[Suit] draft-tschofenig-suit-firmware-encryption-00

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Tue, 25 May 2021 11:37 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B097C3A0DDC for <suit@ietfa.amsl.com>; Tue, 25 May 2021 04:37:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=hMvHiijj; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=hMvHiijj
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ttY3I0kPrntL for <suit@ietfa.amsl.com>; Tue, 25 May 2021 04:36:56 -0700 (PDT)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-eopbgr60041.outbound.protection.outlook.com [40.107.6.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0D4073A0883 for <suit@ietf.org>; Tue, 25 May 2021 04:36:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=xzfqEcMs/9PVrCVh3QB4BE2Uscw6qEtHP6kRNbXnkP8=; b=hMvHiijjXz1eBioGJBF2sJRbu1BmcAUF/GKpTDi009szLD/BBLZ2Swp+INROgMKUuV00v7ap2xtJZvwohKQWz1mHW/AYwMrH84rO2sI7+9hmvWl1Z+bdNeQjOAFtfKF/M8jaMlY1dpcphuYpf5+Tvw8/Ae7v3IPWBEcxOHnqAw4=
Received: from AM6P191CA0102.EURP191.PROD.OUTLOOK.COM (2603:10a6:209:8a::43) by VE1PR08MB5150.eurprd08.prod.outlook.com (2603:10a6:803:10a::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4150.23; Tue, 25 May 2021 11:36:53 +0000
Received: from VE1EUR03FT031.eop-EUR03.prod.protection.outlook.com (2603:10a6:209:8a:cafe::a0) by AM6P191CA0102.outlook.office365.com (2603:10a6:209:8a::43) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4150.23 via Frontend Transport; Tue, 25 May 2021 11:36:53 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT031.mail.protection.outlook.com (10.152.18.69) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4129.25 via Frontend Transport; Tue, 25 May 2021 11:36:52 +0000
Received: ("Tessian outbound 6c8a2be3c2e7:v92"); Tue, 25 May 2021 11:36:51 +0000
X-CR-MTA-TID: 64aa7808
Received: from 52371f946eae.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 3E49B6EC-046C-40D3-B280-ABE1BCBCA14B.1; Tue, 25 May 2021 11:36:45 +0000
Received: from EUR04-VI1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 52371f946eae.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Tue, 25 May 2021 11:36:45 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=EewttidlZSX6n5RW6yTDZk5nkHHLc4j2zmfO6ezZ1DHejVJJxSOC5wnGIP3rmJGvA6BJOg2FVvGZCvz05kaBxXWonBRsjUaxc+OudmbXO7NM6Abro4ci2nEib5ssGQ6sbU1m00INblDa+rJ5KXPUuacQ6Kbp3YwgGZ12D3OvI5CLY53tOIF5nnmNLFP+HsqV3Hl55pBHw8Vgh32zrnXh8G8RSkuJZEUpIKMXzIrhPVQcGmWTQqOafYj1QT7wa6d93RDi5hJm5ktBwZtOn6DCf7zZKW407WIJlsczBCAUjSRGRkBuLpiPRh8YJq+rludvl2EAlNAjd5xXnA1RSWyxow==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=xzfqEcMs/9PVrCVh3QB4BE2Uscw6qEtHP6kRNbXnkP8=; b=GYcqaXhDdqprLKwYKqXnpRhBtbO8nOe1J7X7b1a2edMbvBJiMN1aqyE3aYO287mMkU9WSyXm9dl7X5VMZd85VM83HxtxdTWImoLJiadqaVsyE3DWQTvkoMpOoum+Naxs1FAA+sBklM6bkfWJxtcHLa3wdKDwUGA0W8E+wAneV6aAOYyoCfeXPNk8OpPRQ1syThjpzXeb7vpxFT8lcWrcPhy3/wwhFEQljEkPhstUkL0U7B6vcHMAwI5wkWw2zul12jvPqk4smDwgBpKdEN3m4Z7ftrw8QPVPRqbiR4wL8id6HKNGM/mUt/4MmtmdQHj5cHEAVML1ilC+jmp894av2w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=xzfqEcMs/9PVrCVh3QB4BE2Uscw6qEtHP6kRNbXnkP8=; b=hMvHiijjXz1eBioGJBF2sJRbu1BmcAUF/GKpTDi009szLD/BBLZ2Swp+INROgMKUuV00v7ap2xtJZvwohKQWz1mHW/AYwMrH84rO2sI7+9hmvWl1Z+bdNeQjOAFtfKF/M8jaMlY1dpcphuYpf5+Tvw8/Ae7v3IPWBEcxOHnqAw4=
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com (2603:10a6:10:20d::17) by DBBPR08MB6089.eurprd08.prod.outlook.com (2603:10a6:10:206::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4150.26; Tue, 25 May 2021 11:36:44 +0000
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::3405:8699:991d:b2e9]) by DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::3405:8699:991d:b2e9%9]) with mapi id 15.20.4150.027; Tue, 25 May 2021 11:36:44 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "suit@ietf.org" <suit@ietf.org>
Thread-Topic: draft-tschofenig-suit-firmware-encryption-00
Thread-Index: AddRWUDAvarTrSOxSNGU1d2WOJs4oQ==
Date: Tue, 25 May 2021 11:36:43 +0000
Message-ID: <DBBPR08MB59156008CEA8C320267044E7FA259@DBBPR08MB5915.eurprd08.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 51E22CF612FB4740B841D9E4DB5AA578.0
x-checkrecipientchecked: true
Authentication-Results-Original: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
x-originating-ip: [213.162.73.248]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: 10862153-beb1-44f0-dde6-08d91f716469
x-ms-traffictypediagnostic: DBBPR08MB6089:|VE1PR08MB5150:
X-Microsoft-Antispam-PRVS: <VE1PR08MB51509272A0AD8A22C8C1435DFA259@VE1PR08MB5150.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:8273;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: a9PEW2L0lSwROrxfq6A0u47QaymLcO/DI/XJ89RGqjEu9pyn4k5Qf2h3Uov2RRfoBZ0PK95jJ0jGcKmMwco0GCBJZvNRG5QQyTIvE7OR0v1dtHaBCxQ7BVtRUD0GXDdJeNNpcBcZEq3KRAUTwQuVxtrAIIJgfi937+D4fdmmWM5Qy3NSr9Z4QVM8+BHtJRhk2vaBLi+1LUf5kOZ5B7VSEFUXbMQeDbpzkdwxw1BPrpjS8MUSOD6TTKZtcLEzfl02QW5HD/F5SaZLIY9U9uqnI1tajq3m8vKbJUnGg7qAOzOCV4BlQdtLhysf4bQ7phV3NTKC0RsZFrefReHiu5UziC9fAwTPJ9z1TBGiDmmc1jLTaKL/+YFtsOt5Nhepkj3EnFYilpS0nhhKdDJjtvHvF4nooSH21NdCpi1LTDIn4sBZf0kXyg/89nxIg9bA74wrOo+Js5JKe2g89sgTW74j6BkT1Dow91hwOaWsOYQan0K7FvXuuGVvK3RYKHuZa0ILCHZmN+839ytz1vavbzhHEzvT44NNQfv9gPSNB3sZG7RKIhpWtmHKvYRD3oZnbIJtlG9qC3Cu+idWeSiehi2aYbg6VKRaqyjSinw0pRCrauWs7Mp6nWuaG4bMGjOjIYsewhOgCWAUuDGPRbWYqgdMVK54GCF7Fb+LoTmSv0WL+cbqttkEKqAxo4asXl2ORrqhLwBK3Jx52QO3U6HzGzBduQ==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBBPR08MB5915.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(396003)(136003)(346002)(376002)(39860400002)(366004)(55016002)(6916009)(66476007)(86362001)(64756008)(316002)(7696005)(38100700002)(66556008)(66446008)(76116006)(66946007)(5660300002)(122000001)(26005)(966005)(83380400001)(166002)(8936002)(6506007)(8676002)(186003)(33656002)(2906002)(52536014)(71200400001)(9686003)(478600001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: =?us-ascii?Q?pIQXW9Ag0AH/K4zJc+i9M7Wmgf9inlSbMRx5LH6mgrCij2ZGHUpeW/5sEiVe?= =?us-ascii?Q?xEZXZHWYYKxF9PIy0N5xW83eEkVhob1cMd2xbgZtE0KuGn+pMFMP7H0UG/TF?= =?us-ascii?Q?FpocLwczXbOWfZed5glkvfiXsmkfqvuRUqpxHd23I3tOVXghoruWH/AVHJBb?= =?us-ascii?Q?V4wp6X5t2HebBsS14w6qy8dgOEFcu2DVoQRE2p62syrLad/kVRG025zAHxrl?= =?us-ascii?Q?ElFcFT8EkDM+kpx71qHhaxev3/OxyvN7H4D7hXVQoT3bWj6eImD6R81vFRdC?= =?us-ascii?Q?T9Jt/9Gb+jt8Eptm1WJWerREfEiC5cdsp28iLCg/VO/OSu8H4G9vs6AuoSJD?= =?us-ascii?Q?f1wbYCBHEnfom2SO+IVCrnPqL2oDO8G2U1YkxSE95S9uZKuXztGc1FpHFena?= =?us-ascii?Q?Xglaa5rOjxbJ5hdfjdPbzCGZn4a+Bi3/IANCc9yGqxsnscp7ZtvjRW21CIHG?= =?us-ascii?Q?1w0nNkvA8pVMb5bGuPyO5AZuAdCgi9rpGCKstp8PRr0BkCwc2llYPyE3CqTG?= =?us-ascii?Q?Lr4Xt3C8udksBrQeWPA+szQkjcSTQXZv1euhQtLtVC+ptHee8qeICDMrp8fR?= =?us-ascii?Q?7QTHZwaDLxn7OADATRxufqD+XBBgW7PBoTKa373ThGwLaF4fs7kf6QLz9HS4?= =?us-ascii?Q?7zso1StxEcGDbBAv1h/dRUSx7p8u94BBUXVgTizgUJwMyDHrku0+2dxjBi1d?= =?us-ascii?Q?ZedGSRMw+OPUmRZNx1Z2x/DP0LpY5qObbou1CFWczU948PEsYQEhVCAphIOF?= =?us-ascii?Q?i8HUpwhCCgubLuwuLHLDwsGaYImMeuFYqolUBwuWUBG6TokF3dV+v2z2o580?= =?us-ascii?Q?3JLYrazQLUk6eE0ivHrzWAhAufj6oL0t8GGW4J+soce1BCmp5cAIFmx83WIN?= =?us-ascii?Q?WBRRKKZLctSk7jO2b86T1j+Y/LHRM2LuWwPWsjwAqd+o05a24QiFl/N0Lmyz?= =?us-ascii?Q?1VQQ9oShTmn/nba4IMndd/En0Y9zJPSEz0rxKXw64mJG7tzBb/A20cEXrH7R?= =?us-ascii?Q?Dj/l79rQW31FcObyYIIhd82EidIQPOBqcQJkPSoz1xMrSnCCpqnHQWHdd8QM?= =?us-ascii?Q?BvplxRhIHKCpNhMk9yPJfmGWjIRreVVPVYYHr+Ru89JoGI1sxWwkXUh+vS9v?= =?us-ascii?Q?h3kufwXACVwB+85rTeaKLr/tlGb9GtY+NN2cGzM8mkKfPXOCZ965dBILrrK9?= =?us-ascii?Q?q5fd0Ar4bID715VN4nXaPdZ8ZdttZIMntTnHf2ot7jK1G/aFPGCfRzY/6g57?= =?us-ascii?Q?W74+UP8a9bRHz0Gxn5mAIsiXHnJgXiC/tBwskDeKdhDQEPt77ZrU1hrEbfzC?= =?us-ascii?Q?YIH8Z5RcdGbGAq6c5VBO0dsq?=
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_DBBPR08MB59156008CEA8C320267044E7FA259DBBPR08MB5915eurp_"
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBBPR08MB6089
Original-Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT031.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: b906ebcc-5400-4689-83e8-08d91f715f49
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: WwjGWVawhsPGDPZcHmCnHuTUmHpTAVczoh2LO/Dd7f/HaqVeqRE1NCtqdH0mcvJyn9oi5NAxsgBgF1ek4f4j/l0UExcUDRNl6m3dlWGIhEBSAOiZli8gf+QANzI8rgwXBv285da6PWUQJMuNRrsNbJ1G1Zo0HnHBJIZV2RrPGfMCEgAqCK2w27dRLB+CSce6bIwDotLsS56+gr1AHF9DSe8i/7XO8xKUVLdc9p8Y7/B1qAHv+KvwzNT6BDmb/Ri1iSKZnvoZTO9iCotsvN8Zk0x9gHX5Gwe9GIgx/ttupqzbJGsYY59b7Au3HVR4oBRqBXD6jrld5kb2li7Uv2wbgprGqOKG1XO1ZcUqBEDoGOSPS5cDhuJsRsH1VK93FIK+FmFGFHZMc/vI3/FVPaMh8fVlt4GcxA59J59s7qAmyzO7ukwXXcqwj2HZQhWrjh26hq7dcV3EnurCWE6YLdUtsDRkEyYgF11Z0GoS6BxS2Xpb9Jom+WqdYrHYsakXjK9wKvTydUgcvlA6IN0SDYXmwnZJexyeL0S5IYnaBHC4qZu5w2sJEqw1iT+09brsqNfuMSkIdta2CoEi+q8jsjucSO9AyqS7aMSqmZwh2EQFbUexThLr4S+e2GnB+N3ORHvy2+nG1plVHDhhGfCjIM9zr42SqwOtqLPf+P2fE3jiScG3Qye75V/evwoaUjJnDosdflER9nEMaC5ockcNwQ/lq6haOzj+a6L07luRpvBJ9NW8VsFlTFlm6HzewnlS8Ptq
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(39860400002)(376002)(346002)(136003)(396003)(46966006)(36840700001)(8676002)(166002)(9686003)(6916009)(316002)(356005)(336012)(82310400003)(26005)(7696005)(82740400003)(55016002)(8936002)(36860700001)(6506007)(47076005)(33656002)(70206006)(81166007)(2906002)(86362001)(5660300002)(52536014)(83380400001)(478600001)(70586007)(186003)(966005); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 May 2021 11:36:52.4781 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 10862153-beb1-44f0-dde6-08d91f716469
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: VE1EUR03FT031.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VE1PR08MB5150
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/nLW9oz-1D1t2WY8n2wNJNYYBBdM>
Subject: [Suit] draft-tschofenig-suit-firmware-encryption-00
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 May 2021 11:37:01 -0000

Hi all,

At the last IETF meeting I presented the hackathon results of the firmware encryption work. I talked through some of the challenges in implementing firmware encryption with COSE and the group decided to put the guidance of firmware encryption into a separate document.

Here is a first write-up of the firmware encryption for SUIT using AES-Key Wrap and HPKE. This is a first version and still incomplete. The solution for AES Key Wrap is in better shape (thanks to Russ) than the HPKE-based version. Unlike what I presented at the last IETF meeting this document uses HPKE for the public key encryption mechanism. There is code available for HPKE even though it is a fairly recent development in the CFRG. HPKE is used with the TLS ESNI and the MLS work.

I wanted to submit this snapshot for the virtual interim meeting today.

Here is the draft:
https://datatracker.ietf.org/doc/html/draft-tschofenig-suit-firmware-encryption

Ciao
Hannes

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.