[ZTCPP] Re: Draft Review

Benfeng Chen <benfeng@gmail.com> Mon, 06 July 2026 04:52 UTC

Return-Path: <benfeng@gmail.com>
X-Original-To: ztcpp@mail2.ietf.org
Delivered-To: ztcpp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 58BCA10F993A4 for <ztcpp@mail2.ietf.org>; Sun, 5 Jul 2026 21:52:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783313569; bh=NciKMr/XukoxyF9CcmqQJ3jttO3ZUWKmN0NfWj5BI8M=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=UlpVnuYtH89+1nt4YTSFfq9gMBs4m4LlHpiojDruvA7jwb73KkJyQ0cqAUnUokJ+S y4emGvTFBCN/ynXkPRTF51E/sVdwtVRTmPIriURn3gJE/y98JlOUU9UP/Qn4+ci8aj CsOtFOqc7VjMU0vGGZNyS80OgMU2BrBKdfcH7skw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id spz4auSpqlvH for <ztcpp@mail2.ietf.org>; Sun, 5 Jul 2026 21:52:48 -0700 (PDT)
Received: from mail-ed1-x52d.google.com (mail-ed1-x52d.google.com [IPv6:2a00:1450:4864:20::52d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4E1C310F9929D for <ztcpp@ietf.org>; Sun, 5 Jul 2026 21:51:49 -0700 (PDT)
Received: by mail-ed1-x52d.google.com with SMTP id 4fb4d7f45d1cf-698a9f11776so3441260a12.1 for <ztcpp@ietf.org>; Sun, 05 Jul 2026 21:51:49 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1783313508; cv=none; d=google.com; s=arc-20260327; b=oYW728MdFvMabHxO4dPbnddNSrXpix7fikz5DECCsICGd7BXfTtM6nN3Oe+iydTZLc /ph8DhjvEF8efImD5nDY0qCpokaDAvUXtH99K405ZLjMjT73jXRXnDj9uxZjKnbA4LZt OclIOKcesJlFxbviJ8vuhiFbpG1G6nkFiZsikX0k6MLagTql41SsoBpChaQpvyhwXeDm 0LzbU542lGIRHmtT2rSJ8yqubngD/adgx7TvN04XihNE/hdtoYeLIcGmHtUpC8HftAx5 yGBvZBag5ggcpozIvR2RazqNb3PhYmo/4LLhvf7o4BE7uzc8o9HKaWJzmZiF2kHan5z5 lbCQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=QmXMhREl2WOySFGq7LCmAE8uDq7zQHsz3coD8u4MRHw=; fh=er3W12aVpTmeuJ8u4b62cncczSDIn5dJQGTHaq76fsU=; b=KBNyM2HElYA4cbciFOya8cwY/+TeS8L/ZiE3yUb6RnsOnQdYT5VxaCjQvQDG6yF9pG 5pLbDNHLChxmHAfL/PisjTMSVKJF0qEkp+qlxIQ6OrHaJe1PLEwdLPxULwBcY9mzbnoz GD0OmlGyCBtta+qwJUKGa/wM0P1BeEcaXhnoW4hS7SPlQ6dMos+hq668fgY+zBz7/9lK aRmMYNzQl20h83hHWjAshNrvNHq+nKXRlkIVyncPsRQ09Ng1RMqHHIMXuKIuXktGacOB BbMdd6hqtiHnyz+AgoGJsRFOhRp/buPBa04atwtylrp+09VxvWQgFmgleY5oZiIRb5pR wSGA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783313508; x=1783918308; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=QmXMhREl2WOySFGq7LCmAE8uDq7zQHsz3coD8u4MRHw=; b=MLF1E4BoOBnZ2a94UkrMk1nKlNt9HUndA0bRoil6A7zI1WTy+GgVGU+zHZ3ninMuJm SW52mB1Xa1GSULwzbYlOKF4TRvAXRM/fZuJyHbf72wDVqVGY9C0CuvaqNmYpj+o2ukHJ gKmJxFjk0YP9h7V9Mu1oflLlGEDTiqewFNr0wZqgrD+LH7KWyGkGM40r5lSHVow+Ude8 zOK1JX0Q/5eh+3JhTWnFUuQm7zwncmKPplO8mbGCVbu4vrwOvqifdLeFqvU64fd5sdLq /oDN+R6taDG6qUI+8MZZtXTGID9I//l7jJNSlvZjdr50N3cWwLsTHOs5jBG04buQoVlN vHqQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783313508; x=1783918308; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=QmXMhREl2WOySFGq7LCmAE8uDq7zQHsz3coD8u4MRHw=; b=c6xkoxBVXQLfduDwlRN1aiQyZM7eGsjPj7n6+jXTgb7112t/5xvhFOJjIZOjzJAOqh SI/UBByKsiqfAt9y6JHG1wjmXP/VX50jfpp1/gROwqSKqYVmIxeUbwPaezTUaN0N6cN9 UjFTVaNlcsXjM5aQiACmP/ONGTmFkgfArgiPqtYdTAlyjEtFKMZsI+xt6VJxuGlrIXlZ 4GWxMRFd3J0JvUVcEc13pECw7Kthw9FYAcjvjuF/kZ7m9oP11A7BcuRrZZoDnlm14aG8 T3iP4iegn5LXBmlcGTfqDBIiS18iVcD9y8EWoQA4Nx6yshRmhoVkl+vrg4kVmsIddgyf 7UQg==
X-Forwarded-Encrypted: i=1; AHgh+Ro9l1GsapbgwrInQw9sigkXhxk2XZbcMuegobK9c+G5z52ttpywKG/ZAMlxLPddcs0AcSBL3A==@ietf.org
X-Gm-Message-State: AOJu0Ywfr7fqeBTR6kobdC+FGV/ZO/o+27KZF0m1BQhDHeaPWoCbAEaG 442FQYPejNVGrYldVTa1VAjf5gYstncB857xkheEmUIjDVwWUOGa66JdkR0lGWHCAP6yQ+CDmN3 /NQhWER6dA2DcCLF8q5ZusOYvFzMjqI8Zt/32NQI=
X-Gm-Gg: AfdE7clsJDy7W8+nu1bJ4vl0rN5jBeJSNZWRVNdtACQOQ3ApKv2cPEL1uAhqY1ev4ys yvgFkKw/OQmlK43EBzZxic4HieyASF4YSi2iPBmpvmxtD8Bvvbj7lujX/vm2ngIgCrDQV6K+L7w kaIs4wHhGjHPphPv8JlgXipQunoycoy/f8o0Co2w9a/uGaLmhLOXm81LD7jm8/cYa/R1hxN9BSh uyJfsbIlxLtCbqXfuXZHJW4rO5i4slFbdu/86ZUjjPT80ETFFY9Lh3Ypsk300Er8rTp/eU=
X-Received: by 2002:a05:6402:13ce:b0:698:aea2:260a with SMTP id 4fb4d7f45d1cf-69a1a2a8a23mr2890657a12.25.1783313507888; Sun, 05 Jul 2026 21:51:47 -0700 (PDT)
MIME-Version: 1.0
References: <AS8PR04MB8344F8915A38C39EF11A4C2BE3F42@AS8PR04MB8344.eurprd04.prod.outlook.com> <CAJuQJ1Ew4u2sJHgkHnxKiJVAB8pzbQmXOqmELfxbzK2EMaHJZQ@mail.gmail.com>
In-Reply-To: <CAJuQJ1Ew4u2sJHgkHnxKiJVAB8pzbQmXOqmELfxbzK2EMaHJZQ@mail.gmail.com>
From: Benfeng Chen <benfeng@gmail.com>
Date: Sun, 05 Jul 2026 21:51:36 -0700
X-Gm-Features: AVVi8CexJZXkKB7O_qBPpERsbb8TUasgsDryzY1_12fOZWFWdp6Dw3hD3mdIjtw
Message-ID: <CAPSJW7DTUqoeA12OkpeALc0FC_UKr_HKr=SbhZXyvvknA--7+w@mail.gmail.com>
To: Philip Griffiths <philipleonardgriffiths@gmail.com>
Message-ID-Hash: WOLOYVEEFR3VCJUFWSHTBK4YZTBP5TWG
X-Message-ID-Hash: WOLOYVEEFR3VCJUFWSHTBK4YZTBP5TWG
X-MailFrom: benfeng@gmail.com
X-Mailman-Rule-Hits: member-moderation
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address
Content-Transfer-Encoding: base64
Content-Type: text/plain; charset="UTF-8"
X-Content-Filtered-By: Mailman/MimeDel 3.3.9rc6
CC: Houda CHIHI <houda.chihi@supcom.tn>, "ztcpp@ietf.org" <ztcpp@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [ZTCPP] Re: Draft Review
List-Id: Zero Trust Control and Policy Protocol <ztcpp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ztcpp/cdojxucs1daplnenPPOGiUdDvdQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ztcpp>
List-Help: <mailto:ztcpp-request@ietf.org?subject=help>
List-Owner: <mailto:ztcpp-owner@ietf.org>
List-Post: <mailto:ztcpp@ietf.org>
List-Subscribe: <mailto:ztcpp-join@ietf.org>
List-Unsubscribe: <mailto:ztcpp-leave@ietf.org>

Hi Houda,

Thank you for sharing this interesting work. I appreciate the effort that
went into extending the Network Hiding Protocol (NHP) concepts to 5G/6G
Service-Based Architectures and exploring how authenticate-before-connect
principles can be applied to autonomous telecom environments.

The ideas around intent-based authorization, pre-connection authentication,
and exposure control are very much aligned with the broader direction of
Zero Trust networking and with ongoing work around NHP. We would be happy
to explore how some of these concepts could be incorporated into the
evolving NHP standards and specifications, particularly for telecom and
service-based architecture deployment profiles.

I also appreciate Philip’s comments regarding the importance of focusing on
interoperability surfaces rather than assuming a single Zero Trust
implementation model. From my perspective, the NHP-SBA work could provide
valuable input to discussions around:

   - PEP capability registration and discovery;
   - Controller-to-PEP policy distribution, update, and revocation;
   - Pre-connection authorization and exposure control;
   - Binding policy decisions to authenticated sessions, flows, and
   channels;
   - Enforcement telemetry, auditing, and reporting.

One question I had while reading the draft: do you currently have an
open-source implementation or prototype of the proposed NHP-SBA
architecture? As you know, the IETF has a strong tradition of “rough
consensus and running code,” and implementation experience would be
extremely valuable for evaluating the proposed mechanisms.

If you already have an implementation, we would be very interested in
learning more about it. We would also welcome contributions to the OpenNHP
open-source project (https://github.com/OpenNHP/opennhp) which already
provides an open implementation of NHP and related Zero Trust networking
components. Integrating or demonstrating the NHP-SBA extensions within the
OpenNHP ecosystem could provide a practical way for the community to
evaluate and validate these concepts in 5G/6G and service-based network
environments.

I believe this would also help demonstrate how NHP-based
authenticate-before-connect mechanisms can interoperate with broader Zero
Trust policy enforcement frameworks currently being discussed within ZTCPP.

Thank you again for sharing this work, and I look forward to further
discussions.

Best regards,

Benfeng Chen

On Sun, Jul 5, 2026 at 10:38 AM Philip Griffiths <
philipleonardgriffiths@gmail.com> wrote:

> Hi Houda,
>
> Thank you for sharing this draft.
>
> I think this is useful input for the ZTCPP discussion, particularly around
> authenticated-before-connect, resource hiding, and possible 5G/6G
> deployment profiles.
>
> Given the recent feedback from SAAG/ADs, I think we should be careful not
> to frame any one mechanism as the assumed solution for ZTCPP. The narrower
> direction we are discussing is *Policy Enforcement Point interoperability*:
> how heterogeneous PEPs register capabilities, receive policy lifecycle
> updates, enforce pre-connection authorization, bind policy decisions to
> sessions/flows/channels, and report enforcement outcomes.
>
> In that framing, NHP/NHP-SBA could be a useful candidate implementation or
> profile to map against the requirements, especially for the pre-connection
> authorization / exposure-control seam. It would be helpful if the draft
> could also show how it maps to the broader PEP interoperability surfaces:
> controller-to-PEP lifecycle, policy update/revocation, session/flow
> binding, and enforcement reporting.
>
> This could be a good topic for the proposed IETF 126 side meeting,
> alongside other prototype and implementation inputs.
>
> Best regards,
> Philip
>
>
> On Fri, 3 Jul 2026 at 07:04, Houda CHIHI <houda.chihi@supcom.tn> wrote:
>
> > Dear All,
> >
> > Hope that you are doing well, kindly the submitted draft entitled :
> > Network Hiding Protocol (NHP) Extensions for 5G/6G Service-Based
> > Architectures
> > https://datatracker.ietf.org/doc/draft-alsahati-nhp-sba-nhp-protocol/
> >
> > For Review and comments !
> >
> >
> > Good Day !
> > ZTCPP mailing list
> > To subscribe or manage your subscription:
> > https://mailman3.ietf.org/mailman3/lists/ztcpp.ietf.org/
> >
> ZTCPP mailing list
> To subscribe or manage your subscription:
> https://mailman3.ietf.org/mailman3/lists/ztcpp.ietf.org/
>