hold up it progressing.  Thus, we have changed the document's status to being in WG LC and have set a deadline of 4 weeks from now.  Thus, WG LC will end on April 6th, AOE (anywhere on earth).

We encourage all participants of the WG to read the document,  suggest any changes you feel are needed from simple editorial suggestions to calling out major issues you find with the document.  WG participants should also express their opinions about whether or not the document is ready to progress and you support it's publication.

All comments should be sent to the mailing list.

--
Wes Hardaker
USC/ISI

--
sat mailing list
sat@ietf.org
https://www.ietf.org/mailman/listinfo/sat 

--
sat mailing list
sat@ietf.org
https://www.ietf.org/mailman/listinfo/sat