Hello ACE,

We have recently submitted a new draft "Group OSCORE Profile of the
Authentication and Authorization for Constrained Environments Framework"

https://tools.ietf.org/html/draft-tiloca-ace-group-oscore-profile

The document describes a profile of ACE where client and server can
communicate with OSCORE and Group OSCORE. This supports fine-grained
access control in group communication environments, where different
group members have different access rights to resources of other group
members.

The pairwise OSCORE security context between the client and server is
established in a way similar to the OSCORE profile of ACE, and is
securely bound to the Group OSCORE security context previously obtained
when joining the OSCORE group.

Comments are very welcome!

Best,
/Marco


-------- Forwarded Message --------
Subject:        New Version Notification for
draft-tiloca-ace-group-oscore-profile-00.txt
Date:   Sat, 6 Jul 2019 02:43:36 -0700
From:   [email protected]
To:     Ludwig Seitz <[email protected]>, Marco Tiloca
<[email protected]>, Rikard Hoeglund <[email protected]>, Francesca
Palombini <[email protected]>




A new version of I-D, draft-tiloca-ace-group-oscore-profile-00.txt
has been successfully submitted by Marco Tiloca and posted to the
IETF repository.

Name: draft-tiloca-ace-group-oscore-profile
Revision: 00
Title: Group OSCORE Profile of the Authentication and Authorization for
Constrained Environments Framework
Document date: 2019-07-06
Group: Individual Submission
Pages: 29
URL:
https://www.ietf.org/internet-drafts/draft-tiloca-ace-group-oscore-profile-00.txt
Status:
https://datatracker.ietf.org/doc/draft-tiloca-ace-group-oscore-profile/
Htmlized:
https://tools.ietf.org/html/draft-tiloca-ace-group-oscore-profile-00
Htmlized:
https://datatracker.ietf.org/doc/html/draft-tiloca-ace-group-oscore-profile


Abstract:
This document specifies a profile for the Authentication and
Authorization for Constrained Environments (ACE) framework. The
profile uses Object Security for Constrained RESTful Environments
(OSCORE) and/or Group OSCORE to provide communication security
between a Client and (a group of) Resource Server(s). Furthermore,
the profile uses (Group) OSCORE to provide server authentication, and
OSCORE to achieve proof-of-possession for a key owned by the Client
and bound to an OAuth 2.0 Access Token. Also, the profile provides
proof-of-group-membership for the Client, by securely binding the
pre-established Group OSCORE Security Context to the pairwise OSCORE
Security Context newly established with the Resource Server.



Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Ace mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ace

Reply via email to