Re: [siesta] Eastbound - Westbound

Robert Moskowitz <rgm@labs.htt-consult.com> Fri, 29 November 2013 14:59 UTC

Return-Path: <rgm@labs.htt-consult.com>
X-Original-To: siesta@ietfa.amsl.com
Delivered-To: siesta@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A92F11AD8CD for <siesta@ietfa.amsl.com>; Fri, 29 Nov 2013 06:59:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.5
X-Spam-Level:
X-Spam-Status: No, score=-0.5 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CV5rfXVhrsuM for <siesta@ietfa.amsl.com>; Fri, 29 Nov 2013 06:59:25 -0800 (PST)
Received: from klovia.htt-consult.com (klovia.htt-consult.com [IPv6:2607:f4b8:3:0:218:71ff:fe83:66b9]) by ietfa.amsl.com (Postfix) with ESMTP id 98B7C1AD6BF for <siesta@ietf.org>; Fri, 29 Nov 2013 06:59:24 -0800 (PST)
Received: from localhost (unknown [127.0.0.1]) by klovia.htt-consult.com (Postfix) with ESMTP id 4EBE062A7B; Fri, 29 Nov 2013 14:59:21 +0000 (UTC)
X-Virus-Scanned: amavisd-new at localhost
Received: from klovia.htt-consult.com ([127.0.0.1]) by localhost (klovia.htt-consult.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OspFpKcGU9xr; Fri, 29 Nov 2013 09:59:09 -0500 (EST)
Received: from lx120e2.htt-consult.com (106.sub-70-208-161.myvzw.com [70.208.161.106]) (Authenticated sender: rgm@labs.htt-consult.com) by klovia.htt-consult.com (Postfix) with ESMTPA id 1972C62A62; Fri, 29 Nov 2013 09:59:07 -0500 (EST)
Message-ID: <5298ABB8.4000404@labs.htt-consult.com>
Date: Fri, 29 Nov 2013 09:59:04 -0500
From: Robert Moskowitz <rgm@labs.htt-consult.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130625 Thunderbird/17.0.7
MIME-Version: 1.0
To: "Diego R. Lopez" <diego@tid.es>
References: <52973F0B.6080900@labs.htt-consult.com> <79062E4D-BE01-4E6C-AFA5-063B8D9C66E9@tid.es>
In-Reply-To: <79062E4D-BE01-4E6C-AFA5-063B8D9C66E9@tid.es>
Content-Type: multipart/alternative; boundary="------------050408090505040100000407"
Cc: "<siesta@ietf.org>" <siesta@ietf.org>
Subject: Re: [siesta] Eastbound - Westbound
X-BeenThere: siesta@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "SessIon layEr SecuriTy Approach discussion list." <siesta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/siesta>, <mailto:siesta-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/siesta/>
List-Post: <mailto:siesta@ietf.org>
List-Help: <mailto:siesta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/siesta>, <mailto:siesta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Nov 2013 14:59:27 -0000

On 11/28/2013 10:20 AM, Diego R. Lopez wrote:
> Hi,
>
> I tend to imagine the KMP to the West and the application to the East, just because of the left-to-right order for the elements in a normal exchange.

Kind of what I thought as well.  Great minds think alike!

> And I have employed this similar idea of the "East/West-bound" interface when talking about SDN controller interconnection (actually, I always used "Eastbound" because of the above idea on order)

Sigh.  Thought it would be obvious.  East/West that is.  But that means 
the 'coin' is out there so others will understand what we are refering to.

> Be goode,

Got 4 grandsons (6 yrs, 3 yrs, 2 yrs, 6 mos) here to enjoy and two sets 
of parents to take care of the messy diapers!

>
> On 28 Nov 2013, at 14:03 , Robert Moskowitz wrote:
>
>> I *think* I have coined a new terminology that I have clearly stolen from others that talk about a southbound and northbound set of interfaces (e.g. Openflow).
>>
>> A Siesta-like process, like my SSE, sits in user space next to a communicating application, performing the necessary session level security functions.  This SSE process MUST follow all the current Best Practices on maintaining a proper security boundary.  But SSE does not do the key management; next to it is a KMP also sitting in user space.
>>
>> So to the east of SSE is the communicting application that is using its security services.  To the west of SSE is a KMP which actually manages the security state for SSE.
>>
>> So unless someone else can point me to somewhere else where East/West bound interfaces and APIs are named as such...
>>
>> Or is the app to the west and KMP to the east?
>>
>> Sheesh, I got to finish packing and get on the road already!!  ;)'
>>
>>
>> _______________________________________________
>> siesta mailing list
>> siesta@ietf.org
>> https://www.ietf.org/mailman/listinfo/siesta
>
> --
> "Esta vez no fallaremos, Doctor Infierno"
>
> Dr Diego R. Lopez
> Telefonica I+D
> http://people.tid.es/diego.lopez/
>
> e-mail: diego@tid.es
> Tel:    +34 913 129 041
> Mobile: +34 682 051 091
> -----------------------------------------
>
>
> ________________________________
>
> Este mensaje se dirige exclusivamente a su destinatario. Puede consultar nuestra política de envío y recepción de correo electrónico en el enlace situado más abajo.
> This message is intended exclusively for its addressee. We only send and receive email on the basis of the terms set out at:
> http://www.tid.es/ES/PAGINAS/disclaimer.aspx
> _______________________________________________
> siesta mailing list
> siesta@ietf.org
> https://www.ietf.org/mailman/listinfo/siesta

-- 
Standard Robert Moskowitz
Senior Technical Advisor
Security & Standards
Verizon Business Systems
C:248-928-6233
F:248-968-2824
E:robert.moskowitz@verizon.com

There's no limit to what can be accomplished if it doesn't matter who 
gets the credit