[Seat] Re: I-D Action: draft-ietf-seat-use-cases-01.txt

tirumal reddy <kondtir@gmail.com> Mon, 21 September 2026 06:27 UTC

Received: from mail-oo2-x0f.google.com (mail-oo2-x0f.google.com [IPv6:2607:f8b0:4864:31::f]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id 9EF3630 for <seat@ietf.org>; Mon, 21 Sep 2026 06:27:55 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=gmail.com header.s=20251104 header.b="cN/SL0zx"; arc=pass ("google.com:s=arc-20260327:i=1"); dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx.ietf.org: domain of kondtir@gmail.com designates 2607:f8b0:4864:31::f as permitted sender) smtp.mailfrom=kondtir@gmail.com
Received: by mail-oo2-x0f.google.com with SMTP id 006d021491bc7-6b1ae7166edso1252727eaf.3 for <seat@ietf.org>; Sun, 20 Sep 2026 23:27:55 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1789972069; cv=none; d=google.com; s=arc-20260327; b=WXCFWh1gVrCCrxoniFZNP09tV3ioy8dkAM4CqZwPfpPQisiqFnwwA7QUJvT/gMCOI2 m1du2BYyzxFsCCcKnz+54b/vOIxVnbWILGULbdkM4ycUkXDi3XWViL39jCsw9OW8b+Zl X6jH80voUkU2NH8NBtNSwIF2Afu/XjuNpMMqYWBbeHgJHfJ2fiO7B5zrK7IjRdUyMixl KzLHE9ssUNmRiT+oMRP5ScDq3H1aNaM9OnkGAXSsN+aNgZUQwvj0trDNw5BcuJI3+oAa jTgMGzZI/0Do3TpcJ5vXa1FiqVLlSokt7nUBFWj4Z3P3AA7T5Fy0ceF8d//38pQrVM0r z1bA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=EUIFzwfHzjSic9TbufoLFFeBiqvXd7U5FUYltYWGOhw=; fh=XOFI0pnS5xmuHFs5cj2+Q/C2rv0M3Fw1Y3VkRfA1dD0=; b=MpO5DG3SkVglTxn+7y20L1X3Wk3iT/wGKueDuI/3DlHemLP+ivzzSkLjrAhaa8lXnX u3jWng7T1Dm7pSX06OXrFh8LDGK0fwMRx/BzXot9eQwyWWl8A/XPjrny4VrQ4bz31xrG wboKg8ZRrLq9yjw3U2dUA60ZkOQzcIK1W0RthcwhhokaW8hwDIjNGLJmQVpdY3kr6ufl YDeUyp4hxpqEt6MWj2geexgssny39V9kHTVkMlMMmF5dkpNCCrx6lDnlojQaoU4AoPF5 n4ma66uZcUIGey8sw8YnOUkcXuFXJwkt8UcPueVQPb6lnzA7WNvwYMxg2CI3/6v3tu0H rVSw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789972069; x=1790576869; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=EUIFzwfHzjSic9TbufoLFFeBiqvXd7U5FUYltYWGOhw=; b=cN/SL0zxdzjZSq4DX3roZZ6F7sQ/SmHZPSqWYf9+jcREwP0OTMFyZxmlc/buKTBIw5 MQ8Jeml7i+3jpHGpHJfMRr+VQhygrZ1Hut7eNFo8UOp6t0QFXzlhDwPCblPghwKTzGWW 0zsl5JJbkDJaLxEFNihIBZ/xwbdwqn9dJLn0WkT2WBLA1A5GYXxb+Xpo6X4Bu81Y8xnQ WSdWcXvS0mGVaq4z5iZ0nfbWtSXU4LWgxeK1jtLmVKVGRnrIdwpeA/qFr2hFjvCQFfak px4CIZfrziuf72W52bOreCnGQSdaRL9TGhrNjo/gbmKU+H1j4mZSLQ0sR6JB88jQK+r4 2XBg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789972069; x=1790576869; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=EUIFzwfHzjSic9TbufoLFFeBiqvXd7U5FUYltYWGOhw=; b=T9BVNkNwE14b0Ak62bCGeydZxz0/zHJVOH7DDMIg/l4YnLOydlRS2Y/03YOOOA4g97 QxUYtL8RhBZQsvsZ6EVGNQ17vMvDyySr4adMYugRfQpRcSshFB2pSYOSRG2JDDe7dNaT fDSSRNgJpgGbREBb/NP1U4V7AoclQ13DoSYqeen2kMxvRh7RcLJPHQKLcGLu3vTX5muY 8+Oi/S+dpMaadDrn9RT991zoQnFuX25+1LbWoKCcbUzybPrVNpy9DTyWGw4ciE/1DXl/ I2ex8LzhymKW72MjqjS4uygnahIUyS6/ssxCtRsBPR0pCYcq2EPQpg+rykINkRa7M8IS 8GYg==
X-Gm-Message-State: AFuF++nzdxaYOsvUh4JnLZSADi2T9OlXi6+KCdQ2IfFEpKJ+IWQ80OaY G+bGThMv7r0RKvgtFVzXTIIOUV2uSZtX0KFFLVopWSrHb+ICYmbrP4SupZewX8LDRB41Lg7DqIg AdPfFVrIWtfa1fQM8U7rXQPvUw8rJ4d3JCkjP
X-Gm-Gg: AYBFou3ayhp9IX56nM6UYBw9bp9Dp0nXscb/p3utxPmb8Wtf4dDhaA8NIn7PegFiP06 y09iIH5fnA4TAlo3Pd2fTZVNpMvCt5U/hAtpqve3fD4olOXwbINHhumcxHOfbpzG5TELPFNst0m cgFvYla1+OtCA4AxufKn1QfuyedJ/vfyswb8ZTwaaYMHJZsXQ9HW10BZpp+2hsHHmHF+i6SLue8 KuoVxjrP7KYiqHlFZALEp0RlGZABNnTBiO8f80uJ0oMxzDjAfrrPrDoJ3PY3u6hF8fhqpvUmMW/ pYUChLFK8OdO2MX1jPBV7FunmCtk+02/ihj8BKqu1d8JJOvN0Kniq12mbGvzp12kFy58YTdM7xA rAsGEruBw1g==
X-Received: by 2002:a05:6820:4b09:b0:6b6:c0bc:365c with SMTP id 006d021491bc7-6ca9aa4212fmr8560695eaf.22.1789972068782; Sun, 20 Sep 2026 23:27:48 -0700 (PDT)
MIME-Version: 1.0
References: <178948036606.865643.17120592835880638955@dt-datatracker-597c8c8754-4t7c8> <VI0PR08MB1156572A735D2BD7CAE6E82868ABA2@VI0PR08MB11565.eurprd08.prod.outlook.com>
In-Reply-To: <VI0PR08MB1156572A735D2BD7CAE6E82868ABA2@VI0PR08MB11565.eurprd08.prod.outlook.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Mon, 21 Sep 2026 11:57:10 +0530
X-Gm-Features: AcwNN1UESaQ8lPEU1LKeEMdhFZ6Wr0dwicsbcuTGDJuudbhKmiOOMIsMDzPxf5Y
Message-ID: <CAFpG3gfar87ih8_hSDLmJCF85nN2DKEqz4T-_gNFZYTbF5sXqQ@mail.gmail.com>
To: Ionut Mihalcea <Ionut.Mihalcea@arm.com>
Content-Type: multipart/alternative; boundary="00000000000051566b065bf85933"
X-Spamd-Bar: --
Message-ID-Hash: RWPIWOKS2FHXX6Q24HDL32N5XHELKBK4
X-Message-ID-Hash: RWPIWOKS2FHXX6Q24HDL32N5XHELKBK4
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-seat.ietf.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "seat@ietf.org" <seat@ietf.org>, nd <nd@arm.com>
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Seat] Re: I-D Action: draft-ietf-seat-use-cases-01.txt
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/9R6guyZj35OrkZMal671rEW-87U>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>

Hi all,

The latest -01 version captures the relevant threat model and security
requirements. The use-cases document is focused on defining these threats,
use cases, and security requirements. Analysis of specific protocol
mechanisms is outside the scope of this document.

As the chairs have clarified, formal analysis of external drafts, their
implementations, CVEs or publications outside the WG's active specification
work is out of scope for the SEAT discussion.

I suggest we therefore focus the discussion on whether the identified
threats and security requirements are adequately covered in the document.

Best regards,
-Tiru

On Tue, 15 Sept 2026 at 19:51, Ionut Mihalcea <Ionut.Mihalcea@arm.com>
wrote:

> Hello all,
>
> A new version of the use-cases draft has been published, adding the
> recently discussed attacker model. For updates to that section, please
> create new PRs or new issues in Github [1].
>
> As proposed previously [2], I plan to create a new PR to move the
> use-cases section to a templated model. When that is available I will
> provide a summary for the mailing list.
>
> Thank you,
> Ionut
>
> [1] https://github.com/ietf-wg-seat/draft-ietf-seat-use-cases
> [2]
> https://mailarchive.ietf.org/arch/msg/seat/5iQlAOciB2deQ6FukrLwoeX7zvk/
>
> *From: *internet-drafts@ietf.org <internet-drafts@ietf.org>
> *Date: *Tuesday, 15 September 2026 at 14:53
> *To: *i-d-announce@ietf.org <i-d-announce@ietf.org>
> *Cc: *seat@ietf.org <seat@ietf.org>
> *Subject: *[Seat] I-D Action: draft-ietf-seat-use-cases-01.txt
>
> Internet-Draft draft-ietf-seat-use-cases-01.txt is now available. It is a
> work
> item of the Secure Evidence and Attestation Transport (SEAT) WG of the
> IETF.
>
>    Title:   Security Goals and Use Cases for Integrating Remote
> Attestation with Secure Channel Protocols
>    Author:  Ionuț Mihalcea
>    Name:    draft-ietf-seat-use-cases-01.txt
>    Pages:   23
>    Dates:   2026-09-15
>
> Abstract:
>
>    This document outlines desirable security goals and use cases for
>    integrating remote attestation (RA) capabilities with secure channel
>    establishment protocols (e.g., TLS and DTLS).  Peer authentication in
>    such protocols establishes trust in a peer's network identifiers but
>    provides no assurance regarding the integrity of its underlying
>    software and hardware stack.  Remote attestation addresses this gap
>    by enabling a peer to provide verifiable evidence about the current
>    state of the Target Environment.  This document specifies a set of
>    essential security goals the protocol solution must have, including
>    cryptographic binding to the secure connection, evidence freshness,
>    and flexibility to support different attestation models.  It then
>    explores relevant use cases, such as confidential data collaboration
>    and secure secrets provisioning, to motivate the need for this
>    integration.  This document is intended to serve as an input to the
>    design of protocol solutions within the SEAT working group.
>
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-seat-use-cases/
>
> There is also an HTML version available at:
> https://www.ietf.org/archive/id/draft-ietf-seat-use-cases-01.html
>
> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-seat-use-cases-01
>
> Internet-Drafts are also available by rsync at:
> rsync.ietf.org::internet-drafts
>
>
> _______________________________________________
> Seat mailing list -- seat@ietf.org
> To unsubscribe send an email to seat-leave@ietf.org
> _______________________________________________
> Seat mailing list -- seat@ietf.org
> To unsubscribe send an email to seat-leave@ietf.org
>