[Suit] Boot vs. Invocation

Brendan Moran <Brendan.Moran@arm.com> Mon, 03 August 2020 11:02 UTC

Return-Path: <Brendan.Moran@arm.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 09E843A0E31 for <suit@ietfa.amsl.com>; Mon, 3 Aug 2020 04:02:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level:
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=BWi0gx9q; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=BWi0gx9q
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3pcWw5B-yfKT for <suit@ietfa.amsl.com>; Mon, 3 Aug 2020 04:01:58 -0700 (PDT)
Received: from EUR02-HE1-obe.outbound.protection.outlook.com (mail-eopbgr10058.outbound.protection.outlook.com [40.107.1.58]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EC09E3A0C95 for <suit@ietf.org>; Mon, 3 Aug 2020 04:01:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=R5fYBqXvPOibrUhsH6C/BLZL/523g4W1rheSEYGl4IY=; b=BWi0gx9qhLEH/UJ6rJS67sxgXpHza0AqvQnsIIjvJU1VYWVPwOWelX1xVhQ7v/DQPf25LEowYFxfL09EChVUnQStCVDR6njP7BbzhvNSOUfG2iNbl36AvDs1PEKibedQBpmR7Axk2GARthnRodP/9ZNfGnqY+nSreO4UTweEMIE=
Received: from DB7PR05CA0056.eurprd05.prod.outlook.com (2603:10a6:10:2e::33) by DB7PR08MB3276.eurprd08.prod.outlook.com (2603:10a6:5:21::26) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3239.20; Mon, 3 Aug 2020 11:01:50 +0000
Received: from DB5EUR03FT003.eop-EUR03.prod.protection.outlook.com (2603:10a6:10:2e:cafe::81) by DB7PR05CA0056.outlook.office365.com (2603:10a6:10:2e::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3239.17 via Frontend Transport; Mon, 3 Aug 2020 11:01:50 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=bestguesspass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by DB5EUR03FT003.mail.protection.outlook.com (10.152.20.157) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3239.17 via Frontend Transport; Mon, 3 Aug 2020 11:01:50 +0000
Received: ("Tessian outbound d7d79595a1cb:v63"); Mon, 03 Aug 2020 11:01:50 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: 0032afdf46beb340
X-CR-MTA-TID: 64aa7808
Received: from b5a8bc98a3a0.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 4192D0C2-B45A-453C-ABC2-609289763416.1; Mon, 03 Aug 2020 11:01:44 +0000
Received: from EUR03-DB5-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id b5a8bc98a3a0.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Mon, 03 Aug 2020 11:01:44 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=N4OVKtQt9aN9JteWJtS/HUUaDbYRep3tw4EsAdVRn7eOavwGXBzhqdrbFCI1y5X/lGWQDhHHeXaI6LtSbve0XT0k903FlZopc1u8r77NncevAlIjxElj81feI3sklsCzI4wcz9wLfBh8oh8CwTwelpUucMs/dwR3zwVnoIIWJ4jOjInK21X9qUEnpCYs8zvR5I00zPaKeiEdoUlbOeO8hWEKHLod7aIVOyI1zoL955sP7q4n4WaB8ZK0r3AVTEX+qTkamWrgZr6tUi9zFQrD2OHPi8gm2GaAoICwf8NE63j+der2ahtzsR+lR0MKhyYHkcSKlKf7ai59L+FTfwqU3Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=R5fYBqXvPOibrUhsH6C/BLZL/523g4W1rheSEYGl4IY=; b=R5wsx+5ha2EEo/XVRS4c/QGpGF4bhOPKsTFV9o9lfvZfNwwlj/AUZR9FEoxHvHwEi3bZ7t47jmvgXLqwLr9ZslLETW0Iqgmhx9K1NIoQSjQgV6XQJUWj+QEbDGJ06QDrTTCfdH8SmyMa20qPCaXdRUS3IhXCNq1Lq6YcPisuhcpRFUOZlzGMkOxP430Xt+82Yq/zuwm0ixEYbxBL+EHMlImphrnsuenK/jzIa2axH6hPdAcNlkyX8ErQcz6dKR6CmbBVP/fMZ2+TaBuUD7J8Y6SHg9tGVNG8mR9YkUnhsSWpVX/7Fumcv+yrYrFVQBNEwKKrLwqkdPeZWpn8F7Z/kg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=R5fYBqXvPOibrUhsH6C/BLZL/523g4W1rheSEYGl4IY=; b=BWi0gx9qhLEH/UJ6rJS67sxgXpHza0AqvQnsIIjvJU1VYWVPwOWelX1xVhQ7v/DQPf25LEowYFxfL09EChVUnQStCVDR6njP7BbzhvNSOUfG2iNbl36AvDs1PEKibedQBpmR7Axk2GARthnRodP/9ZNfGnqY+nSreO4UTweEMIE=
Received: from AM6PR08MB4738.eurprd08.prod.outlook.com (2603:10a6:20b:cf::10) by AM6PR08MB5142.eurprd08.prod.outlook.com (2603:10a6:20b:d4::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3239.16; Mon, 3 Aug 2020 11:01:43 +0000
Received: from AM6PR08MB4738.eurprd08.prod.outlook.com ([fe80::a98d:5ebe:dc1d:ea56]) by AM6PR08MB4738.eurprd08.prod.outlook.com ([fe80::a98d:5ebe:dc1d:ea56%3]) with mapi id 15.20.3239.021; Mon, 3 Aug 2020 11:01:43 +0000
From: Brendan Moran <Brendan.Moran@arm.com>
To: suit <suit@ietf.org>
Thread-Topic: Boot vs. Invocation
Thread-Index: AQHWaYV4nhWrUvTKa0uAzW/mc1pZHw==
Date: Mon, 03 Aug 2020 11:01:43 +0000
Message-ID: <9CA92962-0D40-47CF-BB62-DE325D1D0869@arm.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3608.80.23.2.2)
Authentication-Results-Original: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
x-originating-ip: [82.20.19.206]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: 461aec13-b3ae-4922-b9ae-08d8379c9f70
x-ms-traffictypediagnostic: AM6PR08MB5142:|DB7PR08MB3276:
X-Microsoft-Antispam-PRVS: <DB7PR08MB32769FFDBFE5706027885815EA4D0@DB7PR08MB3276.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:4941;OLM:9508;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: 4Sws3DvbnjmUNM9dfe3ursKnbr/rDPU9rJvThX666ZhpsG38BRnPrl3fkq3Sb4BUBHJedkvS2cwCjqMlx3fRamDpLE0xhgarwA84Vyq93WydB3pUJtptA/x7q0SkAwEJlH5ADUTbJXRcHPQ3pnhXfX4RDlAiJDRPSX3q8VkU1D/eqwFEIOWUudGTu08CTeW2riZ1Gyv9sx68KGfn3fVVLC8nF9nHAJ6hZyHkojtac8j13lVPrq3VNayz7UEuceNH3qYuODhY1ca6wWm7IqxGATV+gycU6gVz7ec+HtA2PaYUOK18zoBnwsbjnCkoDirX/Wlhzl4naJRYf+Iej3oODQ==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM6PR08MB4738.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(376002)(136003)(366004)(346002)(39860400002)(396003)(5660300002)(83380400001)(66476007)(64756008)(66946007)(66556008)(86362001)(4744005)(66446008)(91956017)(76116006)(6512007)(2616005)(36756003)(186003)(2906002)(316002)(6916009)(6486002)(33656002)(26005)(71200400001)(478600001)(8936002)(8676002)(6506007); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: wxkVTW/OnSPT7yJIOkVR/6xGa9vhz1UcA4rfWWYUV1OVrib+CCzzFZkd7RZgS9CY9+kL1UCgRCD9O3jv0m8Kv3wAtkAQkITWUj9v2OGyJYtXqDSm8QSMnp9d8c+3vrYoFgLRHqAlBg155cGaZkhBRGy4qTSeccVUT+hj8O3boj1RBXQVmFoXiwmZcmns3ITWzr4T7cbfbizv7qtA0BAyEssHbxI6fyn1aHkOsfG2tMOgifP3v7BiuBJHVrY0TQBt5J55SvjgGTk7pJH5esktTzmIDc9Nl2EiTjV0+4zI6EYe2VubWk9PuaYHV2QzkowHbjbtUaO2jiVft7NLKWuUAoDbQUNTvi140iEsAChYytAlsp18FXPfqNiudOUJj0tU5H0gOjjFDKullXA/Y/zh8NjHLxA4dW5uDNQO3tpHUaWV4sLipYIZmozJ6NoA+IZLVGkzPCvZ7W3eaAgAW3y7m0VrcbCrP+b/6hRtGt1v2RVhhCUBexV6hy/fl+tg5xguYRsD3jVL96wWfD7n40CyYKL4mUS93APWKKpYqroEQP+qggaFFXy0guocQOXreSj7pvwOs85JM/40QRPnE89KDSKIcYspVQj9rX0dErH9u0Xf5xfFgwAg3AjYq9jIP7c8/2u1d4mOXreNsEhcFIjWtA==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <A429830E014B0142BA9A2F4A3EAFC943@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR08MB5142
Original-Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: DB5EUR03FT003.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: d6a1b89b-91e0-43d0-0204-08d8379c9b71
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: eIx420vKfbyPK8FLr1DEzeanz+dLoo9c62R5vnPabItqg2PHoQkjp5k4cAozcGXmwvStQIfnrVwsUiUbWTLiOYCKvJRGybyFZUxDduLjO4uyDCRaZnvENN1NsBJ2NWrvEovN+fbih/bBLNiwqoO3Myp9C2qEKJQj2V+qarZPFwUK2Rs8regmG0BHUVjdtdWUTS5PhUtzjD+LixwM8nzNy+cW8iU9GAPBnZ4S3QxQHWkiCcPbYnLdYKVmUj6VKmdnntK5GbeZnp9LLvDnkRZ8FrK5Ej+TwDD4J0UDM2ray4qhptoTkkJveilPR2LmJ+waf93GSXEZeWtqK9/LEWbfXc0fCddUsa9zCo/BDZIctDGg3Husxw/YF7uVGAOcQeNpJiINPbx+9kTkYeo/5/JDBQ==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFTY:; SFS:(4636009)(39860400002)(346002)(396003)(376002)(136003)(46966005)(336012)(8676002)(8936002)(2906002)(316002)(86362001)(33656002)(5660300002)(2616005)(82740400003)(4744005)(47076004)(70206006)(6506007)(81166007)(26005)(6512007)(6486002)(478600001)(186003)(356005)(6916009)(36756003)(70586007)(83380400001)(82310400002); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 03 Aug 2020 11:01:50.2245 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 461aec13-b3ae-4922-b9ae-08d8379c9f70
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: DB5EUR03FT003.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB7PR08MB3276
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/EhzJ5mwCrkwONk5rxCNuUOfxxZw>
Subject: [Suit] Boot vs. Invocation
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 03 Aug 2020 11:02:00 -0000

In response to some of Dave T’s comments (specifically, [DT32]) I would like to propose replacing instances of “boot” with “invocation” so that "secure boot" becomes “secure invocation.” This is to make it clearer that SUIT manifests are appropriate for invoking TAs for TEEP. Booting an IoT device securely and running a TA securely are both classes of secure invocation and Dave has raised that it is not obvious that SUIT manifests are appropriate for both.

Best Regards,
Brendan


IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.