Re: [Drip] [Internet]Re: Comments on Re: I-D Action: draft-ietf-drip-arch-16.txt

"shuaiizhao(Shuai Zhao)" <shuaiizhao@tencent.com> Wed, 10 November 2021 21:08 UTC

Return-Path: <shuaiizhao@tencent.com>
X-Original-To: tm-rid@ietfa.amsl.com
Delivered-To: tm-rid@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 972C63A13CB for <tm-rid@ietfa.amsl.com>; Wed, 10 Nov 2021 13:08:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=tencent.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vnnLO-AtRvfF for <tm-rid@ietfa.amsl.com>; Wed, 10 Nov 2021 13:08:19 -0800 (PST)
Received: from mail3.tencent.com (mail3.tencent.com [203.205.248.63]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5F77B3A13BE for <tm-rid@ietf.org>; Wed, 10 Nov 2021 13:08:18 -0800 (PST)
Received: from EX-SZ018.tencent.com (unknown [10.28.6.39]) by mail3.tencent.com (Postfix) with ESMTP id 20B8C94178 for <tm-rid@ietf.org>; Thu, 11 Nov 2021 05:08:15 +0800 (CST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tencent.com; s=s202002; t=1636578495; bh=I6u9F6vAgP0SNYdLXp63wJbrWLeZgwvZylVIPbHEh1A=; h=From:To:Subject:Date:References:In-Reply-To; b=jxx5yETDoOsdmZYx/RiHBfe3W/JRBFeAAWkgnLkMmeqyQesttu2Tb5iKWJ8UnoW6D gDEhMBl6M5sMVrcv/kyIeSdufVYaauRtI7Vb/1V36TXj2+eUgAjvGNJL6OZVh69U7l vkYzhQQo7mO6zjoQH4XezS/VcnRGl7KtaN0Wh3VE=
Received: from EX-US02.tencent.com (10.93.1.208) by EX-SZ018.tencent.com (10.28.6.39) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2242.4; Thu, 11 Nov 2021 05:08:14 +0800
Received: from EX-US01.tencent.com (10.93.1.207) by EX-US02.tencent.com (10.93.1.208) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2242.4; Thu, 11 Nov 2021 05:08:12 +0800
Received: from EX-US01.tencent.com ([fe80::8dc1:248d:475d:7f13]) by EX-US01.tencent.com ([fe80::8dc1:248d:475d:7f13%4]) with mapi id 15.01.2242.008; Thu, 11 Nov 2021 05:08:12 +0800
From: "shuaiizhao(Shuai Zhao)" <shuaiizhao@tencent.com>
To: Robert Moskowitz <rgm@labs.htt-consult.com>, "tm-rid@ietf.org" <tm-rid@ietf.org>
Thread-Topic: [Internet]Re: [Drip] Comments on Re: I-D Action: draft-ietf-drip-arch-16.txt
Thread-Index: AQHXzqAwMnPHZLQTgUW1C5gzGIG1UKv8RJ4A
Date: Wed, 10 Nov 2021 21:08:12 +0000
Message-ID: <6CB22B53-A636-4DDD-994F-DE775BEE0499@tencent.com>
References: <163518948657.6786.15619266169173545208@ietfa.amsl.com> <7a4130bc-97d2-624b-ac86-e91e97b9abdf@labs.htt-consult.com> <2f4a1731-ccf0-ad18-a3cd-d88a146042d7@labs.htt-consult.com>
In-Reply-To: <2f4a1731-ccf0-ad18-a3cd-d88a146042d7@labs.htt-consult.com>
Accept-Language: en-US, zh-CN
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.54.21101001
x-originating-ip: [9.19.161.78]
Content-Type: text/plain; charset="utf-8"
Content-ID: <F3C3373189C4DA488BA04EA334C4A0C7@tencent.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/tm-rid/uYIndOL2fUiO2vPtEItq8-iU6gU>
Subject: Re: [Drip] [Internet]Re: Comments on Re: I-D Action: draft-ietf-drip-arch-16.txt
X-BeenThere: tm-rid@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Drone Remote Identification Protocol <tm-rid.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tm-rid>, <mailto:tm-rid-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tm-rid/>
List-Post: <mailto:tm-rid@ietf.org>
List-Help: <mailto:tm-rid-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tm-rid>, <mailto:tm-rid-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Nov 2021 21:08:25 -0000

Thanks Bob, see reply inline. 

On 10/31/21, 2:42 PM, "Tm-rid on behalf of Robert Moskowitz" <tm-rid-bounces@ietf.org on behalf of rgm@labs.htt-consult.com> wrote:

    Continuing with Sec 5.

    All is good IMO in sec 5.

    Sec 6.

    Para 2:

    Would a reader know what "offline or online" mean?  This is the first 
    and only use of both terms.  So we need to actually define them here.

    Also I do not think Broadcast RID needs to send messages that 
    authenticate all the way to the root.  This is rarely done in other 
    protocols.  Having something signed by the HDA and the HDA's HHIT,HI is 
    necessary, but sufficient along with access to a cache of the rest of 
    the hierarchy.  Similar to web browser CA root cache and DNS root cache.

    so

        An optimization of different DRIP Authentication Messages allows an
        Observer, without Internet connection (offline) or with (online), to be
        able to validate a UAS DRIP ID in real-
        time.  First is the sending of Broadcast Attestations (over
        DRIP Link Authentication Messages) containing the relevant registration
        of the UA's DRIP ID in the claimed Registry.  Next is
        sending DRIP Wrapper Authentication Messages that sign over
        both static (e.g. above registration) and dynamically changing data
        (such as UA location data).  Combining
        these two sets of information an Observer can piece together a chain
        of trust and real-time evidence to make their determination of the
        UAs claims.

Shuai/ Implemented as suggested . Please let me know if anyone has different option. 

    Sec 7

    In 1.3, we used: Surveillance Supplemental Data Service Provider

    We should follow through with that class of SDSP here or drop it in 1.3.

    And in 7.2 perhaps:

        A CS-RID SDSP should appear (i.e. present the same interface) to a
        Net-RID SP as a Net-RID DP.  A CS-RID SDSP aggregates and processes
        (e.g., estimates UA location using including using multilateration when
        possible) information collected by CS-RID Finders.

Shuai/ Implemented as suggested. However, we will update 1.3, so added a reminder in " Editor-note-8: double check above paragraph after editor-note-1 is resolved."

    Sec 8.

    One of the ways in which DRIP can enhance [F3411-19] with


Shuai/ Implemented as suggested

    ============

    And that completes my review.

    Bob


    -- 
    Tm-rid mailing list
    Tm-rid@ietf.org
    https://www.ietf.org/mailman/listinfo/tm-rid