Hi,

I owed you a more detailed analysis of the implications I discussed during the 
call on security and trust implications in ALTO. First of all, my apologies for 
the delay, justified by the overload of this period. I have finally found some 
time, now that I am trying to focus on the coming IETF meeting, and therefore I 
am sharing with you my reflections.

When talking about security and trust in a network capability exposure protocol 
like ALTO, I believe we have to consider four different dimensions:


  *   The security of the transport protocol (typically, TLS, though we could 
even think of other potential encapsulations and consider IPsec, SSH…),  
focused on the specific profiles and requirements for this protocol. That would 
include cyphersuites, requirements for (mutual) authentication, certificate 
profiles, etc.
Another aspect to take into account is how parameters derived from the secure 
transport (think of the identities in the certificates) can be forwarded to the 
application relying on ALTO for making its decisions.
  *   The security of the transferred data itself, associated to data 
serialization. Given the nature of ALTO, the use of mechanisms for signing (and 
even encrypting) JSON would be the obvious choice, though it would be 
interesting to analyze the options at hand, to avoid reinventing a full 
secure-ALTO protocol, and maximize flexibility while addressing relevant use 
cases for securing ALTO statements.
  *   The provenance of the data, in order to properly record the origin and 
history of the data being exposed using ALTO. This includes the different data 
sources aggregated by the ALTO server and the possible re-use of stored or 
post-processed ALTO statements. I have submitted a proposal on YANG provenance 
() that could be applicable here.

  *   The expression of security properties (and trust assessment. Note the 
difference) as ALTO metrics. This would require an extension to the protocol, 
of a nature similar to the ones being discussed for other aspects like energy 
consumption.

If you find this discussion interesting enough, I’d be more than happy to make 
an introduction to these matters, with the idea of exploring the WG interest on 
the different aspects, at the coming IETF 117, time permitting…

Be goode,



--
“Esta vez no fallaremos, Doctor Infierno”

Dr Diego R. Lopez
Telefonica I+D
https://www.linkedin.com/dr2lopez/

e-mail: diego.r.lo...@telefonica.com<mailto:diego.r.lo...@telefonica.com>
Mobile: +34 682 051 091
---------------------------------


________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su destinatario, puede 
contener información privilegiada o confidencial y es para uso exclusivo de la 
persona o entidad de destino. Si no es usted. el destinatario indicado, queda 
notificado de que la lectura, utilización, divulgación y/o copia sin 
autorización puede estar prohibida en virtud de la legislación vigente. Si ha 
recibido este mensaje por error, le rogamos que nos lo comunique inmediatamente 
por esta misma vía y proceda a su destrucción.

The information contained in this transmission is confidential and privileged 
information intended only for the use of the individual or entity named above. 
If the reader of this message is not the intended recipient, you are hereby 
notified that any dissemination, distribution or copying of this communication 
is strictly prohibited. If you have received this transmission in error, do not 
read it. Please immediately reply to the sender that you have received this 
communication in error and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu destinatário, pode 
conter informação privilegiada ou confidencial e é para uso exclusivo da pessoa 
ou entidade de destino. Se não é vossa senhoria o destinatário indicado, fica 
notificado de que a leitura, utilização, divulgação e/ou cópia sem autorização 
pode estar proibida em virtude da legislação vigente. Se recebeu esta mensagem 
por erro, rogamos-lhe que nos o comunique imediatamente por esta mesma via e 
proceda a sua destruição
________________________________

Le informamos de que el responsable del tratamiento de sus datos es la entidad 
del Grupo Telefónica vinculada al remitente, con la finalidad de mantener el 
contacto profesional y gestionar la relación establecida con el destinatario o 
con la entidad a la que está vinculado. Puede contactar con el responsable del 
tratamiento y ejercitar sus derechos escribiendo a 
privacidad....@telefonica.com<mailto:privacidad....@telefonica.com>. Puede 
consultar información adicional sobre el tratamiento de sus datos en nuestra 
Política de 
Privacidad<https://www.telefonica.com/es/telefonica-politica-de-privacidad-de-terceros/>.

We inform you that the data controller is the Telefónica Group entity linked to 
the sender, for the purpose of maintaining professional contact and managing 
the relationship established with the recipient or with the entity to which it 
is linked. You may contact the data controller and exercise your rights by 
writing to privacidad....@telefonica.com<mailto:privacidad....@telefonica.com>. 
You may consult additional information on the processing of your data in our 
Privacy 
Policy<https://www.telefonica.com/en/wp-content/uploads/sites/5/2022/12/Telefonica-Third-data-subjects-Privacy-Policy.pdf>.

Informamos que o responsável pelo tratamento dos seus dados é a entidade do 
Grupo Telefónica vinculada ao remetente, a fim de manter o contato professional 
e administrar a relação estabelecida com o destinatário ou com a entidade à 
qual esteja vinculado. Você pode entrar em contato com o responsável do 
tratamento de dados e exercer os seus direitos escrevendo a 
privacidad....@telefonica.com<mailto:privacidad....@telefonica.com>. Você pode 
consultar informação adicional sobre o tratamento do seus dados na nossa 
Política de 
Privacidade<https://www.telefonica.com/es/politica-de-privacidade-de-terceiros/>.
_______________________________________________
alto mailing list
alto@ietf.org
https://www.ietf.org/mailman/listinfo/alto

Reply via email to