Re: [Teep] Charter Text

"Wheeler, David M" <david.m.wheeler@intel.com> Fri, 22 September 2017 14:26 UTC

Return-Path: <david.m.wheeler@intel.com>
X-Original-To: teep@ietfa.amsl.com
Delivered-To: teep@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A445B134454 for <teep@ietfa.amsl.com>; Fri, 22 Sep 2017 07:26:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.919
X-Spam-Level:
X-Spam-Status: No, score=-6.919 tagged_above=-999 required=5 tests=[AC_DIV_BONANZA=0.001, BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R0OiWikrwkK3 for <teep@ietfa.amsl.com>; Fri, 22 Sep 2017 07:26:53 -0700 (PDT)
Received: from mga01.intel.com (mga01.intel.com [192.55.52.88]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 25BAF134313 for <teep@ietf.org>; Fri, 22 Sep 2017 07:26:53 -0700 (PDT)
Received: from orsmga005.jf.intel.com ([10.7.209.41]) by fmsmga101.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 22 Sep 2017 07:26:52 -0700
X-ExtLoop1: 1
X-IronPort-AV: E=Sophos;i="5.42,427,1500966000"; d="scan'208,217";a="152236019"
Received: from fmsmsx107.amr.corp.intel.com ([10.18.124.205]) by orsmga005.jf.intel.com with ESMTP; 22 Sep 2017 07:26:52 -0700
Received: from fmsmsx114.amr.corp.intel.com (10.18.116.8) by fmsmsx107.amr.corp.intel.com (10.18.124.205) with Microsoft SMTP Server (TLS) id 14.3.319.2; Fri, 22 Sep 2017 07:26:41 -0700
Received: from crsmsx103.amr.corp.intel.com (172.18.63.31) by FMSMSX114.amr.corp.intel.com (10.18.116.8) with Microsoft SMTP Server (TLS) id 14.3.319.2; Fri, 22 Sep 2017 07:26:40 -0700
Received: from crsmsx102.amr.corp.intel.com ([169.254.2.58]) by CRSMSX103.amr.corp.intel.com ([169.254.4.74]) with mapi id 14.03.0319.002; Fri, 22 Sep 2017 08:26:39 -0600
From: "Wheeler, David M" <david.m.wheeler@intel.com>
To: Jeremy O'Donoghue <jodonogh@qti.qualcomm.com>, "Nancy Cam-Winget (ncamwing)" <ncamwing@cisco.com>
CC: "teep@ietf.org" <teep@ietf.org>
Thread-Topic: [Teep] Charter Text
Thread-Index: AQHTAThspOOzQmirT2iZHvEI0ch6jqJcdntwgFVjmoD///O1Z4AOzTRbgACDgACAADU3AIAABZKw
Date: Fri, 22 Sep 2017 14:26:38 +0000
Message-ID: <0627F5240443D2498FAA65332EE46C8436743A75@CRSMSX102.amr.corp.intel.com>
References: <6EFD27BC-CE56-4112-AD20-C787520BEE87@cisco.com> <DM5PR20MB1228DEC9757FCBDCA4254052AAA70@DM5PR20MB1228.namprd20.prod.outlook.com> <d6015c71-04de-3323-bb08-5ac66a5c21d0@mixmax.com> <35502548-8d02-4af2-b409-d8be73dd6a6d.max.ldp@alibaba-inc.com> <CAKcc6AdZV7HsUvTiKnSP7dXf9Q4PMfBmNyWnwMLnGF6re3aKAQ@mail.gmail.com> <201709221010555677461@bjleisen.com> <06E2371B-CD39-4205-B663-FF8C0AD300A6@cisco.com> <6573BB65-A7AD-4CF2-996D-A0C64B8BD8B8@qti.qualcomm.com>
In-Reply-To: <6573BB65-A7AD-4CF2-996D-A0C64B8BD8B8@qti.qualcomm.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-titus-metadata-40: eyJDYXRlZ29yeUxhYmVscyI6IiIsIk1ldGFkYXRhIjp7Im5zIjoiaHR0cDpcL1wvd3d3LnRpdHVzLmNvbVwvbnNcL0ludGVsMyIsImlkIjoiMDU0MGYxN2ItMThmNy00MDkxLWJlYzAtZGY2NmMzNDNjODBhIiwicHJvcHMiOlt7Im4iOiJDVFBDbGFzc2lmaWNhdGlvbiIsInZhbHMiOlt7InZhbHVlIjoiQ1RQX0lDIn1dfV19LCJTdWJqZWN0TGFiZWxzIjpbXSwiVE1DVmVyc2lvbiI6IjE2LjUuOS4zIiwiVHJ1c3RlZExhYmVsSGFzaCI6Ik1tR1RaWXJXNVlpVDYyNzhNbU8xSTBEN1dBM3FoOUVBUWxsSzJFMVZXM2s9In0=
x-ctpclassification: CTP_IC
dlp-product: dlpe-windows
dlp-version: 11.0.0.116
dlp-reaction: no-action
x-originating-ip: [172.18.205.10]
Content-Type: multipart/alternative; boundary="_000_0627F5240443D2498FAA65332EE46C8436743A75CRSMSX102amrcor_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/teep/A-xP4zOA0BejshUcgH4N6sOpif0>
Subject: Re: [Teep] Charter Text
X-BeenThere: teep@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: A Protocol for Dynamic Trusted Execution Environment Enablement <teep.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/teep>, <mailto:teep-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/teep/>
List-Post: <mailto:teep@ietf.org>
List-Help: <mailto:teep-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/teep>, <mailto:teep-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Sep 2017 14:26:58 -0000

Jeremy,
I understand your perspective and concern (I think, but would like to hear more). From Intel’s side, we have some issues with “too close” relationship to GP, because GP’s definition of TEE security ties that security to trusted boot. I understand that TZ, and even some of Intel’s TEEs (Android Trusty implementation) require a trusted secure boot in order to themselves be secure, but Intel also has TEEs that are *completely separated* from secure boot, and therefore do not require a secure booted platform to retain security.

Too close a relationship to GP will create issues around this definition. We need greater discussion around this, otherwise, by definition it rejects certain Intel TEEs (SGX primarily) and then Intel would consider this an implementation specific definition aligned to TrustZone, and not a general TEE protocol.

I think we need to talk more about this. I agree there is a lot of good stuff in GP that we should leverage.

Are you open to changing some of these core definitions, and working through the implications of those changes with us? This will separate us somewhat form GP standards, I think.

Very interested in your thoughts and perspective.
Thanks,
Dave Wheeler

From: TEEP [mailto:teep-bounces@ietf.org] On Behalf Of Jeremy O'Donoghue
Sent: Friday, September 22, 2017 1:00 AM
To: Nancy Cam-Winget (ncamwing) <ncamwing@cisco.com>
Cc: teep@ietf.org
Subject: Re: [Teep] Charter Text

Qualcomm would like to ensure that the charter and proposed deliverables are properly differentiated from work occurring in GlobalPlatform based on the OTrP contribution which has been accepted as a GlobalPlatform work item.

Since the proposed charter for teep includes a close relationship with GlobalPlatform, Qualcomm suggests some alignment between the organisations to ensure that there is a single, definitive, set of standards defining OTrP as the best outcome for all participants.

---
Jeremy O’Donoghue                            email: jodonogh@qti.qualcomm.com<mailto:jodonogh@qti.qualcomm.com>
Engineer, Principal/Manager                  tel:   +44 1252 363189
NFC & Secure Software and Systems




On 22 Sep 2017, at 05:49, Nancy Cam-Winget (ncamwing) <ncamwing@cisco.com<mailto:ncamwing@cisco.com>> wrote:

Thank you all for responding  and for demonstrating there is good support to move this work along.

It would be good to get discussions started on the current drafts and milestones as well.

                Nancy

From: TEEP <teep-bounces@ietf.org<mailto:teep-bounces@ietf.org>> on behalf of "zhoup@bjleisen.com<mailto:zhoup@bjleisen.com>" <zhoup@bjleisen.com<mailto:zhoup@bjleisen.com>>
Date: Thursday, September 21, 2017 at 7:10 PM
To: Dapeng Liu <maxpassion@gmail.com<mailto:maxpassion@gmail.com>>, Lubna Dajani <lubnadajani@gmail.com<mailto:lubnadajani@gmail.com>>, "ppeterka@verimatrix.com<mailto:ppeterka@verimatrix.com>" <ppeterka@verimatrix.com<mailto:ppeterka@verimatrix.com>>, teep-bounces <teep-bounces@ietf.org<mailto:teep-bounces@ietf.org>>, teep <teep@ietf.org<mailto:teep@ietf.org>>, Mingliang Pei <Mingliang_Pei@symantec.com<mailto:Mingliang_Pei@symantec.com>>, "Marc.Canel" <Marc.Canel@arm.com<mailto:Marc.Canel@arm.com>>, Richard Parris <richard.parris@intercede.com<mailto:richard.parris@intercede.com>>, Rob Coombs <rob.coombs@arm.com<mailto:rob.coombs@arm.com>>, "qingyang.meng" <qingyang.meng@beanpodtech.com<mailto:qingyang.meng@beanpodtech.com>>, Brian Witten <brian_witten@symantec.com<mailto:brian_witten@symantec.com>>, "henry.j.lee@samsung.com<mailto:henry.j.lee@samsung.com>" <henry.j.lee@samsung.com<mailto:henry.j.lee@samsung.com>>, Nick Cook <Nick.Cook@intercede.com<mailto:Nick.Cook@intercede.com>>, "Mike.M.Parsel@sprint.com<mailto:Mike.M.Parsel@sprint.com>" <Mike.M.Parsel@sprint.com<mailto:Mike.M.Parsel@sprint.com>>, Hannes Tschofenig <hannes.tschofenig@arm.com<mailto:hannes.tschofenig@arm.com>>, "zhijian.zhang" <zhijian.zhang@beanpodtech.com<mailto:zhijian.zhang@beanpodtech.com>>, 魏茂军<maojun.wei@watchdata.com<mailto:maojun.wei@watchdata.com>>, Dominique Bolignano <dominique.bolignano@provenrun.com<mailto:dominique.bolignano@provenrun.com>>, "heekwan.lee@samsung.com<mailto:heekwan.lee@samsung.com>" <heekwan.lee@samsung.com<mailto:heekwan.lee@samsung.com>>, Mike Hendrick <mike.hendrick@seqlabs.com<mailto:mike.hendrick@seqlabs.com>>, XiaYubin <xiayubin@trustkernel.com<mailto:xiayubin@trustkernel.com>>, "sangjin.park@hansol.com<mailto:sangjin.park@hansol.com>" <sangjin.park@hansol.com<mailto:sangjin.park@hansol.com>>, "Paczkowski, Lyle W [CTO]" <lyle.w.paczkowski@sprint.com<mailto:lyle.w.paczkowski@sprint.com>>, Pengcheng Zou <zoupc@thundersoft.com<mailto:zoupc@thundersoft.com>>, "fmw@whty.com.cn<mailto:fmw@whty.com.cn>" <fmw@whty.com.cn<mailto:fmw@whty.com.cn>>, "philip.attfield" <philip.attfield@seqlabs.com<mailto:philip.attfield@seqlabs.com>>, "Andrew.Atyeo" <Andrew.Atyeo@intercede.com<mailto:Andrew.Atyeo@intercede.com>>, paromix <paromix@sola-cia.com<mailto:paromix@sola-cia.com>>, ppeterkaa <ppeterkaa@verimatrix.com<mailto:ppeterkaa@verimatrix.com>>, "max.ldp@alibaba-inc.com<mailto:max.ldp@alibaba-inc.com>" <max.ldp@alibaba-inc.com<mailto:max.ldp@alibaba-inc.com>>
Subject: Re: [Teep] Charter Text

hi,

 Beijing Laser Tech. support it.thanks.

________________________________
周鹏
CEO
北京雷森科技发展有限公司
Beijing Laser Technology Development CO.,LTD
地址:西直门北大街甲43号金运大厦7层  邮编100044
手机:18910750012/15601105750/13911779990
网址:www.bjleisen.c<http://www.opentsm.cn/>om

From: Dapeng Liu<mailto:maxpassion@gmail.com>
Date: 2017-09-13 00:49
To: Lubna Dajani<mailto:lubnadajani@gmail.com>; ppeterka<mailto:ppeterka@verimatrix.com>; teep-bounces<mailto:teep-bounces@ietf.org>; teep<mailto:teep@ietf.org>; Mingliang Pei<mailto:Mingliang_Pei@symantec.com>; Marc Canel<mailto:Marc.Canel@arm.com>; richard.parris@intercede.com<mailto:richard.parris@intercede.com>; Rob Coombs<mailto:rob.coombs@arm.com>; qingyang.meng<mailto:qingyang.meng@beanpodtech.com>; brian_witten<mailto:brian_witten@symantec.com>; henry.j.lee@samsung.com<mailto:henry.j.lee@samsung.com>; Nick Cook<mailto:Nick.Cook@intercede.com>; Mike.M.Parsel@sprint.com<mailto:Mike.M.Parsel@sprint.com>; Hannes Tschofenig<mailto:hannes.tschofenig@arm.com>; zhijian.zhang<mailto:zhijian.zhang@beanpodtech.com>; zhoup<mailto:zhoup@bjleisen.com>; maojun.wei<mailto:maojun.wei@watchdata.com>; dominique.bolignano<mailto:dominique.bolignano@provenrun.com>; heekwan.lee@samsung.com<mailto:heekwan.lee@samsung.com>; mike.hendrick@seqlabs.com<mailto:mike.hendrick@seqlabs.com>; xiayubin<mailto:xiayubin@trustkernel.com>; sangjin.park<mailto:sangjin.park@hansol.com>; lyle.w.paczkowski<mailto:lyle.w.paczkowski@sprint.com>; Pengcheng Zou<mailto:zoupc@thundersoft.com>; fmw<mailto:fmw@whty.com.cn>; philip.attfield<mailto:philip.attfield@seqlabs.com>; Andrew.Atyeo<mailto:Andrew.Atyeo@intercede.com>; paromix<mailto:paromix@sola-cia.com>; ppeterkaa<mailto:ppeterkaa@verimatrix.com>; 成 鹏<mailto:max.ldp@alibaba-inc.com>
Subject: re: [Teep] Charter Text
Hello Nancy,

Thanks!

Actually, there are lots of companies/experts are very interested in the proposed TEEP work. But they may not familiar with IETF process, I hope they would getting more active in the list after the long
summer vacation:)

Note: I have copied to all the experts that are interested in TEEP based on offline discussions.
To all the experts copied in this mail: Please subscribe to TEEP email list first if you want to reply.   Here is how to subscribe: https://www.ietf.org/mailman/listinfo/teep

Thanks,
Max
------------------------------------------------------------------
From:Nancy Cam-Winget (ncamwing) <ncamwing@cisco.com<mailto:ncamwing@cisco.com>>
Send Time:2017年9月12日(星期二) 23:50
To:Lubna Dajani <lubnadajani@gmail.com<mailto:lubnadajani@gmail.com>>; Petr Peterka <ppeterka@verimatrix.com<mailto:ppeterka@verimatrix.com>>
Cc:teep@ietf.org<mailto:Cc%3Ateep@ietf.org> <teep@ietf.org<mailto:teep@ietf.org>>
Subject:Re: [Teep] Charter Text

Thank you Lubna and Petr!

Would still like to hear from others and also solicit feedback on the proposed charter text.

Warm regards,
                Nancy

From: Lubna Dajani <lubnadajani@gmail.com<mailto:lubnadajani@gmail.com>>

Date: Tuesday, September 12, 2017 at 4:40 AM
To: Petr Peterka <ppeterka@verimatrix.com<mailto:ppeterka@verimatrix.com>>
Cc: "ncamwing@cisco.com<mailto:ncamwing@cisco.com>" <ncamwing@cisco.com<mailto:ncamwing@cisco.com>>, "teep@ietf.org<mailto:teep@ietf.org>" <teep@ietf.org<mailto:teep@ietf.org>>

Subject: Re: [Teep] Charter Text

please allow me to echo Petr's responses.
1. Yes
2. Yes
3. Yes
4. Yes
 I am personally very excited to see this WG form and I look forward to actively contributing to the evolution of this protocol as I have since the ideation stages of this protocol …

Thank you Nancy, Petr and everyone here…

Lubna
__________________________________________________
Lubna Dajani  I  Allternet Ltd.
@lubnadajani
@futuristasORG
+ 1 201 982 0934<tel:(201)%20982-0934>


Confidentiality Notice: The information contained in this email and any attachments is intended only for the recipient[s] listed above and may be privileged and confidential. Any dissemination, copying, or use of or reliance upon such information by or to anyone other than the recipient[s] listed above is prohibited. If you have received this message in error, please notify the sender immediately at the email address above and destroy any and all copies of this message.

Sent with Mixmax<https://mixmax.com/s/Sjmasx74wNoX3uu2B?utm_source=mixmax&utm_medium=email&utm_campaign=signature_link&utm_content=sent_with_mixmax>


On Thu, Jul 20, 2017 2:48 AM, Petr Peterka ppeterka@verimatrix.com<mailto:ppeterka@verimatrix.com> wrote:
Hi Nancy
I think we had a very productive meeting yesterday. Here are my answers to your questions:

1) Do you understand what TEEP is trying to achieve?
ANSWER: Yes, I do. I’d like to add that the charter may re-emphasize that the proposed WG is not going to define the TEE or the TAM service themselves but just the protocol between them.

2) Is this work that should be done in general?
ANSWER: Yes, it should since there are going to be more and more trusted execution environments (lower case) especially with the proliferation of IoT devices which will need more security than what they have today.

3) Is this work that should be done in the IETF, or does it belong to somewhere else?
ANSWER: Since we are trying to define a protocol that is independent of the different TEE implementations, I believe that IETF is the right home for it.

4) Should we form a WG with given charter to work on this?
ANSWER: Yes, that is my recommendation.

Thanks
          Petr
 <x-msg://13/#m_4019887533134155472_this>
From: TEEP [mailto:teep-bounces@ietf.org<mailto:teep-bounces@ietf.org>] On Behalf Of Nancy Cam-Winget (ncamwing)
Sent: Thursday, July 20, 2017 11:13 AM
To: teep@ietf.org<mailto:teep@ietf.org>
Subject: Re: [Teep] Charter Text

All,
Please provide feedback on the results of yesterday’s side meeting.  In particular, we’d like to get feedback on whether this the right scope and if we have captured it appropriately. If it is not, also please comment and if possible, provide suggestions for improvement.

We would like to continue discussion over email and get consensus around the 2nd week of September so that we can have a path forward.  In particular we would like to get answers for:

1) Do you understand what TEEP is trying to achieve?
2) Is this work that should be done in general?
3) Is this work that should be done in the IETF, or does it belong to somewhere else?
4) Should we form a WG with given charter to work on this?

Warm regards,
    Nancy & Tero (TEEP BoF Chairs)

From: TEEP <teep-bounces@ietf.org<mailto:teep-bounces@ietf.org>> on behalf of Hannes Tschofenig <Hannes.Tschofenig@arm.com<mailto:Hannes.Tschofenig@arm.com>>
Date: Wednesday, July 19, 2017 at 5:56 AM
To: "teep@ietf.org<mailto:teep@ietf.org>" <teep@ietf.org<mailto:teep@ietf.org>>
Subject: [Teep] Charter Text

Here is the charter text we came up in the side-meeting today.

------



TEEP -- A Protocol for Dynamic Trusted Execution Environment Enablement Charter

The Trusted Execution Environment (TEE) is a secure area of a processor. The TEE provides security features, such as isolated execution, integrity of Trusted Applications along with confidentiality of their assets. In general terms, the TEE offers an execution space that provides a higher level of security than a "rich" operating system and more functionality than a secure element. For example, implementations of the TEE concept have been developed by ARM, and Intel using the TrustZone and the SGX technology, respectively.

To programmatically install, update, and delete applications running in the TEE, this protocol runs between a service running within the TEE, a relay application or service access point on the device's network stack and a server-side infrastructure that interacts with and optionally maintains the applications. Some tasks are security sensitive and the server side requires information about the device characteristics in form of attestation and the device-side may require information about the server.

Privacy considerations have to be taken into account with authentication features and attestation.

This working group aims to develop an application layer protocol providing TEEs with the following functionality,
* lifecycle management of trusted applications, and
* security domain management.

A security domain allows a service provider's applications to be isolated so that one security domain cannot be influenced by another, unless it exposes an API to allow it.

The solution approach must take a wide range of TEE and relevant technologies into account and will focus on the use of public key cryptography.

The group will produce the following deliverables. First, an architecture document describing the involved entities, their relationships, assumptions, the keying framework and relevant use cases. Second, a solution document that describes the above-described functionality. The choice of encoding format(s) will be decided in the working group. The group may document several attestation technologies considering the different hardware capabilities, performance, privacy and operational properties.

The group will maintain a close relationship with the GlobalPlatform, Trusted Computing Group,  and other relevant standards to ensure proper use of existing TEE-relevant application layer interfaces.

Milestones

Dec 2017     Submit "TEEP Architecture" document as WG item.

Feb 2018     Submit "TEEP Protocol" document as WG item.

July 2018     Submit "TEEP Architecture" to the IESG for publication as an Informational RFC.

Feb 2019     Submit "TEEP Protocol" to the IESG for publication as a Proposed Standard.

Additional calendar items:

Nov 2017     IETF #100 Hackathon to work on TEEP protocol prototype implementations.

Mar 2018     1st interoperability event (at IETF #101).

Jul 2018       2nd interoperability event (at IETF #102).

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.




_______________________________________________
TEEP mailing list
TEEP@ietf.org<mailto:TEEP@ietf.org>
https://www.ietf.org/mailman/listinfo/teep