> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:muscle-
> [EMAIL PROTECTED] On Behalf Of Scott Guthery
> Sent: Tuesday, April 12, 2005 9:30 AM
> To: MUSCLE
> Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED]
> Subject: RE: [Muscle] NIST Services
> 
> Anders:
> 
> NIST/PIV has nothing whatsoever to do with physical transmission or the
> physicality of the platform. You can run it on a USB token, a PCMCIA
> token, a harddisk, a TPM, a cell-phone or a tom-tom.

That's interesting. So in the NIST vision (i.e. US position to ISO), one can
ping the TPM as a PIV device, and transfer the keying material to a soft
cryptomodule, like a harddrive. And the transfer format is a PKCS#12 file,
or something similar.

Presumably, the TPM will have multiple personalities - the PIV set (which
facilitate key export and mobility of "personal id" information between form
factors, and other sets that identify you otherwise for non PIV purposes
(e.g. DRM enforcement, evidentiary purposes, crypto export control
enforcement per login, etc). There will be a distinction between "personal"
id information that you have privacy rights over (the PIV set), and other
identification data that is "non-personal" and you probably wont really know
even exist.

When I talked to Wave at the RSA Show, they were singularly unable to
articulate how the fixed motherboard TPM would interact with the
smartcard/mobile-device: as a cooperating peer, and as a secure channel
partner. They just went on and on about the usual HP Bristol Labs integrity
metrics stuff for controlling what particular users might do with a software
platform (i.e. the Personal Computer). Viewing the PIV as a common
interface, with mobility and roaming properties, and as the linkup between
the TPM and one or other mobile token (that is not a TPM) is an interesting
concept.

Still doesn't address the end-end security problem tho., one PIV device to
another, with some degree of writer-to-reader security suited to personal id
information flow. If the PIV is on a near field device, users don't want the
RFID personal privacy problem - where any other local NF terminal can scan
your existence and presence, usefully, and possibly pull your data. There
has to be PIV-PIV authentication - independent of the mobile form factor -
and some W3C-like privacy handling scheme for then controlling the automatic
release of personal data items, to authenticated peers.

_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to