
From nobody Thu Dec  4 01:02:47 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5AFB51A8972 for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 01:02:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.422
X-Spam-Level: 
X-Spam-Status: No, score=-1.422 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CN_BODY_35=0.339, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DGIPbJMhqjSq for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 01:02:43 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C2D531A8968 for <Ace@ietf.org>; Thu,  4 Dec 2014 01:02:42 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml403-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BPO18940; Thu, 04 Dec 2014 09:02:41 +0000 (GMT)
Received: from SZXEMA412-HUB.china.huawei.com (10.82.72.71) by lhreml403-hub.china.huawei.com (10.201.5.217) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 4 Dec 2014 09:02:39 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.142]) by SZXEMA412-HUB.china.huawei.com ([10.82.72.71]) with mapi id 14.03.0158.001; Thu, 4 Dec 2014 17:02:30 +0800
From: Likepeng <likepeng@huawei.com>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "Ace@ietf.org" <Ace@ietf.org>
Thread-Topic: [Ace] CORRECTION -- Call For Adoption: draft-seitz-ace-usecases-02
Thread-Index: AQHQA9yi78Bi4V+TuEa1zlbGg/Fo05x/OU8Q
Date: Thu, 4 Dec 2014 09:02:30 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F2581D0C7D@SZXEMA501-MBS.china.huawei.com>
References: <546C5F50.4040905@gmx.net> <546C6513.1040508@gmx.net>
In-Reply-To: <546C6513.1040508@gmx.net>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.63.185.71]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/J_V1MCmMclxmO81HOl5YSeFuFLY
Subject: Re: [Ace] CORRECTION -- Call For Adoption: draft-seitz-ace-usecases-02
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Dec 2014 09:02:45 -0000

PiBUaGlzIG5vdGUgYmVnaW5zIGEgQ2FsbCBGb3IgQWRvcHRpb24gZm9yIGRyYWZ0LXNlaXR6LWFj
ZS11c2VjYXNlcy0wMgl0bw0KPiBiZSBhZG9wdGVkIGFzIGFuIEFDRSB3b3JraW5nIGdyb3VwIGl0
ZW0uIFRoZSBDYWxsIGVuZHMgb24gRGVjZW1iZXIgMywgMjAxNC4NCg0KQmFzZWQgb24gdGhlIHJl
Y2VpdmVkIGZlZWRiYWNrLCBpdCBpcyBjb25jbHVkZWQgdGhhdCB0aGlzIGRvY3VtZW50IGlzIGFk
b3B0ZWQgYXMgYW4gQUNFIHdvcmtpbmcgZ3JvdXAgaXRlbS4NCg0KQXV0aG9ycywgcGxlYXNlIHN1
Ym1pdCB0aGUgZG9jdW1lbnQgYXMgZHJhZnQtaWV0Zi1hY2UtdXNlY2FzZXMtMDAuDQoNClRoYW5r
cywNCg0KS2luZCBSZWdhcmRzDQpLZXBlbmcgJiBIYW5uZXMgKGFzIGNvLWNoYWlycykNCg0KPiAt
LS0tLdPKvP7Urbz+LS0tLS0NCj4gt6K8/sjLOiBBY2UgW21haWx0bzphY2UtYm91bmNlc0BpZXRm
Lm9yZ10gtPqx7SBIYW5uZXMgVHNjaG9mZW5pZw0KPiC3osvNyrG85DogMjAxNMTqMTHUwjE5yNUg
MTc6MzgNCj4gytW8/sjLOiBBY2VAaWV0Zi5vcmcNCj4g1vfM4jogW0FjZV0gQ09SUkVDVElPTiAt
LSBDYWxsIEZvciBBZG9wdGlvbjogZHJhZnQtc2VpdHotYWNlLXVzZWNhc2VzLTAyDQo+IA0KPiBU
aGlzIG5vdGUgYmVnaW5zIGEgQ2FsbCBGb3IgQWRvcHRpb24gZm9yIGRyYWZ0LXNlaXR6LWFjZS11
c2VjYXNlcy0wMgl0bw0KPiBiZSBhZG9wdGVkIGFzIGFuIEFDRSB3b3JraW5nIGdyb3VwIGl0ZW0u
IFRoZSBDYWxsIGVuZHMgb24gRGVjZW1iZXIgMywgMjAxNC4NCj4gDQo+IEtlZXAgaW4gbWluZCB0
aGF0IGFkb3B0aW9uIG9mIGEgZG9jdW1lbnQgZG9lcyBub3QgbWVhbiB0aGUgZG9jdW1lbnQgYXMt
aXMNCj4gaXMgcmVhZHkgZm9yIHB1YmxpY2F0aW9uLiBJdCBpcyBtZXJlbHkgYWNjZXB0YW5jZSBv
ZiB0aGUgZG9jdW1lbnQgYXMgYSBzdGFydGluZw0KPiBwb2ludCBmb3Igd2hhdCB3aWxsIGJlIHRo
ZSBmaW5hbCBwcm9kdWN0IG9mIHRoZSBBQ0Ugd29ya2luZyBncm91cC4gVGhlIHdvcmtpbmcNCj4g
Z3JvdXAgaXMgZnJlZSB0byBtYWtlIGNoYW5nZXMgdG8gdGhlIGRvY3VtZW50IGFjY29yZGluZyB0
byB0aGUgbm9ybWFsDQo+IGNvbnNlbnN1cyBwcm9jZXNzLg0KPiANCj4gVGhlcmUgd2FzIGZhdm9y
YWJsZSBodW0gdG93YXJkIGFkb3B0aW9uIG9mIHRoaXMgZG9jdW1lbnQgYXQgSUVURiA5MSBpbg0K
PiBIYXdhaWkuIFdlIHdpbGwgZmFjdG9yIHRoaXMgaW50byB0aGUgZGVjaXNpb24gYXQgdGhlIGNs
b3NlIG9mIHRoaXMgQ2FsbC4NCj4gDQo+IFBsZWFzZSByZXBseSBvbiB0aGlzIHRocmVhZCB3aXRo
IGV4cHJlc3Npb25zIG9mIHN1cHBvcnQgb3Igb3Bwb3NpdGlvbiwNCj4gcHJlZmVyYWJseSB3aXRo
IGNvbW1lbnRzLCByZWdhcmRpbmcgYWNjZXB0aW5nIHRoaXMgYXMgYSB3b3JrIGl0ZW0uDQo+IA0K
PiBDaWFvDQo+IEhhbm5lcyAmIEtlcGVuZw0KDQo=


From nobody Thu Dec  4 05:58:34 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 720AC1AD3B3 for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 05:58:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H0V0Ra2Hxl5v for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 05:58:21 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 497C61AD3A3 for <Ace@ietf.org>; Thu,  4 Dec 2014 05:58:10 -0800 (PST)
Received: from [192.168.131.134] ([80.92.119.109]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0MUoma-1YUXMg3y2e-00YESf for <Ace@ietf.org>; Thu, 04 Dec 2014 14:58:07 +0100
Message-ID: <5480686E.1080406@gmx.net>
Date: Thu, 04 Dec 2014 14:58:06 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.2.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="F1cmo6M4OCi1P5CvhXOSuJEHQrNMCD9cm"
X-Provags-ID: V03:K0:eUcpPCILXUzy3/MK8gKbgLSQ1qTQfe382ybAHsW9tK+cQgQpg0I wrD8xwh0hEl2D51KWLlssb4D47503sd/thXrAmafdBGuLyvOiwCgSYfrpulsqiFChhNM54U Ehz9A6cIbbIpmozKpMzD3pBH8VReyQ1lCn3fd313XSgDmngos2sXvs+w2+XfE2baqEWn66l KqLA9yx7X1tvEpZpAqSGg==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/YzDRTguWdrR9YmLL5mH10S5p2yc
Subject: [Ace] draft-ietf-ace-usecases-00
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Dec 2014 13:58:25 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--F1cmo6M4OCi1P5CvhXOSuJEHQrNMCD9cm
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi all,

we are happy to see the use case document adopted.

Here is the draft:
http://www.ietf.org/id/draft-ietf-ace-usecases-00.txt

Please take a look at the document; we would like to advance it.

Ciao
Hannes & Kepeng


--F1cmo6M4OCi1P5CvhXOSuJEHQrNMCD9cm
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUgGhuAAoJEGhJURNOOiAtMgEH/08yOpVrKLk2qjM2J56VDr+5
5iqSacvqbbzEHPzXQmF9k5pTpAKhXA819stRwLizRAY6gkbCRsT+FNJ3YhAgzS1G
tRRYhbphx63I4Y3J5E69twhgvvxt3sq6//mcBMUpr+NQjat7ffecP3xmmq9NmT+W
82wm/QNPwA249SZaEgFhM+yVgkdyXRos35PAvtqu20MsgmI+v8qhspxxaENPul3c
wmZIzWevhUUybGkEatWeBdDd9LlqdlDMsrbXJ0ArbXh5iVCkahtb1OWL3z/NvIp0
8YK9nF3rs6DhnL4aGQJdAZKzK9MpjCRzbZy7ccYPOT1R41FFi0o8krxq4fVY6i0=
=XTuJ
-----END PGP SIGNATURE-----

--F1cmo6M4OCi1P5CvhXOSuJEHQrNMCD9cm--


From nobody Thu Dec  4 06:07:38 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0724F1AD3A1 for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 06:07:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.26
X-Spam-Level: 
X-Spam-Status: No, score=-2.26 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id m1jeO1iuPDcR for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 06:07:24 -0800 (PST)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 299691AD3AC for <ace@ietf.org>; Thu,  4 Dec 2014 06:07:12 -0800 (PST)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id D4B2D626 for <ace@ietf.org>; Thu,  4 Dec 2014 15:07:10 +0100 (CET)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id sB4E7AFA003999 for <ace@ietf.org>; Thu, 4 Dec 2014 15:07:10 +0100
Received: from norm.sics.se (norm.sics.se [193.10.64.192]) by letter.sics.se (Postfix) with ESMTPS id BB46B40118 for <ace@ietf.org>; Thu,  4 Dec 2014 15:07:10 +0100 (CET)
Received: from [192.168.0.108] (unknown [85.235.11.178]) by norm.sics.se (Postfix) with ESMTPSA id 13CAC20B for <ace@ietf.org>; Thu,  4 Dec 2014 15:07:10 +0100 (CET)
Message-ID: <54806A87.6050707@sics.se>
Date: Thu, 04 Dec 2014 15:07:03 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <20141204135611.7629.62021.idtracker@ietfa.amsl.com>
In-Reply-To: <20141204135611.7629.62021.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20141204135611.7629.62021.idtracker@ietfa.amsl.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms050009050503010106040702"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7028; _longitude=3D13.1927; _http://maps.google.com/maps=3Fq=3D55.7028,13.1927&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09Nnq7au8 - 8a3e5e2d5679 - 20141204
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09Nnq7au8&m=8a3e5e2d5679&t=20141204&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09Nnq7au8&m=8a3e5e2d5679&t=20141204&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09Nnq7au8&m=8a3e5e2d5679&t=20141204&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/8FMsU6qwpV-lgHENQ4VNk1knNj8
Subject: [Ace] Fwd: New Version Notification for draft-ietf-ace-usecases-00.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Dec 2014 14:07:29 -0000

This is a cryptographically signed message in MIME format.

--------------ms050009050503010106040702
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: quoted-printable

Hello all,

I have just re-submitted draft-seitz-ace-usecases as=20
draft-ietf-ace-usecases, as by the WG chair's instructions.

Currently the only change is one line added in the acknowledgments.=20
However as was stressed in the ACE session at IETF 91, this doesn't mean =

we consider the document to be finished.

I encourage everyone to review the document and suggest changes and=20
improvements, so that we can move forward with it quickly.

Perhaps the WG chairs can give the IETF newbies among us a short=20
overview of how the document update procedure is going to be handled=20
from now on?

Regards,

Ludwig


-------- Forwarded Message --------
Subject: New Version Notification for draft-ietf-ace-usecases-00.txt
Date: Thu, 04 Dec 2014 05:56:11 -0800
From: internet-drafts@ietf.org
To: Mehdi Mani <mehdi.mani@itron.com>, Sandeep Kumar=20
<sandeep.kumar@philips.com>, Goeran Selander=20
<goran.selander@ericsson.com>, Sandeep S. Kumar=20
<sandeep.kumar@philips.com>, Ludwig Seitz <ludwig@sics.se>, Goran=20
Selander <goran.selander@ericsson.com>, Stefanie Gerdes=20
<gerdes@tzi.org>, Stefanie Gerdes <gerdes@tzi.org>, Ludwig Seitz=20
<ludwig@sics.se>, Mehdi Mani <mehdi.mani@itron.com>


A new version of I-D, draft-ietf-ace-usecases-00.txt
has been successfully submitted by Ludwig Seitz and posted to the
IETF repository.

Name:		draft-ietf-ace-usecases
Revision:	00
Title:		ACE use cases
Document date:	2014-12-02
Group:		ace
Pages:		24
URL:=20
http://www.ietf.org/internet-drafts/draft-ietf-ace-usecases-00.txt
Status:         https://datatracker.ietf.org/doc/draft-ietf-ace-usecases/=

Htmlized:       http://tools.ietf.org/html/draft-ietf-ace-usecases-00


Abstract:
    Constrained devices are nodes with limited processing power, storage
    space and transmission capacities.  These devices in many cases do
    not provide user interfaces and are often intended to interact
    without human intervention.

    This document comprises a collection of representative use cases for
    the application of authentication and authorization in constrained
    environments.  These use cases aim at identifying authorization
    problems that arise during the lifecylce of a constrained device and
    are intended to provide a guideline for developing a comprehensive
    authentication and access control solution for this class of
    scenarios.

    Where specific details are relevant, it is assumed that the devices
    use the Constrained Application Protocol (CoAP) as communication
    protocol, however most conclusions apply generally.

=20



Please note that it may take a couple of minutes from the time of submiss=
ion
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat





--------------ms050009050503010106040702
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDEyMDQxNDA3MDNaMCMGCSqGSIb3DQEJBDEW
BBSgLhO+sxQgLoePLg8EqKbYTj+IOjBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAgGfWISl7g73z5OLwLCXYB+Oq6hnsNBf7Z2AtMr8ZL4NiBkR701s40niAgkUWdCDF+5Mo
U8IlXc2SzIGgw5NfbRRIwsAX6RX94x388I0c8gUQYCn23S1DiozkN3ltl+8w5K4te7QAphcC
NinAJExT0sMofYpFaZXmLhVyywECluapXdJLt6WB9k+Ko7lermqZ50Kh1vvuPv0wgYp0Vbav
V9O97hdTWuT9c9JxoPKl/lhQGBfnt75rBialRwmp/QXuNQm59UtxJ+kJPUZ5e2rVms9+bkgr
cYsmn1kjefzoHDwOn6h9YWT7ND19RwV8VqsaMyNJYxqkA4thKQVnVrB+zAAAAAAAAA==
--------------ms050009050503010106040702--


From nobody Thu Dec  4 07:02:57 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C36521AD416 for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 07:02:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.51
X-Spam-Level: 
X-Spam-Status: No, score=-0.51 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tgQYiFLlEwTh for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 07:02:50 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E12F1AD413 for <Ace@ietf.org>; Thu,  4 Dec 2014 07:02:50 -0800 (PST)
Received: from [192.168.131.134] ([80.92.119.109]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0LbM2k-1XZ0UM01NK-00kviE for <Ace@ietf.org>; Thu, 04 Dec 2014 16:02:48 +0100
Message-ID: <54807796.7030504@gmx.net>
Date: Thu, 04 Dec 2014 16:02:46 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.2.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="xsWmorihmF5l0BEp5SohBbpmdlbINddIO"
X-Provags-ID: V03:K0:EuDEFWe5VWq9SXmTw6HJ0blxcrXXbXhWXFJvOmXkPpSCBsKZou1 0Ov4ZZJE/NPWWMciDJEeU8hVhkLQfdE4OTGcnBFwOdxw87jtIp+354svtUz9BQAZ/ZRnKwl zz8e2rPEMlqz/jSvrlnZ3Y2/tbsWo6PYY9EHzcdWPriM4QCOOcjDnRrGbYgacCG0QyxX0sL tI5gbgH8S0phWgTzRVA/w==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/7CMmAxbywLImj_SB8R-ji24HVYM
Subject: [Ace] Container Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Dec 2014 15:02:56 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--xsWmorihmF5l0BEp5SohBbpmdlbINddIO
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi all,

I read through the container use case and have a few questions.

The individual boxes (with bananas) are equipped with sensors and these
sensors communicate in a multi-hop fashion with each other to finally
reach a gateway (at the container level). This gateway then has access
to the Internet (sometimes, depending on where it is). Is this network
setup roughly correct?

You are saying that the boxes (+their sensors) may belong to different
owners. Since it is relevant for the use case I think it would be good
to have a list of the persons that seek access to different resources.
The container itself may belong to a party that is different from the
owner of the box. Does the ownership of the box change when it reaches
the supermarket? I guess the container will be sent back but I doubt
that this is true for the boxes?

It would be good to say whether you assume that the sensors upload their
data to different Internet servers or to the same and who wants to get
access to the data. I got a bit confused by the terminology you
introduced in Section 2.1.2 where you suddenly talk about "device owner"
whereas the terminology talks about resource owner and the actual text
refers to multiple owners (different owners for the different boxes, and
for the containers). Then, there is also the supermarket ordered the
goods and is supposed to own them afterwards.

Maybe there is also the possibility to be more specific about the
authorization challenges. For example, instead of saying "U1.1 The
device owner wants to grant different access rights to a resource to
different parties." you might want to state that "The owner of the
container grants read access the temperature information (?) to the
truck company." (I don't know if that makes sense but it's just an
example.) Since we talk about very specific use cases here we can also
be specific in the challenges.

Requirements U1.4 and U1.5 are not authorization requirements/challenges
but communication security requirements. Do you think that they are
essential for the work in ACE? I don't think so. I would leave them aside=
=2E

Regarding requirement U1.8: "Messages between client and resource server
might need to be forwarded over multiple hops." Where did you derive
this requirement from? Who is the client and who is the resource server
in this example?

Ciao
Hannes


--xsWmorihmF5l0BEp5SohBbpmdlbINddIO
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUgHeWAAoJEGhJURNOOiAtLwAH/115yprBns/qHvrVRLi38UHF
y68i+z+6iVmTH1J5xktiAnbkexmsfPawuAZHufapS0U5OfIZw+Z/e6zMAOeuBswT
23pfvdWLhcaxDGQ5sEjTSCPBCsTouWjlb71pilQiEHY88sEOZO2XuFCOCb/OyfSh
aQoPI73cs1KgC7XF1GZEItLODKjSOkWIdyf2y6Uum8bUi7D1QWLny5dSCEKYlFjB
+TRThxQ0X0nVpS3FIW+h0qmEFF33gK+in6vNhep5UTOhZaTy2Feeo4aBiTa5AvcC
UUiO0snB9lPeS2JEzNSn5DyFnD3uXfqotxEYVTanvZGO88Aqu25TTJloUy/P0nk=
=s08Q
-----END PGP SIGNATURE-----

--xsWmorihmF5l0BEp5SohBbpmdlbINddIO--


From nobody Thu Dec  4 10:09:40 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B7461A1B91 for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 10:09:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r2dheKVaS8YG for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 10:09:35 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 666381A1B72 for <Ace@ietf.org>; Thu,  4 Dec 2014 10:09:35 -0800 (PST)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 4DE232002A for <Ace@ietf.org>; Thu,  4 Dec 2014 13:12:57 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id 35179637F4; Thu,  4 Dec 2014 13:09:33 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 1F41F637EA for <Ace@ietf.org>; Thu,  4 Dec 2014 13:09:33 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "Ace\@ietf.org" <Ace@ietf.org>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F2581D0C7D@SZXEMA501-MBS.china.huawei.com>
References: <546C5F50.4040905@gmx.net> <546C6513.1040508@gmx.net> <34966E97BE8AD64EAE9D3D6E4DEE36F2581D0C7D@SZXEMA501-MBS.china.huawei.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Thu, 04 Dec 2014 13:09:33 -0500
Message-ID: <628.1417716573@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/nIHLkvFJLv0eihWolBrA_I__aos
Subject: Re: [Ace] CORRECTION -- Call For Adoption: draft-seitz-ace-usecases-02
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Dec 2014 18:09:37 -0000

--=-=-=
Content-Transfer-Encoding: quoted-printable


Likepeng <likepeng@huawei.com> wrote:
    > Based on the received feedback, it is concluded that this document is
    > adopted as an ACE working group item.=20

I suggest a WG LC be started for this document.

=2D-=20
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBVICjWoCLcPvd0N1lAQIthgf9Hp+61AlEW+sNXV/3uj3I9/zWYDxREjQg
hAtLsWFP0BcHrVPjulhOe9yVsdpIoEwS2OdKcC7h/j9p22f2K+0wgZCSdiH7gA1S
VGV1QNU5lRaBFm/9KeLJNZ0szwd5KizmacBBeSg1p7fh9uJ9WaUfnQ4GmkHb3gi7
cPI7a98xeikwktF6cHM//tiqamWxHT6KDvIotYVFRUSx3ZuII/CyZvAHz4kvwV8K
ceeWMgFZMn+bFDvx9GRlfmQFBXnV6kgompqJYmCv+f2haC1g9P+gn7loe4NlE9Gm
+sI7P1uGtF2LOvsluNXPH4sTICYBGBySGEZH6co0h4ZBfFY40msbPQ==
=FxbN
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Thu Dec  4 10:43:47 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4067D1A1B75 for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 10:43:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vXg0CdHtBTDD for <ace@ietfa.amsl.com>; Thu,  4 Dec 2014 10:43:43 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 01A6E1A1B91 for <Ace@ietf.org>; Thu,  4 Dec 2014 10:43:43 -0800 (PST)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 277A22002A for <Ace@ietf.org>; Thu,  4 Dec 2014 13:47:06 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id E9649637F4; Thu,  4 Dec 2014 13:43:41 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id CE6F8637EA for <Ace@ietf.org>; Thu,  4 Dec 2014 13:43:41 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "Ace\@ietf.org" <Ace@ietf.org>
In-Reply-To: <54807796.7030504@gmx.net>
References: <54807796.7030504@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Thu, 04 Dec 2014 13:43:41 -0500
Message-ID: <8541.1417718621@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/N_YgUrdXN-NdY1wqUeH0wPhCGaI
Subject: Re: [Ace] Container Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Dec 2014 18:43:45 -0000

--=-=-=
Content-Transfer-Encoding: quoted-printable


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > The individual boxes (with bananas) are equipped with sensors and the=
se
    > sensors communicate in a multi-hop fashion with each other to finally
    > reach a gateway (at the container level). This gateway then has access
    > to the Internet (sometimes, depending on where it is). Is this network
    > setup roughly correct?

I think so.

    > You are saying that the boxes (+their sensors) may belong to different
    > owners. Since it is relevant for the use case I think it would be good
    > to have a list of the persons that seek access to different resources.

I think that this is incorrect; I think that the bananas belong to different
owners.  The boxes started off owned by the producer, which is why the
producer was able to arrange for them to mesh together.  However, they
producer wants to delegate access to the sensors to different owners (of ba=
nanas).

    > The container itself may belong to a party that is different from the
    > owner of the box. Does the ownership of the box change when it reaches
    > the supermarket? I guess the container will be sent back but I doubt
    > that this is true for the boxes?

Does it matter if the boxes are recycled (firmware wiped/reset/etc.) or if
they are disposable?  As long as that process involves resetting things?

    > It would be good to say whether you assume that the sensors upload th=
eir
    > data to different Internet servers or to the same and who wants to get
    > access to the data. I got a bit confused by the terminology you
    > introduced in Section 2.1.2 where you suddenly talk about "device own=
er"
    > whereas the terminology talks about resource owner and the actual text
    > refers to multiple owners (different owners for the different boxes, =
and
    > for the containers). Then, there is also the supermarket ordered the
    > goods and is supposed to own them afterwards.

My understanding is that a key thing about this use case is that the
*container* needs access to the data, so that the *container* can make sure
the environment is correct.  (the truck, boat, train, etc. the container is
on)

There might not be connectivity for much of the voyage.

    > Maybe there is also the possibility to be more specific about the
    > authorization challenges. For example, instead of saying "U1.1 The
    > device owner wants to grant different access rights to a resource to
    > different parties." you might want to state that "The owner of the
    > container grants read access the temperature information (?) to the
    > truck company." (I don't know if that makes sense but it's just an
    > example.) Since we talk about very specific use cases here we can also
    > be specific in the challenges.

I agree with this change, let's be really clear.

    > Requirements U1.4 and U1.5 are not authorization requirements/challen=
ges
    > but communication security requirements. Do you think that they are
    > essential for the work in ACE? I don't think so. I would leave them a=
side.

I would leave them there and say that they out of scope.

    > Regarding requirement U1.8: "Messages between client and resource ser=
ver
    > might need to be forwarded over multiple hops." Where did you derive
    > this requirement from? Who is the client and who is the resource serv=
er
    > in this example?

and what layer are the multiple hops?
I think the point of this requirement is that we are assuming layer-3, IP
networking, not, for instance, Bluetooth, for which there would be no
authorization issues (because there is always only one owner in BT).

=2D-=20
]               Never tell me the odds!                 | ipv6 mesh network=
s [=20
]   Michael Richardson, Sandelman Software Works        | network architect=
  [=20
]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails  =
  [=20
=09

--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBVICrW4CLcPvd0N1lAQKqpAf/UsuTI+OdzVWhWV2k3xHyVSLjR2Qbtl15
onFaG1y3V9j7+BKk5sTy2vQ1cwXxvJDWRU32bWYbF28o5m3/iojmyv5u86Cucv+U
cw39UvSJ3SZE8hhPJTLB1BdoqMDHQAE8sCt+EJooVnI3cjyMVjrogLLNY8v3pqQS
aee0Oe3C/NmQkzE4c6lDx1J07iIwmINmg+ajiA1Lj5ct0KuMKiFynNUA33QnhA5r
amZKvWUX3KiRL07vCjepzwyOLxsIyMYb6D8xOwkBLy9E3vhhNCn55J3YTyMfh68N
T2EjAzc/usOaSPUxjE5Y9JBQBfKg1ifDZLa3uqlhFfrNg/Hi4FR3Bg==
=g84Y
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Fri Dec  5 01:08:19 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D9B0C1ACE0B for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 01:08:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ut71CcFLJdfK for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 01:08:14 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6855B1A0075 for <Ace@ietf.org>; Fri,  5 Dec 2014 01:08:13 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml401-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BMK04380; Fri, 05 Dec 2014 09:08:11 +0000 (GMT)
Received: from SZXEMA411-HUB.china.huawei.com (10.82.72.70) by lhreml401-hub.china.huawei.com (10.201.5.240) with Microsoft SMTP Server (TLS) id 14.3.158.1; Fri, 5 Dec 2014 09:08:11 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.142]) by szxema411-hub.china.huawei.com ([10.82.72.70]) with mapi id 14.03.0158.001; Fri, 5 Dec 2014 17:07:23 +0800
From: Likepeng <likepeng@huawei.com>
To: Ludwig Seitz <ludwig@sics.se>
Thread-Topic: [Ace] Fwd: New Version Notification for draft-ietf-ace-usecases-00.txt
Thread-Index: AQHQD8vOGWl/Lr23FUqhltVOP+fPBJyAs+VA
Date: Fri, 5 Dec 2014 09:07:23 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F2581D1117@SZXEMA501-MBS.china.huawei.com>
References: <20141204135611.7629.62021.idtracker@ietfa.amsl.com> <54806A87.6050707@sics.se>
In-Reply-To: <54806A87.6050707@sics.se>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.63.185.71]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Cy9ddD1nlgF6u1xK_Me0nBU6pTg
Cc: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "Ace@ietf.org" <Ace@ietf.org>
Subject: Re: [Ace] Fwd: New Version Notification for draft-ietf-ace-usecases-00.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 09:08:17 -0000

PiBQZXJoYXBzIHRoZSBXRyBjaGFpcnMgY2FuIGdpdmUgdGhlIElFVEYgbmV3YmllcyBhbW9uZyB1
cyBhIHNob3J0IG92ZXJ2aWV3IG9mDQo+IGhvdyB0aGUgZG9jdW1lbnQgdXBkYXRlIHByb2NlZHVy
ZSBpcyBnb2luZyB0byBiZSBoYW5kbGVkIGZyb20gbm93IG9uPw0KDQpNeSBleHBlcmllbmNlIGlz
IHRoYXQsIHlvdSBuZWVkIHRvIG1ha2UgdXBkYXRlcyBiZWZvcmUgZWFjaCBGMkYgbWVldGluZywg
YWNjb3JkaW5nIHRvIHRoZSBkaXNjdXNzaW9uIHJlc3VsdHMgcmVjZWl2ZWQgaW4gdGhlIG1haWxp
bmcgbGlzdC4NCg0KQWxzbyBpbiBlYWNoIEYyRiBtZWV0aW5nLCB5b3UgbmVlZCB0byBwcmVzZW50
IHRoZSByZWNlbnQgY2hhbmdlcyBhbmQgb3BlbiBpc3N1ZXMgZm9yIGRpc2N1c3Npb24uDQoNCkFj
Y29yZGluZyB0byBvdXIgbWlsZXN0b25lcywgd2Ugc2hvdWxkIGZpbmlzaCB0aGlzIGRvY3VtZW50
IGJ5IG9uZSBvciB0d28gRjJGIG1lZXRpbmdzLg0KDQpLaW5kIFJlZ2FyZHMNCktlcGVuZw0KDQo+
IC0tLS0t6YKu5Lu25Y6f5Lu2LS0tLS0NCj4g5Y+R5Lu25Lq6OiBBY2UgW21haWx0bzphY2UtYm91
bmNlc0BpZXRmLm9yZ10g5Luj6KGoIEx1ZHdpZyBTZWl0eg0KPiDlj5HpgIHml7bpl7Q6IDIwMTTl
ubQxMuaciDTml6UgMjI6MDcNCj4g5pS25Lu25Lq6OiBhY2VAaWV0Zi5vcmcNCj4g5Li76aKYOiBb
QWNlXSBGd2Q6IE5ldyBWZXJzaW9uIE5vdGlmaWNhdGlvbiBmb3IgZHJhZnQtaWV0Zi1hY2UtdXNl
Y2FzZXMtMDAudHh0DQo+IA0KPiBIZWxsbyBhbGwsDQo+IA0KPiBJIGhhdmUganVzdCByZS1zdWJt
aXR0ZWQgZHJhZnQtc2VpdHotYWNlLXVzZWNhc2VzIGFzIGRyYWZ0LWlldGYtYWNlLXVzZWNhc2Vz
LCBhcw0KPiBieSB0aGUgV0cgY2hhaXIncyBpbnN0cnVjdGlvbnMuDQo+IA0KPiBDdXJyZW50bHkg
dGhlIG9ubHkgY2hhbmdlIGlzIG9uZSBsaW5lIGFkZGVkIGluIHRoZSBhY2tub3dsZWRnbWVudHMu
DQo+IEhvd2V2ZXIgYXMgd2FzIHN0cmVzc2VkIGluIHRoZSBBQ0Ugc2Vzc2lvbiBhdCBJRVRGIDkx
LCB0aGlzIGRvZXNuJ3QgbWVhbiB3ZQ0KPiBjb25zaWRlciB0aGUgZG9jdW1lbnQgdG8gYmUgZmlu
aXNoZWQuDQo+IA0KPiBJIGVuY291cmFnZSBldmVyeW9uZSB0byByZXZpZXcgdGhlIGRvY3VtZW50
IGFuZCBzdWdnZXN0IGNoYW5nZXMgYW5kDQo+IGltcHJvdmVtZW50cywgc28gdGhhdCB3ZSBjYW4g
bW92ZSBmb3J3YXJkIHdpdGggaXQgcXVpY2tseS4NCj4gDQo+IFBlcmhhcHMgdGhlIFdHIGNoYWly
cyBjYW4gZ2l2ZSB0aGUgSUVURiBuZXdiaWVzIGFtb25nIHVzIGEgc2hvcnQgb3ZlcnZpZXcgb2YN
Cj4gaG93IHRoZSBkb2N1bWVudCB1cGRhdGUgcHJvY2VkdXJlIGlzIGdvaW5nIHRvIGJlIGhhbmRs
ZWQgZnJvbSBub3cgb24/DQo+IA0KPiBSZWdhcmRzLA0KPiANCj4gTHVkd2lnDQo+IA0KPiANCj4g
LS0tLS0tLS0gRm9yd2FyZGVkIE1lc3NhZ2UgLS0tLS0tLS0NCj4gU3ViamVjdDogTmV3IFZlcnNp
b24gTm90aWZpY2F0aW9uIGZvciBkcmFmdC1pZXRmLWFjZS11c2VjYXNlcy0wMC50eHQNCj4gRGF0
ZTogVGh1LCAwNCBEZWMgMjAxNCAwNTo1NjoxMSAtMDgwMA0KPiBGcm9tOiBpbnRlcm5ldC1kcmFm
dHNAaWV0Zi5vcmcNCj4gVG86IE1laGRpIE1hbmkgPG1laGRpLm1hbmlAaXRyb24uY29tPiwgU2Fu
ZGVlcCBLdW1hcg0KPiA8c2FuZGVlcC5rdW1hckBwaGlsaXBzLmNvbT4sIEdvZXJhbiBTZWxhbmRl
cg0KPiA8Z29yYW4uc2VsYW5kZXJAZXJpY3Nzb24uY29tPiwgU2FuZGVlcCBTLiBLdW1hcg0KPiA8
c2FuZGVlcC5rdW1hckBwaGlsaXBzLmNvbT4sIEx1ZHdpZyBTZWl0eiA8bHVkd2lnQHNpY3Muc2U+
LCBHb3Jhbg0KPiBTZWxhbmRlciA8Z29yYW4uc2VsYW5kZXJAZXJpY3Nzb24uY29tPiwgU3RlZmFu
aWUgR2VyZGVzIDxnZXJkZXNAdHppLm9yZz4sDQo+IFN0ZWZhbmllIEdlcmRlcyA8Z2VyZGVzQHR6
aS5vcmc+LCBMdWR3aWcgU2VpdHogPGx1ZHdpZ0BzaWNzLnNlPiwgTWVoZGkgTWFuaQ0KPiA8bWVo
ZGkubWFuaUBpdHJvbi5jb20+DQo+IA0KPiANCj4gQSBuZXcgdmVyc2lvbiBvZiBJLUQsIGRyYWZ0
LWlldGYtYWNlLXVzZWNhc2VzLTAwLnR4dCBoYXMgYmVlbiBzdWNjZXNzZnVsbHkNCj4gc3VibWl0
dGVkIGJ5IEx1ZHdpZyBTZWl0eiBhbmQgcG9zdGVkIHRvIHRoZSBJRVRGIHJlcG9zaXRvcnkuDQo+
IA0KPiBOYW1lOgkJZHJhZnQtaWV0Zi1hY2UtdXNlY2FzZXMNCj4gUmV2aXNpb246CTAwDQo+IFRp
dGxlOgkJQUNFIHVzZSBjYXNlcw0KPiBEb2N1bWVudCBkYXRlOgkyMDE0LTEyLTAyDQo+IEdyb3Vw
OgkJYWNlDQo+IFBhZ2VzOgkJMjQNCj4gVVJMOg0KPiBodHRwOi8vd3d3LmlldGYub3JnL2ludGVy
bmV0LWRyYWZ0cy9kcmFmdC1pZXRmLWFjZS11c2VjYXNlcy0wMC50eHQNCj4gU3RhdHVzOiAgICAg
ICAgIGh0dHBzOi8vZGF0YXRyYWNrZXIuaWV0Zi5vcmcvZG9jL2RyYWZ0LWlldGYtYWNlLXVzZWNh
c2VzLw0KPiBIdG1saXplZDogICAgICAgaHR0cDovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQt
aWV0Zi1hY2UtdXNlY2FzZXMtMDANCj4gDQo+IA0KPiBBYnN0cmFjdDoNCj4gICAgIENvbnN0cmFp
bmVkIGRldmljZXMgYXJlIG5vZGVzIHdpdGggbGltaXRlZCBwcm9jZXNzaW5nIHBvd2VyLCBzdG9y
YWdlDQo+ICAgICBzcGFjZSBhbmQgdHJhbnNtaXNzaW9uIGNhcGFjaXRpZXMuICBUaGVzZSBkZXZp
Y2VzIGluIG1hbnkgY2FzZXMgZG8NCj4gICAgIG5vdCBwcm92aWRlIHVzZXIgaW50ZXJmYWNlcyBh
bmQgYXJlIG9mdGVuIGludGVuZGVkIHRvIGludGVyYWN0DQo+ICAgICB3aXRob3V0IGh1bWFuIGlu
dGVydmVudGlvbi4NCj4gDQo+ICAgICBUaGlzIGRvY3VtZW50IGNvbXByaXNlcyBhIGNvbGxlY3Rp
b24gb2YgcmVwcmVzZW50YXRpdmUgdXNlIGNhc2VzIGZvcg0KPiAgICAgdGhlIGFwcGxpY2F0aW9u
IG9mIGF1dGhlbnRpY2F0aW9uIGFuZCBhdXRob3JpemF0aW9uIGluIGNvbnN0cmFpbmVkDQo+ICAg
ICBlbnZpcm9ubWVudHMuICBUaGVzZSB1c2UgY2FzZXMgYWltIGF0IGlkZW50aWZ5aW5nIGF1dGhv
cml6YXRpb24NCj4gICAgIHByb2JsZW1zIHRoYXQgYXJpc2UgZHVyaW5nIHRoZSBsaWZlY3lsY2Ug
b2YgYSBjb25zdHJhaW5lZCBkZXZpY2UgYW5kDQo+ICAgICBhcmUgaW50ZW5kZWQgdG8gcHJvdmlk
ZSBhIGd1aWRlbGluZSBmb3IgZGV2ZWxvcGluZyBhIGNvbXByZWhlbnNpdmUNCj4gICAgIGF1dGhl
bnRpY2F0aW9uIGFuZCBhY2Nlc3MgY29udHJvbCBzb2x1dGlvbiBmb3IgdGhpcyBjbGFzcyBvZg0K
PiAgICAgc2NlbmFyaW9zLg0KPiANCj4gICAgIFdoZXJlIHNwZWNpZmljIGRldGFpbHMgYXJlIHJl
bGV2YW50LCBpdCBpcyBhc3N1bWVkIHRoYXQgdGhlIGRldmljZXMNCj4gICAgIHVzZSB0aGUgQ29u
c3RyYWluZWQgQXBwbGljYXRpb24gUHJvdG9jb2wgKENvQVApIGFzIGNvbW11bmljYXRpb24NCj4g
ICAgIHByb3RvY29sLCBob3dldmVyIG1vc3QgY29uY2x1c2lvbnMgYXBwbHkgZ2VuZXJhbGx5Lg0K
PiANCj4gDQo+IA0KPiANCj4gDQo+IFBsZWFzZSBub3RlIHRoYXQgaXQgbWF5IHRha2UgYSBjb3Vw
bGUgb2YgbWludXRlcyBmcm9tIHRoZSB0aW1lIG9mIHN1Ym1pc3Npb24NCj4gdW50aWwgdGhlIGh0
bWxpemVkIHZlcnNpb24gYW5kIGRpZmYgYXJlIGF2YWlsYWJsZSBhdCB0b29scy5pZXRmLm9yZy4N
Cj4gDQo+IFRoZSBJRVRGIFNlY3JldGFyaWF0DQo+IA0KPiANCj4gDQoNCg==


From nobody Fri Dec  5 04:48:56 2014
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5ECA11ACE67 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 04:48:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, MIME_QP_LONG_LINE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Uleru-E4vjJk for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 04:48:53 -0800 (PST)
Received: from mail-qa0-x22d.google.com (mail-qa0-x22d.google.com [IPv6:2607:f8b0:400d:c00::22d]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 30C1D1ACE62 for <Ace@ietf.org>; Fri,  5 Dec 2014 04:48:53 -0800 (PST)
Received: by mail-qa0-f45.google.com with SMTP id x12so350157qac.4 for <Ace@ietf.org>; Fri, 05 Dec 2014 04:48:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=from:content-type:mime-version:subject:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=fMHQ+hoCB2/CmkNp+Tfvvnn2PNtpEaaXsbtoD9Aeo4E=; b=e5ADaa2sXx3Zb0XSor+6Iy91zrPcuIOKFl0PojQpOUXzc4DOd0zEru1vSj9ivpxSDb YVOZWrLwA4rLGeM7d3HKBpDpmzH3tct5bPantJeg/IYjJ+MDtUJm32lsrHrrjT3LrIg9 oexpgjs6vZKKrMAgPrdJ863Vd9Q1ffsy1ctRsJVp3wXcTnvHHOUkfl1xPlsByMdP7T34 JLsaWrbUeoOVw37vB0kVVXfhod6JvVtoyXKS9cq4LV+MXv3Rh4/ejUtmQ6NjV50PYsXq MOTiiab08hUe/JVG0MUqC33onvPFdCWxYu1pKnv16KU81zCkETt1s/jSVr6zPjk2TPjv 4geg==
X-Received: by 10.229.248.132 with SMTP id mg4mr25180339qcb.29.1417783732340;  Fri, 05 Dec 2014 04:48:52 -0800 (PST)
Received: from [192.168.1.3] (209-6-114-252.c3-0.arl-ubr1.sbo-arl.ma.cable.rcn.com. [209.6.114.252]) by mx.google.com with ESMTPSA id t17sm29539160qgt.43.2014.12.05.04.48.50 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 05 Dec 2014 04:48:50 -0800 (PST)
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
X-Google-Original-From: Kathleen Moriarty <Kathleen.Moriarty.ietf@gmail.com>
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (1.0)
X-Mailer: iPhone Mail (11D257)
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F2581D1117@SZXEMA501-MBS.china.huawei.com>
Date: Fri, 5 Dec 2014 07:48:50 -0500
Content-Transfer-Encoding: quoted-printable
Message-Id: <4F8F0EA7-8803-47BB-B4F2-6F67E019C3E6@gmail.com>
References: <20141204135611.7629.62021.idtracker@ietfa.amsl.com> <54806A87.6050707@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F2581D1117@SZXEMA501-MBS.china.huawei.com>
To: Likepeng <likepeng@huawei.com>
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/aywK6SdkAc72jHKfy93DJGE1X_Q
Cc: Hannes Tschofenig <hannes.tschofenig@gmx.net>, Ludwig Seitz <ludwig@sics.se>, "Ace@ietf.org" <Ace@ietf.org>
Subject: Re: [Ace] Fwd: New Version Notification for draft-ietf-ace-usecases-00.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 12:48:55 -0000

Sent from my iPhone

On Dec 5, 2014, at 4:07 AM, Likepeng <likepeng@huawei.com> wrote:

>> Perhaps the WG chairs can give the IETF newbies among us a short overview=
 of
>> how the document update procedure is going to be handled from now on?
>=20
> My experience is that, you need to make updates before each F2F meeting, a=
ccording to the discussion results received in the mailing list.

This is a typical pattern, however you can update the draft as often as nece=
ssary and doing work between meeting cycles is encouraged.

Thank you,
Kathleen=20
>=20
> Also in each F2F meeting, you need to present the recent changes and open i=
ssues for discussion.
>=20
> According to our milestones, we should finish this document by one or two =
F2F meetings.
>=20
> Kind Regards
> Kepeng
>=20
>> -----=E9=82=AE=E4=BB=B6=E5=8E=9F=E4=BB=B6-----
>> =E5=8F=91=E4=BB=B6=E4=BA=BA: Ace [mailto:ace-bounces@ietf.org] =E4=BB=A3=E8=
=A1=A8 Ludwig Seitz
>> =E5=8F=91=E9=80=81=E6=97=B6=E9=97=B4: 2014=E5=B9=B412=E6=9C=884=E6=97=A5 2=
2:07
>> =E6=94=B6=E4=BB=B6=E4=BA=BA: ace@ietf.org
>> =E4=B8=BB=E9=A2=98: [Ace] Fwd: New Version Notification for draft-ietf-ac=
e-usecases-00.txt
>>=20
>> Hello all,
>>=20
>> I have just re-submitted draft-seitz-ace-usecases as draft-ietf-ace-useca=
ses, as
>> by the WG chair's instructions.
>>=20
>> Currently the only change is one line added in the acknowledgments.
>> However as was stressed in the ACE session at IETF 91, this doesn't mean w=
e
>> consider the document to be finished.
>>=20
>> I encourage everyone to review the document and suggest changes and
>> improvements, so that we can move forward with it quickly.
>>=20
>> Perhaps the WG chairs can give the IETF newbies among us a short overview=
 of
>> how the document update procedure is going to be handled from now on?
>>=20
>> Regards,
>>=20
>> Ludwig
>>=20
>>=20
>> -------- Forwarded Message --------
>> Subject: New Version Notification for draft-ietf-ace-usecases-00.txt
>> Date: Thu, 04 Dec 2014 05:56:11 -0800
>> From: internet-drafts@ietf.org
>> To: Mehdi Mani <mehdi.mani@itron.com>, Sandeep Kumar
>> <sandeep.kumar@philips.com>, Goeran Selander
>> <goran.selander@ericsson.com>, Sandeep S. Kumar
>> <sandeep.kumar@philips.com>, Ludwig Seitz <ludwig@sics.se>, Goran
>> Selander <goran.selander@ericsson.com>, Stefanie Gerdes <gerdes@tzi.org>,=

>> Stefanie Gerdes <gerdes@tzi.org>, Ludwig Seitz <ludwig@sics.se>, Mehdi Ma=
ni
>> <mehdi.mani@itron.com>
>>=20
>>=20
>> A new version of I-D, draft-ietf-ace-usecases-00.txt has been successfull=
y
>> submitted by Ludwig Seitz and posted to the IETF repository.
>>=20
>> Name:        draft-ietf-ace-usecases
>> Revision:    00
>> Title:        ACE use cases
>> Document date:    2014-12-02
>> Group:        ace
>> Pages:        24
>> URL:
>> http://www.ietf.org/internet-drafts/draft-ietf-ace-usecases-00.txt
>> Status:         https://datatracker.ietf.org/doc/draft-ietf-ace-usecases/=

>> Htmlized:       http://tools.ietf.org/html/draft-ietf-ace-usecases-00
>>=20
>>=20
>> Abstract:
>>    Constrained devices are nodes with limited processing power, storage
>>    space and transmission capacities.  These devices in many cases do
>>    not provide user interfaces and are often intended to interact
>>    without human intervention.
>>=20
>>    This document comprises a collection of representative use cases for
>>    the application of authentication and authorization in constrained
>>    environments.  These use cases aim at identifying authorization
>>    problems that arise during the lifecylce of a constrained device and
>>    are intended to provide a guideline for developing a comprehensive
>>    authentication and access control solution for this class of
>>    scenarios.
>>=20
>>    Where specific details are relevant, it is assumed that the devices
>>    use the Constrained Application Protocol (CoAP) as communication
>>    protocol, however most conclusions apply generally.
>>=20
>>=20
>>=20
>>=20
>>=20
>> Please note that it may take a couple of minutes from the time of submiss=
ion
>> until the htmlized version and diff are available at tools.ietf.org.
>>=20
>> The IETF Secretariat
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


From nobody Fri Dec  5 04:50:53 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4E8411ACE69 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 04:50:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pHJV3jOUr3xb for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 04:50:48 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C2CD1ACE59 for <Ace@ietf.org>; Fri,  5 Dec 2014 04:50:48 -0800 (PST)
Received: from [192.168.131.135] ([80.92.119.109]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0LpKY5-1XSmvP2z6z-00fEDC; Fri, 05 Dec 2014 13:50:43 +0100
Message-ID: <5481AA21.8060004@gmx.net>
Date: Fri, 05 Dec 2014 13:50:41 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Likepeng <likepeng@huawei.com>, Ludwig Seitz <ludwig@sics.se>
References: <20141204135611.7629.62021.idtracker@ietfa.amsl.com> <54806A87.6050707@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F2581D1117@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F2581D1117@SZXEMA501-MBS.china.huawei.com>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="WQVwARCrTnAx2Ixg7Ue5wkOcWio8PckeI"
X-Provags-ID: V03:K0:G/8NyM9waQhiugJ6ES2VFFx8AvAJS6v1xBxonxJcznIfxWQzSse X1l8Dn7l/2NL7YGsvF0XVabbxXIJ5MNGE2t9sPUweXIuQ0eTS9phm23ObKIZZhrjV0OXoDR K52g2AT0p3xbnY68V528bf6jkYs+SBCGXqdAhlK75dqRzM28MhDebCL4F75jhCdbt5wU78g qhz0gOmK2VkBPk8BM0VzA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/NVls7SbZToaw_Qh_4mY7SVv-gpg
Cc: "Ace@ietf.org" <Ace@ietf.org>
Subject: Re: [Ace] Fwd: New Version Notification for draft-ietf-ace-usecases-00.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 12:50:50 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--WQVwARCrTnAx2Ixg7Ue5wkOcWio8PckeI
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi Ludwig,

On 12/05/2014 10:07 AM, Likepeng wrote:
> My experience is that, you need to make updates before each F2F meeting=
, according to the discussion results received in the mailing list.

Of course, it would be nice if you could make more frequent updates when
enough feedback has been provided.

Ciao
Hannes


--WQVwARCrTnAx2Ixg7Ue5wkOcWio8PckeI
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUgaohAAoJEGhJURNOOiAthm4IAJc94Ycbr9js/IWVlnwoWmPk
VwlAZnYxOLJk1PLM91XdtnJrkbh3LxprzuvDdVvaKczF8zPJj1ghXUuIntqPiU9Y
cdHBcNoxmo0UV5E2DCbA/LEGLPyUVPpXGHz609b0WWmR/6LF13TpwDNfMKfs2M5G
A7VWExaiusfE9CP4t3NCmJryrv7+0IKb2XOTVymYp2DIMSulk0GFVpfSHmbGPJzZ
n3BS4YBvNDjlWkUFaqSF4LKTORTBf/9sV0J09UMKs1xDAKQqrX9lOp9KhggCYYQT
a8BOj7spzRWDDbtz0MGE+XFeDJ5/RJ1TI7Pd5IbViWESmgtJhwG/F2vCo7Dbr5A=
=uQ1q
-----END PGP SIGNATURE-----

--WQVwARCrTnAx2Ixg7Ue5wkOcWio8PckeI--


From nobody Fri Dec  5 05:12:07 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3D8DC1ACE74 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 05:11:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0I_LeuVLiHuY for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 05:11:26 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D7FAC1ACE65 for <Ace@ietf.org>; Fri,  5 Dec 2014 05:11:25 -0800 (PST)
Received: from [192.168.131.135] ([80.92.119.109]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0MDhba-1YDtgb0C4M-00H7Gc; Fri, 05 Dec 2014 14:11:23 +0100
Message-ID: <5481AEF9.2030109@gmx.net>
Date: Fri, 05 Dec 2014 14:11:21 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>, "Ace@ietf.org" <Ace@ietf.org>
References: <54807796.7030504@gmx.net> <8541.1417718621@sandelman.ca>
In-Reply-To: <8541.1417718621@sandelman.ca>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="FSO7JdQSTtXaclQejm0b4hg6jxFhdMkkv"
X-Provags-ID: V03:K0:LYM+pcAOk3Kl7aXmiK/RFRfkgJQUdLNGxYoP/VphGgU9B+iESR0 rA6F+JI0YtGCmuZ4of/WiRATudZx55o0333qh5bgx16KZpYjQiFBFixBSrGbePqj1Uv4Ao4 teK0ElA53Zhkuaoix3QO/7ZjSaI3XIYKZpy3lq98PuWzrmaDSBMf5/SZJJJBZKkzJkyTxI0 a1twUtu2SLeiSIZbxrphQ==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/nXCEjo7_1L3dJtX-HNvat-fUUzg
Subject: Re: [Ace] Container Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 13:11:47 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--FSO7JdQSTtXaclQejm0b4hg6jxFhdMkkv
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Michael,

thanks for sharing your views.


On 12/04/2014 07:43 PM, Michael Richardson wrote:
>=20
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>     > The individual boxes (with bananas) are equipped with sensors and=
 these
>     > sensors communicate in a multi-hop fashion with each other to fin=
ally
>     > reach a gateway (at the container level). This gateway then has a=
ccess
>     > to the Internet (sometimes, depending on where it is). Is this ne=
twork
>     > setup roughly correct?
>=20
> I think so.
>=20
>     > You are saying that the boxes (+their sensors) may belong to diff=
erent
>     > owners. Since it is relevant for the use case I think it would be=
 good
>     > to have a list of the persons that seek access to different resou=
rces.
>=20
> I think that this is incorrect; I think that the bananas belong to diff=
erent
> owners.  The boxes started off owned by the producer, which is why the
> producer was able to arrange for them to mesh together.  However, they
> producer wants to delegate access to the sensors to different owners (o=
f bananas).

Ok. This might be good to state since I don't see that anywhere. I am
sure the producer may also keep track of the status while the shipments
travel to the different owners (customers, like supermarket).


>=20
>     > The container itself may belong to a party that is different from=
 the
>     > owner of the box. Does the ownership of the box change when it re=
aches
>     > the supermarket? I guess the container will be sent back but I do=
ubt
>     > that this is true for the boxes?
>=20
> Does it matter if the boxes are recycled (firmware wiped/reset/etc.) or=
 if
> they are disposable?  As long as that process involves resetting things=
?

I think it is lifecycle issue. For example, if the boxes are indeed
change ownership to the supermarket then the producers should not have
access to the sensor data in the future. Right?

>=20
>     > It would be good to say whether you assume that the sensors uploa=
d their
>     > data to different Internet servers or to the same and who wants t=
o get
>     > access to the data. I got a bit confused by the terminology you
>     > introduced in Section 2.1.2 where you suddenly talk about "device=
 owner"
>     > whereas the terminology talks about resource owner and the actual=
 text
>     > refers to multiple owners (different owners for the different box=
es, and
>     > for the containers). Then, there is also the supermarket ordered =
the
>     > goods and is supposed to own them afterwards.
>=20
> My understanding is that a key thing about this use case is that the
> *container* needs access to the data, so that the *container* can make =
sure
> the environment is correct.  (the truck, boat, train, etc. the containe=
r is
> on)

Interesting. I didn't understood that this is the main use case. I
thought that the main point was that you get the data to the Internet
and that access to the data is provided from there to the different
stakeholders (supermarket, producer, etc.)

>=20
> There might not be connectivity for much of the voyage.
>=20
>     > Maybe there is also the possibility to be more specific about the=

>     > authorization challenges. For example, instead of saying "U1.1 Th=
e
>     > device owner wants to grant different access rights to a resource=
 to
>     > different parties." you might want to state that "The owner of th=
e
>     > container grants read access the temperature information (?) to t=
he
>     > truck company." (I don't know if that makes sense but it's just a=
n
>     > example.) Since we talk about very specific use cases here we can=
 also
>     > be specific in the challenges.
>=20
> I agree with this change, let's be really clear.
>=20
>     > Requirements U1.4 and U1.5 are not authorization requirements/cha=
llenges
>     > but communication security requirements. Do you think that they a=
re
>     > essential for the work in ACE? I don't think so. I would leave th=
em aside.
>=20
> I would leave them there and say that they out of scope.
>=20
>     > Regarding requirement U1.8: "Messages between client and resource=
 server
>     > might need to be forwarded over multiple hops." Where did you der=
ive
>     > this requirement from? Who is the client and who is the resource =
server
>     > in this example?
>=20
> and what layer are the multiple hops?
> I think the point of this requirement is that we are assuming layer-3, =
IP
> networking, not, for instance, Bluetooth, for which there would be no
> authorization issues (because there is always only one owner in BT).

Your understanding of Bluetooth is incorrect.

Ciao
Hannes

>=20
>=20
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--FSO7JdQSTtXaclQejm0b4hg6jxFhdMkkv
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUga75AAoJEGhJURNOOiAtHqEH/2KWGUZS57tPnFSW6N3ZhZIW
DsVz1TQ5NppwZGDEUPLtMb4epCt8mht1h9Y9Fk5MPLb/GMARk36oC+wggtiyEGka
fM7GTBYnq3DItaz4DkOmre3Fov9vWVP6PvfUUOtDp3wX0kyv8Kyca/okxfHi8OlH
ed5UoFwgztYnwsVS3dVrxq+365tgIOhKwetNp09IRPDO6WIZmxwo6Zgnj3Ch7rOD
G/Fy/euxKhr+4+rhBwmB+I0D5GDgzfxHZQO50IKfcHtBY34k/tP49NuJVvFZdjAA
L/GhqVE8i67A3eqhinms3Egnq+Qe8cD+TbBoVaefss/XyhnPNHHs3XxShAeiSLg=
=6Op6
-----END PGP SIGNATURE-----

--FSO7JdQSTtXaclQejm0b4hg6jxFhdMkkv--


From nobody Fri Dec  5 07:35:31 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D97DD1ACEC9 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 07:35:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.349
X-Spam-Level: 
X-Spam-Status: No, score=0.349 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id swjOqiF4EBjf for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 07:35:27 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 16D481ACEC2 for <Ace@ietf.org>; Fri,  5 Dec 2014 07:35:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sB5FZLKO013337; Fri, 5 Dec 2014 16:35:21 +0100 (CET)
Received: from [134.102.218.239] (dynamic-218-9.informatik.uni-bremen.de [134.102.218.239]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3jvHzs3YYmz4v5N; Fri,  5 Dec 2014 16:35:21 +0100 (CET)
Message-ID: <5481D0B9.6020905@tzi.de>
Date: Fri, 05 Dec 2014 16:35:21 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "Ace@ietf.org" <Ace@ietf.org>
References: <54807796.7030504@gmx.net>
In-Reply-To: <54807796.7030504@gmx.net>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/HlLEF-YYxxhO92hTrr-_iimga7M
Subject: Re: [Ace] Container Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 15:35:30 -0000

Hi Hannes,

thank you for your feedback.

On 12/04/2014 04:02 PM, Hannes Tschofenig wrote:
> Hi all,
> 
> I read through the container use case and have a few questions.
> 
> The individual boxes (with bananas) are equipped with sensors and 
> these sensors communicate in a multi-hop fashion with each other
> to finally reach a gateway (at the container level). This gateway
> then has access to the Internet (sometimes, depending on where it
> is). Is this network setup roughly correct?

The boxes do not in every case want to access a server in the
Internet. An important part of the use case is the climate control
during shipments and in the ripening facilities. In this case, the
measurements of the sensors in the boxes (e.g. temperature or ethylene
sensors) are used to control the temperature of the goods.

It might not always be possible to reach servers in the Internet
during shipment. Therefore, recorded values might need to be stored
locally, at least until a connection is available. If a connection is
available there is not necessarily a need for anything other than an
IP router.

> 
> You are saying that the boxes (+their sensors) may belong to 
> different owners. Since it is relevant for the use case I think it 
> would be good to have a list of the persons that seek access to 
> different resources. The container itself may belong to a party 
> that is different from the owner of the box. Does the ownership of 
> the box change when it reaches the supermarket? I guess the 
> container will be sent back but I doubt that this is true for the 
> boxes?

I guess the ownership of the box will change. I will try to get more
information about this aspect.

> 
> It would be good to say whether you assume that the sensors upload 
> their data to different Internet servers or to the same and who 
> wants to get access to the data. I got a bit confused by the 
> terminology you introduced in Section 2.1.2 where you suddenly
> talk about "device owner" whereas the terminology talks about
> resource owner and the actual text refers to multiple owners
> (different owners for the different boxes, and for the containers).
> Then, there is also the supermarket ordered the goods and is
> supposed to own them afterwards.

For the climate control part of the use case, the banana box sensors
will communicate with the temperature regulation system, e.g. with the
fan next to them.

For locating goods of specific customers, the transloading personnel
will likely use devices which ask the sensors directly.

We used the term "device owner" instead of "resource owner" since
authorization might not only be needed to protect a resource but also
to protect a client. The owner of the client will want to decide if a
resource server is allowed to provide data and the owner of the
resource will want to make sure that only authorized entities are
allowed to request a resource.

> 
> Maybe there is also the possibility to be more specific about the 
> authorization challenges. For example, instead of saying "U1.1 The
>  device owner wants to grant different access rights to a resource 
> to different parties." you might want to state that "The owner of 
> the container grants read access the temperature information (?)
> to the truck company." (I don't know if that makes sense but it's
> just an example.) Since we talk about very specific use cases here
> we can also be specific in the challenges.

I am not sure if we want to go into this level of detail. I would
rather state the relevant problems and leave it to the implementers to
decide how exactly they want to solve them. Otherwise we might end up
with very specific solutions to a handful of use cases while slightly
different use cases cannot be addressed.

> 
> Requirements U1.4 and U1.5 are not authorization 
> requirements/challenges but communication security requirements.
> Do you think that they are essential for the work in ACE? I don't 
> think so. I would leave them aside.

The question is why we do authorization in the first place. Reasons
for authorization are to protect the integrity and confidentiality. If
we don't need either of these we won't need authorization.

> 
> Regarding requirement U1.8: "Messages between client and resource 
> server might need to be forwarded over multiple hops." Where did 
> you derive this requirement from? Who is the client and who is the 
> resource server in this example?

I am not sure if I understand that question. 2.1.1 states that because
of the high water content of the bananas, it might not be possible to
have a direct communication between two nodes. In this case, client
and resource server might also not be able to communicate directly.

Steffi


From nobody Fri Dec  5 08:52:57 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E1851AD051 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 08:52:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.15
X-Spam-Level: 
X-Spam-Status: No, score=-0.15 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ebeXG48y9Tan for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 08:52:53 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7DA3A1A8AFE for <Ace@ietf.org>; Fri,  5 Dec 2014 08:52:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sB5Gqn9k013747; Fri, 5 Dec 2014 17:52:49 +0100 (CET)
Received: from [134.102.218.239] (dynamic-218-9.informatik.uni-bremen.de [134.102.218.239]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3jvKjF55JYz4v7j; Fri,  5 Dec 2014 17:52:49 +0100 (CET)
Message-ID: <5481E2E1.2060703@tzi.de>
Date: Fri, 05 Dec 2014 17:52:49 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, Michael Richardson <mcr+ietf@sandelman.ca>, "Ace@ietf.org" <Ace@ietf.org>
References: <54807796.7030504@gmx.net> <8541.1417718621@sandelman.ca> <5481AEF9.2030109@gmx.net>
In-Reply-To: <5481AEF9.2030109@gmx.net>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/-m923ZO3RI94Slgjc9q8EsldJ1I
Subject: Re: [Ace] Container Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 16:52:55 -0000

Hi all,

On 12/05/2014 02:11 PM, Hannes Tschofenig wrote:
> Hi Michael,
> 
> thanks for sharing your views.
> 
> 
> On 12/04/2014 07:43 PM, Michael Richardson wrote:
>> 
>> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>> 
>>> You are saying that the boxes (+their sensors) may belong to
>>> different owners. Since it is relevant for the use case I think
>>> it would be good to have a list of the persons that seek access
>>> to different resources.
>> 
>> I think that this is incorrect; I think that the bananas belong
>> to different owners.  The boxes started off owned by the
>> producer, which is why the producer was able to arrange for them
>> to mesh together.  However, they producer wants to delegate
>> access to the sensors to different owners (of bananas).
> 
> Ok. This might be good to state since I don't see that anywhere. I
> am sure the producer may also keep track of the status while the
> shipments travel to the different owners (customers, like
> supermarket).

I think the boxes in a container will likely belong to single
customer. During the shipment to the ripening facility, the owner of
the boxes will likely still be the fruit vendor.

Steffi


From nobody Fri Dec  5 09:13:05 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A7E2F1A0164 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 09:13:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ThW5Z5lKex1H for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 09:12:59 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3B8491ACECE for <Ace@ietf.org>; Fri,  5 Dec 2014 09:12:59 -0800 (PST)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id F080F20098; Fri,  5 Dec 2014 12:16:24 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id 73F8C637F5; Fri,  5 Dec 2014 12:12:57 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 60A73637EA; Fri,  5 Dec 2014 12:12:57 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <5481AEF9.2030109@gmx.net>
References: <54807796.7030504@gmx.net> <8541.1417718621@sandelman.ca> <5481AEF9.2030109@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Fri, 05 Dec 2014 12:12:57 -0500
Message-ID: <23072.1417799577@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/3YVhVrCIOh22zrwtusWkD1UquBI
Cc: "Ace@ietf.org" <Ace@ietf.org>
Subject: Re: [Ace] Container Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 17:13:01 -0000

--=-=-=
Content-Transfer-Encoding: quoted-printable


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    >> > The container itself may belong to a party that is different from =
the
    >> > owner of the box. Does the ownership of the box change when it rea=
ches
    >> > the supermarket? I guess the container will be sent back but I dou=
bt
    >> > that this is true for the boxes?
    >>=20
    >> Does it matter if the boxes are recycled (firmware wiped/reset/etc.)=
 or if
    >> they are disposable?  As long as that process involves resetting thi=
ngs?

    > I think it is lifecycle issue. For example, if the boxes are indeed
    > change ownership to the supermarket then the producers should not have
    > access to the sensor data in the future. Right?

I don't know if the ownership changes, or if the boxes are returned to the
producer.  I don't know, but I think that it doesn't matter.=20=20
What I believe is that the bananas are removed from the boxes when they get
to the supermarket, and the boxes are "destroyed"=20

Maybe I'm wrong here, and they sit in the supermarket in the boxes in the
aisles.  Maybe the producer gets access further access, or maybe they do
not....   So I guess your point is correct that there is an end-of-lifecycle
issue, and a possible transfer of ownership.  It could be that the box is
destroyed, and the sensors are returned to the sensor-owning-consortium.

    >> > It would be good to say whether you assume that the sensors upload=
 their
    >> > data to different Internet servers or to the same and who wants to=
 get
    >> > access to the data. I got a bit confused by the terminology you
    >> > introduced in Section 2.1.2 where you suddenly talk about "device =
owner"
    >> > whereas the terminology talks about resource owner and the actual =
text
    >> > refers to multiple owners (different owners for the different boxe=
s, and
    >> > for the containers). Then, there is also the supermarket ordered t=
he
    >> > goods and is supposed to own them afterwards.
    >>=20
    >> My understanding is that a key thing about this use case is that the
    >> *container* needs access to the data, so that the *container* can ma=
ke sure
    >> the environment is correct.  (the truck, boat, train, etc. the conta=
iner is
    >> on)

    > Interesting. I didn't understood that this is the main use case. I
    > thought that the main point was that you get the data to the Internet
    > and that access to the data is provided from there to the different
    > stakeholders (supermarket, producer, etc.)

If the data could always go up to the Internet (live), then we could use
unconstrained OAUTH to provide access to the data.

    >> > Regarding requirement U1.8: "Messages between client and resource =
server
    >> > might need to be forwarded over multiple hops." Where did you deri=
ve
    >> > this requirement from? Who is the client and who is the resource s=
erver
    >> > in this example?

    >> and what layer are the multiple hops?
    >> I think the point of this requirement is that we are assuming layer-=
3, IP
    >> networking, not, for instance, Bluetooth, for which there would be no
    >> authorization issues (because there is always only one owner in BT).

    > Your understanding of Bluetooth is incorrect.

A BT can only pair with one other device.  You can not (sadly) mesh with it.
BTLE 4.1, can apparently, let you pair with multiple devices, but not
simultaneously.  I'm told that one can change in a matter of 10ms, so it
might be possible to do some kind of 6tisch-like scheduled mesh with BTLE.

Of course, we could run IP over BT, at which point, there could be multiple
hops involved, but that assumes we run a layer-3 protocol.  When I say using
BT and not doing "networking", I mean that the BT device would show up as a
straight rfcomm or microphone or something, and it would just spit data over
the virtual serial port/etc.=20=20

=2D-=20
]               Never tell me the odds!                 | ipv6 mesh network=
s [=20
]   Michael Richardson, Sandelman Software Works        | network architect=
  [=20
]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails  =
  [=20
=09

--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBVIHnmYCLcPvd0N1lAQJZEwgAleAZAT24jU53jqyK+MJ9EyBDw86C/BAr
SohcQzvONEUhFSYKJ3/gJ73p8TJYsmBgQSlPNcQV9/ku4unX6u3O4f15vTEarYuw
eCxkF2waSk8wqNW2yRTHfZ9hdFMQYxXjEj1xwpFOu7K1GmoxzGM13Zuk3D/x4YRI
a5S55V6grFEvWW57vWAWFp/BjA/zP3UZIOhAzOQp9nbZLQYBtP46hFLYjH1GTPOL
v1J04jXRjLRe3MeBcsKLlakXMWyDzIZpNXZ8v/2xWrotPObJmXfrG9NBU12yxHjy
UZpEF25NitFdN+duVff5K44KTTjILGU5lzjhLeZaaJYAnLcvfscjiw==
=ryM9
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Fri Dec  5 11:56:40 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B84511A00E1 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 11:56:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5XZiUy-m-ST6 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 11:56:36 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 335821AD8E8 for <Ace@ietf.org>; Fri,  5 Dec 2014 11:56:35 -0800 (PST)
Received: from [192.168.131.135] ([80.92.119.109]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0MZkNy-1YHOBZ1Jni-00LYFk; Fri, 05 Dec 2014 20:56:27 +0100
Message-ID: <54820DE9.5040800@gmx.net>
Date: Fri, 05 Dec 2014 20:56:25 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <54807796.7030504@gmx.net> <8541.1417718621@sandelman.ca> <5481AEF9.2030109@gmx.net> <23072.1417799577@sandelman.ca>
In-Reply-To: <23072.1417799577@sandelman.ca>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="LrKKUX6m2JHxMltBS9MlaQVc6JGFUMQNN"
X-Provags-ID: V03:K0:LbVlIhc5gVg5liCURkmiDYLK8xJ+mRFT7IRCtmqfTCFuLD9aNdM FgpzJ5F/DytM51SYzswYiMcnJYaW+nGFXN+g3B09FetRzGDp8wMu97AaCTaTZEI1KNzDdFU OCSmPbiCSQJAdW7NYX/M+IuL3mB8mVIvnDhfaN2NlxyhgaecpWCq7qA/7whlJB11boTeeJd 2FcLvYgvwSXgJp1MVCh5w==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/FrtFo19E6z_ldFFMfNYSukLS85s
Cc: "Ace@ietf.org" <Ace@ietf.org>
Subject: Re: [Ace] Container Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 19:56:38 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--LrKKUX6m2JHxMltBS9MlaQVc6JGFUMQNN
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Michael,

thanks again for the quick feedback.

On 12/05/2014 06:12 PM, Michael Richardson wrote:
>=20
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>     >> > The container itself may belong to a party that is different f=
rom the
>     >> > owner of the box. Does the ownership of the box change when it=
 reaches
>     >> > the supermarket? I guess the container will be sent back but I=
 doubt
>     >> > that this is true for the boxes?
>     >>=20
>     >> Does it matter if the boxes are recycled (firmware wiped/reset/e=
tc.) or if
>     >> they are disposable?  As long as that process involves resetting=
 things?
>=20
>     > I think it is lifecycle issue. For example, if the boxes are inde=
ed
>     > change ownership to the supermarket then the producers should not=
 have
>     > access to the sensor data in the future. Right?
>=20
> I don't know if the ownership changes, or if the boxes are returned to =
the
> producer.  I don't know, but I think that it doesn't matter. =20
> What I believe is that the bananas are removed from the boxes when they=
 get
> to the supermarket, and the boxes are "destroyed"=20
>=20
> Maybe I'm wrong here, and they sit in the supermarket in the boxes in t=
he
> aisles.  Maybe the producer gets access further access, or maybe they d=
o
> not....   So I guess your point is correct that there is an end-of-life=
cycle
> issue, and a possible transfer of ownership.  It could be that the box =
is
> destroyed, and the sensors are returned to the sensor-owning-consortium=
=2E

It would of course be nice to have (useful) examples where the ownership
of IoT devices changes. If this is not one of those cases that's fine as
well. Was just wondering because nothing was said about this topic.

>     >> > It would be good to say whether you assume that the sensors up=
load their
>     >> > data to different Internet servers or to the same and who want=
s to get
>     >> > access to the data. I got a bit confused by the terminology yo=
u
>     >> > introduced in Section 2.1.2 where you suddenly talk about "dev=
ice owner"
>     >> > whereas the terminology talks about resource owner and the act=
ual text
>     >> > refers to multiple owners (different owners for the different =
boxes, and
>     >> > for the containers). Then, there is also the supermarket order=
ed the
>     >> > goods and is supposed to own them afterwards.
>     >>=20
>     >> My understanding is that a key thing about this use case is that=
 the
>     >> *container* needs access to the data, so that the *container* ca=
n make sure
>     >> the environment is correct.  (the truck, boat, train, etc. the c=
ontainer is
>     >> on)
>=20
>     > Interesting. I didn't understood that this is the main use case. =
I
>     > thought that the main point was that you get the data to the Inte=
rnet
>     > and that access to the data is provided from there to the differe=
nt
>     > stakeholders (supermarket, producer, etc.)
>=20
> If the data could always go up to the Internet (live), then we could us=
e
> unconstrained OAUTH to provide access to the data.

Sure and that might be a good thing.

Another case would be that the data cannot always be sent to the
Internet and is instead cached in the meanwhile. Once Internet
connectivity is present then the data is uploaded.

I sort of read the use case in this way.

>     >> > Regarding requirement U1.8: "Messages between client and resou=
rce server
>     >> > might need to be forwarded over multiple hops." Where did you =
derive
>     >> > this requirement from? Who is the client and who is the resour=
ce server
>     >> > in this example?
>=20
>     >> and what layer are the multiple hops?
>     >> I think the point of this requirement is that we are assuming la=
yer-3, IP
>     >> networking, not, for instance, Bluetooth, for which there would =
be no
>     >> authorization issues (because there is always only one owner in =
BT).
>=20
>     > Your understanding of Bluetooth is incorrect.
>=20
> A BT can only pair with one other device.
>  You can not (sadly) mesh with it.
> BTLE 4.1, can apparently, let you pair with multiple devices, but not
> simultaneously.  I'm told that one can change in a matter of 10ms, so i=
t
> might be possible to do some kind of 6tisch-like scheduled mesh with BT=
LE.
>=20
> Of course, we could run IP over BT, at which point, there could be mult=
iple
> hops involved, but that assumes we run a layer-3 protocol.  When I say =
using
> BT and not doing "networking", I mean that the BT device would show up =
as a
> straight rfcomm or microphone or something, and it would just spit data=
 over
> the virtual serial port/etc. =20
>=20

Let us discuss the features of Bluetooth Smart in a separate thread
since it is not essential for the use case document.

Ciao
Hannes


--LrKKUX6m2JHxMltBS9MlaQVc6JGFUMQNN
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUgg3pAAoJEGhJURNOOiAtgJEH/3MqITQVnIC0ZauXEm/qqAN3
0vz510x+2ZPD2oym2EcMuZZXLrQ+LFDmQLArQrYOt6qixOqwDqk4K71dGxR0t4k0
+bYyd7FVdOPreconoROgGLvwnNPu1HNd0x/37qzgzjFt7EebGys7bjfv3N8eW0TM
1iJWRHlNEL+W/gmhQFA7i2TLmrgw73mOLymY3B71tHgEZ5U7GqawaUaWbWLeinvi
KiOaKjojWMTKC4iLzsQ/JrPrppkRaS/pn4m445QYavt4QL+wfrqOzVN03sOiCduf
Es1G442Q3rPHRTbwXU3KbCQVzwCNAmDHeZUifxzNvbMo91H76o1PRBe3RSVRcms=
=ydLm
-----END PGP SIGNATURE-----

--LrKKUX6m2JHxMltBS9MlaQVc6JGFUMQNN--


From nobody Fri Dec  5 12:04:29 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D2DD71AD8E3 for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 12:04:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gqGEpoY_Dd4C for <ace@ietfa.amsl.com>; Fri,  5 Dec 2014 12:04:18 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3DD1B1A008F for <Ace@ietf.org>; Fri,  5 Dec 2014 12:04:18 -0800 (PST)
Received: from [192.168.131.135] ([80.92.119.109]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0M5tof-1XmTQw22vJ-00xvjF; Fri, 05 Dec 2014 21:04:03 +0100
Message-ID: <54820FB2.8030608@gmx.net>
Date: Fri, 05 Dec 2014 21:04:02 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Stefanie Gerdes <gerdes@tzi.de>,  Michael Richardson <mcr+ietf@sandelman.ca>, "Ace@ietf.org" <Ace@ietf.org>
References: <54807796.7030504@gmx.net> <8541.1417718621@sandelman.ca> <5481AEF9.2030109@gmx.net> <5481E2E1.2060703@tzi.de>
In-Reply-To: <5481E2E1.2060703@tzi.de>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="ia41Alaun3LNQUugGWEECbQXaxQtw3g0c"
X-Provags-ID: V03:K0:NpejsymAtZox5KDlLdLyD3dr1wja4i+/nlGpfUexiSTtoAB/UIU Xbq+Ec6gHtLivqCSHLlmyIp95atBBksUbnDcJlMf0wpXR/yhY4j/GHxEIQVi+DTF5gZb03E k/t0eWW/CAfZyzQXqEofBDvFfGQ3Nnkd9fmJL0BqjNJZvihRtFHysMgS1I5a555fxmX+uM8 jf5qfnGlrVcBDL/IS69DA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Q_raInU2jLn9_DS9wxP-W2ZUUms
Subject: Re: [Ace] Container Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Dec 2014 20:04:27 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--ia41Alaun3LNQUugGWEECbQXaxQtw3g0c
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Stefanie,

thanks for your input.

On 12/05/2014 05:52 PM, Stefanie Gerdes wrote:
> I think the boxes in a container will likely belong to single
> customer. During the shipment to the ripening facility, the owner of
> the boxes will likely still be the fruit vendor.

I read this paragraph:

"
   Due to the high water content of the fruits, the propagation of radio
   waves is hindered, thus often inhibiting direct communication between
   nodes [Jedermann14].  Instead, messages are forwarded over multiple
   hops.  Those relaying nodes might belong to different owners.  The
   sensors in the banana boxes cannot always reach the internet during
   the journey.
"

I got the impression that the relay nodes are essentially the sensors at
the different boxes. And from the statement that the relay nodes belong
to different owners I concluded that the boxes belong to different owners=
=2E

Regardless what the story is I think there is room for better describing
the stakeholders and the ownership a bit better to illustrate which
entity communicates with whom and who asks for access to what data.

Ciao
Hannes


--ia41Alaun3LNQUugGWEECbQXaxQtw3g0c
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUgg+yAAoJEGhJURNOOiAt1bcIAKUr+D4NW0a/kGv5ozowgyFZ
i9C/hVcYRAFiOjys20OtcPjIfxoOsVurhS7UVRVGBJ0IehD/0o4hB1YK/PxD/joI
w+29i4HM22MMoTTfrF/pvlwkjTgQKcKCj8NCiB8O6UnpLqwPrkszkotcywz1X7WC
1DKrKSmyu4hZUNC0kmRWcCInWWqKhnt9FYsDNxodYSSrQY6ZMazqeDEU7Na7bQFj
6oNatMdSCXsp8CkSlUYfjYmt6uI7v00zJpKCybxU2cHHHiLUrDTwuv095bmTGHMO
QWqUydG+GCoj989QaWnh65w8iGUM+mQseTbcfKFs7DtUpqaHguQk7JSIaE7VgcU=
=EXfg
-----END PGP SIGNATURE-----

--ia41Alaun3LNQUugGWEECbQXaxQtw3g0c--


From nobody Sat Dec  6 04:12:34 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 37CFA1A8A0E for <ace@ietfa.amsl.com>; Sat,  6 Dec 2014 04:12:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.011
X-Spam-Level: 
X-Spam-Status: No, score=-0.011 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Fxs8Buyzt16f for <ace@ietfa.amsl.com>; Sat,  6 Dec 2014 04:12:28 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8FE4E1A0127 for <Ace@ietf.org>; Sat,  6 Dec 2014 04:12:27 -0800 (PST)
Received: from [192.168.131.135] ([80.92.119.109]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0Lwarz-1Xvbhm18al-018GOw for <Ace@ietf.org>; Sat, 06 Dec 2014 13:12:25 +0100
Message-ID: <5482F2A8.2090801@gmx.net>
Date: Sat, 06 Dec 2014 13:12:24 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="1QcdXiLvcjdx9Leq2qLl4nOgtcFMsc9wC"
X-Provags-ID: V03:K0:A/GlBQlxPclPGkzU3Zhwoj7ArJ3UzKTAxtmvp6a66bzKHCilvSf 7ubXS0H99Riel8LzaUxIjjczGQ5dTgeT1/kaXH4A+rwy87jJNHbfqG+B6jNLmJHjzcxYjZW iDs1lPXXdNu/GwgsA4R5LpPJiIIfa/CZz+9vn2K63wvqr7b073Nec5ogzGX8hTLK0AdFqF5 839hZ7WVLcnLiEeTU0FHA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/onwmCDAJRQ11Mx1p53UZleoaoes
Subject: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 06 Dec 2014 12:12:31 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--1QcdXiLvcjdx9Leq2qLl4nOgtcFMsc9wC
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

I read through the home automation case and I have a few remarks.


In Section 2.2.2. "Seamless Authorization" you write:

"
   Jane buys a new light bulb for the corridor and integrates it into
   the home network (how she does that is not in scope).  George is not
   at home, but Jane wants him to be able to control the new device with
   his smart phone without the need for additional administration
   effort.
"

Could you be a bit more specific about what is out of scope? I could
imagine that the way how Jane configures access control policies when
she integrates the light bulb into her home is quite similar to the way
how she would do that for George.

I am also wondering what you mean by "Jane wants him [George] to be able
to control the new device with his smart phone without the need for
additional administration effort.". I am sure it again requires some
configuration. It might not require any effort for George but someone
has to do that since otherwise how should the authorization server know
that it has to grant permissions to George to turn the light on or off.

In Section 2.2.3. you describe the case for remotely letting in a
visitor. Would it be possible to add a scenario that is less
sophisticated since this scenario requires some form of messaging
infrastructure to exist.

Here is what I have in mind:

-----

Jane and George have equipped their home with Internet connected door-loc=
ks.

Joe, a friend of George, frequently visits them and they would like to
give them access to their home. Once, when Joe was at their home George
uses his smart phone to create a digital access token. He
transfers that access token to Joe's phone using short range radio
communication technology. The token allows Joe to open the door.

Jane and George know that they can revoke access at any time and are
also able to modify the permissions with that access token. Joe is also
not able to use the obtained access token to mint new access tokens to
grant his friends to gain access to the house of Jane and George.

-----

I would delete this sentence from the description in Section 2.2.3 since
it is difficult to compare a regular door lock with the features of the
Internet connected door lock scenario currently described in that section=
=2E

"

   The security system controlling the door-locks and alarm system needs
   to be at least as secure as for a comparable unautomated home.
"

In Section 2.2.4. you describe the challenges of the presented use case.
You use the term "home owner" while the scenario talks about two
persons. I would either explain somewhere earlier that the two persons
are actually the owners (since you quite likely do not assume that there
only has to be one owner) or change the term home owner to Jane & George


In Section 2.2.4 you write "
  o  U2.4 A home owner wants to apply context-based conditions
      (presence, time) to authorizations, and the devices need to be
      able to verify these conditions.
"

I could not see how you got to this problem description from the use
cases. I think what you want to say is that
"George and Jane want to put time restrictions to the permissions they
grant to others."

I believe the following items are outside the scope of the work in ACE:

"
   o  U2.6 The access control configuration of the automated home needs
      to be secure by default.

Reason: I guess you want to have a default policy of deny at the
beginning. I don't think it will impact the technical work.


   o  U2.7 The access control policies need to be easy to edit, even
      remotely and it needs to be easy to get access with correct
      authorization.

This problems deals with the UI of the authorization policy editor and
this is clearly outside the scope of our work.

   o  U2.8 The owners of the automated home wants to prevent
      eavesdroppers form being able to deduce behavioral profiles from
      the home network.

I believe this item calls for a communication security solution. Right?

   o  U2.9 Usability is particularly important in this scenario since
      administrative tasks such as installation, configuration and
      decommissioning of devices likely need to be performed by the home
      owners who in most cases have little knowledge of security.

This again a UI issue.

   o  U2.10 Home Owners want their devices to seamlessly (and in some
      cases even unnoticeably) fulfill their purpose.  The
      administration effort needs to be kept at a minimum.

This calls partially for a good UI but also for a solid implementation.

"

Ciao
Hannes




--1QcdXiLvcjdx9Leq2qLl4nOgtcFMsc9wC
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUgvKoAAoJEGhJURNOOiAtA3MH/joIFRYg838qf8sm8TMGMq4C
Lvz3rNSN9ojBBdTNAXZzDOPrG6fEUi2K0mI2qyGRiYyo2xpiZ/pruiP6IJHXe5jS
0AbMoGvHwDIFAWdNyFTFC3lfKUWfyUZvEhSM16I+un3EJxFsRRFnwu3eRYRPP+T9
X4jneEBfxUgA3xg0nwWJH+N1MoaTXCu2fiPPIZ+J4bhfC6xRN+nlt4J49//aohlc
TRgyTIFLhq8WTEc9aHk2kJSGk4xnumBvJ+8pgue6xYMwSSBPsTw1YypmJKaDxo9e
cRZgjg6rIYoxSOJ/drb83NzMCkzqB/M/1AVfbFSiJf2IVh0GNq51+jhs+3HcT/8=
=H8W6
-----END PGP SIGNATURE-----

--1QcdXiLvcjdx9Leq2qLl4nOgtcFMsc9wC--


From nobody Sat Dec  6 04:58:00 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CC0F71A9040 for <ace@ietfa.amsl.com>; Sat,  6 Dec 2014 04:57:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.79
X-Spam-Level: 
X-Spam-Status: No, score=0.79 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BmCE9Pvd7Iqm for <ace@ietfa.amsl.com>; Sat,  6 Dec 2014 04:57:56 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 155411A903F for <Ace@ietf.org>; Sat,  6 Dec 2014 04:57:54 -0800 (PST)
Received: from [192.168.131.135] ([80.92.119.109]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0Lw2dd-1Xw8xe3tsb-017igE for <Ace@ietf.org>; Sat, 06 Dec 2014 13:57:52 +0100
Message-ID: <5482FD4F.70105@gmx.net>
Date: Sat, 06 Dec 2014 13:57:51 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="HXckArx8hwaTiUINI72We3NOmU2gfWoP9"
X-Provags-ID: V03:K0:4A+u3LzrTpJMK9pNPmd8xZvlK4WYFn48jGA8OyxXEREIzAipqJW lveXRpQXW38fVb/h6dfvlfiC4vz3vIBGkBZBGEN1oW3rj+FRzY6yVrhS+oaNqmYsP9KjhXj dU1sHLeruWgr6MAB8FPXypVYqs00pUk0WY2sVodkMNW12UIo9ZPxR8COSGIzplHlfzQqB0Z 0AcS0+eP5pbMFNSZU0q+A==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/8rIc7lxuPaWCko_JX_ZeUM0ksAY
Subject: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 06 Dec 2014 12:57:59 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--HXckArx8hwaTiUINI72We3NOmU2gfWoP9
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

I read through the personal health monitoring and have a few remarks

I would re-write the first paragraph to

"
he use of wearable technology for use with fitness and health monitoring
is growing strongly, as a multitude of novel devices are made available
to end customers.

The need for open industry standards to ensure interoperability between
products has lead to initiatives such as Continua Alliance
(continuaalliance.org) and Personal Connected Health Alliance
(pchalliance.org).

Personal fitness and health devices are typically battery powered, and
located physically on the users body to monitor heart rate, temperature,
blood pressure, movement, etc. They are typically connected to the
Internet through the use of smart phones. The uploaded data can be used
for Through this connection they report the monitored data is made
available to the user for measuring training success, monitor health
status, to alert emergency services personnel in case of problems, and
to motivate the user to improve their lifestyle. Data sharing to
friends, relatives, personal trainers and doctors is common.
"


"
   The HeartGuard also broadcasts emergency
   information in the neighborhood to notify doctors or people with
   certain skills who have been enrolled in an emergency program, e.g.
   people who got training in heart and lung rescue.  For doctors,
   medical information or diagnosis can be provided with the
   notification to improve immediate treatment.
"

How is this going to work? I guess it is more realistic to get help when
you call 1-1-2 or 9-1-1 than broadcasting beacons on Bluetooth or WiFi
for help (since others in close proximity need to have an application
listening for it). It is more likely that they will see you on the ground=
=2E


"
   The device includes some smart logic, with which it identifies its
   owner John and allows him to configure the device's settings,
   including access control.
   This prevents situation where someone else wearing that device can
   act as the owner and mess up the access control and security
   settings.
"

I guess by device you do not mean the heart rate monitor itself but
rather some other device. Typically, heart rate monitors are quite small
(since you often carry them around your chest). It would make sense if
the smart device is something like a smart phone since that also has a
display.

"
   However John is a rather private person, and is worried that Jill
   might use HeartGuard to monitor his location while there is no
   emergency.  Furthermore he doesn't want his health insurance to get
   access to the HeartGuard data, or even to the fact that he is wearing
   a HeartGuard, since they might refuse to renew his insurance if they
   decided he was too big a risk for them.
"

You should write "John is a privacy conscious persons and is worried
that Jill ...."


I also notice again the out-of-scope requirements for secure by default,
easy to use, etc.

Ciao
Hannes




--HXckArx8hwaTiUINI72We3NOmU2gfWoP9
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUgv1PAAoJEGhJURNOOiAtoH4H/iHDcPByiW46kiEUQco9j/Wc
ydx8vOwmDQe1pe9UtJ/H4uRr1jl3wf6bX0W+dwDE+lCqHinJnqCC7zXEhPbkZ0uW
KTw7hVv2yKKIx0vF11Px/90Z8lx2Xt3QTZw9ijd3xKEJHGH1QC4E2XdUt1ghVQiS
OnNqRhhMa94tPQNfirJKBfCilX2ph+LaWdh2v34DRXrrpXMp3afuCRnIZoG0aQcK
ReUc0uZit2UByohzd5rxXys+orqjU9bpFVkE84xQCmv1Xqwj/SVPrmihG0Pf7sSs
UvI33zeNU8C7lKUlxNe3VgDtyx1cGuwSMqjSfWgsaSSmaePFgueeHDqodDyx13Y=
=CrzD
-----END PGP SIGNATURE-----

--HXckArx8hwaTiUINI72We3NOmU2gfWoP9--


From nobody Sat Dec  6 06:26:32 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D7B01A0302 for <ace@ietfa.amsl.com>; Sat,  6 Dec 2014 06:26:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bMzFF7EfSVy9 for <ace@ietfa.amsl.com>; Sat,  6 Dec 2014 06:26:29 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 11BA11A0363 for <Ace@ietf.org>; Sat,  6 Dec 2014 06:26:29 -0800 (PST)
Received: from [192.168.131.135] ([80.92.119.109]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0MIuft-1XzCG33y0n-002bxZ for <Ace@ietf.org>; Sat, 06 Dec 2014 15:26:27 +0100
Message-ID: <54831212.8090002@gmx.net>
Date: Sat, 06 Dec 2014 15:26:26 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>
References: <5482FD4F.70105@gmx.net>
In-Reply-To: <5482FD4F.70105@gmx.net>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="22gGsjHRuRhnKblT9xh6CdMBd67WfX5s4"
X-Provags-ID: V03:K0:l8tVh2EkBkq5TPe1V70Ni3dQCsZVP1bzgEYS3griRGvU0jl+5CU 8IXA2u52z+25iy2NZoxC7tKmaAyvi1xTy2LXK41C6fsfPP+/YhHYZ/O6+aNxyTqVZOhHA5u lEKETW3veza/0z9e9xS5CRrQpJuCog6iY1OTUDTkrZSFOeACqBn+d5PbxSCIByCEdAF0fos +PeYtw8R6el7Hdv/7x0kQ==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/GSOWiFXoe4utazXK-IuK-ytrM30
Subject: Re: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 06 Dec 2014 14:26:31 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--22gGsjHRuRhnKblT9xh6CdMBd67WfX5s4
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

I wanted to add some thoughts about the use of health information for
emergency services situations.

Here is how this works today with a solution called Smart911 from Rave
Mobile Security (as it was explained to me by Mark Fletcher). To my
knowledge Smart911 has a pretty reasonable deployment in the US.

I call 911.

The PSAP takes my calling party number to the Smart 911 system and
queries the database.

Smart911 responds with my personal safety profile that I have created.
(Obviously, the PSAP needs to have software running to do all this.)

I can store anything there from floor plans to meds, emergency contacts,
etc. (This is the data described in the IETF ECRIT additional data work:
http://tools.ietf.org/html/draft-ietf-ecrit-additional-data-25)

Today, these systems do not provide ways to say "I am OK with sharing
the data with the emergency services system but don't share it with Dr. N=
o."

The reason is not so much about the complexity of the authorization
policies (or the lack of interest to configure policies in such a way)
but rather tied to the way how the emergency services system works with
the PSAP call takers and the largely independent first responders and
the rest of the healthcare infrastructure. It is all or nothing. That
makes also a lot of sense to give the emergency services system some
flexibility regarding my emergency response.

Hence, I believe this requirement is really sci-fi:

"
   o  U3.3 A device owner wants to block access to specific persons in
      an otherwise allowed group (e.g. doctors in an emergency), if he
      mistrusts them.
"

I would suggest to delete it or mark it as something nice to have in the
future when many other preconditions are fulfilled.

Ciao
Hannes


On 12/06/2014 01:57 PM, Hannes Tschofenig wrote:
> I read through the personal health monitoring and have a few remarks
>=20
> I would re-write the first paragraph to
>=20
> "
> he use of wearable technology for use with fitness and health monitorin=
g
> is growing strongly, as a multitude of novel devices are made available=

> to end customers.
>=20
> The need for open industry standards to ensure interoperability between=

> products has lead to initiatives such as Continua Alliance
> (continuaalliance.org) and Personal Connected Health Alliance
> (pchalliance.org).
>=20
> Personal fitness and health devices are typically battery powered, and
> located physically on the users body to monitor heart rate, temperature=
,
> blood pressure, movement, etc. They are typically connected to the
> Internet through the use of smart phones. The uploaded data can be used=

> for Through this connection they report the monitored data is made
> available to the user for measuring training success, monitor health
> status, to alert emergency services personnel in case of problems, and
> to motivate the user to improve their lifestyle. Data sharing to
> friends, relatives, personal trainers and doctors is common.
> "
>=20
>=20
> "
>    The HeartGuard also broadcasts emergency
>    information in the neighborhood to notify doctors or people with
>    certain skills who have been enrolled in an emergency program, e.g.
>    people who got training in heart and lung rescue.  For doctors,
>    medical information or diagnosis can be provided with the
>    notification to improve immediate treatment.
> "
>=20
> How is this going to work? I guess it is more realistic to get help whe=
n
> you call 1-1-2 or 9-1-1 than broadcasting beacons on Bluetooth or WiFi
> for help (since others in close proximity need to have an application
> listening for it). It is more likely that they will see you on the grou=
nd.
>=20
>=20
> "
>    The device includes some smart logic, with which it identifies its
>    owner John and allows him to configure the device's settings,
>    including access control.
>    This prevents situation where someone else wearing that device can
>    act as the owner and mess up the access control and security
>    settings.
> "
>=20
> I guess by device you do not mean the heart rate monitor itself but
> rather some other device. Typically, heart rate monitors are quite smal=
l
> (since you often carry them around your chest). It would make sense if
> the smart device is something like a smart phone since that also has a
> display.
>=20
> "
>    However John is a rather private person, and is worried that Jill
>    might use HeartGuard to monitor his location while there is no
>    emergency.  Furthermore he doesn't want his health insurance to get
>    access to the HeartGuard data, or even to the fact that he is wearin=
g
>    a HeartGuard, since they might refuse to renew his insurance if they=

>    decided he was too big a risk for them.
> "
>=20
> You should write "John is a privacy conscious persons and is worried
> that Jill ...."
>=20
>=20
> I also notice again the out-of-scope requirements for secure by default=
,
> easy to use, etc.
>=20
> Ciao
> Hannes
>=20
>=20
>=20
>=20
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--22gGsjHRuRhnKblT9xh6CdMBd67WfX5s4
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUgxISAAoJEGhJURNOOiAtgMoH/3LB3edKjQDRg1eyDwoNnEBx
5xKkECizX4UQ08ISLf7AWsXAknhOkeGlJQz+MA/3ktwVioHdEqRwthjWhrqLCLQ0
owRhyL8WR0HFhNY5RsPsTd/ZfBLTOfl5pdWPBZ+eHxoHDKMcK3hZ3tuxyNts1db7
N+4nrvX1Ed5s1fVPvnLnyRaOtbSjQP1FuQW72pnZPACmrIbt3duq717V0FVNfQk5
UH60YPATcoivEyNt0X0oWhz0yNCTYT5aKXIAXPAinq/wtMG+5MT1fR5UgidAEaWI
PLoWMY52RQ7OkeuQpA8SUNaj41Me4kzzGoGd88Vq7+LWNCXBYTvFS7B2+jMsdig=
=0JFH
-----END PGP SIGNATURE-----

--22gGsjHRuRhnKblT9xh6CdMBd67WfX5s4--


From nobody Mon Dec  8 01:08:09 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8C6CB1A871B for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 01:08:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.361
X-Spam-Level: 
X-Spam-Status: No, score=-0.361 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5MX92cmUB3yg for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 01:08:00 -0800 (PST)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id AC6111A1B45 for <ace@ietf.org>; Mon,  8 Dec 2014 01:07:59 -0800 (PST)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 64110313 for <ace@ietf.org>; Mon,  8 Dec 2014 10:07:58 +0100 (CET)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id sB897vuM015004 for <ace@ietf.org>; Mon, 8 Dec 2014 10:07:58 +0100
Received: from norm.sics.se (norm.sics.se [193.10.64.192]) by letter.sics.se (Postfix) with ESMTPS id 8639C40118 for <ace@ietf.org>; Mon,  8 Dec 2014 10:07:58 +0100 (CET)
Received: from [192.168.0.108] (unknown [85.235.11.178]) by norm.sics.se (Postfix) with ESMTPSA id D701E3E for <ace@ietf.org>; Mon,  8 Dec 2014 10:07:57 +0100 (CET)
Message-ID: <54856A6C.8080700@sics.se>
Date: Mon, 08 Dec 2014 10:07:56 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: ace@ietf.org
References: <5482F2A8.2090801@gmx.net>
In-Reply-To: <5482F2A8.2090801@gmx.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms060908000107090107060100"
X-Bayes-Prob: 0.9999 (Score 5, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7028; _longitude=3D13.1927; _http://maps.google.com/maps=3Fq=3D55.7028,13.1927&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09NoV7WL2 - 9afa880656ea - 20141208
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09NoV7WL2&m=9afa880656ea&t=20141208&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09NoV7WL2&m=9afa880656ea&t=20141208&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09NoV7WL2&m=9afa880656ea&t=20141208&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/8Y67Su-m5BteZDohEQ6OtXGQrMc
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Dec 2014 09:08:05 -0000

This is a cryptographically signed message in MIME format.

--------------ms060908000107090107060100
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/06/2014 01:12 PM, Hannes Tschofenig wrote:
> I read through the home automation case and I have a few remarks.
>
>
> In Section 2.2.2. "Seamless Authorization" you write:
>
> "
>     Jane buys a new light bulb for the corridor and integrates it into
>     the home network (how she does that is not in scope).  George is no=
t
>     at home, but Jane wants him to be able to control the new device wi=
th
>     his smart phone without the need for additional administration
>     effort.
> "
>
> Could you be a bit more specific about what is out of scope? I could
> imagine that the way how Jane configures access control policies when
> she integrates the light bulb into her home is quite similar to the way=

> how she would do that for George.

The exact procedure how the bulb is integrated into the home network is=20
out of scope for this document.  It might for example require Jane to=20
read a QR-code off the package of the bulb and set a few attributes for=20
the newly installed device (e.g. type=3Dlightbulb  location=3DlivingRoom)=
=2E

>
> I am also wondering what you mean by "Jane wants him [George] to be abl=
e
> to control the new device with his smart phone without the need for
> additional administration effort.". I am sure it again requires some
> configuration. It might not require any effort for George but someone
> has to do that since otherwise how should the authorization server know=

> that it has to grant permissions to George to turn the light on or off.=

>

I envision the following procedure: When the light bulb is installed, it =

will be configured as part of the lighting system of the house. Besides=20
enabling the bulb for the corresponding switches, it also makes all=20
existing access control policies apply to that bulb, including the ones=20
that gave George access to the old light bulb in that place.

Therefore "no additional administration effort" (besides the normal=20
installation procedure) is needed to give George access.


> In Section 2.2.3. you describe the case for remotely letting in a
> visitor. Would it be possible to add a scenario that is less
> sophisticated since this scenario requires some form of messaging
> infrastructure to exist.
>
> Here is what I have in mind:
>
> -----
>
> Jane and George have equipped their home with Internet connected door-l=
ocks.
>
> Joe, a friend of George, frequently visits them and they would like to
> give them access to their home. Once, when Joe was at their home George=

> uses his smart phone to create a digital access token. He
> transfers that access token to Joe's phone using short range radio
> communication technology. The token allows Joe to open the door.
>
> Jane and George know that they can revoke access at any time and are
> also able to modify the permissions with that access token. Joe is also=

> not able to use the obtained access token to mint new access tokens to
> grant his friends to gain access to the house of Jane and George.
>

Ok, I'll put that into the next update

> -----
>
> I would delete this sentence from the description in Section 2.2.3 sinc=
e
> it is difficult to compare a regular door lock with the features of the=

> Internet connected door lock scenario currently described in that secti=
on.
>
> "
>     The security system controlling the door-locks and alarm system nee=
ds
>     to be at least as secure as for a comparable unautomated home.
> "
>

Ok


> In Section 2.2.4. you describe the challenges of the presented use case=
=2E
> You use the term "home owner" while the scenario talks about two
> persons. I would either explain somewhere earlier that the two persons
> are actually the owners (since you quite likely do not assume that ther=
e
> only has to be one owner) or change the term home owner to Jane & Georg=
e
>
>
> In Section 2.2.4 you write "
>    o  U2.4 A home owner wants to apply context-based conditions
>        (presence, time) to authorizations, and the devices need to be
>        able to verify these conditions.
> "
>
> I could not see how you got to this problem description from the use
> cases. I think what you want to say is that
> "George and Jane want to put time restrictions to the permissions they
> grant to others."
>

Yes I was trying to generalize from "time restrictions" to other=20
context-based restrictions. I think originally we also had "presence" in =

mind, i.e. that certain users cannot turn on lights unless they are in=20
the right room. I will see if I can fit that into the description.

> I believe the following items are outside the scope of the work in ACE:=

>
> "
>     o  U2.6 The access control configuration of the automated home need=
s
>        to be secure by default.
>
> Reason: I guess you want to have a default policy of deny at the
> beginning. I don't think it will impact the technical work.
>
>
>     o  U2.7 The access control policies need to be easy to edit, even
>        remotely and it needs to be easy to get access with correct
>        authorization.
>
> This problems deals with the UI of the authorization policy editor and
> this is clearly outside the scope of our work.
>

Both correct, I'll remove them.


>     o  U2.8 The owners of the automated home wants to prevent
>        eavesdroppers form being able to deduce behavioral profiles from=

>        the home network.
>
> I believe this item calls for a communication security solution. Right?=


If I recall correctly, we introduced this as a reaction to comments,=20
that we also should address privacy concerns. Perhaps this would be=20
better addressed in the "Privacy Considerations" section.

>
>     o  U2.9 Usability is particularly important in this scenario since
>        administrative tasks such as installation, configuration and
>        decommissioning of devices likely need to be performed by the ho=
me
>        owners who in most cases have little knowledge of security.
>
> This again a UI issue.
>
>     o  U2.10 Home Owners want their devices to seamlessly (and in some
>        cases even unnoticeably) fulfill their purpose.  The
>        administration effort needs to be kept at a minimum.
>
> This calls partially for a good UI but also for a solid implementation.=

>
>


Thank you for your comments.


Regards,

Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms060908000107090107060100
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDEyMDgwOTA3NTZaMCMGCSqGSIb3DQEJBDEW
BBS4DjjEoaUCyiylyBQyM6SDXJ2f+TBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEALlPdutDZ1nWPICtvEmwb1MGKOJ1t48sIDa9WDtSGKH8hBnOCtg8fFjVwS5DfoIvyp47t
zVwgbYk8t9mTASgL7i8weSCnE8mabcFo0734SU/FlE5PWUi1+0dIs3Ymn6XFRffQBdIlbg2V
BGRblAFSBzMc9byUzi6BSpw/JCck/SQmqgVXwJOs6HCfz+Rc3KsTSbiKwKMWzqut7JBP0oza
ASU1y7+gWxnTNEjmsCbiRie37Qf6Gf1OomQ4QJ/bt3hSeXe547NxBU1gQK2qTMBBtp5lAEGZ
EDuAj/t1FI/OUFFu/F4GOFzjvX+WxRk79lpxquFPwzRkBt9yFOrCHgqjWQAAAAAAAA==
--------------ms060908000107090107060100--


From nobody Mon Dec  8 01:16:31 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B02BA1A871B for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 01:16:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.26
X-Spam-Level: 
X-Spam-Status: No, score=-2.26 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wEKO6uvYwCmd for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 01:16:25 -0800 (PST)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 590E01A1A28 for <ace@ietf.org>; Mon,  8 Dec 2014 01:16:25 -0800 (PST)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id B0D2D680 for <ace@ietf.org>; Mon,  8 Dec 2014 10:16:24 +0100 (CET)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id sB89GOdR019738 for <ace@ietf.org>; Mon, 8 Dec 2014 10:16:24 +0100
Received: from norm.sics.se (norm.sics.se [193.10.64.192]) by letter.sics.se (Postfix) with ESMTPS id 0AFAE40118 for <ace@ietf.org>; Mon,  8 Dec 2014 10:16:25 +0100 (CET)
Received: from [192.168.0.108] (unknown [85.235.11.178]) by norm.sics.se (Postfix) with ESMTPSA id 395A53E for <ace@ietf.org>; Mon,  8 Dec 2014 10:16:24 +0100 (CET)
Message-ID: <54856C67.1040604@sics.se>
Date: Mon, 08 Dec 2014 10:16:23 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: ace@ietf.org
References: <5482FD4F.70105@gmx.net>
In-Reply-To: <5482FD4F.70105@gmx.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms060408080207080308050102"
X-Bayes-Prob: 0.9999 (Score 5, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7028; _longitude=3D13.1927; _http://maps.google.com/maps=3Fq=3D55.7028,13.1927&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09NoVgo61 - a50a8f85622d - 20141208
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09NoVgo61&m=a50a8f85622d&t=20141208&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09NoVgo61&m=a50a8f85622d&t=20141208&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09NoVgo61&m=a50a8f85622d&t=20141208&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Hp7hab9szm0pOHbONgkb5ASlJsg
Subject: Re: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Dec 2014 09:16:28 -0000

This is a cryptographically signed message in MIME format.

--------------ms060408080207080308050102
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/06/2014 01:57 PM, Hannes Tschofenig wrote:
> I read through the personal health monitoring and have a few remarks
>
> I would re-write the first paragraph to
>
> "
> he use of wearable technology for use with fitness and health monitorin=
g
> is growing strongly, as a multitude of novel devices are made available=

> to end customers.
>
> The need for open industry standards to ensure interoperability between=

> products has lead to initiatives such as Continua Alliance
> (continuaalliance.org) and Personal Connected Health Alliance
> (pchalliance.org).
>
> Personal fitness and health devices are typically battery powered, and
> located physically on the users body to monitor heart rate, temperature=
,
> blood pressure, movement, etc. They are typically connected to the
> Internet through the use of smart phones. The uploaded data can be used=

> for Through this connection they report the monitored data is made
> available to the user for measuring training success, monitor health
> status, to alert emergency services personnel in case of problems, and
> to motivate the user to improve their lifestyle. Data sharing to
> friends, relatives, personal trainers and doctors is common.
> "
>
>
> "
>     The HeartGuard also broadcasts emergency
>     information in the neighborhood to notify doctors or people with
>     certain skills who have been enrolled in an emergency program, e.g.=

>     people who got training in heart and lung rescue.  For doctors,
>     medical information or diagnosis can be provided with the
>     notification to improve immediate treatment.
> "
>
> How is this going to work? I guess it is more realistic to get help whe=
n
> you call 1-1-2 or 9-1-1 than broadcasting beacons on Bluetooth or WiFi
> for help (since others in close proximity need to have an application
> listening for it). It is more likely that they will see you on the grou=
nd.
>

When I wrote that I was thinking that the device would have an Internet=20
connection through some intermediate device (e.g. the smartphone of the=20
individual carrying the device).

Are you thinking of a device that would have a SIM card and thus be=20
connected to the mobile network?

>
> "
>     The device includes some smart logic, with which it identifies its
>     owner John and allows him to configure the device's settings,
>     including access control.
>     This prevents situation where someone else wearing that device can
>     act as the owner and mess up the access control and security
>     settings.
> "
>
> I guess by device you do not mean the heart rate monitor itself but
> rather some other device. Typically, heart rate monitors are quite smal=
l
> (since you often carry them around your chest). It would make sense if
> the smart device is something like a smart phone since that also has a
> display.
>

That's actually a very interesting question: Do we consider the heart=20
rate monitor a stand-alone device, or does it need an additional (more=20
powerful) device to function?

If we consider the second case, how is the connection between the=20
monitor and the more powerful device secured?

I tried to get some feedback from the ECRIT WG at IETF 90 in order to=20
improve this use case, but I didn't get any response.


> "
>     However John is a rather private person, and is worried that Jill
>     might use HeartGuard to monitor his location while there is no
>     emergency.  Furthermore he doesn't want his health insurance to get=

>     access to the HeartGuard data, or even to the fact that he is weari=
ng
>     a HeartGuard, since they might refuse to renew his insurance if the=
y
>     decided he was too big a risk for them.
> "
>
> You should write "John is a privacy conscious persons and is worried
> that Jill ...."
>
>
> I also notice again the out-of-scope requirements for secure by default=
,
> easy to use, etc.

Ok



/Ludwig

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms060408080207080308050102
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDEyMDgwOTE2MjNaMCMGCSqGSIb3DQEJBDEW
BBQqXkmleJFvLkDRVTnZm/6yMD/tejBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEACJe8Qp0Stt/c6nVRu/OxRa/gVZT3+j4BiYf5KglgpzTv6q0EH9rYqeRWh5PtnKDfvbKU
xtCTmdqPUP8YlE5TGkGON3N4UIRcHZoFEoa+J/I/TsIkvIizNH8BIM+XHK7TN69iaBGdkI9F
2NXaN7I8pFxhQGUMpCOHgZQ414Nr4OSrK0OmStGBc4C+lN96U6ZwYcJzk1MaRezS5k8LDX6C
Qtifj9DQPlUGPKidFnStkvRFbbsKxYZKEFYfiQqcsZylBXKqJ9PovE7lYVg7uZnlbRGXr4Qe
hYyoMSnk7Ct7DhRH9p3xwnYQuzNds6u7OGs5Q7PJZKTSPG81bDaMOhXY3wAAAAAAAA==
--------------ms060408080207080308050102--


From nobody Mon Dec  8 01:21:12 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4123F1A8722 for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 01:21:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.26
X-Spam-Level: 
X-Spam-Status: No, score=-2.26 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oTn2SDI1CiDF for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 01:21:07 -0800 (PST)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 427CE1A871F for <ace@ietf.org>; Mon,  8 Dec 2014 01:21:07 -0800 (PST)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 9DB7864B for <ace@ietf.org>; Mon,  8 Dec 2014 10:21:06 +0100 (CET)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id sB89L6V0022190 for <ace@ietf.org>; Mon, 8 Dec 2014 10:21:06 +0100
Received: from norm.sics.se (norm.sics.se [193.10.64.192]) by letter.sics.se (Postfix) with ESMTPS id 4464F40118 for <ace@ietf.org>; Mon,  8 Dec 2014 10:21:06 +0100 (CET)
Received: from [192.168.0.108] (unknown [85.235.11.178]) by norm.sics.se (Postfix) with ESMTPSA id 2D6CA3E for <ace@ietf.org>; Mon,  8 Dec 2014 10:21:06 +0100 (CET)
Message-ID: <54856D80.1050709@sics.se>
Date: Mon, 08 Dec 2014 10:21:04 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: ace@ietf.org
References: <5482FD4F.70105@gmx.net> <54831212.8090002@gmx.net>
In-Reply-To: <54831212.8090002@gmx.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms050604050107070507060401"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7028; _longitude=3D13.1927; _http://maps.google.com/maps=3Fq=3D55.7028,13.1927&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09NoVl6hc - b27bda6b12b3 - 20141208
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09NoVl6hc&m=b27bda6b12b3&t=20141208&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09NoVl6hc&m=b27bda6b12b3&t=20141208&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09NoVl6hc&m=b27bda6b12b3&t=20141208&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/0l04tC0tAyHBi_Ocyp0zUkY4yTc
Subject: Re: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Dec 2014 09:21:09 -0000

This is a cryptographically signed message in MIME format.

--------------ms050604050107070507060401
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/06/2014 03:26 PM, Hannes Tschofenig wrote:

>
> Hence, I believe this requirement is really sci-fi:
>
> "
>     o  U3.3 A device owner wants to block access to specific persons in=

>        an otherwise allowed group (e.g. doctors in an emergency), if he=

>        mistrusts them.
> "
>
> I would suggest to delete it or mark it as something nice to have in th=
e
> future when many other preconditions are fulfilled.


It was actually a requirement in a Swedish patient-record management=20
system I once worked on. However I think it was never used in practice=20
and certainly not on constrained devices.

I'll delete this in the next update.

/Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms050604050107070507060401
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDEyMDgwOTIxMDRaMCMGCSqGSIb3DQEJBDEW
BBRMLkzlyt32Dctl1Uu4YBlus3nIMzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAekBqHMYatmX42pFPX9qCo2p+i4Cv3uP7po4MYZd2y8iWfDCIeO2kA6Gx7lPCWe64YI40
N7hJz3Loe7l6nAnis/A8hzvaK/oJmaCrgzRAEbqeSQsYj6hU3Clrj1M7M4OOpDWP2Pf0TaH1
ScvvfPUc1pSH2AyJThzkrEcP8/uHI5z7ftzkLbDP2av836S4qCbQpyND3V4PF0FuaCoP2vaR
jnk8C6hfqk6sbOiq2lPzaiXDKUhd6JO+q2gxAPW8idRLapD2dgKVgnm1L3HlVbVtyvtRQsMk
oAAIVdIACPyoOQp2mVodPJ1Wv29PzxefGYHDk3BZ+OqQPnkcxKuDM2ZVUAAAAAAAAA==
--------------ms050604050107070507060401--


From nobody Mon Dec  8 01:29:51 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE70C1A88BB for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 01:29:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uqL-k81qjtk4 for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 01:29:48 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BF2471A871F for <Ace@ietf.org>; Mon,  8 Dec 2014 01:29:47 -0800 (PST)
Received: from [192.168.131.135] ([80.92.119.109]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0LuPYt-1XoJZy2c1X-011lVJ; Mon, 08 Dec 2014 10:29:41 +0100
Message-ID: <54856F84.4040403@gmx.net>
Date: Mon, 08 Dec 2014 10:29:40 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="rU7qCuVoJolfw4Ue4rK3rI7qHNqt9xngf"
X-Provags-ID: V03:K0:6hR/aGRRuzRzaGNBhpRgvwTsoK60rIKmJJa5gfjYrF7IoOLdMQV 16Q10TpeVQzdeqx9iSW+lRzl+IBkVpV6NXmUmGeGY+tMVkNX6rbVosk1YPLbgjSIXdlb/yd DMKW8wCMVFrInPzhSZ2Hx7Ovqlr9VHnZtmiTRZFqzhp6O+7CKXDPXOgDtm77ApUToTiUjqi 8hbLuMHuYtIVYRM5U/EnA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/6Np7WLThKlCUo7DHlP3a6cHls7k
Cc: Eve Maler <eve@xmlgrrl.com>
Subject: [Ace] Webinar on "Kantara User-Managed Access (UMA)"
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Dec 2014 09:29:49 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--rU7qCuVoJolfw4Ue4rK3rI7qHNqt9xngf
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi all,

earlier this year we organized a couple of webinars to hear about ACE-
relevant technologies, including OAuth, Kerberos, and the
PKI/certificate model.

In a recent chat with Eve Maler, who co-chairs the Kantara User-Managed
Access (UMA) working group, she volunteered to explain their ongoing
work to us. Eve is employed by Forgerock, a company developing identity
management solutions, and has been working in the identity management
space for a very long time.

UMA is a profile and application of OAuth that defines how resource
owners can control resource access by clients operated by arbitrary
requesting parties, where the resources reside on any number of resource
servers, and where a centralized authorization server governs access
based on resource owner policy. Recent investigations have shown promise
for applying UMA to Internet of Things authorization use cases.

The webinar will take place on January 13th 2015 at 8am PST.

We are looking forward to hear from Eve.

Ciao
Hannes & Kepeng

---------

Here is the Webex meeting info.

Webex Link:
https://ietf.webex.com/ietf/j.php?MTID=3Dmf6d0740b7959df0377a74117c49a0ff=
3

Meeting #: 641 684 081
Meeting password: test

Join by phone:
+1-877-668-4493 Call-in toll free number (US/Canada)
+1-650-479-3208 Call-in toll number (US/Canada)
Access code: 641 684 081

(As mentioned during earlier calls, the IETF Webex bridge does not offer
other dial-in numbers. If you want to dial-in from remote please use
Skype or some other VoIP tool to keep the costs at a reasonable level.)

Add this meeting to your calendar:
https://ietf.webex.com/ietf/j.php?MTID=3Dmaca56e1e06cf3b2bc8322bd9a6d5afb=
a

We are planning to enable recording but we do not promise that it will
work since there have been problems with the IETF Webex configuration in
the past.


--rU7qCuVoJolfw4Ue4rK3rI7qHNqt9xngf
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUhW+EAAoJEGhJURNOOiAtfE4H/j9Ym/g9cLPSoRNKHmCCUm2D
9OFMtUfFV9MyPl3XU3UkqKWZ7UTmDw92HM3UCGxwSO40IRd8z6z8kvLOxVppxQne
03QnF41gyh8UVTaYHeVBbeWArIX+AAQxahu8DIT58QLEt7ZLCOrhA16gDitNJQKE
jigS4OuB/EAHXRAkqGEkFQvLljKWBqTQAiI8HdwqKLsMsCakfFdmQDUXXYSG8zw8
abV1UlD3RI5d54XHUf2BuGt9rsREdPPp8CVBKhOCo3bzgNzI5rfdGZeyysp7fjqX
l8r7G4flb7cGxYBIgM7nCNywdn1ePpq5+pkaarLgR0jFBEdkADeZpz2ux36VsP0=
=ZxWb
-----END PGP SIGNATURE-----

--rU7qCuVoJolfw4Ue4rK3rI7qHNqt9xngf--


From nobody Mon Dec  8 09:26:20 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 912B31AC42A for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 09:26:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level: 
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BcrDXTqe0WET for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 09:26:14 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 690F51ACCD9 for <ace@ietf.org>; Mon,  8 Dec 2014 09:26:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sB8HQBYh000562; Mon, 8 Dec 2014 18:26:11 +0100 (CET)
Received: from [192.168.1.147] (pD9F61968.dip0.t-ipconnect.de [217.246.25.104]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3jxBJM17mYz4vbM; Mon,  8 Dec 2014 18:26:11 +0100 (CET)
Message-ID: <5485DF32.8040002@tzi.de>
Date: Mon, 08 Dec 2014 18:26:10 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se>
In-Reply-To: <54856A6C.8080700@sics.se>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/ZYMwuHucm6Cl-_8lb9vUXvmEcjc
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Dec 2014 17:26:16 -0000

Hi all,

On 12/08/2014 10:07 AM, Ludwig Seitz wrote:
> On 12/06/2014 01:12 PM, Hannes Tschofenig wrote:

>>
>>
>>     o  U2.7 The access control policies need to be easy to edit, even
>>        remotely and it needs to be easy to get access with correct
>>        authorization.
>>
>> This problems deals with the UI of the authorization policy editor and
>> this is clearly outside the scope of our work.

I don't think we should dismiss UI problems so easily as not in scope.
An important limitation of constrained devices is that they may not have
any user interfaces. An authorization solution needs to deal with that fact.

Moreover, I don't think that this section is primarily about UI
problems. It states two problems: Remotely editing the authorization
policies and usability for authorized users. Maybe some rephrasing would
help.
How about:

U2.7.1 The home users want to be able to configure authorization
policies remotely.
U2.7.2 Home Users may have litte technical skills.
U2.7.3 Authorized users want to be able to obtain access with little effort.

>>
> 
> Both correct, I'll remove them.
> 
> 
>>     o  U2.8 The owners of the automated home wants to prevent
>>        eavesdroppers form being able to deduce behavioral profiles from
>>        the home network.
>>
>> I believe this item calls for a communication security solution. Right?
> 
> If I recall correctly, we introduced this as a reaction to comments,
> that we also should address privacy concerns. Perhaps this would be
> better addressed in the "Privacy Considerations" section.

I think privacy is essential to consider, especially for home use cases.
Therefore it is a good idea to mention it in the problem summary section
for the home automation use case.

I don't think it is a problem if the use case document states problems
that may be solved by a communication security solution. But I think it
is a problem if we don't see the relevant problems when we try to design
an authorization solution. I guess an authorization solution would use
communication security at some point, e.g. DTLS. So it would be helpful
to have in mind why we need it.

If we really don't want to address specific problems in ACE, we might
just say so. That might be more helpful than to pretend that some
problems are not there.

> 
>>
>>     o  U2.9 Usability is particularly important in this scenario since
>>        administrative tasks such as installation, configuration and
>>        decommissioning of devices likely need to be performed by the home
>>        owners who in most cases have little knowledge of security.
>>
>> This again a UI issue.

Usability is also essential to consider in home use cases since the
users may not have the technical knowledge to conduct complex security
configurations. It is important for an authorization solution to have
this problem in mind. I don't think that installation, configuration and
decommissiong of devices are simply UI problems.


Steffi


From nobody Mon Dec  8 09:33:27 2014
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 596EA1A1A82 for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 09:33:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level: 
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UtO-48NTadDU for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 09:33:25 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F06A11A1A56 for <ace@ietf.org>; Mon,  8 Dec 2014 09:33:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::b]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sB8HXMkB021050 for <ace@ietf.org>; Mon, 8 Dec 2014 18:33:22 +0100 (CET)
Received: from [IPv6:2002:5489:a14::4dfb:2795:7c5a:f225] (unknown [IPv6:2002:5489:a14:0:4dfb:2795:7c5a:f225]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3jxBSf0lP7z4vpB; Mon,  8 Dec 2014 18:33:22 +0100 (CET)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 8.1 \(1993\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <5485DF32.8040002@tzi.de>
Date: Mon, 8 Dec 2014 18:33:20 +0100
X-Mao-Original-Outgoing-Id: 439752800.566133-0237c8a19edb78bbbaa3187eb8a767e6
Content-Transfer-Encoding: quoted-printable
Message-Id: <5745E49D-E57B-4C2E-8678-4BD60FF5CED1@tzi.org>
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de>
To: Stefanie Gerdes <gerdes@tzi.de>
X-Mailer: Apple Mail (2.1993)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/SCdM3YT0TDASO9jG8wpX-ckDKZw
Cc: ace@ietf.org
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Dec 2014 17:33:26 -0000

On 08 Dec 2014, at 18:26, Stefanie Gerdes <gerdes@tzi.de> wrote:
>=20
> If we really don't want to address specific problems in ACE, we might
> just say so. That might be more helpful than to pretend that some
> problems are not there.

In particular, the use cases document is not the place for =
=E2=80=9Crequirements engineering=E2=80=9D, i.e., the changing of =
requirements until they fit the solution that somebody wants to promote.

Gr=C3=BC=C3=9Fe, Carsten


From nobody Mon Dec  8 23:56:29 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A39711A6EF1 for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 23:56:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.26
X-Spam-Level: 
X-Spam-Status: No, score=-2.26 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HAB3lZ60UHoR for <ace@ietfa.amsl.com>; Mon,  8 Dec 2014 23:56:25 -0800 (PST)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 7F3FD1A3BA4 for <ace@ietf.org>; Mon,  8 Dec 2014 23:56:24 -0800 (PST)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 09810680; Tue,  9 Dec 2014 08:56:23 +0100 (CET)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id sB97uMCE022322; Tue, 9 Dec 2014 08:56:22 +0100
Received: from norm.sics.se (norm.sics.se [193.10.64.192]) by letter.sics.se (Postfix) with ESMTPS id BE59A40118; Tue,  9 Dec 2014 08:56:22 +0100 (CET)
Received: from [192.168.0.108] (unknown [85.235.11.178]) by norm.sics.se (Postfix) with ESMTPSA id 386CA8D; Tue,  9 Dec 2014 08:56:22 +0100 (CET)
Message-ID: <5486AB1F.4060302@sics.se>
Date: Tue, 09 Dec 2014 08:56:15 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Stefanie Gerdes <gerdes@tzi.de>, ace@ietf.org
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de>
In-Reply-To: <5485DF32.8040002@tzi.de>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms000008090303050504080606"
X-Bayes-Prob: 0.5 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7028; _longitude=3D13.1927; _http://maps.google.com/maps=3Fq=3D55.7028,13.1927&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09NpjUmNg - b742f397e331 - 20141209
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09NpjUmNg&m=b742f397e331&t=20141209&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09NpjUmNg&m=b742f397e331&t=20141209&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09NpjUmNg&m=b742f397e331&t=20141209&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/8EtK8_3H8tVsG7KHsTlAyXNXeao
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Dec 2014 07:56:28 -0000

This is a cryptographically signed message in MIME format.

--------------ms000008090303050504080606
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/08/2014 06:26 PM, Stefanie Gerdes wrote:
> Hi all,
>
> On 12/08/2014 10:07 AM, Ludwig Seitz wrote:
>> On 12/06/2014 01:12 PM, Hannes Tschofenig wrote:
>
>>>
>>>
>>>      o  U2.7 The access control policies need to be easy to edit, eve=
n
>>>         remotely and it needs to be easy to get access with correct
>>>         authorization.
>>>
>>> This problems deals with the UI of the authorization policy editor an=
d
>>> this is clearly outside the scope of our work.
>
> I don't think we should dismiss UI problems so easily as not in scope.
> An important limitation of constrained devices is that they may not hav=
e
> any user interfaces. An authorization solution needs to deal with that =
fact.
>
> Moreover, I don't think that this section is primarily about UI
> problems. It states two problems: Remotely editing the authorization
> policies and usability for authorized users. Maybe some rephrasing woul=
d
> help.
> How about:
>
> U2.7.1 The home users want to be able to configure authorization
> policies remotely.
> U2.7.2 Home Users may have litte technical skills.
> U2.7.3 Authorized users want to be able to obtain access with little ef=
fort.
>

Alternatively we could dedicate a paragraph to UI problems and usability =

in the security considerations. I don't deny these are important=20
problems (and I don't think Hannes does either), but I'm unsure it is=20
within the scope of ACE to solve them.

>>>
>>
>> Both correct, I'll remove them.
>>
>>
>>>      o  U2.8 The owners of the automated home wants to prevent
>>>         eavesdroppers form being able to deduce behavioral profiles f=
rom
>>>         the home network.
>>>
>>> I believe this item calls for a communication security solution. Righ=
t?
>>
>> If I recall correctly, we introduced this as a reaction to comments,
>> that we also should address privacy concerns. Perhaps this would be
>> better addressed in the "Privacy Considerations" section.
>
> I think privacy is essential to consider, especially for home use cases=
=2E
> Therefore it is a good idea to mention it in the problem summary sectio=
n
> for the home automation use case.
>
> I don't think it is a problem if the use case document states problems
> that may be solved by a communication security solution. But I think it=

> is a problem if we don't see the relevant problems when we try to desig=
n
> an authorization solution. I guess an authorization solution would use
> communication security at some point, e.g. DTLS. So it would be helpful=

> to have in mind why we need it.
>
> If we really don't want to address specific problems in ACE, we might
> just say so. That might be more helpful than to pretend that some
> problems are not there.
>

I don't pretend these problems do not exist, I just suggested we move=20
the description to the Privacy Considerations section, in order to avoid =

bloating the use cases.


/Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms000008090303050504080606
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDEyMDkwNzU2MTVaMCMGCSqGSIb3DQEJBDEW
BBToMsvgvu03S/9qvZkoDokHrD48JTBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAR2ePITmUqhkAoUDnMecy84c8CF+M6wSp1n2gTDjhm/ghQbx/nXlaqji4SZENotHq9tmr
fhCq3qujADRCu8mvX8mm1KAm6DhIoMG3+Li4mX8N2KwgivO91DtRIp87pGyI5EU3Tnu039Qh
o/H7nifkH2R2Hi/NPSphNXHEcscfG6pxDJbcBwQ4m1YuPcJNqf3bmwWiWL9eZc0goyhXXaK5
TWRoSNm3g7v7js1gaAV0LIxpQ9Hi+o5Zcq7IwNpQSdhl5rLT7sQ2Bz7mZ+FpB2DvOE6sJw8V
hZpkciEaCBk38QPfoBV7oXaEwmXwit9ISKQJaWQN7fv4ZoExTUwxunwOigAAAAAAAA==
--------------ms000008090303050504080606--


From nobody Tue Dec  9 02:23:07 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3EC911A019B for <ace@ietfa.amsl.com>; Tue,  9 Dec 2014 02:23:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.549
X-Spam-Level: 
X-Spam-Status: No, score=-1.549 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, MSGID_FROM_MTA_HEADER=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K946N_eDXDB5 for <ace@ietfa.amsl.com>; Tue,  9 Dec 2014 02:23:05 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AEF2A1A016B for <ace@ietf.org>; Tue,  9 Dec 2014 02:23:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sB9AN0kt017750; Tue, 9 Dec 2014 11:23:00 +0100 (CET)
Message-Id: <201412091023.sB9AN0kt017750@mailhost.informatik.uni-bremen.de>
Received: from [192.168.1.246] (dynamic-218-7.informatik.uni-bremen.de [134.102.218.237]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3jxcsc3xNmz4v26; Tue,  9 Dec 2014 11:23:00 +0100 (CET)
Date: Tue, 09 Dec 2014 11:22:57 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
To: Ludwig Seitz <ludwig@sics.se>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: base64
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/b-Yaz8yWAZ3RiuInmLjwSzmITC0
Cc: ace@ietf.org
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Dec 2014 10:23:06 -0000

SGkgTHV3aWcsCgpBbSAwOS4xMi4yMDE0IDA4OjU2IHNjaHJpZWIgTHVkd2lnIFNlaXR6IDxsdWR3
aWdAc2ljcy5zZT46Cj4KPiBPbiAxMi8wOC8yMDE0IDA2OjI2IFBNLCBTdGVmYW5pZSBHZXJkZXMg
d3JvdGU6IAo+ID4gSGkgYWxsLCAKPiA+IAo+ID4gT24gMTIvMDgvMjAxNCAxMDowNyBBTSwgTHVk
d2lnIFNlaXR6IHdyb3RlOiAKPiA+PiBPbiAxMi8wNi8yMDE0IDAxOjEyIFBNLCBIYW5uZXMgVHNj
aG9mZW5pZyB3cm90ZTogCj4gPiAKPiA+Pj4gCj4gPj4+IAo+ID4+PsKgwqDCoMKgwqAgb8KgIFUy
LjcgVGhlIGFjY2VzcyBjb250cm9sIHBvbGljaWVzIG5lZWQgdG8gYmUgZWFzeSB0byBlZGl0LCBl
dmVuIAo+ID4+PsKgwqDCoMKgwqDCoMKgwqAgcmVtb3RlbHkgYW5kIGl0IG5lZWRzIHRvIGJlIGVh
c3kgdG8gZ2V0IGFjY2VzcyB3aXRoIGNvcnJlY3QgCj4gPj4+wqDCoMKgwqDCoMKgwqDCoCBhdXRo
b3JpemF0aW9uLiAKPiA+Pj4gCj4gPj4+IFRoaXMgcHJvYmxlbXMgZGVhbHMgd2l0aCB0aGUgVUkg
b2YgdGhlIGF1dGhvcml6YXRpb24gcG9saWN5IGVkaXRvciBhbmQgCj4gPj4+IHRoaXMgaXMgY2xl
YXJseSBvdXRzaWRlIHRoZSBzY29wZSBvZiBvdXIgd29yay4gCj4gPiAKPiA+IEkgZG9uJ3QgdGhp
bmsgd2Ugc2hvdWxkIGRpc21pc3MgVUkgcHJvYmxlbXMgc28gZWFzaWx5IGFzIG5vdCBpbiBzY29w
ZS4gCj4gPiBBbiBpbXBvcnRhbnQgbGltaXRhdGlvbiBvZiBjb25zdHJhaW5lZCBkZXZpY2VzIGlz
IHRoYXQgdGhleSBtYXkgbm90IGhhdmUgCj4gPiBhbnkgdXNlciBpbnRlcmZhY2VzLiBBbiBhdXRo
b3JpemF0aW9uIHNvbHV0aW9uIG5lZWRzIHRvIGRlYWwgd2l0aCB0aGF0IGZhY3QuIAo+ID4gCj4g
PiBNb3Jlb3ZlciwgSSBkb24ndCB0aGluayB0aGF0IHRoaXMgc2VjdGlvbiBpcyBwcmltYXJpbHkg
YWJvdXQgVUkgCj4gPiBwcm9ibGVtcy4gSXQgc3RhdGVzIHR3byBwcm9ibGVtczogUmVtb3RlbHkg
ZWRpdGluZyB0aGUgYXV0aG9yaXphdGlvbiAKPiA+IHBvbGljaWVzIGFuZCB1c2FiaWxpdHkgZm9y
IGF1dGhvcml6ZWQgdXNlcnMuIE1heWJlIHNvbWUgcmVwaHJhc2luZyB3b3VsZCAKPiA+IGhlbHAu
IAo+ID4gSG93IGFib3V0OiAKPiA+IAo+ID4gVTIuNy4xIFRoZSBob21lIHVzZXJzIHdhbnQgdG8g
YmUgYWJsZSB0byBjb25maWd1cmUgYXV0aG9yaXphdGlvbiAKPiA+IHBvbGljaWVzIHJlbW90ZWx5
LiAKPiA+IFUyLjcuMiBIb21lIFVzZXJzIG1heSBoYXZlIGxpdHRlIHRlY2huaWNhbCBza2lsbHMu
IAo+ID4gVTIuNy4zIEF1dGhvcml6ZWQgdXNlcnMgd2FudCB0byBiZSBhYmxlIHRvIG9idGFpbiBh
Y2Nlc3Mgd2l0aCBsaXR0bGUgZWZmb3J0LiAKPiA+IAo+Cj4gQWx0ZXJuYXRpdmVseSB3ZSBjb3Vs
ZCBkZWRpY2F0ZSBhIHBhcmFncmFwaCB0byBVSSBwcm9ibGVtcyBhbmQgdXNhYmlsaXR5IAo+IGlu
IHRoZSBzZWN1cml0eSBjb25zaWRlcmF0aW9ucy4gSSBkb24ndCBkZW55IHRoZXNlIGFyZSBpbXBv
cnRhbnQgCj4gcHJvYmxlbXMgKGFuZCBJIGRvbid0IHRoaW5rIEhhbm5lcyBkb2VzIGVpdGhlciks
IGJ1dCBJJ20gdW5zdXJlIGl0IGlzIAo+IHdpdGhpbiB0aGUgc2NvcGUgb2YgQUNFIHRvIHNvbHZl
IHRoZW0uCgpUaGUgdXNlIGNhc2VzIGRvY3VtZW50IGlzIG5vdCB0aGUgY2hhcnRlci4gSWYgd2Ug
YXJlIG5vdCBzdXJlIHdoZXRoZXIgYSBjZXJ0YWluIHByb2JsZW0gaXMgaW4gc2NvcGUgaXQgaXMg
YSBnb29kIGlkZWEgdG8gbWVudGlvbiBpdC4KClRoYXQgaG9tZSB1c2VycyBtYXkgaGF2ZSBsaXR0
bGUgdGVjaG5pY2FsIHNraWxscyBpcyBhIG1ham9yIHNlY3VyaXR5IHByb2JsZW0gaW4gaG9tZSBz
Y2VuYXJpb3MuIEkgY2FuJ3QgcmVhbGx5IGltYWdpbmUgdGhhdCBpdCB3b3VsZCBiZSBhIGdvb2Qg
aWRlYSB0byBkZXNpZ24gYSBzb2x1dGlvbiB3aXRob3V0IGJlaW5nIGF3YXJlIG9mIHRoaXMgcHJv
YmxlbS4gSSBkb24ndCBzZWUgYSByZWFzb24gdG8gb21pdCB0aGF0IGZhY3QgaW4gdGhlIHJlc3Bl
Y3RpdmUgdXNlIGNhc2VzLgoKVG8gYWRkaXRpb25hbGx5IG1lbnRpb24gdXNhYmlsaXR5IHByb2Js
ZW1zIGluIHRoZSBzZWN1cml0eSBjb25zaWRlcmF0aW9ucyBpcyBhIGdvb2QgaWRlYSwgdGhvdWdo
LiBXZSBhbHJlYWR5IGhhdmUgc29tZSB0ZXh0IGFib3V0IHRoYXQgaW4gMy4zLiBEbyB3ZSBuZWVk
IHRvIGV4dGVuZCBpdD8KCj4KPiA+Pj4gCj4gPj4gCj4gPj4gQm90aCBjb3JyZWN0LCBJJ2xsIHJl
bW92ZSB0aGVtLiAKPiA+PiAKPiA+PiAKPiA+Pj7CoMKgwqDCoMKgIG/CoCBVMi44IFRoZSBvd25l
cnMgb2YgdGhlIGF1dG9tYXRlZCBob21lIHdhbnRzIHRvIHByZXZlbnQgCj4gPj4+wqDCoMKgwqDC
oMKgwqDCoCBlYXZlc2Ryb3BwZXJzIGZvcm0gYmVpbmcgYWJsZSB0byBkZWR1Y2UgYmVoYXZpb3Jh
bCBwcm9maWxlcyBmcm9tIAo+ID4+PsKgwqDCoMKgwqDCoMKgwqAgdGhlIGhvbWUgbmV0d29yay4g
Cj4gPj4+IAo+ID4+PiBJIGJlbGlldmUgdGhpcyBpdGVtIGNhbGxzIGZvciBhIGNvbW11bmljYXRp
b24gc2VjdXJpdHkgc29sdXRpb24uIFJpZ2h0PyAKPiA+PiAKPiA+PiBJZiBJIHJlY2FsbCBjb3Jy
ZWN0bHksIHdlIGludHJvZHVjZWQgdGhpcyBhcyBhIHJlYWN0aW9uIHRvIGNvbW1lbnRzLCAKPiA+
PiB0aGF0IHdlIGFsc28gc2hvdWxkIGFkZHJlc3MgcHJpdmFjeSBjb25jZXJucy4gUGVyaGFwcyB0
aGlzIHdvdWxkIGJlIAo+ID4+IGJldHRlciBhZGRyZXNzZWQgaW4gdGhlICJQcml2YWN5IENvbnNp
ZGVyYXRpb25zIiBzZWN0aW9uLiAKPiA+IAo+ID4gSSB0aGluayBwcml2YWN5IGlzIGVzc2VudGlh
bCB0byBjb25zaWRlciwgZXNwZWNpYWxseSBmb3IgaG9tZSB1c2UgY2FzZXMuIAo+ID4gVGhlcmVm
b3JlIGl0IGlzIGEgZ29vZCBpZGVhIHRvIG1lbnRpb24gaXQgaW4gdGhlIHByb2JsZW0gc3VtbWFy
eSBzZWN0aW9uIAo+ID4gZm9yIHRoZSBob21lIGF1dG9tYXRpb24gdXNlIGNhc2UuIAo+ID4gCj4g
PiBJIGRvbid0IHRoaW5rIGl0IGlzIGEgcHJvYmxlbSBpZiB0aGUgdXNlIGNhc2UgZG9jdW1lbnQg
c3RhdGVzIHByb2JsZW1zIAo+ID4gdGhhdCBtYXkgYmUgc29sdmVkIGJ5IGEgY29tbXVuaWNhdGlv
biBzZWN1cml0eSBzb2x1dGlvbi4gQnV0IEkgdGhpbmsgaXQgCj4gPiBpcyBhIHByb2JsZW0gaWYg
d2UgZG9uJ3Qgc2VlIHRoZSByZWxldmFudCBwcm9ibGVtcyB3aGVuIHdlIHRyeSB0byBkZXNpZ24g
Cj4gPiBhbiBhdXRob3JpemF0aW9uIHNvbHV0aW9uLiBJIGd1ZXNzIGFuIGF1dGhvcml6YXRpb24g
c29sdXRpb24gd291bGQgdXNlIAo+ID4gY29tbXVuaWNhdGlvbiBzZWN1cml0eSBhdCBzb21lIHBv
aW50LCBlLmcuIERUTFMuIFNvIGl0IHdvdWxkIGJlIGhlbHBmdWwgCj4gPiB0byBoYXZlIGluIG1p
bmQgd2h5IHdlIG5lZWQgaXQuIAo+ID4gCj4gPiBJZiB3ZSByZWFsbHkgZG9uJ3Qgd2FudCB0byBh
ZGRyZXNzIHNwZWNpZmljIHByb2JsZW1zIGluIEFDRSwgd2UgbWlnaHQgCj4gPiBqdXN0IHNheSBz
by4gVGhhdCBtaWdodCBiZSBtb3JlIGhlbHBmdWwgdGhhbiB0byBwcmV0ZW5kIHRoYXQgc29tZSAK
PiA+IHByb2JsZW1zIGFyZSBub3QgdGhlcmUuIAo+ID4gCj4KPiBJIGRvbid0IHByZXRlbmQgdGhl
c2UgcHJvYmxlbXMgZG8gbm90IGV4aXN0LCBJIGp1c3Qgc3VnZ2VzdGVkIHdlIG1vdmUgCj4gdGhl
IGRlc2NyaXB0aW9uIHRvIHRoZSBQcml2YWN5IENvbnNpZGVyYXRpb25zIHNlY3Rpb24sIGluIG9y
ZGVyIHRvIGF2b2lkIAo+IGJsb2F0aW5nIHRoZSB1c2UgY2FzZXMuCgpTdGF0aW5nIHRoZSByZWxl
dmFudCBwcm9ibGVtcyBmb3IgYSB1c2UgY2FzZSBpcyBub3QgYmxvYXRpbmcuIEkgdGhpbmsgaXQg
aXMgYSBtaXN0YWtlIHRvIHJlbW92ZSByZWxldmFudCBwcm9ibGVtcyBmcm9tIHRoZSB1c2UgY2Fz
ZXMgc2VjdGlvbnMuCgpTdGVmZmkK


From nobody Tue Dec  9 03:20:42 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F05761A1BC7 for <ace@ietfa.amsl.com>; Tue,  9 Dec 2014 03:20:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.349
X-Spam-Level: 
X-Spam-Status: No, score=0.349 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CnzeMYwscYtY for <ace@ietfa.amsl.com>; Tue,  9 Dec 2014 03:20:37 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DBBBC1A1BB1 for <Ace@ietf.org>; Tue,  9 Dec 2014 03:20:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sB9BKXuv001900; Tue, 9 Dec 2014 12:20:33 +0100 (CET)
Received: from [134.102.218.239] (dynamic-218-9.informatik.uni-bremen.de [134.102.218.239]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3jxf812Y5Jz4tp2; Tue,  9 Dec 2014 12:20:33 +0100 (CET)
Message-ID: <5486DAFA.7090002@tzi.de>
Date: Tue, 09 Dec 2014 12:20:26 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "Ace@ietf.org" <Ace@ietf.org>
References: <5482FD4F.70105@gmx.net>
In-Reply-To: <5482FD4F.70105@gmx.net>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/iaZTe99QrkgXtee71J8wMwrlSpY
Subject: Re: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Dec 2014 11:20:38 -0000

Hi Hannes,

On 12/06/2014 01:57 PM, Hannes Tschofenig wrote:

> " The device includes some smart logic, with which it identifies
> its owner John and allows him to configure the device's settings, 
> including access control. This prevents situation where someone
> else wearing that device can act as the owner and mess up the
> access control and security settings. "
> 
> I guess by device you do not mean the heart rate monitor itself
> but rather some other device. Typically, heart rate monitors are
> quite small (since you often carry them around your chest). It
> would make sense if the smart device is something like a smart
> phone since that also has a display.

I think the heart rate monitor itself should be able to enforce
authorization policies of the owner. Otherwise the device would not be
able to decide if someone is supposed to access data on the device,
e.g. health data. Since privacy is a concern for medical data, only
authorized users should be able to access it.

> 
> " However John is a rather private person, and is worried that
> Jill might use HeartGuard to monitor his location while there is
> no emergency.  Furthermore he doesn't want his health insurance to
> get access to the HeartGuard data, or even to the fact that he is
> wearing a HeartGuard, since they might refuse to renew his
> insurance if they decided he was too big a risk for them. "
> 
> You should write "John is a privacy conscious persons and is
> worried that Jill ...."
> 
> 
> I also notice again the out-of-scope requirements for secure by
> default, easy to use, etc.

As I stated before, I don't think that usability is out of scope.
Neither is privacy.

Steffi


From nobody Thu Dec 11 05:33:03 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2E0131A1A20 for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 05:33:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.79
X-Spam-Level: 
X-Spam-Status: No, score=0.79 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZdX7h8lniaDp for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 05:33:00 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3E6971A1B45 for <Ace@ietf.org>; Thu, 11 Dec 2014 05:33:00 -0800 (PST)
Received: from [192.168.131.137] ([80.92.119.109]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0MMTZa-1Y2sou0btu-008Ndt; Thu, 11 Dec 2014 14:32:50 +0100
Message-ID: <54899D01.9050804@gmx.net>
Date: Thu, 11 Dec 2014 14:32:49 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Stefanie Gerdes <gerdes@tzi.de>, "Ace@ietf.org" <Ace@ietf.org>
References: <5482FD4F.70105@gmx.net> <5486DAFA.7090002@tzi.de>
In-Reply-To: <5486DAFA.7090002@tzi.de>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="DQ7mOh3Rcxcub3glwhQPOP9mqBQ1PURO5"
X-Provags-ID: V03:K0:bd1knSHjxzKB+vE8jfEyILvubytSagRUcCVcQOMQUTi4otL2TGH DYjB16MSMOxAMM15uFhVAZaVFt5BjN6Pu3FqAdx4wVJ+lelDk/URyYUsZZlZZM5a9DcbYal KYkGuA9qV8p9V8l0ioALn+dhW8rkK65PlFxlUvB3K9Peofro8eEGW4T0fBHeDeUq32J1YBf Zcwtyu38svRephJzUq2OQ==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/eXa8n11gRzi1nt1CntNJIpUkhNE
Subject: Re: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Dec 2014 13:33:02 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--DQ7mOh3Rcxcub3glwhQPOP9mqBQ1PURO5
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Steffi,

On 12/09/2014 12:20 PM, Stefanie Gerdes wrote:
> Hi Hannes,
>=20
> On 12/06/2014 01:57 PM, Hannes Tschofenig wrote:
>=20
>> " The device includes some smart logic, with which it identifies
>> its owner John and allows him to configure the device's settings,=20
>> including access control. This prevents situation where someone
>> else wearing that device can act as the owner and mess up the
>> access control and security settings. "
>>
>> I guess by device you do not mean the heart rate monitor itself
>> but rather some other device. Typically, heart rate monitors are
>> quite small (since you often carry them around your chest). It
>> would make sense if the smart device is something like a smart
>> phone since that also has a display.
>=20
> I think the heart rate monitor itself should be able to enforce
> authorization policies of the owner. Otherwise the device would not be
> able to decide if someone is supposed to access data on the device,
> e.g. health data. Since privacy is a concern for medical data, only
> authorized users should be able to access it.

It would be worthwhile to point this out in the document since this is
certainly quite different to the way how heart rate sensors work today.

Most of these types of appliances are using ANT/ANT+ and more recently
Bluetooth Smart to talk to some other device. The wireless connection is
basically a replacement for a pure wire since you could compare the
heart rate sensor with a computer mouse. The mouse gathers data but the
processing really happens at the device it is attached to. Since ANT and
Bluetooth Smart are short range radio technologies you need to have some
other device nearby.

The standards for these heart rate monitors are in fact quite
restrictive in terms of functionality. For example, the Bluetooth Smart
heart rate profile only allows a single instance of a Heart Rate Service
and multiple bonds are outside the scope of the spec.

So, the question is really whether there is any value to deviate from
the current use of the technology? If there is, then there might be
reasons for doing so. We should state them.

>> " However John is a rather private person, and is worried that
>> Jill might use HeartGuard to monitor his location while there is
>> no emergency.  Furthermore he doesn't want his health insurance to
>> get access to the HeartGuard data, or even to the fact that he is
>> wearing a HeartGuard, since they might refuse to renew his
>> insurance if they decided he was too big a risk for them. "
>>
>> You should write "John is a privacy conscious persons and is
>> worried that Jill ...."
>>
>>
>> I also notice again the out-of-scope requirements for secure by
>> default, easy to use, etc.
>=20
> As I stated before, I don't think that usability is out of scope.
> Neither is privacy.

The question for the standardization work is whether it will have an
impact on protocol interoperability. Usability as well as default
policies for security and privacy are important but they are not
something we would define in the specification.

Ciao
Hannes

>=20
> Steffi
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--DQ7mOh3Rcxcub3glwhQPOP9mqBQ1PURO5
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUiZ0BAAoJEGhJURNOOiAthpsH/Av2KPmRNTMUxqX8EhYnZaJ9
S6fVuOaywV5otcbAYhDTmzp8XqovKBNhvFA0A4Tgfl+VcnpxOO49jpa9NvBUxikY
7OTsAAYUijumPeoa5hUtMro/OMvA3TP88hMoI2DWdbxAxKNVdCGiXV8TbWD7ZXz8
QtbLE0sQ92JdNfOj+Rpth3r//vFq13mP2FUxpDQrrHila36CEo/LPrP10O6MCFpc
0mGeMJM9eFNSMPLcckjVDITkCIe8qjsamAd0JfvWI/qQfJ0mi5dZPpAPdlKUeSyr
h/lcd0vTViF5T1n9P2vf5oLh5C31jmNkrWHGOwKolr3k4dE2DDHIBhi6FgSrdOY=
=Szfy
-----END PGP SIGNATURE-----

--DQ7mOh3Rcxcub3glwhQPOP9mqBQ1PURO5--


From nobody Thu Dec 11 06:00:52 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 642671A896D for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:00:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.79
X-Spam-Level: 
X-Spam-Status: No, score=0.79 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yhWrmgjfkieC for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:00:41 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2B8E81A8963 for <ace@ietf.org>; Thu, 11 Dec 2014 06:00:41 -0800 (PST)
Received: from [192.168.131.137] ([80.92.119.109]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0MSv6D-1YQKUZ2f7V-00Ro9c; Thu, 11 Dec 2014 15:00:34 +0100
Message-ID: <5489A381.8080700@gmx.net>
Date: Thu, 11 Dec 2014 15:00:33 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se>
In-Reply-To: <54856A6C.8080700@sics.se>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="exV9O7d4e4efvegFLifXRMOmAoclGf09k"
X-Provags-ID: V03:K0:RjpE1SEQQD87w29+zNSguj8cFjFwTeMlG8Bu4F1ktIBVzUIbck4 9heV6zEaUi768YuS07dAkblXiUEuvaUBlqbyENS+EkfUQehE7nQzyNss1AxFSbVMjTdJGKV MTT270fq1ZWNuf9kryLsQiOvGeLnyvZbA+HrlvT+0V361N5MjWtQR0ulHRCecYdKyDSfpRw UTYLvmmAd+TVF1HmGQpgg==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/oZ_MVKq8lh-z7GhUXGmPswyQkzE
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Dec 2014 14:00:47 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--exV9O7d4e4efvegFLifXRMOmAoclGf09k
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Ludwig,


On 12/08/2014 10:07 AM, Ludwig Seitz wrote:
> On 12/06/2014 01:12 PM, Hannes Tschofenig wrote:
>> I read through the home automation case and I have a few remarks.
>>
>>
>> In Section 2.2.2. "Seamless Authorization" you write:
>>
>> "
>>     Jane buys a new light bulb for the corridor and integrates it into=

>>     the home network (how she does that is not in scope).  George is n=
ot
>>     at home, but Jane wants him to be able to control the new device w=
ith
>>     his smart phone without the need for additional administration
>>     effort.
>> "
>>
>> Could you be a bit more specific about what is out of scope? I could
>> imagine that the way how Jane configures access control policies when
>> she integrates the light bulb into her home is quite similar to the wa=
y
>> how she would do that for George.
>=20
> The exact procedure how the bulb is integrated into the home network is=

> out of scope for this document.  It might for example require Jane to
> read a QR-code off the package of the bulb and set a few attributes for=

> the newly installed device (e.g. type=3Dlightbulb  location=3DlivingRoo=
m).

This makes sense.



>>
>> I am also wondering what you mean by "Jane wants him [George] to be ab=
le
>> to control the new device with his smart phone without the need for
>> additional administration effort.". I am sure it again requires some
>> configuration. It might not require any effort for George but someone
>> has to do that since otherwise how should the authorization server kno=
w
>> that it has to grant permissions to George to turn the light on or off=
=2E
>>
>=20
> I envision the following procedure: When the light bulb is installed, i=
t
> will be configured as part of the lighting system of the house. Besides=

> enabling the bulb for the corresponding switches, it also makes all
> existing access control policies apply to that bulb, including the ones=

> that gave George access to the old light bulb in that place.
>=20
> Therefore "no additional administration effort" (besides the normal
> installation procedure) is needed to give George access.

This is useful additional information that the existing access control
policies are inherited by the newly installed lightbulb by the nature of
the device.

It is useful to state such assumptions because this is ensured by some
form of policy automation and the same might not apply to other users or
to other devices.


>=20
>=20
>> In Section 2.2.3. you describe the case for remotely letting in a
>> visitor. Would it be possible to add a scenario that is less
>> sophisticated since this scenario requires some form of messaging
>> infrastructure to exist.
>>
>> Here is what I have in mind:
>>
>> -----
>>
>> Jane and George have equipped their home with Internet connected
>> door-locks.
>>
>> Joe, a friend of George, frequently visits them and they would like to=

>> give them access to their home. Once, when Joe was at their home Georg=
e
>> uses his smart phone to create a digital access token. He
>> transfers that access token to Joe's phone using short range radio
>> communication technology. The token allows Joe to open the door.
>>
>> Jane and George know that they can revoke access at any time and are
>> also able to modify the permissions with that access token. Joe is als=
o
>> not able to use the obtained access token to mint new access tokens to=

>> grant his friends to gain access to the house of Jane and George.
>>
>=20
> Ok, I'll put that into the next update
>=20

Thanks.

>> -----
>>
>> I would delete this sentence from the description in Section 2.2.3 sin=
ce
>> it is difficult to compare a regular door lock with the features of th=
e
>> Internet connected door lock scenario currently described in that
>> section.
>>
>> "
>>     The security system controlling the door-locks and alarm system ne=
eds
>>     to be at least as secure as for a comparable unautomated home.
>> "
>>
>=20
> Ok
>=20
>=20
>> In Section 2.2.4. you describe the challenges of the presented use cas=
e.
>> You use the term "home owner" while the scenario talks about two
>> persons. I would either explain somewhere earlier that the two persons=

>> are actually the owners (since you quite likely do not assume that the=
re
>> only has to be one owner) or change the term home owner to Jane & Geor=
ge
>>
>>
>> In Section 2.2.4 you write "
>>    o  U2.4 A home owner wants to apply context-based conditions
>>        (presence, time) to authorizations, and the devices need to be
>>        able to verify these conditions.
>> "
>>
>> I could not see how you got to this problem description from the use
>> cases. I think what you want to say is that
>> "George and Jane want to put time restrictions to the permissions they=

>> grant to others."
>>
>=20
> Yes I was trying to generalize from "time restrictions" to other
> context-based restrictions. I think originally we also had "presence" i=
n
> mind, i.e. that certain users cannot turn on lights unless they are in
> the right room. I will see if I can fit that into the description.

Thanks.

>=20
>> I believe the following items are outside the scope of the work in ACE=
:
>>
>> "
>>     o  U2.6 The access control configuration of the automated home nee=
ds
>>        to be secure by default.
>>
>> Reason: I guess you want to have a default policy of deny at the
>> beginning. I don't think it will impact the technical work.
>>
>>
>>     o  U2.7 The access control policies need to be easy to edit, even
>>        remotely and it needs to be easy to get access with correct
>>        authorization.
>>
>> This problems deals with the UI of the authorization policy editor and=

>> this is clearly outside the scope of our work.
>>
>=20
> Both correct, I'll remove them.

Thanks.

>=20
>=20
>>     o  U2.8 The owners of the automated home wants to prevent
>>        eavesdroppers form being able to deduce behavioral profiles fro=
m
>>        the home network.
>>
>> I believe this item calls for a communication security solution. Right=
?
>=20
> If I recall correctly, we introduced this as a reaction to comments,
> that we also should address privacy concerns. Perhaps this would be
> better addressed in the "Privacy Considerations" section.

Makes sense.

>=20
>>
>>     o  U2.9 Usability is particularly important in this scenario since=

>>        administrative tasks such as installation, configuration and
>>        decommissioning of devices likely need to be performed by the h=
ome
>>        owners who in most cases have little knowledge of security.
>>
>> This again a UI issue.
>>
>>     o  U2.10 Home Owners want their devices to seamlessly (and in some=

>>        cases even unnoticeably) fulfill their purpose.  The
>>        administration effort needs to be kept at a minimum.
>>
>> This calls partially for a good UI but also for a solid implementation=
=2E
>>
>>
>=20
>=20
> Thank you for your comments.
>=20
>=20

Ciao
Hannes

> Regards,
>=20
> Ludwig
>=20
>=20
>=20
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--exV9O7d4e4efvegFLifXRMOmAoclGf09k
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUiaOBAAoJEGhJURNOOiAtvZsH/iDyem+2WZbyUwpzOBv2CDkR
/HAlCJailWkOZukDkR3DxEijAMFz0v6mcNm+16o84NqRtyVAzgcb6d3yVqbecUsg
rRpkHDYC1U+MOGNYV4qhOhNocYXb5qET+VCI7dNpWxR301UqThf9TZeMU1Xc6VI4
FpYW61b7S+jcc6525F3kMYO2emLe/sCSfbkkbHB4oXUColMO3ujypiWD5Uqfqk7t
/+ExvT8wWS2tDosay+j3EkJmrGRhuf4brSdOSnL7KIoUH1cy3Pq/vXUWfUlNd6U7
paAuCXvNEWG8Yvod6e4oz4QKgy4Q1Z+EUTClqQ4Nfq3zv6HKHtPG0OgC+1GjrKg=
=obYB
-----END PGP SIGNATURE-----

--exV9O7d4e4efvegFLifXRMOmAoclGf09k--


From nobody Thu Dec 11 06:11:09 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6DB01A895E for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:11:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.31
X-Spam-Level: 
X-Spam-Status: No, score=-1.31 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, J_CHICKENPOX_21=0.6, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Rc3cuW_zwEFR for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:11:03 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 97D661A1B65 for <ace@ietf.org>; Thu, 11 Dec 2014 06:11:02 -0800 (PST)
Received: from [192.168.131.137] ([80.92.119.109]) by mail.gmx.com (mrgmx001) with ESMTPSA (Nemesis) id 0LaXIV-1XXgFM0Kkx-00mIQs; Thu, 11 Dec 2014 15:10:47 +0100
Message-ID: <5489A5E5.10101@gmx.net>
Date: Thu, 11 Dec 2014 15:10:45 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Stefanie Gerdes <gerdes@tzi.de>, Ludwig Seitz <ludwig@sics.se>,  ace@ietf.org
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de>
In-Reply-To: <5485DF32.8040002@tzi.de>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="gTvasCwtb8cmITFbUcDIepJJHTpCl3WOn"
X-Provags-ID: V03:K0:zQpYiPk6BlQkl5/DnQRhQhYvQ9tQLm4T3Ri+VpBmcr4uVX49KC/ gplpe8qkTdwmTOYyUKKIZO6swavuoGt1QDxTwfUydOQa6KlRKCe/dZwyrcUe515alDESFOs Fu2DD5SUc9TzlncqJVZf6ZH7YRsZHHoPzJS3KdM6LVa06Qk0jXMMsze/PfmLRFJBVuZN1Gl 1h56/CZjC1DsZhMRkbkfg==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/6hht6ErQjI1-tu9nfqecthu-dx4
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Dec 2014 14:11:06 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--gTvasCwtb8cmITFbUcDIepJJHTpCl3WOn
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Steffi,



On 12/08/2014 06:26 PM, Stefanie Gerdes wrote:
> Hi all,
>=20
> On 12/08/2014 10:07 AM, Ludwig Seitz wrote:
>> On 12/06/2014 01:12 PM, Hannes Tschofenig wrote:
>=20
>>>
>>>
>>>     o  U2.7 The access control policies need to be easy to edit, even=

>>>        remotely and it needs to be easy to get access with correct
>>>        authorization.
>>>
>>> This problems deals with the UI of the authorization policy editor an=
d
>>> this is clearly outside the scope of our work.
>=20
> I don't think we should dismiss UI problems so easily as not in scope.
> An important limitation of constrained devices is that they may not hav=
e
> any user interfaces. An authorization solution needs to deal with that =
fact.
>=20
> Moreover, I don't think that this section is primarily about UI
> problems. It states two problems: Remotely editing the authorization
> policies and usability for authorized users. Maybe some rephrasing woul=
d
> help.
> How about:
>=20
> U2.7.1 The home users want to be able to configure authorization
> policies remotely.
> U2.7.2 Home Users may have litte technical skills.
> U2.7.3 Authorized users want to be able to obtain access with little ef=
fort.


I agree that the IoT device most likely does not have a UI but some
other device (like a smart phone or tablet) will and somehow the
policies need to be maintained at the authorization server.

We are not going standardize a UI for editing these policies. We could,
however, standardize an authorization policy language (like XACML) or
standardize the protocol that allows editing (such as WebDAV).

Currently, these things would be outside the ACE WG charter but that's
something that one could imagine. Is this your intention with these
requirements?


>=20
>>>
>>
>> Both correct, I'll remove them.
>>
>>
>>>     o  U2.8 The owners of the automated home wants to prevent
>>>        eavesdroppers form being able to deduce behavioral profiles fr=
om
>>>        the home network.
>>>
>>> I believe this item calls for a communication security solution. Righ=
t?
>>
>> If I recall correctly, we introduced this as a reaction to comments,
>> that we also should address privacy concerns. Perhaps this would be
>> better addressed in the "Privacy Considerations" section.
>=20
> I think privacy is essential to consider, especially for home use cases=
=2E
> Therefore it is a good idea to mention it in the problem summary sectio=
n
> for the home automation use case.
>=20
> I don't think it is a problem if the use case document states problems
> that may be solved by a communication security solution. But I think it=

> is a problem if we don't see the relevant problems when we try to desig=
n
> an authorization solution. I guess an authorization solution would use
> communication security at some point, e.g. DTLS. So it would be helpful=

> to have in mind why we need it.
>=20
> If we really don't want to address specific problems in ACE, we might
> just say so. That might be more helpful than to pretend that some
> problems are not there.
>=20

Ludwig suggested to discuss the topic in the privacy consideration
section and that appears to be the right place. The problem is, as I
mentioned, the scope of what we are trying to do in ACE. For example, if
you are concerned about the ability of a energy company to learn about
the use of home appliances by a household based on the reported energy
consumption then there is nothing in the scope of ACE we can do about
it. Even thought it is an interesting privacy aspect we still shouldn't
list it as a requirement for our work.


>>
>>>
>>>     o  U2.9 Usability is particularly important in this scenario sinc=
e
>>>        administrative tasks such as installation, configuration and
>>>        decommissioning of devices likely need to be performed by the =
home
>>>        owners who in most cases have little knowledge of security.
>>>
>>> This again a UI issue.
>=20
> Usability is also essential to consider in home use cases since the
> users may not have the technical knowledge to conduct complex security
> configurations. It is important for an authorization solution to have
> this problem in mind. I don't think that installation, configuration an=
d
> decommissiong of devices are simply UI problems.

The items marked as Ux.x should have something to do with the protocol
work we are doing. If there are protocol related implications in this
item then we should list them. If there aren't, then we need to move the
text somewhere else (or delete it).

Ciao
Hannes

>=20
>=20
> Steffi
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--gTvasCwtb8cmITFbUcDIepJJHTpCl3WOn
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUiaXlAAoJEGhJURNOOiAtP3cIAKcEYAjND+JdNezI7ZlrlZsY
ZbyAuhWCTVt4b8wpxXi1UcexpumNkkBeGX8k2g3EILV8NQYTEa4ID+gjD8XBvRoh
jNzLg67jthzNHkbxiU/ONsgu/c9k/BhBwSRWpOrp7aRjZjUSXHXNguNJLrgxADiF
yCl72R+ltQd86TFR3LxrWkTtnY2387d5DMfTmq1m3bbITWkDaZWlHU2fvTkxzsrQ
hdT905oNUu5aXYY65SsESLqd/brE3EyifIH/ZSMP3mFi3JWUa+pLuR5GAgCof1p+
KRhwHr76WBmaYRtlH4ETB4AwXxPaAeVutWGtgLBCmIKLgvKPct5hPJ8HnwJEBug=
=Odj6
-----END PGP SIGNATURE-----

--gTvasCwtb8cmITFbUcDIepJJHTpCl3WOn--


From nobody Thu Dec 11 06:14:03 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1379D1A0439 for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:14:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JwTcujCd-_cn for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:13:58 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D64791A03A9 for <ace@ietf.org>; Thu, 11 Dec 2014 06:13:57 -0800 (PST)
Received: from [192.168.131.137] ([80.92.119.109]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0LeNGL-1XbY3L2eXl-00qCtq; Thu, 11 Dec 2014 15:13:54 +0100
Message-ID: <5489A6A1.5020108@gmx.net>
Date: Thu, 11 Dec 2014 15:13:53 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Carsten Bormann <cabo@tzi.org>, Stefanie Gerdes <gerdes@tzi.de>
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de> <5745E49D-E57B-4C2E-8678-4BD60FF5CED1@tzi.org>
In-Reply-To: <5745E49D-E57B-4C2E-8678-4BD60FF5CED1@tzi.org>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="BejJ3p9sQRJbwPoGua6eQu8KEHGfiO7c2"
X-Provags-ID: V03:K0:Xh4i8tKAAMqVBT6LLwknKBbZxMvulT0sb58ks0LfhLv09l9186f i+gv0qRmt2/zAvpD+asdNYAiu+GaK41c17005aTJlmlkoyfOlJIG9jqQd36f/mjokHbqq4r AVYu7klbLtUpwH+EKLv/j9VIohs8jL2U/hITc+xzA7RbSntIm/giqoX1kXkK6he0WXUfcPx zsex+mBndtYpArZvFAVlA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/r00L66OR49pGGYyWK4RysAhMY7A
Cc: ace@ietf.org
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Dec 2014 14:14:01 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--BejJ3p9sQRJbwPoGua6eQu8KEHGfiO7c2
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi Carsten,

On 12/08/2014 06:33 PM, Carsten Bormann wrote:
> In particular, the use cases document is not the place for
> =E2=80=9Crequirements engineering=E2=80=9D, i.e., the changing of requi=
rements until
> they fit the solution that somebody wants to promote.

I still believe it is important to focus on problems we want to solve
and to label others as outside the scope (even though the are important).=


I fully agree that good user interfaces, built-in security, privacy by
default, etc. are important.

It does not make them worse if we say that they are outside the scope of
our standardization work (particularly if we know that we cannot solve
them as part of the standardization work we are doing).

Ciao
Hannes


--BejJ3p9sQRJbwPoGua6eQu8KEHGfiO7c2
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUiaahAAoJEGhJURNOOiAtrjwH/3dnwKRRuJULJMfdEFmNapgw
+VJvEeIxPdItgqLe1nHny7tHERBuMFwPia93uZQ3b8XCQfT6DvxRhVErCN347ABy
crG0Lrf7CabWy7Kp42C1vcDJe7SYHajHP842Cx/ew59SvK3eu9tbaPi7mL9T1mgW
AfsQSDUAPm8uzOb45iuHuzzHwV2sEWxDt4Gvs4Be/+ZgLatdFjLMIU46ACRBOD6T
xVBqHNi4YHmuiCV9Rckff/uUrfHUygbkdai1F2KJ/Hn7R4MOYIF8ItxIiyPqaHiQ
3TgKjWT1NRG0PZ8RWOTw+aRDQhv3qhiHo38Q5JLMA6Za9dayI9k+M8ScxRnzSOM=
=/mLm
-----END PGP SIGNATURE-----

--BejJ3p9sQRJbwPoGua6eQu8KEHGfiO7c2--


From nobody Thu Dec 11 06:16:31 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D2401A1A77 for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:16:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NDSsBTm9oWyN for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:16:26 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 372E81A0439 for <ace@ietf.org>; Thu, 11 Dec 2014 06:16:26 -0800 (PST)
Received: from [192.168.131.137] ([80.92.119.109]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0MHbpA-1Xxybz2m9k-003J31; Thu, 11 Dec 2014 15:16:23 +0100
Message-ID: <5489A736.8070702@gmx.net>
Date: Thu, 11 Dec 2014 15:16:22 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>, Stefanie Gerdes <gerdes@tzi.de>,  ace@ietf.org
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de> <5486AB1F.4060302@sics.se>
In-Reply-To: <5486AB1F.4060302@sics.se>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="QxUsVVueaNWTxCajj4RKqEHQt7RxhifXn"
X-Provags-ID: V03:K0:4y+jgr58t7W2eH2SZ3GSTwUjtyU4vnhVnk66Y4qkdwyVSiL2Ah8 BzcN+B0EOONRwkH6AzxXUstmyn0B6rlWEQ6pI7yhSrKN+LoBD7FqRMhCi419zhjq0Tp7XMn FqCrRSGPjIanLrUz2a2jAJjUYSVifQTq7Lmje5Ky3MlnNp3TMCy3RHFPO3YrnV4mqCyhIUN Mv5gw35W9Uk+GpvroAWSQ==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Zz044uIA1ExXerbcbYMQVRzneJw
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Dec 2014 14:16:28 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--QxUsVVueaNWTxCajj4RKqEHQt7RxhifXn
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Ludwig,

if you could add a section about user interface challenges to gather
existing text concerning UI aspects that would be good for me. One could
use that text as a call for help from the research community.

Ciao
Hannes


On 12/09/2014 08:56 AM, Ludwig Seitz wrote:
> On 12/08/2014 06:26 PM, Stefanie Gerdes wrote:
>> Hi all,
>>
>> On 12/08/2014 10:07 AM, Ludwig Seitz wrote:
>>> On 12/06/2014 01:12 PM, Hannes Tschofenig wrote:
>>
>>>>
>>>>
>>>>      o  U2.7 The access control policies need to be easy to edit, ev=
en
>>>>         remotely and it needs to be easy to get access with correct
>>>>         authorization.
>>>>
>>>> This problems deals with the UI of the authorization policy editor a=
nd
>>>> this is clearly outside the scope of our work.
>>
>> I don't think we should dismiss UI problems so easily as not in scope.=

>> An important limitation of constrained devices is that they may not ha=
ve
>> any user interfaces. An authorization solution needs to deal with that=

>> fact.
>>
>> Moreover, I don't think that this section is primarily about UI
>> problems. It states two problems: Remotely editing the authorization
>> policies and usability for authorized users. Maybe some rephrasing wou=
ld
>> help.
>> How about:
>>
>> U2.7.1 The home users want to be able to configure authorization
>> policies remotely.
>> U2.7.2 Home Users may have litte technical skills.
>> U2.7.3 Authorized users want to be able to obtain access with little
>> effort.
>>
>=20
> Alternatively we could dedicate a paragraph to UI problems and usabilit=
y
> in the security considerations. I don't deny these are important
> problems (and I don't think Hannes does either), but I'm unsure it is
> within the scope of ACE to solve them.
>=20
>>>>
>>>
>>> Both correct, I'll remove them.
>>>
>>>
>>>>      o  U2.8 The owners of the automated home wants to prevent
>>>>         eavesdroppers form being able to deduce behavioral profiles
>>>> from
>>>>         the home network.
>>>>
>>>> I believe this item calls for a communication security solution. Rig=
ht?
>>>
>>> If I recall correctly, we introduced this as a reaction to comments,
>>> that we also should address privacy concerns. Perhaps this would be
>>> better addressed in the "Privacy Considerations" section.
>>
>> I think privacy is essential to consider, especially for home use case=
s.
>> Therefore it is a good idea to mention it in the problem summary secti=
on
>> for the home automation use case.
>>
>> I don't think it is a problem if the use case document states problems=

>> that may be solved by a communication security solution. But I think i=
t
>> is a problem if we don't see the relevant problems when we try to desi=
gn
>> an authorization solution. I guess an authorization solution would use=

>> communication security at some point, e.g. DTLS. So it would be helpfu=
l
>> to have in mind why we need it.
>>
>> If we really don't want to address specific problems in ACE, we might
>> just say so. That might be more helpful than to pretend that some
>> problems are not there.
>>
>=20
> I don't pretend these problems do not exist, I just suggested we move
> the description to the Privacy Considerations section, in order to avoi=
d
> bloating the use cases.
>=20
>=20
> /Ludwig
>=20
>=20
>=20
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--QxUsVVueaNWTxCajj4RKqEHQt7RxhifXn
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUiac2AAoJEGhJURNOOiAtKUkIAJWVe5NhBIM+ElzsDcX8RuJJ
p67M8KAPC7gyLT39LV/jAeLyrhLXQjIzzDOIQWSKzQX4qhQt1ytN+I6vrfXHQaE7
IcjHFL+0ltfy+59g7c3bhPLud0HJbvlGlIOWFCfmQ7aTvKk+i2f7Ph9DAOfsxpb7
d7OW+DawtKjFykuf5HchFQq5L0xsezAI+EiUp/yeDGw276z98Z87vMSCipCEB0Xy
NblMdHtLpOyw7EjWpLvNawdHcep3XvD9vTlpHvZbzwXgeL9iEKsuuVNZ4BQwYEC5
uAqbjZb+npSY9OBVgHnnhGJB2RxIEIhgM//tDxGiwKjrgadbAkqYoTzwS5VDR98=
=tbvs
-----END PGP SIGNATURE-----

--QxUsVVueaNWTxCajj4RKqEHQt7RxhifXn--


From nobody Thu Dec 11 06:36:58 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 330821ACEF6 for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:36:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9Ww_118iIaXF for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 06:36:55 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B0E6E1ACEEE for <ace@ietf.org>; Thu, 11 Dec 2014 06:36:54 -0800 (PST)
Received: from [192.168.131.137] ([80.92.119.109]) by mail.gmx.com (mrgmx001) with ESMTPSA (Nemesis) id 0MUYnD-1YPmVX245j-00RKt8; Thu, 11 Dec 2014 15:36:40 +0100
Message-ID: <5489ABF7.8080104@gmx.net>
Date: Thu, 11 Dec 2014 15:36:39 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Carsten Bormann <cabo@tzi.org>, Stefanie Gerdes <gerdes@tzi.de>
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de> <5745E49D-E57B-4C2E-8678-4BD60FF5CED1@tzi.org>
In-Reply-To: <5745E49D-E57B-4C2E-8678-4BD60FF5CED1@tzi.org>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="Ndm6mTF7ug2xxnDMxsFx3usCCed0EMj8L"
X-Provags-ID: V03:K0:IWJisFy8muK5iQXc1BqVVcnJ4p4y+MzS8L+PPIHKPyJ25T5Ewel mp4CMlcAK/VzFdW9gJ7KdlPzgGW5gGwiKO7xO1IrfdsE0A5Kh5lys8Hbak27qPBHbLtB/CM zCQv1ndONlgEq+oEuC0mz3LkKCl/MCafAMlaeyDWEKz8Vjt6m3xmRm5EqyvXuJkLYLuhl/X zyJQzVWj2Dl/XodnaO8RA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/CTq4TcKlNB3eWNWFjFHlGzh-FW8
Cc: ace@ietf.org
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Dec 2014 14:36:57 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--Ndm6mTF7ug2xxnDMxsFx3usCCed0EMj8L
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi Carsten,

re-read this email and I think my earlier response was actually off-topic=
=2E

I believe the issue you raise is about the separation of the solution
from the actual use case description.

In an ideal world these would of course be completely separate but in
practical terms we are of course documenting user stories that assume a
certain architecture to be in place.

The case that Steffi raised earlier about the heart rate sensor is such
an example. You can, in the use case description, assume that the access
control would be done at the heart rate sensor or it could be done at
some other device.

We could, of course, keep the description at such an abstract level that
this difference vanishes but it will then also give us less input for
the work we are doing.

The discussion also raised the question how much we want to leverage
existing industry practices or whether we want to design new approaches.
The healthcare example with excluding certain doctors was an example in
that category of designing some new approaches.

I guess we will not able to able to come up with answers to those
questions but it is nevertheless useful for us to understand where we
standardize existing practices and were we are entering new territory.

I agree with you that we shouldn't tailor the use cases in such a way
that they fit our preferred solution. Of course, this will happen
nevertheless but we can at least try.

Ciao
Hannes

On 12/08/2014 06:33 PM, Carsten Bormann wrote:
> On 08 Dec 2014, at 18:26, Stefanie Gerdes <gerdes@tzi.de> wrote:
>>
>> If we really don't want to address specific problems in ACE, we might
>> just say so. That might be more helpful than to pretend that some
>> problems are not there.
>=20
> In particular, the use cases document is not the place for =E2=80=9Creq=
uirements engineering=E2=80=9D, i.e., the changing of requirements until =
they fit the solution that somebody wants to promote.
>=20
> Gr=C3=BC=C3=9Fe, Carsten
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--Ndm6mTF7ug2xxnDMxsFx3usCCed0EMj8L
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUiav3AAoJEGhJURNOOiAtYC4H/38hbIaxUp8yj9aj1LSXq3u1
a0NOpnRME+m+fuRUbXSdb3eoWpvKDv4bwCSQvnjjogi0h0Hk8wFIHwEDZahcN2NO
Rz7KP222p8PYsqt2z+WhxwByTOGTcTHheBSIayNUhP246vi9ybP/Bupb3qLqWmaD
tRmiZeOyVS4yL4Q/l0jj5NGmyj85NcRiOQ5/t7YJXSDBDxkSseyzUNpTdx20Tkal
wSiF6Ss4psY0j/JtUNuMImgXduNXDZDDzK4jylKHJvtPXgkNdUN8loJtuIpOvQwP
DE3FK3qzTfi1c3LstPHP6DW7AzJyPbUcCdilfHZEbNB55+b1WhpIpQD415LVybo=
=K0SX
-----END PGP SIGNATURE-----

--Ndm6mTF7ug2xxnDMxsFx3usCCed0EMj8L--


From nobody Thu Dec 11 18:44:59 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 29C601A878A for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 12:57:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.099
X-Spam-Level: 
X-Spam-Status: No, score=0.099 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, J_CHICKENPOX_72=0.6, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XKzAnkaWkZ9L for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 12:57:31 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 33C011A0066 for <ace@ietf.org>; Thu, 11 Dec 2014 12:57:31 -0800 (PST)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 163B820012; Thu, 11 Dec 2014 16:01:18 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id E2DFD637F5; Thu, 11 Dec 2014 15:57:28 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id CC097637F4; Thu, 11 Dec 2014 15:57:28 -0500 (EST)
From: Michael Richardson <mcr@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <5489A5E5.10101@gmx.net>
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de> <5489A5E5.10101@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Thu, 11 Dec 2014 15:57:28 -0500
Message-ID: <24639.1418331448@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/HWr_sgfz5gRVMFXsPxWJj-wzhqQ
X-Mailman-Approved-At: Thu, 11 Dec 2014 18:44:58 -0800
Cc: Stefanie Gerdes <gerdes@tzi.de>, Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
Subject: [Ace] privacy and ACE in the Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Dec 2014 20:57:33 -0000

--=-=-=


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    >>> If I recall correctly, we introduced this as a reaction to comments,
    >>> that we also should address privacy concerns. Perhaps this would be
    >>> better addressed in the "Privacy Considerations" section.

    >> I think privacy is essential to consider, especially for home use cases.
    >> Therefore it is a good idea to mention it in the problem summary section
    >> for the home automation use case.

...

    > Ludwig suggested to discuss the topic in the privacy consideration
    > section and that appears to be the right place. The problem is, as I
    > mentioned, the scope of what we are trying to do in ACE. For example, if
    > you are concerned about the ability of a energy company to learn about
    > the use of home appliances by a household based on the reported energy
    > consumption then there is nothing in the scope of ACE we can do about
    > it. Even thought it is an interesting privacy aspect we still shouldn't
    > list it as a requirement for our work.

a) It might be useful to have a use case that addresses the goals, even if only
   so that we can rule it out of scope.

b) so, I agree we can't do anything when the utility polls their meter to
   find out about my energy use.  There are existing situations, not captured
   in our Smart Meter use case.  The case I'm aware of comes from Floria,
   where the energy company sends out (an analog) signal that causes aircon
   systems in homes to turn of for awhile.  Essentially, it's a rolling
   selective blackout on cooling.
   https://www.clearlyenergy.com/residential-demand-response-programs

   so imagine the IoT post-ACE situation.  You want to authorize the power
   company to turn off your AC in your home. The layer-2/3 connectivity could
   be via your meter, or via your Internet connection.
   This part seems like a simple authorization process.

   But, the energy supplier might want to know if your device is on;
   afterall, if your device is not on, they won't save anything by turning it
   on.  Further,if there is a financial incentive to accepting this system,
   you might want to lie (the existing systems have a switch inline with the
   power supply to the chiller which the energy company controls).

So now we have a situation where the power company can monitor the on/off
status of a bunch of appliances.  Do you want to give them access to the
minute by minute data, or some other average situation?  The details do not
exactly matter... what I have in mind is that your privacy could be protected
if you can provide authorization for what appears to be resource "FOO",
but really, you have authorized access to resource "FOOPRIME", in a way
detectable to your device, but not detectable by others.

Possibly, the privacy situation is aided by providing for private aliases.
This might have no protocol  implications, only location implementation
issues, or maybe it has protocol implications.

--
]               Never tell me the odds!                 | ipv6 mesh networks [
]   Michael Richardson, Sandelman Software Works        | network architect  [
]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails    [





--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBVIoFOICLcPvd0N1lAQKIHwf7B8Pp8y2lcAyYXJiS0Xx9Ss0vj9yzNv6A
x117QE2s/ky95x38XR/UigKT2X5PA/aVnLLQhcYMW4z7U9wT+Sq0lHvbjNxjWxWy
F+yQD5eIMIGf2QA+yHS4Y+NznWSLALUc7sEEYe4EyrbDOr7m6CDh1ule2b20/cP1
ZyTasR2IXx1/1fKTd8YozveQeJREQyUrv26x55UFQ0aQXPeXCkjW9W0lZTW4tVAj
clmJKDvBmBmECqva3MqnyDZPhSBzYT+WVbgZFEXXOhIATlYcEy4tiXmvGabsqXwB
SiLk1u+G4Z49b2MZQzGqNJ0auEz6kY66RNl+1XEYZVFgRC6ReZNZKQ==
=3u7y
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Thu Dec 11 23:51:49 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BEBF71AC402 for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 23:51:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.31
X-Spam-Level: 
X-Spam-Status: No, score=-1.31 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, J_CHICKENPOX_72=0.6, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MhSIHQ0UBsV0 for <ace@ietfa.amsl.com>; Thu, 11 Dec 2014 23:51:46 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C2801AC415 for <ace@ietf.org>; Thu, 11 Dec 2014 23:51:46 -0800 (PST)
Received: from [192.168.131.137] ([80.92.119.109]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0LpKrt-1XVkxR0dGP-00f7ro; Fri, 12 Dec 2014 08:51:28 +0100
Message-ID: <548A9E7E.6080401@gmx.net>
Date: Fri, 12 Dec 2014 08:51:26 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Michael Richardson <mcr@sandelman.ca>
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de> <5489A5E5.10101@gmx.net> <24639.1418331448@sandelman.ca>
In-Reply-To: <24639.1418331448@sandelman.ca>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="tKD0A91IB9STXNbWig8GWCmIo5DjK6Cc8"
X-Provags-ID: V03:K0:zDZjC7gVP++yiYViDt5fH3K296RO8E1iU0y1xOQpCUkCdsFCM3+ XcG5Y58hg6LauhhtM2gt8U9yMHZRKVyAs5rqRKcZ1lZZCLQWR4lRjKoYfqwehDMpEGJnVjE uUDWfKk6jq2HMIa30jyAm/CIqzYaGV+2tMmuWbBggpeO/iMBMQbvPD36ml1PfQMwXCH+mIt MHChXHkoPP02UV4ksdvtA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/4KQbhA7A4pjJmHkGddHetuK8mfQ
Cc: Stefanie Gerdes <gerdes@tzi.de>, Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
Subject: Re: [Ace] privacy and ACE in the Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Dec 2014 07:51:49 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--tKD0A91IB9STXNbWig8GWCmIo5DjK6Cc8
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Michael,

thanks for your feedback.


On 12/11/2014 09:57 PM, Michael Richardson wrote:
>=20
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>     >>> If I recall correctly, we introduced this as a reaction to comm=
ents,
>     >>> that we also should address privacy concerns. Perhaps this woul=
d be
>     >>> better addressed in the "Privacy Considerations" section.
>=20
>     >> I think privacy is essential to consider, especially for home us=
e cases.
>     >> Therefore it is a good idea to mention it in the problem summary=
 section
>     >> for the home automation use case.
>=20
> ...
>=20
>     > Ludwig suggested to discuss the topic in the privacy consideratio=
n
>     > section and that appears to be the right place. The problem is, a=
s I
>     > mentioned, the scope of what we are trying to do in ACE. For exam=
ple, if
>     > you are concerned about the ability of a energy company to learn =
about
>     > the use of home appliances by a household based on the reported e=
nergy
>     > consumption then there is nothing in the scope of ACE we can do a=
bout
>     > it. Even thought it is an interesting privacy aspect we still sho=
uldn't
>     > list it as a requirement for our work.
>=20
> a) It might be useful to have a use case that addresses the goals, even=
 if only
>    so that we can rule it out of scope.
>=20
> b) so, I agree we can't do anything when the utility polls their meter =
to
>    find out about my energy use.  There are existing situations, not ca=
ptured
>    in our Smart Meter use case.  The case I'm aware of comes from Flori=
a,
>    where the energy company sends out (an analog) signal that causes ai=
rcon
>    systems in homes to turn of for awhile.  Essentially, it's a rolling=

>    selective blackout on cooling.
>    https://www.clearlyenergy.com/residential-demand-response-programs
>=20
>    so imagine the IoT post-ACE situation.  You want to authorize the po=
wer
>    company to turn off your AC in your home. The layer-2/3 connectivity=
 could
>    be via your meter, or via your Internet connection.
>    This part seems like a simple authorization process.

This use case seems relevant for our authorization work.

I was, however, more thinking about a scenario where the energy
companies learns about detailed device use through the data collected
via smart metering, as shown in this figure:
http://spectrum.ieee.org/image/1711246


>=20
>    But, the energy supplier might want to know if your device is on;
>    afterall, if your device is not on, they won't save anything by turn=
ing it
>    on.  Further,if there is a financial incentive to accepting this sys=
tem,
>    you might want to lie (the existing systems have a switch inline wit=
h the
>    power supply to the chiller which the energy company controls).
>=20
> So now we have a situation where the power company can monitor the on/o=
ff
> status of a bunch of appliances.  Do you want to give them access to th=
e
> minute by minute data, or some other average situation?  The details do=
 not
> exactly matter... what I have in mind is that your privacy could be pro=
tected
> if you can provide authorization for what appears to be resource "FOO",=

> but really, you have authorized access to resource "FOOPRIME", in a way=

> detectable to your device, but not detectable by others.

To protect against the leakage of individual device usage aggregation
helps. Your example sounds a bit like aggregation of resources to me.

If aggregation is the solution then one could think about providing
features in the access control system that deny too regular read
requests (since the aggregation interval would be too small) or just
return the same value within the given time period.

>=20
> Possibly, the privacy situation is aided by providing for private alias=
es.
> This might have no protocol  implications, only location implementation=

> issues, or maybe it has protocol implications.
I don't think that this will help since you have a nailed-up connection
with your energy company and since the energy company wants to know you
(since they have to charge you) a pseudonym would only help for someone
looking on the messages transmitted over the wire. We are, however,
assuming communication security using DTLS/TLS for most of these
applications.

Ciao
Hannes

> --
> ]               Never tell me the odds!                 | ipv6 mesh net=
works [
> ]   Michael Richardson, Sandelman Software Works        | network archi=
tect  [
> ]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rai=
ls    [
>=20
>=20
>=20
>=20
>=20
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--tKD0A91IB9STXNbWig8GWCmIo5DjK6Cc8
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUip5+AAoJEGhJURNOOiAtH7cH/0ZOLxTvk7snTIqz+dggqZqU
V8KCZ3S7wignu9zfW9F/XwKTccw4YepfW5Cr8vSit2e/SSv0fPQtJlI/t5wP4e04
RuWgfOPxPwl+SLYPN+gsRaRmXfynrgU4vntIHGLrC51i2MhLdTLTYvVW0Il2KrRi
DQn2MtIPrbNxZZrEF2wpgEQspIjj7LbeQmCVOX117JQK9f0IfYFnJ6Z7R2ERK8IC
lGohsQX4cJsYqwAp98hXiK/+iFPpa54EkJEVzUIV9agKoIrxpS6Gb/mU13jwECkt
0Fxj6VeaECNTN65OkXULs07Lc1ekmWvv8sbvkPz2fRQe7vkJsSJ11UzmgPrGUOY=
=KPBT
-----END PGP SIGNATURE-----

--tKD0A91IB9STXNbWig8GWCmIo5DjK6Cc8--


From nobody Fri Dec 12 05:29:30 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0ABF81A1B07 for <ace@ietfa.amsl.com>; Fri, 12 Dec 2014 05:29:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level: 
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SWUUKVYGOmye for <ace@ietfa.amsl.com>; Fri, 12 Dec 2014 05:29:26 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 78EFE1A1EEA for <Ace@ietf.org>; Fri, 12 Dec 2014 05:29:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::b]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sBCDTLCg022745; Fri, 12 Dec 2014 14:29:21 +0100 (CET)
Received: from [134.102.218.219] (dynamic-218-t.informatik.uni-bremen.de [134.102.218.219]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3jzXsF5DGmz7wK2; Fri, 12 Dec 2014 14:29:21 +0100 (CET)
Message-ID: <548AEDB1.5080700@tzi.de>
Date: Fri, 12 Dec 2014 14:29:21 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "Ace@ietf.org" <Ace@ietf.org>
References: <5482FD4F.70105@gmx.net> <5486DAFA.7090002@tzi.de> <54899D01.9050804@gmx.net>
In-Reply-To: <54899D01.9050804@gmx.net>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/ST1vYHeSgUg2ymb1G3p4q1d7jq8
Subject: Re: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Dec 2014 13:29:29 -0000

Hi Hannes,

On 12/11/2014 02:32 PM, Hannes Tschofenig wrote:
> Hi Steffi,
> 
> On 12/09/2014 12:20 PM, Stefanie Gerdes wrote:
>> Hi Hannes,
>> 
>> On 12/06/2014 01:57 PM, Hannes Tschofenig wrote:
>> 
>>> " The device includes some smart logic, with which it
>>> identifies its owner John and allows him to configure the
>>> device's settings, including access control. This prevents
>>> situation where someone else wearing that device can act as the
>>> owner and mess up the access control and security settings. "
>>> 
>>> I guess by device you do not mean the heart rate monitor
>>> itself but rather some other device. Typically, heart rate
>>> monitors are quite small (since you often carry them around
>>> your chest). It would make sense if the smart device is
>>> something like a smart phone since that also has a display.
>> 
>> I think the heart rate monitor itself should be able to enforce 
>> authorization policies of the owner. Otherwise the device would
>> not be able to decide if someone is supposed to access data on
>> the device, e.g. health data. Since privacy is a concern for
>> medical data, only authorized users should be able to access it.
> 
> It would be worthwhile to point this out in the document since this
> is certainly quite different to the way how heart rate sensors work
> today.

One problem of many medical solutions used today is that they lack
security. If today's solutions do not protect the privacy of their
users and unauthorized users are able to access private data I think
we should try to find better solutions for these problems.

I agree that we should point this out in the document.

> 
> Most of these types of appliances are using ANT/ANT+ and more
> recently Bluetooth Smart to talk to some other device. The wireless
> connection is basically a replacement for a pure wire since you
> could compare the heart rate sensor with a computer mouse. The
> mouse gathers data but the processing really happens at the device
> it is attached to. Since ANT and Bluetooth Smart are short range
> radio technologies you need to have some other device nearby.
> 
> The standards for these heart rate monitors are in fact quite 
> restrictive in terms of functionality. For example, the Bluetooth
> Smart heart rate profile only allows a single instance of a Heart
> Rate Service and multiple bonds are outside the scope of the spec.
> 
> So, the question is really whether there is any value to deviate
> from the current use of the technology? If there is, then there
> might be reasons for doing so. We should state them.

I don't see how that contradicts that the heart rate monitor must be
able to enforce authorization policies and protect the privacy of the
user.

Even if the heart rate monitor is coupled with a stronger device that
helps with the authorization decisions, the heart rate monitor should
still be able to conduct basic security tasks such as enforcing the
policies of the owners. draft-gerdes-ace-actors [1] states which tasks
a constrained device should at least be able to conduct. Without any
security mechanism on the heart rate monitor, everyone could read the
measured data. An inappropriate security mechanism might lead to
breaching security objectives that are important for the use case:
unauthorized entities might be able to access (integrity and
confidentiality breaches) or authorized entities might not be able to
access (availability breaches).

I would not go too deep into solution specific details at this point.
I think it is not the purpose of the use cases document to define use
cases that fit certain solutions but to point out the relevant
authorization problems since this is the first step to reach one goal
of ACE: finding a solution for the exisiting authorization problems.
If we find out that there already are solutions for some of the
problems and we only need to combine them in a useful way, that would
be a good result. If we only see parts of the picture because we are
leaving out main problems as they don't seem to be that interesting at
this point, we might not be able to find the best solution.

> 
>>> " However John is a rather private person, and is worried that 
>>> Jill might use HeartGuard to monitor his location while there
>>> is no emergency.  Furthermore he doesn't want his health
>>> insurance to get access to the HeartGuard data, or even to the
>>> fact that he is wearing a HeartGuard, since they might refuse
>>> to renew his insurance if they decided he was too big a risk
>>> for them. "
>>> 
>>> You should write "John is a privacy conscious persons and is 
>>> worried that Jill ...."
>>> 
>>> 
>>> I also notice again the out-of-scope requirements for secure
>>> by default, easy to use, etc.
>> 
>> As I stated before, I don't think that usability is out of
>> scope. Neither is privacy.
> 
> The question for the standardization work is whether it will have
> an impact on protocol interoperability. Usability as well as
> default policies for security and privacy are important but they
> are not something we would define in the specification.

Usability is important to consider for a specification that is
intended to provide security. I think we agree on that. There are more
ways to ensure usability than to decide how the user interface has to
look like. So I think it has an impact on the protocol design and
interoperability.

I also think it is important to understand why authorization is needed
in the various use cases. For some use cases, privacy is important. I
hope that the need for privacy will have an impact on the solution
design. Since it is especially important for some use cases, it is
useful to mention privacy problems there.

I agree that the secure default settings problem (U3.5) is rather a
configuration problem. Since it is true for all use cases we can
remove it from the problems section. It is already mentioned in 3.3 of
the security considerations section.

Steffi

[1] http://tools.ietf.org/pdf/draft-gerdes-ace-actors


From nobody Fri Dec 12 07:55:46 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D98D91ACDB7 for <ace@ietfa.amsl.com>; Fri, 12 Dec 2014 07:55:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level: 
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DO2JpLB05Dxl for <ace@ietfa.amsl.com>; Fri, 12 Dec 2014 07:55:32 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E3C9C1ACCED for <ace@ietf.org>; Fri, 12 Dec 2014 07:55:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::b]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sBCFtQ3w013110; Fri, 12 Dec 2014 16:55:26 +0100 (CET)
Received: from [134.102.218.219] (dynamic-218-t.informatik.uni-bremen.de [134.102.218.219]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3jzc5p5Lp3z7xFK; Fri, 12 Dec 2014 16:55:26 +0100 (CET)
Message-ID: <548B0FED.3080801@tzi.de>
Date: Fri, 12 Dec 2014 16:55:25 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de> <5489A5E5.10101@gmx.net>
In-Reply-To: <5489A5E5.10101@gmx.net>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/VaxvSJ880xJ3hqOz6PXjPrJu28c
Subject: Re: [Ace] Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Dec 2014 15:55:34 -0000

Hi Hannes,

On 12/11/2014 03:10 PM, Hannes Tschofenig wrote:
> Hi Steffi,
> 
> 
> 
> On 12/08/2014 06:26 PM, Stefanie Gerdes wrote:
>> Hi all,
>> 
>> On 12/08/2014 10:07 AM, Ludwig Seitz wrote:
>>> On 12/06/2014 01:12 PM, Hannes Tschofenig wrote:
>> 
>>>> 
>>>> 
>>>> o  U2.7 The access control policies need to be easy to edit,
>>>> even remotely and it needs to be easy to get access with
>>>> correct authorization.
>>>> 
>>>> This problems deals with the UI of the authorization policy
>>>> editor and this is clearly outside the scope of our work.
>> 
>> I don't think we should dismiss UI problems so easily as not in
>> scope. An important limitation of constrained devices is that
>> they may not have any user interfaces. An authorization solution
>> needs to deal with that fact.
>> 
>> Moreover, I don't think that this section is primarily about UI 
>> problems. It states two problems: Remotely editing the
>> authorization policies and usability for authorized users. Maybe
>> some rephrasing would help. How about:
>> 
>> U2.7.1 The home users want to be able to configure authorization 
>> policies remotely. U2.7.2 Home Users may have litte technical
>> skills. U2.7.3 Authorized users want to be able to obtain access
>> with little effort.
> 
> 
> I agree that the IoT device most likely does not have a UI but
> some other device (like a smart phone or tablet) will and somehow
> the policies need to be maintained at the authorization server.
> 
> We are not going standardize a UI for editing these policies. We
> could, however, standardize an authorization policy language (like
> XACML) or standardize the protocol that allows editing (such as
> WebDAV).
> 
> Currently, these things would be outside the ACE WG charter but
> that's something that one could imagine. Is this your intention
> with these requirements?

I agree that topics such as the appearance of graphical user
interfaces are not in scope. But users need to be able to configure
authorization policies in a way that fits their skills, e.g. by using
a device with a pretty user interface instead of pressing five
different buttons in the correct order. This influences the required
architecture, since the constrained devices often don't have any user
interfaces. Therefore, one task that needs to be performed by the
actors in the ACE architecture is obtaining authorization policies
from the owner (see also draft-gerdes-ace-actors [1]).

The authorization policies defined by the owner then have to be
provided to the constrained device since this device needs to be able
to enforce the authorization policies of the owner.

Referring to the architecture introduced in draft-gerdes-ace-actors,
this applies to the communication between the constrained device and
its respective Authorization Manager (constrained to less-constrained
level). How the communication between these actors works should be
defined by ACE. The communication between the less-constrained level
and the principal level must be possible, but the details will be out
of scope, I guess (BTW, defining the required tasks, actors and
architecture as done in draft-gerdes-ace-actors therefore would be
really useful for the work in ACE).

>>> 
>>> Both correct, I'll remove them.
>>> 
>>> 
>>>> o  U2.8 The owners of the automated home wants to prevent 
>>>> eavesdroppers form being able to deduce behavioral profiles
>>>> from the home network.
>>>> 
>>>> I believe this item calls for a communication security
>>>> solution. Right?
>>> 
>>> If I recall correctly, we introduced this as a reaction to
>>> comments, that we also should address privacy concerns. Perhaps
>>> this would be better addressed in the "Privacy Considerations"
>>> section.
>> 
>> I think privacy is essential to consider, especially for home use
>> cases. Therefore it is a good idea to mention it in the problem
>> summary section for the home automation use case.
>> 
>> I don't think it is a problem if the use case document states
>> problems that may be solved by a communication security solution.
>> But I think it is a problem if we don't see the relevant problems
>> when we try to design an authorization solution. I guess an
>> authorization solution would use communication security at some
>> point, e.g. DTLS. So it would be helpful to have in mind why we
>> need it.
>> 
>> If we really don't want to address specific problems in ACE, we
>> might just say so. That might be more helpful than to pretend
>> that some problems are not there.
>> 
> 
> Ludwig suggested to discuss the topic in the privacy consideration 
> section and that appears to be the right place. The problem is, as
> I mentioned, the scope of what we are trying to do in ACE. For
> example, if you are concerned about the ability of a energy company
> to learn about the use of home appliances by a household based on
> the reported energy consumption then there is nothing in the scope
> of ACE we can do about it. Even thought it is an interesting
> privacy aspect we still shouldn't list it as a requirement for our
> work.

We cannot prevent on a technical level that authorized entities may
misuse the data they are allowed to access. But a well-designed
authorization solution can prevent unauthorized entities from
accessing data, thus protecting the privacy of users.

Steffi

[1] http://tools.ietf.org/pdf/draft-gerdes-ace-actors


From nobody Fri Dec 12 08:40:49 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7BFE1ACECC for <ace@ietfa.amsl.com>; Fri, 12 Dec 2014 08:40:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VURQtlsiIC7y for <ace@ietfa.amsl.com>; Fri, 12 Dec 2014 08:40:44 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 686E11ACEC9 for <ace@ietf.org>; Fri, 12 Dec 2014 08:40:44 -0800 (PST)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id EAFF620012; Fri, 12 Dec 2014 11:44:34 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id F07C2637F5; Fri, 12 Dec 2014 11:40:42 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id E67DC637F4; Fri, 12 Dec 2014 11:40:42 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <548A9E7E.6080401@gmx.net>
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de> <5489A5E5.10101@gmx.net> <24639.1418331448@sandelman.ca> <548A9E7E.6080401@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Fri, 12 Dec 2014 11:40:42 -0500
Message-ID: <29648.1418402442@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/c6g9sBdFMRZkgliG1UQryj6fZ6Q
Cc: Stefanie Gerdes <gerdes@tzi.de>, Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
Subject: Re: [Ace] privacy and ACE in the Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Dec 2014 16:40:47 -0000

--=-=-=


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > This use case seems relevant for our authorization work.

    > I was, however, more thinking about a scenario where the energy
    > companies learns about detailed device use through the data collected
    > via smart metering, as shown in this figure:
    > http://spectrum.ieee.org/image/1711246

Yes, I gathered that.  I don't see a way that a home-owner can "defend"
against this directly.  It's the utilities' meter.  The home-owner could
have a bank of batteries that they charge regularly in order to obscure
the traffic analysis that this diagram shows. This might ultimately be a good
thing for the energy system.

    >> So now we have a situation where the power company can monitor the on/off
    >> status of a bunch of appliances.  Do you want to give them access to the
    >> minute by minute data, or some other average situation?  The details do not
    >> exactly matter... what I have in mind is that your privacy could be protected
    >> if you can provide authorization for what appears to be resource "FOO",
    >> but really, you have authorized access to resource "FOOPRIME", in a way
    >> detectable to your device, but not detectable by others.

    > To protect against the leakage of individual device usage aggregation
    > helps. Your example sounds a bit like aggregation of resources to me.

A bit, but that's not what I had in mind.
Rather, when I want to provide an authorization token that appears to say:
        "Energy company can access resource FOO"
but, really, when the device looks at it, it says:
        "Energy company can access resource FOOPRIME"

    >> Possibly, the privacy situation is aided by providing for private aliases.
    >> This might have no protocol  implications, only location implementation
    >> issues, or maybe it has protocol implications.

    > I don't think that this will help since you have a nailed-up connection
    > with your energy company and since the energy company wants to know you
    > (since they have to charge you) a pseudonym would only help for someone
    > looking on the messages transmitted over the wire. We are, however,
    > assuming communication security using DTLS/TLS for most of these
    > applications.

It's not an alias for me.
It's an alias for the resource in the appliance.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBVIsaiICLcPvd0N1lAQKHpQf8C59gR5XaK5hn67ls15AZO0TINx51bkW4
IlUFoDkTjqW9rKUoxm+oXtd4S/FlwUp95Yn3H5c8HR+ZBxl4OEhZZ/dRl1uuxje8
GlirxE8mH7CjDVQHcQnSVSHlrTo1m0T7LFl0jLFEA7oWVUJJRklo5geAOUVz+uBj
4IbExm+MABzp2QATbPFUXq/UFxBGUG0Jx9m8O1DNMEpaeIg96/nrOSTxpJOyAUma
U6I5GEcTCUct89dAQ9Rc/hOe2LVOjz1HwrewFz9/2AhwueYh9ixILLju7B6oU1bu
owuTg1TQX6aDDvo0yEPz4WbtQk4hc7salF7Wo31vQwHJue4Jb4vdUg==
=ex5k
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Fri Dec 12 10:41:27 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 61E1B1A873A for <ace@ietfa.amsl.com>; Fri, 12 Dec 2014 10:41:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rmv9NZuZToJr for <ace@ietfa.amsl.com>; Fri, 12 Dec 2014 10:41:23 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D74F11A0364 for <ace@ietf.org>; Fri, 12 Dec 2014 10:41:22 -0800 (PST)
Received: from [192.168.131.137] ([80.92.119.109]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0M81vR-1XmDUk49eT-00vhq3; Fri, 12 Dec 2014 19:41:12 +0100
Message-ID: <548B36C6.4020508@gmx.net>
Date: Fri, 12 Dec 2014 19:41:10 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <5482F2A8.2090801@gmx.net> <54856A6C.8080700@sics.se> <5485DF32.8040002@tzi.de> <5489A5E5.10101@gmx.net> <24639.1418331448@sandelman.ca> <548A9E7E.6080401@gmx.net> <29648.1418402442@sandelman.ca>
In-Reply-To: <29648.1418402442@sandelman.ca>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="i4BwL9BrIC6BpMKaglGNsvl1hQwAtD32s"
X-Provags-ID: V03:K0:7Aw6/7T6KhwTCoj4Dr1S2++rFOSt6VK8wivlRytmSt9d8Mcp7PA iByopattkqRBbXORCMtcBmN+LDa8kVYdc/DfnMQDhyjVxFHFfA0HRn1Uh2CegHzD1/tpcJl ABTLI/aL0XDMPPA87at3hpzuzhg4bljsGz6X3Uyk6lyEB4XKZ74OJTuNBAvQI8Ag4AO4SX3 nWzlRHSWx36DfNRPhfWkw==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/5tsQfy6_PzelTaMRTcl5szNnjKU
Cc: Stefanie Gerdes <gerdes@tzi.de>, Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
Subject: Re: [Ace] privacy and ACE in the Home Automation Use Case
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Dec 2014 18:41:25 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--i4BwL9BrIC6BpMKaglGNsvl1hQwAtD32s
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Michael,

thanks for your quick response.

On 12/12/2014 05:40 PM, Michael Richardson wrote:
>     > To protect against the leakage of individual device usage aggrega=
tion
>     > helps. Your example sounds a bit like aggregation of resources to=
 me.
>=20
> A bit, but that's not what I had in mind.
> Rather, when I want to provide an authorization token that appears to s=
ay:
>         "Energy company can access resource FOO"
> but, really, when the device looks at it, it says:
>         "Energy company can access resource FOOPRIME"

Hmmm.

I was only involved a little bit in the smart grid/smart metering space
and my understanding was that the device sends the data to the energy
company. Then, you (as a user) can use your browser/app to look at your
energy consumption on the website of the energy company. That was the
story, as I understood it. (I believe that this is also the story for
how the NIST Green Button initiative works but I have not been involved
in that work myself; a few of the guys from the OAuth group have been
active there.)

In that model the energy company was implicitly authorized (by
configuring the meter to send the data to a specific server) to get the
data but let us for a moment assume the model is different. Let us
assume a CoAP server running on a smart meter and the energy company
sends a request to the device to retrieve the info.

For an interoperability point of view I hope that there is some story on
how the resource is discovered and accessed. The OMA LWM2M model, as
Michael presented it at the last IETF meeting is one such possibility.
Here is the slide deck:
http://www.slideshare.net/MichaelKoster/ietf91-ad-hoccoaplwm2mipso-415421=
96

The name of the URI can be changed without any impact but what would be
the benefit? The energy company knows that this is household X and it
also knows that resources it is going to get. If TLS/DTLS is used then
hopefully nobody between the meter and the energy company will be able
to read the communication.

>=20
>     >> Possibly, the privacy situation is aided by providing for privat=
e aliases.
>     >> This might have no protocol  implications, only location impleme=
ntation
>     >> issues, or maybe it has protocol implications.
>=20
>     > I don't think that this will help since you have a nailed-up conn=
ection
>     > with your energy company and since the energy company wants to kn=
ow you
>     > (since they have to charge you) a pseudonym would only help for s=
omeone
>     > looking on the messages transmitted over the wire. We are, howeve=
r,
>     > assuming communication security using DTLS/TLS for most of these
>     > applications.
>=20
> It's not an alias for me.
> It's an alias for the resource in the appliance.

I mentioned the alias thing because that was the "privacy story" for
smart metering in Germany (at least at the time I was involved). I hope
it had changed in the meanwhile.

As argued in the previous paragraph I do not think that the alias for
the resource actually adds a privacy value.

Ciao
Hannes



--i4BwL9BrIC6BpMKaglGNsvl1hQwAtD32s
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUizbGAAoJEGhJURNOOiAtK8QH/igZIezEhkhEwy0RJ7o2BS56
NO3ACX/xpnt2MOXkRoNlZVDwDihK0IzOKoG+Bgi4AowaS48IDfCOZk6fPvHQpybH
HZB1ZnOOBXp3vqTawvxdOGmIBQ4KTt9dV2zJkvMc3mS804Gr45P1dD98LpyaOQ/X
02+BrePwUfZuQVsXSyK7mbGazV/p95glrnsW7y0eyR5Nc6SMGkR+OnhF/UVOJ0CL
KNYWJ+dLv1fO3ziSVtb2Oe5P5OkZXxReXLIjOcXOPJsVxA9wGnzrV+9Gm4VGKdai
WU0NUOYMU29/nim3H6H/htDh9cYe7EYFtc5Q+hf2bUApq6R+j4EsT+nArXJMerI=
=OAE2
-----END PGP SIGNATURE-----

--i4BwL9BrIC6BpMKaglGNsvl1hQwAtD32s--


From nobody Tue Dec 16 01:35:26 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C4DF1ACD5B for <ace@ietfa.amsl.com>; Tue, 16 Dec 2014 01:35:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.79
X-Spam-Level: 
X-Spam-Status: No, score=0.79 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WnQB9xvvC8iW for <ace@ietfa.amsl.com>; Tue, 16 Dec 2014 01:35:22 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A53681A90DC for <Ace@ietf.org>; Tue, 16 Dec 2014 01:35:21 -0800 (PST)
Received: from [192.168.131.138] ([80.92.123.25]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0LuPYt-1XpqbB3C7T-011hJu; Tue, 16 Dec 2014 10:35:11 +0100
Message-ID: <548FFCCD.7050207@gmx.net>
Date: Tue, 16 Dec 2014 10:35:09 +0100
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Stefanie Gerdes <gerdes@tzi.de>, "Ace@ietf.org" <Ace@ietf.org>
References: <5482FD4F.70105@gmx.net> <5486DAFA.7090002@tzi.de> <54899D01.9050804@gmx.net> <548AEDB1.5080700@tzi.de>
In-Reply-To: <548AEDB1.5080700@tzi.de>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="Bv2Jd5jCUtJKRQE2LaC5IILtgdVQOV1Ol"
X-Provags-ID: V03:K0:jdj6o+DweF9rSf8Sosdh40BbanEwkkWMeOv5yor/xuOf035FU4W s4m3y4k7VGfngMTr+bSWZlXyAWZZIOEXxcKZWHzOUqoomQw6BlDS4BbJ4QYN8kKGtDtnyJi MznWbKBJML0KAOWlkbF4hbcl7AEZ2DCVVBEJ0mFrVw3MIDWHiMtPjcd3NWpu53bdAZmfd2/ Q5hszZB6VnMSCr/8qMlSA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/jclCuPHUdJg-M1yABuLg01zs2gc
Subject: Re: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Dec 2014 09:35:25 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--Bv2Jd5jCUtJKRQE2LaC5IILtgdVQOV1Ol
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Steffi,

thanks for the feedback.

A few remarks below.

On 12/12/2014 02:29 PM, Stefanie Gerdes wrote:
> Hi Hannes,
>=20
> On 12/11/2014 02:32 PM, Hannes Tschofenig wrote:
>> Hi Steffi,
>>
>> On 12/09/2014 12:20 PM, Stefanie Gerdes wrote:
>>> Hi Hannes,
>>>
>>> On 12/06/2014 01:57 PM, Hannes Tschofenig wrote:
>>>
>>>> " The device includes some smart logic, with which it
>>>> identifies its owner John and allows him to configure the
>>>> device's settings, including access control. This prevents
>>>> situation where someone else wearing that device can act as the
>>>> owner and mess up the access control and security settings. "
>>>>
>>>> I guess by device you do not mean the heart rate monitor
>>>> itself but rather some other device. Typically, heart rate
>>>> monitors are quite small (since you often carry them around
>>>> your chest). It would make sense if the smart device is
>>>> something like a smart phone since that also has a display.
>>>
>>> I think the heart rate monitor itself should be able to enforce=20
>>> authorization policies of the owner. Otherwise the device would
>>> not be able to decide if someone is supposed to access data on
>>> the device, e.g. health data. Since privacy is a concern for
>>> medical data, only authorized users should be able to access it.
>>
>> It would be worthwhile to point this out in the document since this
>> is certainly quite different to the way how heart rate sensors work
>> today.
>=20
> One problem of many medical solutions used today is that they lack
> security. If today's solutions do not protect the privacy of their
> users and unauthorized users are able to access private data I think
> we should try to find better solutions for these problems.
>=20
> I agree that we should point this out in the document.
>=20
Thanks.

>>
>> Most of these types of appliances are using ANT/ANT+ and more
>> recently Bluetooth Smart to talk to some other device. The wireless
>> connection is basically a replacement for a pure wire since you
>> could compare the heart rate sensor with a computer mouse. The
>> mouse gathers data but the processing really happens at the device
>> it is attached to. Since ANT and Bluetooth Smart are short range
>> radio technologies you need to have some other device nearby.
>>
>> The standards for these heart rate monitors are in fact quite=20
>> restrictive in terms of functionality. For example, the Bluetooth
>> Smart heart rate profile only allows a single instance of a Heart
>> Rate Service and multiple bonds are outside the scope of the spec.
>>
>> So, the question is really whether there is any value to deviate
>> from the current use of the technology? If there is, then there
>> might be reasons for doing so. We should state them.
>=20
> I don't see how that contradicts that the heart rate monitor must be
> able to enforce authorization policies and protect the privacy of the
> user.
>=20
> Even if the heart rate monitor is coupled with a stronger device that
> helps with the authorization decisions, the heart rate monitor should
> still be able to conduct basic security tasks such as enforcing the
> policies of the owners. draft-gerdes-ace-actors [1] states which tasks
> a constrained device should at least be able to conduct. Without any
> security mechanism on the heart rate monitor, everyone could read the
> measured data. An inappropriate security mechanism might lead to
> breaching security objectives that are important for the use case:
> unauthorized entities might be able to access (integrity and
> confidentiality breaches) or authorized entities might not be able to
> access (availability breaches).

I agree that there has to be some security protection for the data
stored at the heart rate monitor and also channel security for the
transmission of the heart rate readings.

If there is a one-to-one relationship between the heart rate monitor and
the parent device (such as a smart phone or a watch) this security
protection is fairly easy to accomplish. The authorization policy at the
heart rate monitor is as simple as: "Only the device I have paired with
is allowed to access the data."

>=20
> I would not go too deep into solution specific details at this point.
> I think it is not the purpose of the use cases document to define use
> cases that fit certain solutions but to point out the relevant
> authorization problems since this is the first step to reach one goal
> of ACE: finding a solution for the exisiting authorization problems.
> If we find out that there already are solutions for some of the
> problems and we only need to combine them in a useful way, that would
> be a good result. If we only see parts of the picture because we are
> leaving out main problems as they don't seem to be that interesting at
> this point, we might not be able to find the best solution.

The good thing about use cases is that they are specific. Whether we
want to make the use cases align with existing technologies (such as
radio technologies) is a decision we make, as document authors and also
within the group. We could also state in the document that some of the
use cases describe approaches that are in use today while others are
more forward-looking because we are not happy with the way how things
are today.

That's perfectly fine with me.

>=20
>>
>>>> " However John is a rather private person, and is worried that=20
>>>> Jill might use HeartGuard to monitor his location while there
>>>> is no emergency.  Furthermore he doesn't want his health
>>>> insurance to get access to the HeartGuard data, or even to the
>>>> fact that he is wearing a HeartGuard, since they might refuse
>>>> to renew his insurance if they decided he was too big a risk
>>>> for them. "
>>>>
>>>> You should write "John is a privacy conscious persons and is=20
>>>> worried that Jill ...."
>>>>
>>>>
>>>> I also notice again the out-of-scope requirements for secure
>>>> by default, easy to use, etc.
>>>
>>> As I stated before, I don't think that usability is out of
>>> scope. Neither is privacy.
>>
>> The question for the standardization work is whether it will have
>> an impact on protocol interoperability. Usability as well as
>> default policies for security and privacy are important but they
>> are not something we would define in the specification.
>=20
> Usability is important to consider for a specification that is
> intended to provide security. I think we agree on that. There are more
> ways to ensure usability than to decide how the user interface has to
> look like. So I think it has an impact on the protocol design and
> interoperability.
>=20
> I also think it is important to understand why authorization is needed
> in the various use cases. For some use cases, privacy is important. I
> hope that the need for privacy will have an impact on the solution
> design. Since it is especially important for some use cases, it is
> useful to mention privacy problems there.
>=20
> I agree that the secure default settings problem (U3.5) is rather a
> configuration problem. Since it is true for all use cases we can
> remove it from the problems section. It is already mentioned in 3.3 of
> the security considerations section.

It would be great if we could figure out how the usability aspect
(security & privacy) impacts our work. RFC 6973 might give us some
hints. Section 7.2, for example, talks about user participation and I
believe we capture the first two points (namely user control and control
over sharing with individual recipients) quite well in
http://tools.ietf.org/html/draft-ietf-ace-usecases-00#section-2.3.2.

We don't talk about preference expressions or the sharing with
intermediaries. Maybe those two aspects are not of interest or not
applicable to this use case.

For the following two items, however, we could provide a bit more context=
:

   o  U3.5 Devices are often used with default access control settings.

[Hannes: I would say that we are talking about the heart rate monitor
initially configured so that it does not share any data with other
sensors (such as a GPS sensor), with intermediaries (like a smart phone,
watch, or a gateway), with a cloud service (although the cloud service
is not explicitly found in the description), or with other
applications/web sites/and users.]

   o  U3.6 Device users are often not trained in computer use and
      especially computer security.

[Hannes: Here I had difficulties providing an additional description of
what this would mean for the use case. Given the previous requirement
the user obviously has to configure the device to share data with
various other parties since otherwise nothing works. He does not need to
understand how the actual protocol mechanisms work or what crypto it
uses but it could be good for the user to know that the device complies
to specific standards and that there may even have been
self-certification/third party certification activities. The latter
aspect is outside the scope of our work and even the IETF and the best
way to deal with the former is to re-use existing patterns users are
already familiar with. In any case I fear that those would also be
outside the scope of our work. We could, however, provide a bit more
background text to explain what we mean and note that this work has to
happen somewhere else. ]

Ciao
Hannes

>=20
> Steffi
>=20
> [1] http://tools.ietf.org/pdf/draft-gerdes-ace-actors
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--Bv2Jd5jCUtJKRQE2LaC5IILtgdVQOV1Ol
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJUj/zNAAoJEGhJURNOOiAtJNAH/1I23TQxSzFtQBFSXS0MCvIp
sXLAPqbab+1AsX2Xsp8kIftgm/61NAWyuNiiKEujdLW82zRMrVkdIJ8Z+o0+fdv9
wLrc0IlHEvGZjwsLp/epX0hUgN3yLaDZH/8whxukKsm+gDMZ3+8t8QUBIS6oW/im
/AW5IwvS7wwfKCwB7DZpQXPesZVbFJ6zNQgsFofrtj12U5MZSmHAr+y0K4EN9qB1
EIGCGgxGk7TX70GjBTo/0ndWeVRwWSR+stYs0pSKoCnJbUC8JR3bSjC/ktaqXFGv
chADVhO8ARloreRLOA0/v5mmFxisipVa7JOXwtXoI3jg3aqbZKZeGZgA/jX3Rto=
=BvAF
-----END PGP SIGNATURE-----

--Bv2Jd5jCUtJKRQE2LaC5IILtgdVQOV1Ol--


From nobody Tue Dec 16 09:07:38 2014
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E74C1A1BE3 for <ace@ietfa.amsl.com>; Tue, 16 Dec 2014 09:07:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level: 
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3OPCt18tnRsF for <ace@ietfa.amsl.com>; Tue, 16 Dec 2014 09:07:33 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5AD6D1A6FEE for <Ace@ietf.org>; Tue, 16 Dec 2014 09:07:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::b]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id sBGH7SPl027166; Tue, 16 Dec 2014 18:07:28 +0100 (CET)
Received: from [IPv6:2002:5489:d3b::704a:122c:70c5:52ac] (unknown [IPv6:2002:5489:d3b:0:704a:122c:70c5:52ac]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3k25W350lDz7xBL; Tue, 16 Dec 2014 18:07:27 +0100 (CET)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 8.1 \(1993\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <548FFCCD.7050207@gmx.net>
Date: Tue, 16 Dec 2014 18:07:25 +0100
X-Mao-Original-Outgoing-Id: 440442445.236447-3ae58284cfad51f98362695c2225ca51
Content-Transfer-Encoding: quoted-printable
Message-Id: <924B1FBE-CB09-4ED7-9227-C11839F05691@tzi.org>
References: <5482FD4F.70105@gmx.net> <5486DAFA.7090002@tzi.de> <54899D01.9050804@gmx.net> <548AEDB1.5080700@tzi.de> <548FFCCD.7050207@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1993)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/40qi_tQqHFvN71QMMoc0xnjazC8
Cc: Stefanie Gerdes <gerdes@tzi.de>, "Ace@ietf.org" <Ace@ietf.org>
Subject: Re: [Ace] Personal Health Monitoring
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Dec 2014 17:07:35 -0000

On 16 Dec 2014, at 10:35, Hannes Tschofenig <hannes.tschofenig@gmx.net> =
wrote:
>=20
> The authorization policy at the
> heart rate monitor is as simple as: "Only the device I have paired =
with
> is allowed to access the data."

That=92s great for =93lifestyle=94 bluetooth smart devices you use with =
your smartphone and, say, HealthKit.

I think 2.3.1 describes a more interesting medical use case.

Gr=FC=DFe, Carsten


From nobody Sat Dec 27 13:42:13 2014
Return-Path: <schmitt@ifi.uzh.ch>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BC8471AC3B4 for <ace@ietfa.amsl.com>; Sat, 27 Dec 2014 13:42:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.739
X-Spam-Level: 
X-Spam-Status: No, score=-0.739 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, HTML_IMAGE_ONLY_12=2.059, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, T_HK_NAME_DR=0.01, T_RP_MATCHES_RCVD=-0.01, UNPARSEABLE_RELAY=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AY2RnVhVjfkD for <ace@ietfa.amsl.com>; Sat, 27 Dec 2014 13:42:08 -0800 (PST)
Received: from bohuslav.ifi.uzh.ch (bohuslav.ifi.uzh.ch [130.60.155.10]) by ietfa.amsl.com (Postfix) with ESMTP id 9E3741AC3D0 for <ace@ietf.org>; Sat, 27 Dec 2014 13:42:06 -0800 (PST)
Received: from authenticated sender schmitt by bohuslav.ifi.uzh.ch (postfix) with ESMTPSA id SA for <8F3FB7FC7C>; ace@ietf.org
Message-ID: <549F27AB.3090807@ifi.uzh.ch>
Date: Sat, 27 Dec 2014 22:42:03 +0100
From: "Dr. Corinna Schmitt" <schmitt@ifi.uzh.ch>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
Content-Type: multipart/alternative; boundary="------------050205090209020308010903"
X-Virus-Scanned: clamav-milter 0.98.1 at bohuslav
X-Virus-Status: Clean
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/vcYNsOzjbiXMlSg72o20FxjugAA
Subject: [Ace] Update of document draft-schmitt-ace-twowayauth-for-iot
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 27 Dec 2014 21:42:10 -0000

This is a multi-part message in MIME format.
--------------050205090209020308010903
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit

Hello all,

I have submitted the following draft update for ACE:

https://datatracker.ietf.org/doc/draft-schmitt-ace-twowayauth-for-iot/ 
<http://datatracker.ietf.org/doc/draft-greevenbosch-ace-comparison/>

Based on offline discussions and meetings during IETF90 we updated the 
draft corresponding Gateway and Access Control Server functionality.
The currently open sections for the two-way authentication solution for 
class1 devices will be filled soon.

Enjoy the last days of 2014,

Corinna
-- 

--------------050205090209020308010903
Content-Type: multipart/related;
 boundary="------------080809040707040705050002"


--------------080809040707040705050002
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p class="MsoNormal">Hello all,<o:p></o:p></p>
    <p class="MsoNormal">I have submitted the following draft update for
      ACE:<o:p></o:p></p>
    <p class="MsoNormal"><a
href="http://datatracker.ietf.org/doc/draft-greevenbosch-ace-comparison/">https://datatracker.ietf.org/doc/draft-schmitt-ace-twowayauth-for-iot/</a><o:p></o:p></p>
    <p class="MsoNormal"><o:p>Based on offline discussions and meetings
        during IETF90 we updated the draft corresponding Gateway and
        Access Control Server functionality.<br>
        The currently open sections for the two-way authentication
        solution for class1 devices will be filled soon.<br>
      </o:p></p>
    <o:p></o:p>
    <p class="MsoNormal">Enjoy the last days of 2014,<o:p></o:p></p>
    Corinna
    <div class="moz-signature">-- <br>
      <img src="cid:part2.09070208.00080000@ifi.uzh.ch" border="0"></div>
  </body>
</html>

--------------080809040707040705050002
Content-Type: image/png; x-mac-type="0"; x-mac-creator="0";
 name="visitenkarte.png"
Content-Transfer-Encoding: base64
Content-ID: <part2.09070208.00080000@ifi.uzh.ch>
Content-Disposition: inline;
 filename="visitenkarte.png"

iVBORw0KGgoAAAANSUhEUgAAASgAAACgCAIAAAAw8WZPAAAAAXNSR0IArs4c6QAAAARnQU1B
AACxjwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAA
buNJREFUeF7t3Qe8FtXRP3CT901i2htTTVeTGE035Z+YZkxijFFjQcVKVXrvvffee6/Se+9I
R0CahSqCgtJBQKTl/9099y4P9yIiEOXq83zwus8+Z8+ePTtzZs7Mb2Y+9p///OeKd/uMGTNm
5cqVWq1atWr//v3v1jz9e3oGPnIzcOWVV/7ud7/z2DfeeON9993n67tMAcZ7p8/s2bMfeeSR
q666Skd14s/o0aOdTH/SM5CegSwzMHny5MAjWAbXYRnMcg7muuKsvz333HOuvPXWW59++ul9
+/ad4/r0T+kZSM9A9hnAdTjopptuwp9nnZ+zMB5mu/nmm8/Nr+m5Ts9AegbedQYIMNKLGMze
MivjVa1alax866233rXTdIP0DKRn4HxmIOifWXjqDMbDdRqdOnXqZPqTnoH0DFyKGcBNmLNP
nz40z1QuPc14NEx86bc0412KCU/3kZ6BaAYC4/k0adKEYEt4L4PxKKP2dUEaphkvTTLpGbhU
M5AwHs4i2Ii3wHsZjJdq/bxgxsvk7XPovWkl9lK90HQ/OWMGUhlvx44d1157bRBvEeNxQdxx
xx0Ju7wnxjtx4sTJEyeSa/fs2b1mzZrp06YPHzp02JAh/jmYOmUyifrGG28kzU6eyBmzlh5l
egYucgZSGQ/9ly1btk2bNhmMh+vw3oUxXrhq586dkyZNatyoYY1q1apXq1anVq0G9eo1rFu3
ob/16tWrU6d61arVq1WvX6/+6FGjt219NVx1kY+Uvjw9A5f/DGRhvJdffpnQixiP4INNSbV1
no/EI+hsBl2/ffuOnj17li9XrmrlKhivaZMmXTt3fnrwoKlTpsyeNXvO7NnTp00bNnRoj27d
WjRv3rhhw+pVq5cuWbpTx46bN28K7KerSGymP+kZ+DDOQBbGQ/CMKYsWLboiMWa+J4kXGGb0
qFHlypatVrVqy+YtunbpsnDBgtkzZo4bOzb7Jm/evGecX75sWa+ePTWuXatW2dKl+/fre/jw
YY2PH08z3oeR6NLPlGLVTJgiIMuuCP9LZZVzSzwsovGunTsbN2pUsUKF5k2bDujf74Xnn8c8
zg8cMLBCuXKv79hhzhM5dvTo2y2bN2/YoMHxY8e12bhhw/BhQ1s0bVa1cuWaNWps2rgxrXam
SfTDOgPZJV5Ak12RP39+3r3zZzwtX968mW5Zr27dNq3bLFiwYPOmTXv37Hb+hRdeaFCvfptW
rVu1aJnwkoO5s+c4o/3gQQN9XfbssmeXLiX9Onbo0KhRw9IlSzr+b8i9YPi55IbU49aY4yfi
5enSKclRT8czPD5pj86HiAuzMx49k7Z5RRbLCgY4h8Tz6ytbtpQpXTrs5ba8vMWZwQMHkn57
du/R47/vvPPfd92FLZ0/cuTI4UOHHIwaOfLef//7zjvuaNWyha99+vRt3qz59te2b33llT69
e7do1qxYkaKB984x4cnSENqkPs/5X3VJXijGyzKYLF8v6C6RvvD228defOGFtWvWHHrzzfPZ
aV/QjdIXva8zkJ3xgn3lCiDOLADqs77y2JryH5EKNnXNmzXr3Knj/v37aJj169WbMX0GY+bK
5cunTJ78VMGCRQsXLl60qM3bcyuemzljhqt6dutWMH/+J/PntxvkynDJvr372rZp88zcuW+8
/kbMe81Lliix5eWXw9Yxu63l2LHjSxYvNs6DBw8ans+xt48tXrSI8ebNN98860Rqc/To0WZN
m+Z54vF169ZdQjrW1fLlyx95ODeJ/fbbb7u7UZHhe/fuveC7RPrC88/f8+9/f+H//u/zn//c
nDlz0ur3+8of/7WbXSzjRULm5Ek806RxEzZJTNK5c+eXXnypdMlSFM6li5doMGHcuP59+w3q
379mjeq7du3EVBs2rHfjwQMGdOvSuX/v3jWrVX/z4MG9+/Y9u2RJm9athw8btmDe/Igze/Zs
3bKVHeORw4dTN4cZwu3kyTffPPSrm276whe+sHbN2iBe9u8/8LOf/vSLX/wipgpSOhB9+DU8
LSfHN77+dfGIvXr0SG2TCMxwSTI1CdtEfcVdht6yCFhnmjZpqtsfXn/9gQMHjr711r3/vucr
X/7y2rXR2MJVZ3QV95X6ZrPcMQy+YIEC+rzt73+rVq3qhg0bLoyHQ1cXdu1/jfbesePsmsI7
jTx5rZdwkBc8S8mFyajO0VXyrpOHfW8Sz2Vjx4whslq3arV169Y1q1a3atmyc8eOc2bNInwi
Ujt5EkNWrVK1ZvXq+fPmxZlUphnTp1PMGjdswOJSrXLlgvny7969J2KJN97ApdOnTp01c2bb
1m22b9/eoV077r4e3bpHhH6md+HUyVOHDh36xc9//vnPfU6fmYy3/yc//jH58NJLEeNl/3jg
48feHjt6NA5n7EkaBHF61kvCSfvC1F+1T7ZeCR/a5TZv3oKEj9ofP/HTn/7ks5/97OZYYqcS
U1ATMroNojzlTJYx/PmPf/z85z+/efPm6PwF4dSzdHjBhBUT9wljiN7FRXzi53jHLXagyH37
9x858lbGHTMfIPWeYcYgLvbu3Xfs2LGLGE7GpfFDnX6lnvQ99RnGGAZ//Ngxo0rOvJPmleW9
nC/jRZR36hQzZrkyZVq1aLFkyeIN69e3b9vu9dffGDVixBtv7Iyf5MT+ffuKFylSqkSJ8mXL
3H7bbfx4M6ZNw0779u3Ndd99LCj8B84vmB+JuPBZtHDRYw8/XKRQ4SOHDlO0WjVv7vL16zdk
ed/uTnH91S9vuuqqLwSp4rP/wIGf/exnX/rSlzZu2Lh39+4qVau0bNmCCM11/3333ntP/379
XMU52aN791q1a7GjEstFixV1d+dPHD9OSyxUqBDLELZp367dnf/61x3//CdPo02pBtOmTS1W
tOjAAf1LlSzlV2cGDhjwQK5ct/7lFiYi82u0NarXGPL009aXEiVKkKsUxNy5czdu0mTcuHGF
Cxfu0rmLnr2fiRMnPvXUU8xXpihsDnfseB2Q4K4777rvnnt5Vg4dPvzKK6+UKF7i29/+1he+
8H+PPfaYTa+Rv1e20X79uvXlypUrUqRI2TJlFi9afDFsE+xSR986+p6IMkvjt98+ijTfiRxx
Ea/Sr3716+B/Mn6zWqVKlddefTXLuvP6668/kvvhv9zyl02bIt/vxQzJteSEV/PSSy8VLVLE
HSN6OG/W03j1qlVVqlTdtXMX/rnrzjvZJ+2ngEN2vrHzrK/swiVeWHL43+rWrt2zRw/W/0kT
Jgzo15/EM61+Oha74Xbv2tm+bZsmjRsVL1KU0Js0aSK6rFK58p7du/kMKlUoX71K5SqVKs5N
2b34SbfPPbdy8qRJWzZvfnrQ4LatW9uVvSfG44hH/V/60hc/9alPfe5zn/vaV79KYSMJly5Z
ao/32//3/3y1GwQMd/DUk0/pnF3nq1/56qc++ckVK1bQb50nTn/60586sINFA40bN3aMl/wl
5Ht07/Hxj30Md/36l78qXqyYHkYMH+Gnf99993MrVlxzzTWf/cxn3Vr7W//ylzGjR/vp61//
OsuTSb/9H7f72r170HVPbtu69ZY//9mZL171RQNwULRoUUP97ne+S2aSeKT67f/4x6HDkVHq
PVGY9rNmzvrSF7/YpHHjMqVKXfPda6ZNm5Zlrc0i6rN8zUIiDerXDyr6WT/n1hpcsn79+rxP
PHFg//7kQbL0w/b2veuus0JFciymMWTg8VetXJml5cL5C0y+peTc488+zuxEbzdeIF++l154
ccf2HTVq1CRCAg4k++esklCzMaNGf/5zn31126vWi+98+9tbt24bOWK4YdsdnPWVXTjjedp9
e/dWrVyJL47DAJXXrlmT6HtlyytBbQsikfb49KBBxYoUQXwMJ+PHje3SqXPRwkU2b9zUskWL
B+6/P+/jjzdt1IhBJfVNWOybN23WsWOHl1560Z6Q2aZyxYpbtkTG0sTEgmAPHz70q1/+8qpo
j5epah7YHyQe3WzrK1u9wv/5n//B2mYk1/33h30dLedvf/3rlZ/6FPfFiuXLceP1P/gByCjx
9bGPfezRRx5hSkXuv/rVr55fu3b5s8u+/73vfeMb39i9a1e7tm01+OY3vwlzQw0mD3XYrGmz
iHliNZXW/Yn//d+HHngAb6Own//sZ/afkDomgXB2U+179+q9Yd26r3z5K9ddey0pF15tgwYN
/PTYo4/ywcycMfNb3/qmUS1auNBk/u63/w83mh/KxQVAeXTuWur3ju2vOc6fL999993rYNu2
baR0o0aNyA2moA4dOljsKlWsNH78eL+aPQxWoWLFCRMmWEb7+/Tt1759+759+qD13/z611On
Th0zekzXLl3r16/ft29feweT7EldK+1VyxYtrarI9403XgdB7Na1K5EFR/HG66+b3s9+5jPl
ypazGw+i4PChw927dStXrvzokSMJ/0YNG331K1955OFHwoZWhzOmT0PKq1etHjpsWLeu3WrX
qt2nV6+XN7/M4/W1r32NimFuF8xfULlSJauz9/j2sbcZGgy1d+/e8+fPN+zWrVozmLOu165d
u3//fnQMQrJevegBJ0+afOjNQ7ZCn/70p5944gnaVvfu3V/dts19bRkqVKjYuWMncqxbNMJy
NlCJjhxeXLJDmThhwnXXXkOhe+CBB1CLm9Kzvvud79h9XGLGi5aiyZOrVanct3dvE2pZmj9v
Xs/uPRgVkiXZxBFfdWvXKl2iBN4rWCA/bHTtGjWeeOzxhfPnFy1cqFTxElTNxx99ZN68eanj
8wLwkvfXrk1b74+QbNywkYmM22RoAIHxfnnTTV+86iq6QZiIAwcO/uynP2Nc2bRxE7fEtddc
861vfSvMY4Xy5RE3kJq3/feY8RZRKU+cuOOfd2AnXPf44499/OMfR08jRowgJ6+++ms/+P73
se6nr7ySyFm/bl37du31QNsM96pZvYavhEm+vHkxcMJ4D+bK5cEt2L/+1a8w3sYYCeDTqVMn
7b1dmqQDil+w1Wh5+23/+N///d+pk6eElsyYH7viiqcHD3Z8y5//5BZWorO+v3eVfq7CeD/+
0Y3r173k2GMa1fbXXnvwgQdKly6NDRhvmIK+fvXX/3LLn8uXL2/GVj73HDpmMKtUsSLSIf//
9te/0R2KFyuKmH584423/f3v3pdrv//97wPhMiA98fjjjzz88E0///mePXtoB48/9pjO/3n7
7XT4z332s3nz5OFM+v3NN1tWSpUs8fWvX61zQsbg0bHjm37xi2rVql1//fVDhwxF93g7f778
mD+T8aYbxuqVq+jhN97ww6pVqnztq18Z0H+A4V199dWYbf78BT/+0Y95s/7+178ZCRv7d77z
bbxqOaMrff6zn9X5jTfeYCbDJYTkvGeeiVaW+Hk5kO1Hrv7a14x85IgRX/7SlxYvXITrvPpy
5cv36dW7Vo2aP/3xT9q2aQvnGI04/jAH7tu7J1CjiaXu6Wr2rJkF8hf49je/2aNHjxGB8V6+
1IxnUlq2bNmsSZNpU6fOnjWrQL78hZ58avOm6DanF+Z4E2jBo4K21rhp0+FDhloL8z6RZ+6c
udAtlhOYsjq1a82de4ahXCe4ZdCAAVga3VAz3Kh+3bpvHz29u4j2eIcOeWfUuUQPsdx+77rv
mcRXXtmC8a757ncxD1+iDpECcqcVZzDelVdivIgfOnZ03j7zuuuuu/GHN9iU2gqSk7RBK6tF
vXevXkOGDLEussdoSVC4yt2ZdpiUCEYnTTrl3rJH4sWM58W8GUnjq64KyoYP6f31q6/+7ne/
S9H9zGc+E7TrsOdElJ/8xCdmTJseWt59190f//jHRg4fbtfxpz/+0TpCfl4s470UMR440c2/
+x3z1be+8Y3q1asRgN/51rc2rN/wk5/8JISE/b9f/waxejSbAjveb3/725jtnnvuKVuGsh19
/n3nXcC3DpB4sVjBxsl2sLSeG274oZf1oxtvLFKoEBFHsg0aOJA2sW7dehTyg+99nwCc/8w8
rLt7d4SsoBQdPHDA5W7kq/UrX958NpA//clPpkyaFJ7XX+IUBa9ZvcpiUalSJWd+8Yufe4/0
+R//6Edert3NH3//B+fnzpn9/eu+x8LHrNWhfdRnty5db/7dzQ6KFStaqlQpBz/76U+s4wcP
HJw0cSK59K1vftMBU/uNN9yw6rmVa9aspoksXby4QH6mwLzhkd3rB9ddZ80KLOeVEQx5Hn+c
HiHsJrTBeFh9x47t48aOY2nXDDE4c4kZz51wfO1aNQkBhIXErZED+/c/cvjIGVvJmPEG9OvH
X3fLH/8oIqFVq1b0GS9m5PARsNF33XFH7vvvb1Cv7jPPnFY1g5pK139m9pxXX3112bPP2gKx
x9SqWdNXUiJZ5smKe/59D7q3CmK5I2+9xQNBdPzpD384fPgI1RTjURR37dplwKVLl4kYr3v3
LIxHInmvn/zkJzEbQ5GWtsX/8z8f/8Pv/0DHCNO6d89ef1u1aqkHARaBJmgsDvCbd+a8NXLK
pMmB8fhYvFpbxM9+9jMzZ8586+hRQ/VQeZ54gnS1M7zlT382gYm1wDvWAxsS4TNr1syvfvWr
FNpNmzYee/voJWG8SNWMTbhUuHz58nF+WpuEokTaY9++r732Ggq2uGjw29/8Bh0XLlS40FOF
xo8bT6ZhvHvvucci69djb79929/+1qhBzHiPPVayZElbod/+9rd0H4IRw8yZNfuGH/7Q47Rr
165bt+5Urx9eHzEeje5HN9zw+o7tkyZOuuGH16OKTMY7aHnq1DFikvzYLm9eKr3BkDxZGG/t
mtUYj2LpjtScXj17zJ8/z8xDbjA7sf1qz8/pdbNzSOM1NrbNWDdN4FtH3ipSuIi1wBnXDh40
GF8xoowbN55YmzB+PDObBZqoF7x23XXXLlm0mJvXJ7x9HwqdJZ5QDZYwBGrPXLBgweBAThiP
Yd80/uJnP7eg6Pa/wnicdZUqVOzfty/RRJR5+LlxxrIzlJ9Tp6KtUes2jz/yCFNPoSefZLKz
DbUXomHmfeLx+++55+EHHyhVongWVRNOSle8eeXLlitbqvTLmzaNGDacO962J7lFsO7QDEkP
VGtl/fGPf+yAAAxKmhWBpkcR4rjz9amnCvm1U4cOGA95OZ4XbywjGnr8CV/pmfNj/yEevuvO
aP/2zW9886+33oqSbM8MqWmTyLjCrBKuMvV/+P3v//ynPzn585/93F2gwx3f8c/bI9Pf0bf/
cdttvtqxMI1SuV1Cif30p690I8SdPIiDCRMm2ohrHGm2n/50tHVsEhmT7F5wL15lbcs6t++q
ZcYNXEXaXPWF/6tRowat8qc/+TGf/ltHjtx9513snLiOZ4V8u+GGG/51xx3aWIOsoZ733nvv
bdSwodEOHjTI17qxnCeBWYft8ZYsWfLQgw8SmJw6P/zh9XCGzlAR1730Em7MlStXv379vYXF
ixfT3J5f+/zY0WO+8bWrX3t1m/0IzblunXp8sJH0OHnKevrLm36h/x98/3vDhgy1xuknvMEw
/kzjynN01zKly7iEUIpcVnNm2w6w6onq5DtlD/vHP/7x8MMP79u3n6pJrLmWfmg5sI1kFi5e
vDgWcS0VhsXBIBs2aGjHMWrkKHa1a7/73WJFi8nR/OUvfXHJokVI9Jvf+EaFCuXJTLLOpvHv
f/ubBciON4iWQAPJMaqmVFvr+/Xrd813vst6BJjlzMZNZ4ccX6BxxS3ZAJh9Md7G9etNk72s
dTSb5fTU3j17atWoQdvs368/QUdjHD923LgxY7t37fbEo4/16tnLDpjUpnNnIayYc9bPmTnr
1a1bEcrkiROrValii5jaLIwe7z36yKM0qN/f/DtK7MQJE6MZOXmS6YLW7n1gJC3tCiypqJCk
kujCcsXOHhlFTv0H0gUNiRikT4Y+Ga8xmLn+/e9+h23sNo8fP0am5c2Td9SokWHSeRSQoAW1
RPHiwYPPKmMppQVYF/XDfkhJ++Mf/mBxpXlqsPWVLV48gYYWkwcJkpPZ84FcD+jt3nvu7dun
L/Jykt7VsH59BEFeZZvb8+O8k6dsd2vWqFmmTBnvi0IY6AWJoHVCb8yoUXjg5z//ueelyJFv
brRi+YqKFSsxhjVv3gwcp1evXjNmzAz384y2RowrWo6MzSFt2rTlzrELbdq0KdXLbNNrSpcq
jb6Z3CxPFDANoAvsAL3KLp0716hZ004s2SzR9umBQ4cMiZTPgwebNWuGl8Lz+mvRsR/zRiwT
4ydMwPyWLZYSYkqfNiMeiOOX8QPgnvT2pnhTV65cpQOLSPv2Hdgdhg0bzt5o9SS6Vz5na7Ky
YsWK7dq2a9q0mS+nTp4YNmxo5cqV586d26RJ02ARwUulSpVs2aI5FjJ7xhC2nYnCmbxBJ9nh
2Jm4o5cvX4ZaQD4YKfiHdu7cddYXd+GMN2rkCM9pO2TG+/XpQzcI+JIsH9qzrVqgVK+qZ4/u
S5csYSgfO2Yswg3nWVCQfhbGMzKq4+yZszp16EiVJbgtwEwj2ZuFTuyUCJlwHCGLjx9PlqXw
Nfzk48WEg6AuZsdYnnFh7BqJrzrt9c6Yej6tlMspk4Fb4saZ3Ub++miNDOexPVMNs0TcQ4aV
KBpqpgNdJ8k4Q4vw9UK57mTq06VOTnIXB5Re3kJrfGaD03OV2syDhDiSM06mTGY0pbGqknxQ
aXwy4yniB8qYRi/Fw3oXqSSYiiXIJKSM9kmz5InCGV1mecbk/SYHJzIHGRxd2T/ZZyk1f0Jq
e2/8bAve6YfKmMNMensnxPyFM97oUSObNGw4aOCANatXYyFCL9ipsjLe668PHjjA4rRg3ryh
Q4dWLF/e1q5e3ToWcraKFcuWPb92DRGRnfEisjtxgnmDJ501zBJr09+hfcSrZ9wiepWR3yKF
QDOwIGG9DCQb+zair5nH0fnIG5wZphS3cybTaXoiK946/JTKAKk3DbfMaKCnTIdK8s7sdkDG
f/Ob3/zPxz8ePGkp98q4NpXlkmdMHuFs7/t8zp3hBs4YZ+QGP33ezpxxclkmHj1pk9F7ZsvM
Z8zwFWUAieKOwin/S+YhzHP0Y+bf1DPJcWr7cDJz6s71aPFbzHiEjDd4+sKMyYxXtvCM8WsO
RynPknqD0/fNPJs8Vvxc5+tKT52qcNMwK9kf5mIYb0STBg1sABg/+vbuQ1PasX171oX51Enb
6B7du61du2bJ4iV0D1av4sWK534oN92M089+w1aYNynVgR5GqSsrIhvM1MmT165ebXfets3Z
GO98aO+cbc4hTM4qbcKUZZ+45GTWu8XtOSHs3Ig7bqjwdBc98EvWQdhRx+p5+vM+zcDFMN4o
sqtf374vb9o8fOgwaiToY3Z6YlRo3KD++LFjJk2YaBNFarEWCH+gNDLiUbvpkFx8z8zNsseL
hJgOqZqCD2wbJowf53bAIqkSL2gyWT6xKHv3JSqs08m1Z7kkFqRZnyhDrGUsDUGlJCoTXora
x4tw6gt0jl4wfuzYZUuXXjzW8ZKTRliUz2fSLvmtP7IdXjjjzZo1i0fO7o6Jn1zCVCReNhTv
qZ2vvzH06aeZJWV5GD9u3HPPrWCoFezHz8bzvmTxInFmAVR9pg4ZEf3uXbsF+DVt3Hj5smep
alUqVZaeLGmGUN566whQKLACRJx/0f9ff8NW0xJ+Pm/Utg0yo0XzFnrI3p6tr3jRYpCWYJ8Z
N7UTO3Vq5vTpDRvU50WwdWbCejh3boYZXgoGJCsFW47gpuyyI3V1OJ+xpdt8uGfgwhnvpRdf
tGGjZLKckntVK1WGLcimap7avXNnm9atGJHZLZk07QnFH4wYPnzqlEnMaM/MmQPCUrlChSyq
Jqai+SyYP09L1iHBdazD3AlgRwnjOXj22We5azm+v/+979/wwxt++hPW8p+wPmfdB57tHWoD
z816TgPs0L79GZfEu8ED+w/w7TA3c9QGPSwe1X969+x19113Pf/883//298pzLkffIiVuU2r
Vjf/9ndQS4zXwXvx4aab9NNd5AxcIOPZtRAIsGAd2rWN4NETJ/bt1WvksGEg3ll4jx8PQgUQ
wVatXp3anTq0nzVj+qwZM8SniwmaOmnStMmTy5YqlYrVjLekkcmLnXfixEmECfNuuzZtuCX4
W1IZD1CLP5S/FSry+ut/wOuNi8ZPiNCG4RPUp3DM4JYchzMEJgt7rvtzrVq5KiiHqXKJD5SR
nRvQEpN6vl+fvgBQrOr/uO0f856ZB3ixcOHC3j17Yjnu6V/8/BfBX3+RLyZ9+Yd7Bi6Q8QKN
Mkvy0tDWGC25E3r16EmyZaE5+h/n2/wFCwYNGkQWsX/CxYEOtG/Tlpth3JgxrNhdO3cJ+Npk
rh2/+MKLTRs3nT59OifysqXPRpCxevXejhDrGa0i5nz7bcIQcAyUjDMN1/3zn/90hhWUX5GM
1fTwkUP82pHR9QDZvA+wYMaM6Ry7RiKGCMNjpNdf3xFQzgsWzHeeXxV4JUBPOHO576iRTViA
ZkcgL+VvwRpvu+22alWr0YS5vAsXKgTnTYCDlYJZ7ty1K0H0fbipJ/10FzwDF8V406dOg9Vi
q+QlB03gN0wiwRMRQeJhMHEMUPDQJ3yRi+3rnn8eAA9Kk1bmQxcNEi/1s2fvXszTulVLTmeQ
P7Z4PsNEiMVSMXrqcAlNVYwCkMRS1ov//IfqG8D+jnfv3oU3YAi2bttmt/blL38ZWpIL+9NX
fgrAh5aoZfC589sKSvDVBzrp0KHDv/zlLwU6XHvtNeGk2KJFcTwbvzAMDe824QZ8LNo92l/u
3MlRy88bocMu+IWkL/xozMCFM575sQsSWQdrv3DBQqSPjnUnxiR8jsrRc+zY9ldf4zSHwo/5
oQ/XeWAVYTUCTMMxYRLhvk+eDFfF/44GnyZLyboXX6SsVixfAWIzizh1iX7hG/9yyy0YI8lH
OGDAAF/hVLS3KED04UlGIJLQpg4CS0YZ64ULBSx+/H8+PmvGTKoj5gTvgquIIi3mz+eWxHga
61zyeVApfYK8ZFkgsn+9rFwFHw0yznlPeeGMFywNZAvjXpVKlbgHunfp2kUIXdu2Hdu3jw/a
AUbyH1SqUKFzhw7du3QRU2eb17VTpy6dOrVs1kxcpgP/BA3Vr1vHgWtdqLEDpk6XQ8oBKHVo
115wQ3auCxIPCAhL/O63v2MFDWwwcOBAZ4SWOBa7ASKMozIZ79uEHkSSn/D2vffe94lPfILH
AtzUJaVKlEwYiWYKF0sGBldHk0YRUDOEJuS895we8WU2AxfOeIHoyROM0axxYzF1AszBncFZ
alStWrJYcdgUdsiSJYqTV+wiUoxxxLVo1hSXVqxQ3p4NrlrqB9wovV+F8uVEo8vCAjztwJap
fNmyMtuKCxbhDvgXAo5SZy+IRKBHGHAIY3HWCc9AtWKSggUKOmNrx/KZMJ4wEPbPkOKFQBYV
ivHIW+nMXAKV5nyYFPKQpcSFIdhPUJIGHirNeJcZDefI4VwU4wXeY9IUEsrMwJjO9gjNLEpN
zPi0KVMdkCQTxk9wnsSgjjKW3HfPPYLBxRAJNxRiSLUTAFq3Th0ijspXl+WzY0cxfngAZzYS
zFi/PvuHG2X18J44CZ4pegM/PFmwIMuJVWDXrt3YyW7QSeGYrqI3iuYWBRMkHsZjBQ3xYIHx
/vcT/wtC2bB+FAPONBJyfjLb4NjAeHzfacbLkdR9GQ/6Yhkv5r1TjRs1Jgrq1a3HrMevBRVF
HEWwzMaN+bKLFC4s8teBXH033nCj8BPmeDEX4tA3btwApSnEi+4HPoYnwcapdrff9neARior
BmYtlEkhOx4FMzCifupTnxRl873rrrWRu1702HXXiR9l5Rdf97Uog8DDbiTQTiiKZAc8H1/5
ylfiCL0Mxrvrrjvxm+Xg2aXP/t///Z9jO7q77767RrXqkaj88Y9lTAlRtqJX/Er8piXeZUzP
OWZol4DxdCHEA2JDkIHkFrAsQoDhbhkwJ44bB8zRo2vXIYMHyXriQIRbrH+W+MY3vl63Vi0h
RXJptmjalK+MRte+TRueCciPAX37yWUiaqNkyRJCE95pd4dp+bgF2tA2JbqQSuhrX/uquFtG
mqJFikoJwV5SoEAB2YfkPhAwwhopPYGgSRKPNkniiQoVqC+oxC369O4jJyet9cpPXVmyRMk3
3zwoQwTx+EKcwkyGGFbNd9pq5pgXnh7o5TEDl4DxgpWFIle2dJnmzZsjX3Aqhkr1Ejq1b1+m
ZKmunbrI605vnD51CiVT2pnyZcpiBtksbJzq162HY/3jKO/TsydoGBu9/EhqLURxbjHRv9Nc
SQYvLdTpj+Pt2wW5eCoBLMRvCKySzUGzYGt9fcfrYGU0yeNxrBAOZF8NAU1hy2ozKdAJPEAM
DCeBzjkJPCNbi2eEGk1jGi8P0s3Zo7gEjBcmIOK9ba8KJcRLHHpt2rQWB2R3JIpRRL1/XNJQ
woKgBQLLsCBHC1w1kWV/JcUFBJYNGKEnmR+/vA2eXNROnluvS6wpWQ7CeLJ8AuI5nEwc3Emb
yDNxZs3opJPgHkhtmbPfeXr0l8EMXDLGC2HUZAtZx1ApE96A/v1BsZIb0DzlgChfpsyTBQqo
RpLniTyMnPIOLJgXGet95JKQb4cuV61K1Tq1a2/bGqUGuwymKD2E9Axc+hm4ZIyXyD3cItIH
DlNFBF4v6BNGS0Dn3Xv2+NuwXv0QF8MKKlWE8jcRimXaNJ43fMiAoaIQeFeI/730j5vuMT0D
l8cMXGLGS0DJ9k7SYJJd0kKxpjSoX89XyWSLFy0yacL4qZMnVShXntuAVGzauBEHoH8ay/YX
cmCmue7yII/0KP5bM3CJGc8wQxR9YB6aJy8f/zhnQ/Wq1TgY+MS5B2r4r3JlTvOqVSqrSaIc
lwwuIuoyWC4leP+/9dzpftMz8IHOwKVnvNTHSQwSUJ2SK4p2le5TZJ0SsIIS4EXomcrHnbZb
XE4JET7Q95K++Yd8Bv67jJeksnkn82OmiEvnHfiQ01n68bLMwH+X8dLTnZ6B9AycdQbSjJcm
jPQMfAAzkGa8D2DS07dMz0Ca8dI0kJ6BD2AGPpKMF2w+mZ/zmfX31PhdO0y9eXbkZzgTRWOk
ZD4+V5+Z+Zsv7SDf9SnSDS5mBnI242VHY57PXCDULBe+61WXFqgZYOXJJwvvqScQygBHjBRV
s36XD7R3AjJVGyCN4X63Cbssfs/BjGfoEpCJJFDDxUeKlMT/fu5k95oJVgLR7tipk7ydIhIC
DPqdPn5dvWZNz569xDGcu+V5vlIDWLN6jVwZ3bt1X71qZZY+fVVnr3jxElteeeW8bnfqpIrN
hvf88y8YQMoacbqkxHkOLN3sfZuBHMx4KEwAqwKOii0LxpPWUshcVAg6qFyZJXgcJEIgZIuQ
4EwyCFnJfvXrX//gB98XOBsQaoFkIx0vviTjZCxNVFFWhW9BnE43yKLkwHGYxDNOuntSR+WM
WhnRANSjEkAo0k8JVaWJw02TSkO+CtuXSDcpc5tUPgoqaBhYUnbHVxVdRB7iPceyYsvYLWGh
XqU5DWWHo/7T4IT3javO40Y5m/EmTpz46U9/pkOHjmKO7vxXVEoS9jr1kYjBKNleZmklxA0L
qoghupdmQq22lzdvUhA8cNHevXtCEuhUPsSD5OquXTvXrn1exs5Enkj+Jy1nKr85Vv8tFLIy
87hFbbTdu/YEvTF5F9JVSMJ7y5/+BCAu6yGJnSDsDr75piSBcoS2adNGVC9MuQhj5cdSxyMD
m7sEXtW/TG6ORQkKXAxh9YraWVNCugqRh4Lyk6Lt50EP6Sbv0wzkbMZTAfiqL1wV6qdLMi0a
XeoHRRQ6deoo64TUg+o0pJZN10w9a/wp5C9hIQc4UCDS9773vWu+e43KktgMyrRixQq9evZU
JlL6sxUrlovKFeCLGYoUKdy9e/e//vWvxKZKLC6H9q5Vq5a6hJLJ537oIdyC4nPdd79q7IqD
Fi9WLMTmxlLq5JEjb/38pz8V6r569ZrTYvP48c6dOunwW9/6drkypQ3v61+7OveDD6ru4kYy
d5LkkkpJhJEvTx55QQUZlyhWTP4YgcUwd5s2bVLYUZZeqXu///3vKT4uf+GggYOUQZUlTVpR
9d+tGmmZ9z5x1Xnc5sPAeKHcHBnw6KOPUgiVDZMB6ZOf/MQd/7yjR48eGC8p3aORDLyf/MQn
1CVPpJCDfn37OVm3Tl3JNr/whf+rXKmiSPZrr/nu16++WtXyBfPnhwy5KJtodfBArlwSY197
zTWqr7BnPPrIw5/8xCeFIFavVv3jH/+YMoCkaL06dWfOnKXqqqroI4ZnVPQOeqngep1IAwMr
HmSsYoNXfvJTTxV8UuXuaVOnafCpT35SNaUuXbpKgla7dm3Z5tVzJ6uxk+f62BVXVK9eQ5Jf
Bd+HDx9uYPJ/eljppG6++feSO+XJk2fK5CmVKlV2F0XGW7RoIaY+bXc5D454n5p8mBjvP2qs
KyA+/5l5aj5ffbWK25EOqSxoQnC+ivdD06rUZzBeJAVOPProI6ovBKVOaW+UunHDevJHnukg
lDCeXCxKN6qy4kCKNCextxzvbx48IKyesMWBG+NkSnZofnVepRZK41VXXdWkcZQGNxJ48Rpw
7NjbzCo33vBD7KcT8vbJgk/qYf++DLy4pGxqNrwYB+Cr7S6HmtxnNrHKEjnTrl27r3z5SwKv
rA62uPICW2vcpWfPnn4lLV3L2uRY9hqrg7ymqXd/nygrfZtzzsCHgfGYWBAWmlZ73gIvhYQg
9x/dcOOBffsz9MlTGVusQJfIXXhuJCIzjSKqnP/5z3+Wy8zJwk899aMf3Sj3EsZTuzyD8fr1
y2S8ufKOKccZGO+mm26SEwnj/eRHP4qDel/A8HL4CryQRRffyu1px2XnmZB+YoORWub+++77
8he/+NILL+bO/fBvf/tbwjncDuMRtspq40kGmEJPPRUYz4LiV0kTv/XNb0iJv2nTxm9945tN
mzSWoA3jqVTuV1U+pc1evSra48ntfc13viNxcHjYNC9cPjPwYWC8efPmI6xhQ4dR6iRaJ0/y
5817w/U/3LN7DyqP0hYpdRJ/NGPHJxBQuaRjEY3LOX/0aJlSpSXefHnzywTSH/7w+7/+9dZX
trwsXyCKPyvjqeXgvLydzCSB8X584402cljl61+/WqVbumgkA48fW7Vq5Re/+MWmKRLPSfUk
QreyHhqMjEw1alT/3Oc+F1JWR4zXurXx2E8eOXLkhz+8PmE8i4JfW7Vs+c1vfF0WpsB4zZo2
SWU8aRaxuiVAyy1btmhQpnSa8S4fjssYSc5mPDsi4uuvf/ubRJ0sCtgAsSK4B+6//+qvfVUq
aHn7ZNGcOmVqEDiB94TCf+ELX7jh+uvt3277+9+nTJqocAIr4q9/9evb/n7b5z73WXwlv5hU
gY89+kjgBNYUN1q0cFHY49kKOkmgsce4S+7cD3FoOOAAkM+ziZj6GjVtGnPlyvWnP/5R+9o1
a4YBUDTfOnpU1m2bwwceeMBmjFDl+mCTNE7M9uCDD1WrUkXCqOBOOHT4kAd5/NFHidNvf/tb
IUVvwwYNlHRWHWXd+nWf+fSnpfpUJ8xdOnXqHD1dr16Ob/nzLSqHSvL7y5t+oe6KwkZvvnno
sqO+j/CAcjDjRX7t1avLly//1JNP2iMxLXJhoTx03LdvX5aSw4cPod1ixUvIlptpVMwogrdk
yRKZJvLlzVumTJmQoX3pkiWly5QhWzjBfN2/b7/k1gMHDoom6NSpRYsWlStXzsZJ/s9y5crL
FoOJevfu3ahRY0qgBBb16tU/fOiwnLlVqlRRBkwy3BbNmxmXHNgMnqHPsMezFRQK7KcCBQr2
6N6dwyNTFK9ma3niiTzdu3aTSLtq1ap6s+1knlGDRQJCObVlpqEvsr5UrVKN319hzWrVqqki
ZmDlK1ScN3++rrgWWrVspX9Zfd1UGaZiRYs1atgoLpT77jiYjzAvvK+PnoMZLwvwKoim4DtP
jsNBIu7iqWVXzJr8L0tXiWxMlZOOQ82jjM5jX3y4Y3KQfTazDCD49pOTKWPOejK6XVzMPdtd
Mu6LiVNulzGwgBA4PciUeyWmnfeVvtI3e4cZyMGM54kCICP5JM8YzoSv72RUOPdVSedJJ6kd
huPkLllud8avmbfJMv/Z736Wx3mHu5zrdpmPnPrUqe3TjHCZzEDOZrzMScyE88d5ls49s7Ek
OXviwFAUNsiZiA1SOzpxdgY+U5ZGl4QJvbC3G+RbKt8GGXthvSVXpfYQS9ywZFxst9lHFeT5
eRpPo3m+yAfLyZfnYMYLalXMJxnFzVNddmd9KciCnVAi97MSDaZl6oTw0HOis6WSLzY4gxmh
yQ4dCkBKn5DS9+jRt0DMLmA3hR/Azdhgjx59O1Bwklz0+LsFKZxDpgW7bpZBBlY0d5eWdJN5
i5Ljv8MKmDHUeInxXJd2ADmotxzMeIYu/bsqPw5e27Zt5MiRGStuCj1loUgvm9Fvfpy7OnlJ
QcI4M3bM2LJlynAqRILr5MlevXoqmB54+9CbB2vWqLEmNpkmOiFoJQxXEhWhKkP//v1nz5rZ
qWOnpNlZNcwst05t075t29WrVrmcfaV69erlyparUaPmwhicfVaqSgafNIjQ1plNiTWrABvp
nrgsWXhMZiR2I3lMzd5Zx5mI3NN3jKYoQ7s++zD8GkmwE6Bt3bt1MxWhWap+Hs6E/ScLsLLy
qswT6HGb00tA/MoybhIdXerV4TJhzhzMeN4fFOWwYcMcrF29mjkxxazwH2rMGV8zzQwd2rdX
F8VPQeVKbcNEmdRIQQ4lixd/KNcDwavO38BTFy5MPvsP7GeHJD/DGX48BlI2RgX9UpvFq39W
m0pQa8MnlSKV5gRDcRICUywSg+2Lz78AL5baONFmk5PPPPPMCy9EjrvsHzRdpnTpBPzN3aLP
uXPnrl+/HtLgrFOUejI1BiI5HwaQxZATfuUyZUNOFqPs42FP5tv0yM8tXx6gQhmTQPU9ccac
ZJmfy4RhLtUwcjbjATEHZti6ZUsokrx27RoHEF4onS9B4T4FjJT88ZxDnh4CzIXspPcM5G55
htKEhLT245l//ON2QOdDh4CJT1HzlLYtVrjIizFBk5PFihThxHPVwAEDXeK+Rw4dIiGbNWuu
OBmfOAwXMSUdfdPGjV0yccIEjgTgSb3Fmt6pdevWqT0GWaLw2PbtO/r169+sWTM98+D79O7Z
S4F1qLckGogDoGbNmkYCitm7V2+IcEU2ZSilD/MouESue9VdDB7MTb0xGG6xF9DhilhzpZBy
XO2G91SBAkHi+bRs0Tx1+bBqqJ7rcaZMnkT2zJgxs0uXLk0aN546dVrTpk1HjBjBf6j8k3ir
nj17jBo5yvysX7/hjTdeBwQ1FRz3oS6Np2ioEsaYsaIlxowZy5uiTevWrT2vmoRmHgZ9/Ljx
O19/49FHHgHdduHE8RN4VlauWKGUd9u2bT2Xik5eh/cFgkPfBtCrV68e2PdpCXipqP4y6CeH
M16PHhxxFDz0V6N6dZuZmjWqL126lMyZO2f22jWrVSnqipQ6d/YWoftR8MO5c8+cPiNQ4YRx
413F+6wi9IplyytUqICybRTDm27epInqYoMHDrRjaVCvXtu2bZC4gs9g1oLcSpUsaWnX26hR
o/jxlPJbv2FDsaJFpk6Z3LJ5c5KTgrdi+Yry5crjk9Dh2tVrli97dvCgwfh/1apV4pjokGTm
ooULJ0+ajDQXLlx0/733GXO8LpzikYO6tr/DLerAvPzylnJlyr7x+uuulX57wfwF4h6sC5gN
0UNI099g06wOHdp3oAh07NABt4wfPz7XffeFrMH4X83QLS9vCeuOvwL5pPQGDADIVtUMB5ol
K8uDDzwAzlr4qULLly2/9S9/GTd2bNHCRejVVjRTQWxWr1YtWo969hTN6NdHcudetHixsocW
l7x58ryyZYvGvKkrn1u5bcuWObNnqZgtOmnDunWtW7cSh4Eb8z7++I7XtoOzzZhuwO29Jrgf
RUsVG9W5laVooUKehVj+UNpgcjrjdcc5EydN4j1HuC+9+MJDDzyABIXwwDELz1F+CCwLir9P
r17oA61079o1YTyiaVG8fVK62RIuvGD9+nW+hl2HIipCSJX1e27Fii5xmQegUChKQkybIUOe
dgv4LMoVE0uNaAe42r0wXpvWrYiRpwoWhFp+5OFH4mJjERR7z569cG21a9dRBX41aRzXW+cc
VzJJjaTFixZFEql58xXLl6cwXjWi28Ixa0a0WACg7Nq5U6Q5BrMXjW8XgXKQOEf53j17H3zg
wU6dO4uHsvRUqVgxCDq3c5UDXcHQIPqE8dxu7uzZvpooSb7bt2urHwjPRvUbOFmnZk2kryq9
Y8vX4oULYdAUuLeiQc84CbNqVmnXVA9fmzVpGuEQSpZc/uwy/JzQlqXNSzG2DRs2KBplzHTR
EsWKLlqw0AriwmiJqV5j+fJloVvIoeHDhls+OnboGJaMJKLyMpBVl2YIOZ3xeii57sVs2bwZ
HYPzI3cUbBexbdurVStXUbeoV4+ezZs2xVpjRo/REouKQI/kXUQoTYT8OOjTp09c46Hl889H
dTAD4ylstH7dOu3xtj5Rw/Rp05FmYDzhORivdu1aGI8hVJsMxpscM17/ARaC5cuXr1m7lh2V
ukipU5hFvomhQ4ay06xa+Zy7h1tPGDcOPwcLCjVvxbJlWRiPNJg5Yzp5VblSZbqfZPj169XT
Zt/+/YSneHYYmvnz52G8fHnzzJkzd8WKFQBlFcqWjRjv1KmK5cqJMAyP3LF9h4DwDh86ZFC8
RTnFjNeOVCf6LEmmgPoAc1eubFk6uQr1JDPgTq0aNaSrSBhPKv6pU6d4Cp24iq2rdMkStsTl
SpdW/dNJJRCB4BYvXkJXN59DBj89bep0ANfiRYsuWbS4Tq1a2hi5NWXF8mUe31cQ9rHxy/Jy
K5YvB/j24bOw5GzG69ShA7LzhtauXmWZP3L4kIrQY8eOmzNn9tZXtqrCZ9OCRqtbpNeuLVu2
7IwZM/55++30yUB2djIVCY2pU9lRtmx5GcosWBRjxjtRvUoVYT5UtVtvuQW5d+3WbdLESRiV
MjZt2lS6mQiAu++6i/Ylao5eR1oWK1x4wrixlDEaoOKbtCb/mBDYcWzkShYvMWH8BMTtdkgz
ADi7dOo8dtQosbyRfjVt2t9uvXXZ0qUx451EjuwiMN842bpgVJUrVcLSipm5+7atVLjZQn7b
t21H4tE2d+/ehR/69+s/b94zIoawa/v27QcPHqTEvP1neK6tW7fBqhmzqaDaPfPMPHFStqYl
ihWn1EGWkdgUh9o1a5gBxQynTJla+MknBUlAfs+bO4eSSQCSe+Da5u3BXLlEA5oiMln/BrZw
wULMbxMrWMmiYAJ6dO9mxZk/f/6/77rTRprMr1O7Di0gz+OP7XzjdcqzXZyWdolUaOuXfhg8
Bw0Y4OmETRbMn4+4jhnvQ6Vy5mDG8yps53CUA+YTlISyrNYtmregpciqYLPEQgDfGCwco0aN
FlBDY6RrhU0XKUT+MGYKnGOnmz17Djt4+IlWNnPGTK9cLDnCcvLZZ5996aV13j5SYyBhGGRI
wIrdunbDdSLfhPkISF+37qUgEl2Ojok4VhDCSqcvvvCiMtQDBgw01Fdf3Yaw3IcNEwNoMHjg
IMF77CUqchqAreabhw5ZGt4+dgxSFFc7iSXQqBxJrvUULVu2tDti15HsqEWLlhs2bIRWpTC3
atXKGYKCqta5c5cRw4YdOhhbjOJ93Yb1G8RGNW3SFOLUyfA4OjQDwiNog0L4bWbNgOAmSw8r
CFMHcaeCvFgkthn9WCMYThTTtsS8tG4dY4n2Otm69ZWxY8dQHQ8ePEA7ZXbasH4dZcE4hw0d
ynwiSNLwbJLhV60pONBusFu3bpCufsVqfBI0BTrLwAH9CUD7z2gVjLyCaca7NFruxfZyNhzj
acRjlhUlC0IyZq0zai/7GsRgGFZG+0x3Q3J5oN3wyeKxSAFyngZwRs0yP8mFp3vIhJVmsdpn
ONDjeyV3yfII2Xs7x5nEMJh9HlIGkzF7wcmS2jLJCpM5RWdBlqZ6F7Iv52cdW+pkJpdk91KE
7FUXSy6X2fU5W+JdZpOZHk56Bs53BnI244WlMDyDv/+NdfG8nEjvgOTM/hKMMAMReib67Hxf
17u1o6clYiQW25dOUMT5qoMwjKc6gqWE40QipaoM7zbSj/rvOZjxImTgsSi5nWc4cvhIAApe
SlIL4XMAlJlozOzE4tY+4dbnRUoxgIad8xwpn0Of59XbmY3CTlL/zDkh7V8MXr2Ans5ySUaw
VZxEmCE3mvaTMqYd0f2xY8cxYvxconwjS+alueWHupcczHgBlGxbz5gmHlQmr8R+EA4CBWec
jMD4Z5yMfsgkkYTQkwszcsyePMkAGNIohJkKxJCx0mceMJ8wHjCuhPMZvUUwwwBFPM1FbJvA
GdBtsgwi3+R2qaPN6OJsMUEBpZ3cInNIp/tnfhRcW6tWTaCZZc8uCyDIlIfKGH/2543Dfc/F
7R6Njy6a6qpVx4we/eqrrzVu2Ei0LjOmK3kO1LiHs6lZs4Zmad5710UjBzOeoUNISIk3e/Zs
tjKZS84EQJ6BwwxaEBRI9l0+MRkLh+NhLlIrKyDFjRs2nC4WHRN+zF0Z3fCYAXIxq0iORBSk
dp6p8sX6WCa78kZwasGy6DbcNwnbTa6dMGHCypUrU7six7MPO+PNRewSc2PMj107dwFzEboO
xsUgmfJ2U0N44+CjTANSKmDVc51VdOtH5l9wNu51YLfXXnuVvZEbAGhG6he99ezenbN029at
7psYjd+V+D7KDXIw43nfDOuSWCZEiWgGDRhYpWrV3r37HH377aefHgLhIWPCqBEjYa840y3M
cICcXc2aN2fdrlql6jPPzMUwjPi0MokkeAIgs6Smrle3Hm8SdPLokchr6759e1u0bFGrVm2+
JmEQfG4w+ERcseLF//WvO3E+vziQNN8G1JVkDbyCL7zwYrt27bnRIdpwV5hoRvmypcsEGyZX
Ne+WA64tcrtJk6Zt2rR9Ye3zd999N+Al2z1HWeUqVYYNG+7K0aPHcJPobeTIUXXq1DVgcBl4
EYiZkLrChx+iQrnyQQ8MH+tRl85denTvsWPH6zzgnpcj0Ug4SPRPUXRrDhjhFJ4XkitSHUMs
YmYPiYQ3G+pMJD0DAwG7hK98DOXKlnFt8utHmaPO89lzNuNhKlnDYrmBlE/xDpUvWxbFYwzw
rkKFCtG7+HaLFi4Mc8hxDOj477vvHj92HLAvyCVvFXyTNZs/2n6Ok7pr5058g8CNWKhK5SpL
Fi/hXwawhF8BziBDZKpdumQpkQKECc4CRgzvAh8t1R9S1icHF6xww/r1YankJuKnKl2ylFCA
RMh07tTZ7dQ/AVXhsufyMmYAK5UPeL2xE5TzyBEjXFizeg1eNU5zmaQrV66M1qGN9UnMQoE8
PWhw6VIljYTHMkhX4+Gdc2DwHGikK6aSahrcxIVgJc57XoPx+Dz4ADe84YSYrE3AAIQYn57L
9cbDKdxB4plEVjds0PD5taejoghtqVy6du2q/arnVsLKOjBmrsjZs2afW2s9T9L8cDfL2YyH
Vp59NgPn4cVDPwyPBSBHMEhHvbp16J8L5y/o1qWLkyWLF/NVPAHUv8zNI0cMf/Pgm+XLlFa9
AJoR40lSBPW7bNmzUBra8+pOmzKldq0oHK5i+fJJqAuEIfRJ7ty5582dC5gClmkSixQqTGpF
AMW4aoIIicGDBgYEI7h9iPSJfcCRrLMdhbDhLyaCpkyZ0qFdO7gtTAuo7VeLBeCVWz/84EO2
jlKhLVq0MGStxYEtmjXXpnKFiuDaoGc4n8pK3YwYYOWqgOR6bfv2jh07YoaNGzcEMKSFwNLj
oG+fvqCVXNjQBWRUtapVwFwAXPwEMSOeIEgt0ljaX0tA4EN/HYen8DW4+PbvP2AAAGh0yxAa
4om6dumapFT7cHPORT5dzmY82wxbi0TDGdCvX8h4CQMFMIUa1r30EjgFxsMMJYsVI5QwHigW
/iRVYD6gojAevnLV9OnTevXoQRSgS19VCALdYE4gScqWKqWyl5PPrXgOdtGODriJXgrKGKCP
gPwEkRgCE8qiiCKHPj0kpHZu0gT8MuCeMwwzjjEerVI8IY6dNjWKbNq2bWvZMmVF2UgyLawB
OLNK5UrSh23dtk3RH1wEo+zXls1bIHxISLAsWiGciicNMwAUTrp6HMe2ZDHmez2hGo2hUSPA
SAc0zxnTpoO/gNFE4M+KFa0drVtGz2t9oW068AjgY8IvILaC7HKSug5ikkx1OLCQlS9bThAQ
/Tlgr23zwMqTh71I6vwQX56DGc+6Kw4I2M/mR6wXzSpCSxYtKmyMQkX+UNIYJKOok3btAK+e
zJ9fcQ9qJ+Ai/oTWlTzTV0GiwJODBw/Ony+/JNBUTUod0rH8Q3VCZgLv2klWqlDRBgnErHSp
UsTUww/lxqgLFiwsXqz42jVr8z2RBy4Z9kpyS4AskmrihImdOnTUj3BvgwkEjSswqruDO9tb
zpg+TdkgLI3oGWkMHnga4llsgQgAjya2TVwfM73dncD5WKlr4MFJb2OzaxXWoDxQIHR/NS5S
uPBo4Q6t2xCSJCSkuPNw4bZ/IP+lSpSkb7OFkI1AniJ94dGo3/aQ1atWE0aQdBVYK5C+kZtq
wFGg6nHjxi1cYCzP2OtaDlh9NbMdtYKYeboAqGp84SXyY3xImS8HM17AFqlZ1a9fX2YMUdi+
KpwgqjJKanDq1Lxn5gpPhVoUFcZ2ggPZJ2logkRffPFFOx+bHNs8+5nVq1d16NCBGAQRtPvC
J6QKsbNl88u6xRiWfVYNbZCySBlCxoZQYBty7NWrN7aBzHQM2ElRpPFKaiAsdeXKVZhEEKBq
dcEHsHvXbtB7Ymfzps1GawtHAut8/vwFbdu2U3VMG/BuDYgOGE7PhVvkcdEJeKf+RXB7cBuz
lSufAxPt06c3QRfkUtAAlyxaRFZ369ZVnmmTYz2KvJHHjsFG4gpD0obMpwaDU5PYrP8Vylc0
5kmTJodOEmZLpfloqnfvxmYqNwgFZGSKZmzYcA6MYJ59dslS97XrE5KX2s+HlHEu9rFyMOMl
pJboP6mQwiABsvwUnjb5KRycFQOZ5WTYRGX/pE5flkQSoXEqyDO6XYqPQ6g7AcKtl9ptAhk9
Y/DvkMbi9NPFZBB4JvsgA7onOZ/l0UClGVTDr+dgmHMgRWP80BkOj3DmYmnzQ319zma8nPtq
zLtNXefOnXfv2nlmIsH3+5nYReWcjtj2PME37/cAP5z3SzPeB/Zes8irD2QciWs+QtsdT8uo
9+8lpBnv/Zvr9J3SM5DMQJrx0sSQnoEPYAbSjPcBTHr6lukZSDNemgbSM/ABzECa8T6ASU/f
Mj0DacZL00B6Bj6AGUgz3gcw6elbpmcgzXhpGkjPwAcwA2nG+wAmPX3L9AykGS9NA+kZ+ABm
IM14H8Ckp2+ZnoEczHhxmscMMH5I7hhCb97rS4WZDLMQgIuOU+H277W3828f7hINOyOO4fSl
IVDg3J8kniCjcQhNCBkv40+YkPiJMrJZJ8EZyU9JCEVSFDI1ju7MsImMyQkhF8ktUoeadBs1
eIfohIxHzoyWOOszhnGeT3xD8qbC857njL3b1L4fv+doxjsugaRMOwoehPcktDQqzfMeP+Lo
JIOQux9QWIidIL04LewJGUfE1L1T6EBCxO/xbqebG3AIKfQ3yTLkZyvHoWgw70hGgR/kL1Ip
QfomyQX90YnAQtmZMugvypwbLUzCC50PS5IDl8R3PPHWkWjqhCbs2bM7JErcs3uvZ08YSdj7
jtdff3Xbq8IRpb2QXdRESQkTzU9mHIObRj9l1pR3awUbBPueIywoZHPzV4LAqBTz2RbKI6rP
HDoUErqde3rdyPOLAIwm8JwgbzdSP1C5lQt+X5f2whzMeN6KkiCFCxcpX768mjvmRSEuQdln
ov5Px6Elj5p6gAIkhhg3Zkwo6dy8aZP1L70Ueli6eHHd2nVioZqZqTqOxQ5SMdBxdJz5axLz
FjFPyoqeiKZIIsWfRFxYo5VFkU9JHGo476/g1Hx58qKSs5Kdk35Sk0z6oxrVqklmMWTw4Pnz
5rujNCoSioWrYu49JEGLHBOK9QiWlQRNLgwJHUJ2DPHjhQsXln9T7LmvIoNKlyotq8XmzS+H
B1RJS+2X2nXqlChRQj4YZ6Q2Gz92rIygoorDg8ho5hYh2UT4KLckv2DqY2al1xMnhSM3adRY
foCe3Xsk61d007ipg0mTJgmxdZyljkKsz2Smr86czEOHolJ7wurDTSPxHmVJy3jvyd39pNRu
wwb1w7u7tFx0Ab3lbMYLOeeIK7m3vH605aVaBRFEyE0kdlu0NbKTalptGhOuio3zcS7naJmX
EkKWPqm+oguPH1ezTra8kKlOqhW14MK6G9ggfFSl079mqhxbm8PqLhDbT/v37Uu4S/0gvzqJ
evQfsu6RTqFlLO2itV8AePWqVTrG6YZcK/+SxJsPP/RQKKyV5Y0GaabmkdQS+MqodCv1g1QU
0YAXLmwYF5TMYOAZM2vXrOUWEq5MnKh82Fi50qSZqVi+whtv7JR/dvLEqFyZgXhezC+4XslI
SdNCD+5ltP6akwH9+jspnp1AM11uahyRgD1yBMWHUuYmXz9SV+jBGwlBydnVPyeV1FMQk9Q1
53oIExjl84z0jKiQ4N69+6gbo0eNxn6+xm9nj+eVsjp5F5HUlUj32DGZF4sWLqTCkZ/27tsb
K9sIIJreAwf2hzGEN67iZ4P69dKMdwHLxBmXmE35C6QeMbOWZNXhlFaUXESevFo1a6urLNeY
1H0Ki1etVk3qFOWOK1WsJNlJqxYtJUeRztkbVU1WZjuqZs8ePWlRsnFpQ0qowuU91aldS+eq
z+lNTgdZfVSQrFatuvSYbVq1/sMf/oA4QqJOmQUlcZHQWvE3SVz69elrRVfRynIg54ocKtu3
vybZniRIJJWsE15/RGsxN0pRERjPZ9SIEf379lXQTycJC4WfgiClK6q8l5o8V5EwCSw0UNFS
TdbQ2EdmJDUDpSSUr0VWmKaNm4Q8ufILyq0iA0WD+g0krUDrMlyE0sqknPRHFqkgE5yRu1Yi
I6wlHYb0FmHOlYyVRUJ9eckpLAFS11A0ypevgLFNmhTD7qgs4e7dewIDJ0MKfbq7BIcmPzCh
rKS4i1yVf0lqDPM5YcLEAf0HFCxYUBHZpc8+a3klq/M8kWf9upeGPP10hQoVpcawQjVp3ERi
JSl0S5coIfWTZlKqCuo/8tYRiVUVnY5qa0s3HKeiqVSpcolixcx/SO59scR30dfnbIknKdgT
jz/x5JNPNmsSZbZq07pNvz59LN5UUDm/VCr2RjGVcseoTQlLqY1e3rzl3rvvlgTJu5w+daqc
JbNnziI6MJu/UdHWoUPkyUOyVE2aiaRjRJAstxUrlKdrPVXgSbLIvkKbGtVrWEddSNkjHCSH
xhV66N2zR8F8+W0nsJZ8gZhZs2NH30aO8rXIfSLlHiZKDANy+6mwafwouE6t2mR1tSqVSYNA
H74qE42BQ+72TZs216xZK17Io0IRDtq1aZsnTx6FKQsWKFi/Xn2XHIlqJ0RqcMkSJf/fb35D
vURrmPmlFyMt2pDGjBqFQ3AsQmzbuo1nlKEoqJdlS5ci2SI+jzvv2qWzTDAOqH/9+kVZKnCm
CntPFsj/zNw5tpSFCz2Fc0yC/bAMn1RN+UtlH5UwSh7BaJwnT3quSZMmWhnDE/krd8uTBQvK
oSYHXKsWzTdt3HDHP26nvCycPx/34u2e3bpT/vv37xfeoIQuMhpa7yxnJtYyKjna448+Kukb
SViiaFF7UfMvMWmp4sXVpldfVvFtSdaktLHLxefyXHl98jgaUprxLmrdiFZf5Ua7dpN6VeYv
mpIcRCqJSuq65eXNqEeWS6RJF6JxeT1jxoxWAN3uR6lXKopMW7Z2gwYOkM6ImiR7LD3KCrp5
40aqqWoMC+fPsxVR1TH3Q7mbNm1WuFAhRRLpdWQdBpOtCK0bg0xbJFggTYmrH3n4YTk7EZbz
XraRyDOp6KQslI8+/EjtWrXUHmgoU1hmfRUXSs2E2hy0bdO2atVqhC1VU1KjIB+sDldccYWF
IFAMc0iF8hVcHudgjxp0aNe+b99+iHhklIEvSr9ZrVpV2fgIfyPctHGT7KOSiNKyQs5pOyvF
n4MUOnb8mOxpshjGtZ2lEjtcoVyUri/6Lb5X9WpVg248beq0wYOj1NG1atRcv36DdKO7d+4k
ssuWKW3XJ0116HDNmjVkjgMZqCRfDCc9nUfo27t3xM+ZezNZp3DF5s2baMKG59WYW3J42dJn
B/bvp8w19Vj604h1T5zUZt2LL9FuHnzgAVkGZVKTetAW14pmybPHw3gjRgwnAx+4PxfhLJep
h2VzkiLR17pxweeN6zeEEtNpxrtYxkNDiMacyq4Z8md6YWafUkfJrFq5UmQ76drVrlob/IAC
vKeqFSsxYsppOX7cWGqkjF00N/obxtOPVJxv7NxZQzmO+fMaNWgwYfw4RPnmm4cOxkVV9UO9
JLJY0uSx9tW2SlXUtavXlCxRwg4K71GfnJcXjG4TLrH8Y0V0tmr1qsM0uSgzV/RJrClKk2um
7rG0fOq8/uWWW9wl2HAYFSWcJaAsGWHfZdl+Ji46Gz6SF6JCB1jOoqNz+iHpLb2f3KHO+5XU
tdAQtr7Wr1sXe4RryZMK5ctZODz+sbeP4l5LQxBKfu3bu0+oEe9DZ+vff4CDMqVKrd+wgagk
1mybCRP6BR4IzVavWa0EswNSS20TBzpT+hxTydUZKdjRJ8PIVKZUaZk5ZWcsX6YsPqGTV65Y
ycj79O5F37ZQhpkk8IcNifIUW0qsj8yqllEagc3qgf0HPG+ZUiWlVLXAUV9NjvRNqtWSvQS4
bYOnsxOJ52dZtGlPG1cuiu3ihVPuV6nUbc/oHl6YysNegL2HN03BkHOWQvj4Y4/LZCklprIK
FmbWDUqLNyd565hRo627pCWZwDxDqWNIWPfii6+/sZNiJnlk3dq1WR3Z+qKq3IMGIg70pLFc
sfrPlzcvC2SDevWdl41PyXXcpZ/evXrTyuyC6I0SUBIINDELBIlE3EkFL5Ulug6Gh4gxZsyU
4jJhJAdVK1UKxqFEPjiOWsfqn61agXz5KYoeH/V36tB+aqzU0cQ8e9KPgsaFnnrKgIsULqLW
NLovUbwEg1CdWrVw7zNz5lIWlExo37YtUrRm2Z3KqDtz5ozQA6lu6iQvpKiTyXaMZL6Huutf
/6Lu1qheTRZ3/dDeLXOutQzhwCWLF4WEtj169AwSL8seD08/v/Z59lL8Zj3yq+LYD+TKRQex
ajxZoGB0bfcexKORFC9aTIp+Sqkq87LQSwFM0bXBk5rNg5PVrFk8D9RL2RatHfJk57rv/pjx
mq5eufLAwQMVypbDqHazkhRbGW1D9J+WeBfJeiet0CNGjLQuBlMEFUj9ILttTIi1qKCUfsV3
hg8fMXnylI0bqX6bvWDrPdcTQqRKIeVZs2exgqgr8NZbR5Xz3r9/H3cg4tCnv7qVqdZ+Q4ER
Ak25Dx2+eehNQ6d5yodp48SAqdkLz6+VSRZXUJ+wmeyuVFbjkQyXuT961LhKOCmEaJJ3H+wl
EmwmcxHl+Vy1yvbpbPQRmf/ci3mDP0AaX5TnqVhuULAkogaT9KMZ48eQIUNtdwMvrVmzdsTI
kbt2RuXEJH72UDNnzjIhhBLzCTvTM1G6segT7fcOHpRp0/RqRvvVP51NNls7KJZh02WG5cx+
bsUK+gLiHjt2rLoRJs2qpzG3xGvbtgX5lvrx1XThEzMZKxEnvaOQXt4uMVS091pf3vwyFXfi
xEkyoCqDYdiS1StJz/eowAMlxcbPezRLVlJjsAQsW7bMhFhq2V3pI5HJ9OhR6wV92DFXkzdI
nblYmrtE1+dg40qqNMiyssZrWkoKyxRpEq5Krj2zslesAmUa9MJFqQt2SjcZtofkzFnzYZ7R
PsW5Fw0ghR5Dsyxn3tHwdmbyzOT9JeNMJYxkAIHtU0abJQ3m6WycyeVZKIOim/I4mbXHYqUx
Ow0lg8nuToi4OqWj1JZZJjx7t6nzmepeP+sYkrechU4uEeNcbDc5m/Eu9unT16dn4AOagRzM
eBbLZPRBOwoC6lLOZOYtguk/rLJZbhCt2SnFYrNInowLM4Esrk0VO6niNFEss8jYLG0iQGnS
W1yJ/Ayxlu3howk5w5OWkez9vc5SIo6S580+1Umb0HmQOUGSx6PIQKWeqUecgYzNuCS+PExd
xtPFVplU8Z78FCpsJhpH7IS/pDTwXmfq/NrnZMY7fpxxcssWxRG2ej0HDhxUEOHSTrqXGpAT
sQUyep1gK1lqptIJbTDsKjOoTZVwu59Dh8LXBJpoJ7bjte0xnOKg3SZkhjH7avuhyMGGjRtY
U5JLbOE2bNjI4geWoQ3XCD+4j32XF+Z2Nqs2OTjQ3mzbtlc3bFivOOtZnz1GyBzne1SyyxgS
pMj5kUdGK0NVOMVGLjx7BAw6cCAq457Sizb2xgyOYRjhjRheJuNFLGQ36CnswWxVudftM5l4
wzzYHJoFM2OEoddQKzce+UZmEvMMPrpp8+bDbx6KqDae54ALDcgyW2VTcekX3/c0U+fdOAcz
nilmqCxQoACsCazjunUvhepwyaoZjkmEQAepP6WKytS5ymJrdgksCNe58wiCAZBlLwJ2pIC5
tOGLZ0EN/b999K08jz/OPZg5jKikEeM7uytfBXplZgRe4dTmxEdMjgEs9PB8XGndYI6+fZQR
r06dOmXKlKlapTLjQblyZSFu6tevhzIxKkc8MynPHuMNFEjevHlq166lxhBTx1nsMXFNJYUs
QXaAeEKxsWha4k+4Y/T3zD1laj/hF2WG2HK13LtnjzEbQ2ob/WGApwoW7NGtW+jfje6+8061
BMMtNN7+2nYGZC+rR7fuVpAWzZt5BP4DDIMhlWoyh0yj/EChZxeqjlKkUCHNmG2xPb8O2IqZ
dIlnZyKGEIAo0nLRosWKGbHfqj2YEMB5c8EH0DBnM556yEyall44abYvrlXIzEgURNrYKedB
+EFEYmo+xueDaKK3EpePVXkHXDPWTML6Gq+cQb+JpYSWjGBPFSjA4a6BGIg+vftwWwErhVcb
tB1m6wL58sVglIhW+KYfffhhjuCEppVibtUy8inrMwYiRmOAseKWcEmtWrWA9AMnJO8/0C4X
Ip+BS/Ati2tykjfZsRKtHhlqhA09/HRW8tEtaczUHiBabkO0sg1akAio0C3RQTQlAtOsRDOT
oSJGz6gSYJ5HH2vXJipbCQ4CjRlVoowrwifzAOf5+COPdOvcOQyGizXXvfc+M3t2Mg9gesEd
J5ri6FtH98NVxvg1dcswlRqd4cIgVONhHyxetCgfaXTy2DFOF04Lx1FVtvETeGUxeVRbs0oV
r4mnbu2aNdtffY3v4aww1w+At855y5zNeKRHcKBXr16DLbtA/ny1atYCwmShZmeP5EyFCtxK
bx48wDmrUhwX9sJ4DSYh8SpGpUEFig+KzYwZylYtdQbtOetaLxicivvBSbKOeAp8kvAqMATg
RQSJOHWKpZ6rmi+R6zkm8ij+BU1wJXNeE1YJbXFgQDBpYJ3u3r370qVLUjknNIM+4zcH91WC
jz+NX85JhcSqVKqs8BjAGvs7lGapUqVZ+XftysB2ZhHvboHTVN4MHhdAFsLKs4tRgLHi4Nqz
ew9NwTKUcL4DZQBVBQuPQEo3atBQnc0O7TOcjZwf0KfJUqGN9U5XADrd4yqZ3Bgtm7ckIWdn
egWxfdmyZUBPpkyZZM6jQcbhHcFJyNOdN29eJQq5ExJG5QUh3HhKleNzkqfE2+TM4OLHaSbc
JDhP4sGaQagErDaVRNG11Mm83FgujCeHM16PHqWjaoktOUxfevGFwk89ZTvUqWMnPiLeapAO
OgxZBPFQIF9e72zunLla8sMiRE68ShUqzJsXvdRkpz5s+PA5szNAIZzOMGj2TlGlxZgqufgq
la/A+5QQh57xGJcgwIqTsKMLFixQjxaAJuqWpH3r6EMPPIDhjYpqRMKAGloa/nXHHevXrder
oIGBAweWKF4c80TdZm6QOAA5fMkiG6rRI0ciUGUrLS7aAEz97re/LV+uLJFjm9S/Xz8162hx
RERQIHm0Bw0cZCsVhwedNAlPPPYYqlUxE4DOP15paiGOov268OlBg1yVaoYB++IfD/w/bOgw
/jF4zgQXpta5KuoJ42kD0wyGCnwXqk+bDY44LLFg3rzQCdfl7X//O7CBn1q2bOV2XkeRIoWB
4/bt248DKedQRDz+bhQumTFt2q233NKlSxfaKfyDMwKXbv7tb82VZRFWRl1eJ7naoXA9CICO
Pv9w880BqHR58lsyqhzPeDVr1qRu2QhZv4MONnTokJHDh9uPzZsblapE0JDQ9WrXpmpGK3GL
FlMnTwKVUBQOzYnKCeQO0QurlS9/vmLFiou7EdngQBktQBNUy6VrpiLGq1AhqJq+gkrnzZMX
TkW19IIFCgBM5H7oIVqQJRk+m/pkli3DDz34IIe4S4gaVIWRoF4QKPBkYm/k66cyhSUgiCxA
DRU2HSQxaQplUi89jnEK/rXkI7hAo6HzZXE5eB+AG9hIkPxAf0ailDRmo2F6EIoiafn4o4/x
Pnv8m37xC0IvuvXxEyJqBw8aDORx/3331YCfbtvWQz2cOzcfOgBa8WLFAn4a4yUSz1chObly
5YJxIzltPufMmQPdakkqWqQIHGmIh8J4ue6/H07aMfgIaCUtkWlEYGGIRQwf8U1hJxkdT5qM
Dx2wCVFeQGHtUe0dDI+4BoUNwDfAIC1FMFN26tdvkDfPE8xI4cEv50/OZjwY6UBePiB5ETWw
uAwcOGrkCLssaAdfMQ8oE5Cetw5WInATjIvwQRDEEUNZWOnhLQirunXrQUELlmFJGzNmTFQV
uUGDu+++O6hA9CUlvyPTYhy1ybo4bNhwberUqY2qFi9eMnDAwN59ehcrVgzFJOEFkPIQzy5n
PEiWc2AL28UQFuRDAQY7jqg/7KxOnoRTiwo4xyFnoQ2lC/W3Ugx5bCQbx40dg3UTksXqNjm+
Ghi8OAlJ4kER6M0eD60LHfAroCblmTRjtCDxdFi0cJFhQ6OtVwhTMkVMGsWLl6BtstzQZgd4
qN69WTUee/QxS4aW1i97vNB5vB7tJ6ysbqVKlbIAqWXta+/evXLnzq2ZWdKG/blkyZK0DA9I
/qsNGEYOj0JHTZ5C1I99e/hqd0fERQcvvqASPXEdxjl92nT6vP02DdPX2lHQUwb0lApqHtwr
dcN8ebJfzma8Xj17jB0zOrwnaK9Qu9yajbZodHQzWigwJ+t8zWrVAb5QFZ3Ei8EDUIt4EjmG
lxQ6oaAmqmY4s3XrKxbXcEwpgg+0ZcowK2T60yiNtosJ9YDVU958Dd2CUJIVjRo2omjZaFnR
O3ToWKhQIbApVGi9V9O4VKmS6DW6JCreesomqljRIqxEemCTJFHhpMlnazwiwyp0SyBJ+z2B
diSAzuG5Q4qHLHu8iPH2G3aFsMezKgm9o28XyC+uZy5IKv4sVbIUiZF6LVmHSZInip9iUbfO
0f7NBzbVGpekWkiaUfYE4yRfgSotYck8AH2VK1OO7AJ8hSZjLnYX4ExbNc8IrWpmPKOY+qAw
W3GaNW4irI51F9SOUs1oqWB14UKFCepXX32VZdhCCZ7qwWkxwLelS5acMSPCml6ezJY6qhzM
eKj21ddeQ0+BYmDWoxQpJ07s2LH9jTeiRADIl34Cx4iWvTZaH20zorC4CPjkKVMIIpEjYTqC
LXPH9h0Qj8G6Gc6Tb9Sz8NUL1qe/Wd6rbqNbZ35sooiUMKqQQGn16jWsKThWz4gG2jNE6MQS
ZpWvhpdCLicobzwHBuVyEQDMKoLiUGSgaY3Jeaq1Y3XJp02bTrsL9snsBBebUt8Kj+9XEl4k
m8gJC5PIJmZAV3GgGXMiJTws76idYWJn9ZMbKc4e1gVTDU1JPmahJLalCP4afzSz3oVY2PAh
vYULG6ox0DPtt6M68ps3G4ApJV1BQ4NETXowBpZbQXfhwe0bx0+YCIubOQ+bpk6dRp671/r1
68yJZchPOcF/npONKymJseL3Gn+SXVMqeDL8mqwxWX5KKCMxsaTSUyoqJfSTnbhDgo/TFBZG
kvIJYwsnU4+zf40vyoBrZHo6znVJ0ttZB5Y6pAyBlg3BmsxYlgFn0daS6T091TGiIPtjvtM8
pK7xqccZbJn5JKlskzxdWALOMXWnW0bzl0auZCfS9Jn0DKRnIEe7E876+s4qtc4io86mkATn
+RkyJEYYhjOpP1EUQuN3IqHkkosZZJo+P8QzkIP3eGd9K1QSWxf/zmHXOvrWW7bmGcn54n18
0FEDa7HCrX3+ed5bEKegv9m6MKPbAs6YPoPrwh4yoBbfifF0yJDDCmLbmJofNhmwQdrC2WVd
/sa3DzHpf7CPlrMZL2Xbdhqn//TTTwe7c8xOpzcGSWOmF5462MuQC1Azlr3Qnj2aoa9xo4YM
bsAuTI6YBO6EV4oFnJlUtGW3rl1eBLOMWSqDac/cQ+pHFgYG1WRfl+w6kjFI4yPj0OkGHywV
pO/+vs9ADma8iGdi0xk8brAQbHt1Gx/xsCFDnh78tLBxDm7cAZEo5Jm5TBuNiTt2wt17MN1e
TgXJMzmvubm279jBssdCPf+ZeTiNKRwaA8SRI5v7wWfylKmSJsGOuTDOWxzJPKZCljfH7nLo
8GEeYSbQ3Xt261b2LrbNKINDDBzzZsNcGwOMr6RMI4YNjwXv0Q8+19z7TnbpG+ZgxkOv0FLl
ypWHHfEiBw4YwIErzaOTeZ/IU7VqFeikyBfUrBlJVbx4cRlQgI/gvzZu2sixK5vlX2+9Fe+1
bNni9zf/XoIGPi7/eCCkypk4YeL9997L7ydjUpfOnSQO4Em//fbbpUtp2iTKJxkJq1P/ASuT
GdYRcJkERDxyNWrWBONgKBejoPOKFStyeERcFzOexpzCXTp37t2zl5Qt0Plc2AaZ1jk/aqyY
UxnPuNHrUwUKBlAIoAmpFXLxQ7s3b9rMDqxSpUpbt2yRlgfWkRe7dKmSXNIA7zKIyP8FMMX3
ChIpb7E2OpHoVnJleaxs88TCgXqSk9WqVMVpoDAEY+sYnl+2dGnJ0oOWSAWV/8cBNNOi2Fk8
Y9p0OZdopFHeruPHuKrlUwqN9QBXEVUFOHUK0AMUAwBaqiwyMGwm05+PzgzkVMYLMoQjWDiJ
FNHgVLBUgb4BxKLceBE8ql4E4GzcGD6LqQOhO1mhbNk5c2djHjpnzHivUB2rx4xH3EmJi9Pk
gcM2sqqCwsAHSwoowSOAYuu4BwBrGXXCvcSqdI0DYVq3ar1s6VLgKeBdQa7u2L5dlBxaQthp
U6P86j4ghe3btAnHVocA/JXzC8Y6zXgfHZYLT5qDGS+ghwkxsEOSqnSJkiG3PugwQL0DYGWM
B7m7dPESMqpl8xYeWA5Glkk4SRfWrVP3tde22+5RQbUXgikAh2pKTI0fO44SmPeJJwCa2rRt
K/BHviqRYJrhyZUrngvTh/F0G/FzhQoyTwtKCGhMEq91XIRAHjuBambZjhRqXjhpcN9rKSWZ
A7E/bLBpxkszHvDTtddee8Wtt96KQMPyHD6X1T7EYEDpJaWVLBkKmdTq2LEjbbN71279+/WX
MNOAYflBpaLkykuXCleV6hz1V6lUUeQBqcX0Iic09K3AH8hJqGKX4C6cIMEjeKRiA5C44FGY
Z+zo0WvWrpXpmX1EgmqAr9mz59jgMZPA4LvR3XfdBbIklTpjZteu3aZOnRKCaOSulKFdRoOn
nx7CCkqiijETmtCrZ69JEybojVjmV0gzXprxcgbjeU+AjIIjxYABXkbrwslTjPhEDd8A6HME
vNyxg1gTSCLOUkESRkvbQtZOqHzmRJdjV1vEkLpD5E6IA1Aoz0n7QDGjYbkRJKql9ObYLAKI
viqkJToOFWrs0BYtWoh7FZojHl24YOFCv8aZRU6wrEBy+mzdGoEYiTtgaE5C5wUZgTtu377D
lvKjRnbp583BqqaXl0jj+PgMGGL4NXm8VIdbuCq5PGkTqCGLkE8AK2d12WVpn3ptfIvTSbJS
73jmsC8vVSLNEu/PDORsxnt/5ih9l/QMXPIZyMGMd56wzOxTFm9YMyK7L4eNaxCA7wRAy/KY
voZ3ltRDPjtNnAk6Df0HFeCsKNN33WSee5CXnC4/9B3mYMbzbpYtWy6vUcI8iQUoOcj+/jQW
GGoPFkfuvR6Fk3+gL9l4hNvZN77TKGBKhYTbpkaPGYO2wWVgYqK0lpkg7ezP66HUalQ55OWX
N6uywJcYb1Zfj/JhZkOZAuLYKvOvvNMy5LxtsL1uFi39A525nH3zHMx4iKBZ0yZRfoTMj/JU
IcW/g7h2+elPwJSFp4XknD51GmMMt4GkfdH5zEC7ZDoyY/ZOB3R7zxmiJlPmRMaSk6nZrDM2
mUnLhEwDh5y5zTu9I+W3UEU5yOHTci8TZcrkw7UYJeTL3JfCo6m5lfp0MppED5gZER9+4tnv
3r0HV6dEZkp/GKp8M+r1hV8Dj4Vj7scK5cpivDNHmHoHNdNHuC87kDXLD2pNhoLVOZv8P7jR
52zGU3VNcishycePvQ2DIv+U5Hxy4xQvXkzCPLZEpsXVa9ZESTgkxoyqdUcVt9XiYsEXcCAB
GQKKQJfHjqmJB4epJDrz4yG5igUl7NoVYTJPnFAfWGQ6OSFHy062yrhouISqfnIlAlabJi5D
o0TOZoPRj58UFla7izMd54SMmu7omKFVOjC5H6XE4pZg3pT1QGIyFxJlADeJjUeGwlWrVovp
VoKPTz+OSY9YRfrAkOCAT9+v7iKdCd8GDKrjUAuJKVU6CZnzpE6RlcSA9+7Z7Xk5UdTc4TUJ
1SfNlXEaAyeK3oTnO3mQBfiNndJym65169dp76TBw52q1KM3hm+w1aefHhzVOr8Myhp/cOxz
4XfO2YwHrSIBifLWXTt3ARC55Za/cLUpaHjLLbeEBGFAm9Wj/MT1uRMgUVCpnLZ8dzhBklaV
2WSMlRcE/cFh+lUmr/vuuUeZO7Qr8xxwCWkg52yUDnDrVkWbpd9CjqNHjxoSZ/gy8T169ChX
tpwkKMDZfHTWAv4JiLCyZctyl1euVNG9otSA+/Yjbn6IRQsXkFdr1z7fpGkT2VflIDEGGACZ
nsmoqHH8oXzCl0n1JSFn+bJlIcsgUSdMGO8nydQsHIBplStXIb2hdv7yl7/ECQ5fhBZQh10e
Md6RO+64Q+Yy2ZnuvfdeTPXs0iUywEoPY7TyC4HLSFgGOOrCjRvWgwpUr1ZdAb1Vq1YpQKmu
rdybUVKTOnXAXC09JnbihPGm4p577sH55kHVctrs5bBJvnDy/+CufEfGy58/P8JN1TYutyk2
NimGZJImpmhTXG1y/vB3m0y5vgkjnAZvqZmVfuHCRSFXCroPBcf9BNglozMyIhlyP/jgnNmz
nh48qG3r1nLOyeEhPzSwGFHTplWrXj16Eq0YMs9jjxFTZGZAqBBxvPa41LF0Q/37RlXCBeMp
m4r96GalS5biMDR1SjHjH7FIdlM6DBMLU0ogG4l8hFguPEX4SUag4XFwEymsN6kyn3/hBWxg
n+avx1RqPGR0pWRKOEsiEbkyqamjkC9PHntXEDlZUlaufE6dR8147WU3mjZlqjLikXq5b7+R
h6TLBw7sl2aTDJ8xY6YM0PJhmgQ7OreQH0ViMnVhZROcOWM6AFDPnlFv1jWLVFrVvGDOzc54
NKCbbrrpiqpVqwL+XuaMR7ysWPEcCIsCvDRJ9U0RLoUQWIwWJKnrvLlzPYJ4BVlxwrMIsSPi
qIING9SXT5LWhIvgXYQSYUiJruCtmzRuBEs5eOBAVYXJrihT6vLl7dq0AcvEWoIhZJgO2fIk
DnJ56Pm1ba/Cdnbu2Im0UcnZmTgZbv0AZONFV80U89t0yfnpDFEmJ6SD9u3bcf1TFKFqMG3o
DbmHxKwYT0QFvVcaNfEWBq9SsfNMMmQUw4m9Wf26Uf4yCq+MmrVq1yarqakGuWH9Biq3NOna
k2x8/ThfAV05wmTgVrs43ItOThrj/HnPPEMaW18sBDLf1qsjT/spD+i83mbNmCFTU7euUW8k
/JLFZ2S/vmAS/GhemJ3xFLumpFwhg2/RokUvc8aT2hUpSAlesVx52zDYMcv2kbeOUNuwnxgc
ATgegUBApgwDTtLTGFRgo6mp2M+mS+o7mqS48pLFi8u3aeNmyS+YL7/U1IhVSnBKJjYr/ORT
UgOKbn/iscfJKM1syeS9kkIzlCUI9nr64fBhQ/2VcJrEK1tabfG3jTBUAnCJVJz6sUwApilR
4BKiiXFFmrAKRNCu3YapK3FG3bp09atr6caGR+IRxX169ZZkNrw2m668efJs2fKyXK6ygHk0
WDn1ekg8GjV0uASb4pjIbUH0+EfPAZ0zsP8AS0OZ0qVkE/NVOQcrl9mZPWumNcjKMmTQYJEZ
AjU8ZqMG9a1fJJ7UzoI8BF65pEXLlhL+Ofhoss3FP3V2xgscd0VAjl3mjCcv+nPLlrEcEHFY
TpSd1OLibiz79jlq7lj7baLwGIrv1bM3/VBouaXdvmh4DKSOFu+2bUNx+qqVq7ZqFSGbyTGp
pnUrSK9gwYKRyDp1Cn+iYDOO1iWTtSHs3iNKV96vbx85p7Foz+7dataoKREtD4fErOqJlyhW
nJa4bes2iE28JOxdks98efJaDkaNGvXE4483btzIMCSEJPEwHouFyKahQ4fRgXfu3GV7ZgXB
xpLwYlTWlyaNGotdAlUjOYkgkRlgop6XJJRJmtosV6xtWMECBUl+T6rAyNKlz9oysP2SY0aL
c+gyZUqXkb1X2maZKsUZCi+kJ9u7UoNpBzQFYVDuiJNZj9q0aknM6g3oVLSUxzd7xi+TvI3i
5bYBuXiWeH96yM54xB2hd4WXdPPNN1svE9673KYYKdOR6E5WcTF1NnUkwPoNG3x1nkyzq0G1
dkchpSSDJFMe6cQJwOgXWeTi2CI2TFXv4t4OImL9RKa/3XvYF0kbPUdugxMnXCjVioOouDYi
PfLWGzsjNKb5YZthtECpLIohyTnepvup0SF1vN5wkZa4RVJkmzSWHssERlq1ehWZaTCYnPSL
IKbHjslFaYemE4MJedfd2rVUSrfWf1zL6Di9kYWGePdePDg902aS0SXq8ODBuKzfgWich9/y
q0+cJ+aE/wkLJMPDa2Ud4WkwFXL1unVczTxqSWzqwSDdSD+GZ0rDjLH6CunwK65Oavq9P8T6
YbpLFsbzpq666ip/I8aTzJxp7rJlvGBbT/xRiVcqOWC0nD49Y2uXnAzaUXioxHCf5WSYlHM3
S9pkX7pwvs1bq1atK1aoGDaZqb2lKhFZ5jal2RkJocP55Eapw07tOXUkyeSkOvdSM9CkdpLl
eVMHnDEJmR7CZE6yDObDxBLvz7NkIZuE1yLGw3+0TRj/8CYuN4l37gkK/rdIvr2/nyj38/Hj
FHVxQ2SCeSNC3wXe9f6OMH23y2EGUhkvldEixvMRrHnfffflUMYLw34nDOR/a/ZjKGQiyoKa
+n6P4b/1bOl+L9kMpDJeqmqZwXgIiKWFvSXHSbxLNkPpjtIz8F+YgYTxmFEEnYeqmj6nGc8p
9pYs0ehn3aikT6ZnID0D72kGbEmYMJPd3BmM5wvrlp8lin1PnaYbp2cgPQPnmAGyDlvhvdQ2
pyVeOEvuPfLII1xAmDA9m+kZSM/AxcwAbrKvo2GmyrqsqmbqDYDI2Dldk2a/i5n39LUf5RmA
Z7jxxhs56pJ93bkkXvIblnMNZx9rJ6OLvR8P7Ed5HtPPnp6Bc89A7FuabadGZ7zyyiuFH2RR
L8+L8ZJGPA0MnsQl9lXqPv1Jz0B6Bs46A5REbILr8N5ZpVwq4/1/9BckHFTJneYAAAAASUVO
RK5CYII=
--------------080809040707040705050002--

--------------050205090209020308010903--


From nobody Mon Dec 29 11:05:11 2014
Return-Path: <schmitt@ifi.uzh.ch>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 415541A9045 for <ace@ietfa.amsl.com>; Mon, 29 Dec 2014 11:05:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.106
X-Spam-Level: 
X-Spam-Status: No, score=-3.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_IMAGE_ONLY_16=1.092, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, T_HK_NAME_DR=0.01, T_RP_MATCHES_RCVD=-0.01, UNPARSEABLE_RELAY=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0fr0M5Cth1-r for <ace@ietfa.amsl.com>; Mon, 29 Dec 2014 11:05:04 -0800 (PST)
Received: from bohuslav.ifi.uzh.ch (bohuslav.ifi.uzh.ch [130.60.155.10]) by ietfa.amsl.com (Postfix) with ESMTP id CFF6D1A904A for <ace@ietf.org>; Mon, 29 Dec 2014 11:05:03 -0800 (PST)
Received: from authenticated sender schmitt by bohuslav.ifi.uzh.ch (postfix) with ESMTPSA id SA; <16D2C7FC77>
Message-ID: <54A1A5DD.3010500@ifi.uzh.ch>
Date: Mon, 29 Dec 2014 20:05:01 +0100
From: "Dr. Corinna Schmitt" <schmitt@ifi.uzh.ch>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <549F27AB.3090807@ifi.uzh.ch> <46A1DF3F04371240B504290A071B4DB66CB3301F@SZXEMA510-MBX.china.huawei.com>
In-Reply-To: <46A1DF3F04371240B504290A071B4DB66CB3301F@SZXEMA510-MBX.china.huawei.com>
Content-Type: multipart/alternative; boundary="------------070008070200070909030307"
X-Virus-Scanned: clamav-milter 0.98.1 at bohuslav
X-Virus-Status: Clean
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/n7i4SIeqWglM2DEWv7NjftRH9Yw
Cc: Bert Greevenbosch <Bert.Greevenbosch@huawei.com>
Subject: Re: [Ace] Update of document draft-schmitt-ace-twowayauth-for-iot - Link update
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Dec 2014 19:05:08 -0000

This is a multi-part message in MIME format.
--------------070008070200070909030307
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit

Hello all,

as Bert pointed out some link problems with my last mail. Here is the 
link again to my updated draft version:

https://datatracker.ietf.org/doc/draft-schmitt-ace-twowayauth-for-iot/

Based on offline discussions and meetings during IETF90 we updated the 
draft corresponding Gateway and Access Control Server functionality.
The currently open sections for the two-way authentication solution for 
class1 devices will be filled soon.

Enjoy the last days of 2014,

Corinna



-- 

--------------070008070200070909030307
Content-Type: multipart/related;
 boundary="------------040702090607050002070706"


--------------040702090607050002070706
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Hello all,<br>
    <br>
    as Bert pointed out some link problems with my last mail. Here is
    the link again to my updated draft version:<br>
    <br>
<a class="moz-txt-link-freetext" href="https://datatracker.ietf.org/doc/draft-schmitt-ace-twowayauth-for-iot/">https://datatracker.ietf.org/doc/draft-schmitt-ace-twowayauth-for-iot/</a><br>
    <p class="MsoNormal"
      style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Based
      on offline discussions and meetings during IETF90 we updated the
      draft corresponding Gateway and Access Control Server
      functionality.<br>
      The currently open sections for the two-way authentication
      solution for class1 devices will be filled soon.<br>
      <br>
      <o:p></o:p></p>
    <p class="MsoNormal"
      style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Enjoy
      the last days of 2014,<o:p></o:p></p>
    <p class="MsoNormal">Corinna </p>
    <br>
    <br>
    <div class="moz-signature">-- <br>
      <img src="cid:part1.04090005.05010702@ifi.uzh.ch" border="0"></div>
  </body>
</html>

--------------040702090607050002070706
Content-Type: image/png; x-mac-type="0"; x-mac-creator="0";
 name="visitenkarte.png"
Content-Transfer-Encoding: base64
Content-ID: <part1.04090005.05010702@ifi.uzh.ch>
Content-Disposition: inline;
 filename="visitenkarte.png"

iVBORw0KGgoAAAANSUhEUgAAASgAAACgCAIAAAAw8WZPAAAAAXNSR0IArs4c6QAAAARnQU1B
AACxjwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAA
buNJREFUeF7t3Qe8FtXRP3CT901i2htTTVeTGE035Z+YZkxijFFjQcVKVXrvvffee6/Se+9I
R0CahSqCgtJBQKTl/9099y4P9yIiEOXq83zwus8+Z8+ePTtzZs7Mb2Y+9p///OeKd/uMGTNm
5cqVWq1atWr//v3v1jz9e3oGPnIzcOWVV/7ud7/z2DfeeON9993n67tMAcZ7p8/s2bMfeeSR
q666Skd14s/o0aOdTH/SM5CegSwzMHny5MAjWAbXYRnMcg7muuKsvz333HOuvPXWW59++ul9
+/ad4/r0T+kZSM9A9hnAdTjopptuwp9nnZ+zMB5mu/nmm8/Nr+m5Ts9AegbedQYIMNKLGMze
MivjVa1alax866233rXTdIP0DKRn4HxmIOifWXjqDMbDdRqdOnXqZPqTnoH0DFyKGcBNmLNP
nz40z1QuPc14NEx86bc0412KCU/3kZ6BaAYC4/k0adKEYEt4L4PxKKP2dUEaphkvTTLpGbhU
M5AwHs4i2Ii3wHsZjJdq/bxgxsvk7XPovWkl9lK90HQ/OWMGUhlvx44d1157bRBvEeNxQdxx
xx0Ju7wnxjtx4sTJEyeSa/fs2b1mzZrp06YPHzp02JAh/jmYOmUyifrGG28kzU6eyBmzlh5l
egYucgZSGQ/9ly1btk2bNhmMh+vw3oUxXrhq586dkyZNatyoYY1q1apXq1anVq0G9eo1rFu3
ob/16tWrU6d61arVq1WvX6/+6FGjt219NVx1kY+Uvjw9A5f/DGRhvJdffpnQixiP4INNSbV1
no/EI+hsBl2/ffuOnj17li9XrmrlKhivaZMmXTt3fnrwoKlTpsyeNXvO7NnTp00bNnRoj27d
WjRv3rhhw+pVq5cuWbpTx46bN28K7KerSGymP+kZ+DDOQBbGQ/CMKYsWLboiMWa+J4kXGGb0
qFHlypatVrVqy+YtunbpsnDBgtkzZo4bOzb7Jm/evGecX75sWa+ePTWuXatW2dKl+/fre/jw
YY2PH08z3oeR6NLPlGLVTJgiIMuuCP9LZZVzSzwsovGunTsbN2pUsUKF5k2bDujf74Xnn8c8
zg8cMLBCuXKv79hhzhM5dvTo2y2bN2/YoMHxY8e12bhhw/BhQ1s0bVa1cuWaNWps2rgxrXam
SfTDOgPZJV5Ak12RP39+3r3zZzwtX968mW5Zr27dNq3bLFiwYPOmTXv37Hb+hRdeaFCvfptW
rVu1aJnwkoO5s+c4o/3gQQN9XfbssmeXLiX9Onbo0KhRw9IlSzr+b8i9YPi55IbU49aY4yfi
5enSKclRT8czPD5pj86HiAuzMx49k7Z5RRbLCgY4h8Tz6ytbtpQpXTrs5ba8vMWZwQMHkn57
du/R47/vvPPfd92FLZ0/cuTI4UOHHIwaOfLef//7zjvuaNWyha99+vRt3qz59te2b33llT69
e7do1qxYkaKB984x4cnSENqkPs/5X3VJXijGyzKYLF8v6C6RvvD228defOGFtWvWHHrzzfPZ
aV/QjdIXva8zkJ3xgn3lCiDOLADqs77y2JryH5EKNnXNmzXr3Knj/v37aJj169WbMX0GY+bK
5cunTJ78VMGCRQsXLl60qM3bcyuemzljhqt6dutWMH/+J/PntxvkynDJvr372rZp88zcuW+8
/kbMe81Lliix5eWXw9Yxu63l2LHjSxYvNs6DBw8ans+xt48tXrSI8ebNN98860Rqc/To0WZN
m+Z54vF169ZdQjrW1fLlyx95ODeJ/fbbb7u7UZHhe/fuveC7RPrC88/f8+9/f+H//u/zn//c
nDlz0ur3+8of/7WbXSzjRULm5Ek806RxEzZJTNK5c+eXXnypdMlSFM6li5doMGHcuP59+w3q
379mjeq7du3EVBs2rHfjwQMGdOvSuX/v3jWrVX/z4MG9+/Y9u2RJm9athw8btmDe/Igze/Zs
3bKVHeORw4dTN4cZwu3kyTffPPSrm276whe+sHbN2iBe9u8/8LOf/vSLX/wipgpSOhB9+DU8
LSfHN77+dfGIvXr0SG2TCMxwSTI1CdtEfcVdht6yCFhnmjZpqtsfXn/9gQMHjr711r3/vucr
X/7y2rXR2MJVZ3QV95X6ZrPcMQy+YIEC+rzt73+rVq3qhg0bLoyHQ1cXdu1/jfbesePsmsI7
jTx5rZdwkBc8S8mFyajO0VXyrpOHfW8Sz2Vjx4whslq3arV169Y1q1a3atmyc8eOc2bNInwi
Ujt5EkNWrVK1ZvXq+fPmxZlUphnTp1PMGjdswOJSrXLlgvny7969J2KJN97ApdOnTp01c2bb
1m22b9/eoV077r4e3bpHhH6md+HUyVOHDh36xc9//vnPfU6fmYy3/yc//jH58NJLEeNl/3jg
48feHjt6NA5n7EkaBHF61kvCSfvC1F+1T7ZeCR/a5TZv3oKEj9ofP/HTn/7ks5/97OZYYqcS
U1ATMroNojzlTJYx/PmPf/z85z+/efPm6PwF4dSzdHjBhBUT9wljiN7FRXzi53jHLXagyH37
9x858lbGHTMfIPWeYcYgLvbu3Xfs2LGLGE7GpfFDnX6lnvQ99RnGGAZ//Ngxo0rOvJPmleW9
nC/jRZR36hQzZrkyZVq1aLFkyeIN69e3b9vu9dffGDVixBtv7Iyf5MT+ffuKFylSqkSJ8mXL
3H7bbfx4M6ZNw0779u3Ndd99LCj8B84vmB+JuPBZtHDRYw8/XKRQ4SOHDlO0WjVv7vL16zdk
ed/uTnH91S9vuuqqLwSp4rP/wIGf/exnX/rSlzZu2Lh39+4qVau0bNmCCM11/3333ntP/379
XMU52aN791q1a7GjEstFixV1d+dPHD9OSyxUqBDLELZp367dnf/61x3//CdPo02pBtOmTS1W
tOjAAf1LlSzlV2cGDhjwQK5ct/7lFiYi82u0NarXGPL009aXEiVKkKsUxNy5czdu0mTcuHGF
Cxfu0rmLnr2fiRMnPvXUU8xXpihsDnfseB2Q4K4777rvnnt5Vg4dPvzKK6+UKF7i29/+1he+
8H+PPfaYTa+Rv1e20X79uvXlypUrUqRI2TJlFi9afDFsE+xSR986+p6IMkvjt98+ijTfiRxx
Ea/Sr3716+B/Mn6zWqVKlddefTXLuvP6668/kvvhv9zyl02bIt/vxQzJteSEV/PSSy8VLVLE
HSN6OG/W03j1qlVVqlTdtXMX/rnrzjvZJ+2ngEN2vrHzrK/swiVeWHL43+rWrt2zRw/W/0kT
Jgzo15/EM61+Oha74Xbv2tm+bZsmjRsVL1KU0Js0aSK6rFK58p7du/kMKlUoX71K5SqVKs5N
2b34SbfPPbdy8qRJWzZvfnrQ4LatW9uVvSfG44hH/V/60hc/9alPfe5zn/vaV79KYSMJly5Z
ao/32//3/3y1GwQMd/DUk0/pnF3nq1/56qc++ckVK1bQb50nTn/60586sINFA40bN3aMl/wl
5Ht07/Hxj30Md/36l78qXqyYHkYMH+Gnf99993MrVlxzzTWf/cxn3Vr7W//ylzGjR/vp61//
OsuTSb/9H7f72r170HVPbtu69ZY//9mZL171RQNwULRoUUP97ne+S2aSeKT67f/4x6HDkVHq
PVGY9rNmzvrSF7/YpHHjMqVKXfPda6ZNm5Zlrc0i6rN8zUIiDerXDyr6WT/n1hpcsn79+rxP
PHFg//7kQbL0w/b2veuus0JFciymMWTg8VetXJml5cL5C0y+peTc488+zuxEbzdeIF++l154
ccf2HTVq1CRCAg4k++esklCzMaNGf/5zn31126vWi+98+9tbt24bOWK4YdsdnPWVXTjjedp9
e/dWrVyJL47DAJXXrlmT6HtlyytBbQsikfb49KBBxYoUQXwMJ+PHje3SqXPRwkU2b9zUskWL
B+6/P+/jjzdt1IhBJfVNWOybN23WsWOHl1560Z6Q2aZyxYpbtkTG0sTEgmAPHz70q1/+8qpo
j5epah7YHyQe3WzrK1u9wv/5n//B2mYk1/33h30dLedvf/3rlZ/6FPfFiuXLceP1P/gByCjx
9bGPfezRRx5hSkXuv/rVr55fu3b5s8u+/73vfeMb39i9a1e7tm01+OY3vwlzQw0mD3XYrGmz
iHliNZXW/Yn//d+HHngAb6Own//sZ/afkDomgXB2U+179+q9Yd26r3z5K9ddey0pF15tgwYN
/PTYo4/ywcycMfNb3/qmUS1auNBk/u63/w83mh/KxQVAeXTuWur3ju2vOc6fL999993rYNu2
baR0o0aNyA2moA4dOljsKlWsNH78eL+aPQxWoWLFCRMmWEb7+/Tt1759+759+qD13/z611On
Th0zekzXLl3r16/ft29feweT7EldK+1VyxYtrarI9403XgdB7Na1K5EFR/HG66+b3s9+5jPl
ypazGw+i4PChw927dStXrvzokSMJ/0YNG331K1955OFHwoZWhzOmT0PKq1etHjpsWLeu3WrX
qt2nV6+XN7/M4/W1r32NimFuF8xfULlSJauz9/j2sbcZGgy1d+/e8+fPN+zWrVozmLOu165d
u3//fnQMQrJevegBJ0+afOjNQ7ZCn/70p5944gnaVvfu3V/dts19bRkqVKjYuWMncqxbNMJy
NlCJjhxeXLJDmThhwnXXXkOhe+CBB1CLm9Kzvvud79h9XGLGi5aiyZOrVanct3dvE2pZmj9v
Xs/uPRgVkiXZxBFfdWvXKl2iBN4rWCA/bHTtGjWeeOzxhfPnFy1cqFTxElTNxx99ZN68eanj
8wLwkvfXrk1b74+QbNywkYmM22RoAIHxfnnTTV+86iq6QZiIAwcO/uynP2Nc2bRxE7fEtddc
861vfSvMY4Xy5RE3kJq3/feY8RZRKU+cuOOfd2AnXPf44499/OMfR08jRowgJ6+++ms/+P73
se6nr7ySyFm/bl37du31QNsM96pZvYavhEm+vHkxcMJ4D+bK5cEt2L/+1a8w3sYYCeDTqVMn
7b1dmqQDil+w1Wh5+23/+N///d+pk6eElsyYH7viiqcHD3Z8y5//5BZWorO+v3eVfq7CeD/+
0Y3r173k2GMa1fbXXnvwgQdKly6NDRhvmIK+fvXX/3LLn8uXL2/GVj73HDpmMKtUsSLSIf//
9te/0R2KFyuKmH584423/f3v3pdrv//97wPhMiA98fjjjzz88E0///mePXtoB48/9pjO/3n7
7XT4z332s3nz5OFM+v3NN1tWSpUs8fWvX61zQsbg0bHjm37xi2rVql1//fVDhwxF93g7f778
mD+T8aYbxuqVq+jhN97ww6pVqnztq18Z0H+A4V199dWYbf78BT/+0Y95s/7+178ZCRv7d77z
bbxqOaMrff6zn9X5jTfeYCbDJYTkvGeeiVaW+Hk5kO1Hrv7a14x85IgRX/7SlxYvXITrvPpy
5cv36dW7Vo2aP/3xT9q2aQvnGI04/jAH7tu7J1CjiaXu6Wr2rJkF8hf49je/2aNHjxGB8V6+
1IxnUlq2bNmsSZNpU6fOnjWrQL78hZ58avOm6DanF+Z4E2jBo4K21rhp0+FDhloL8z6RZ+6c
udAtlhOYsjq1a82de4ahXCe4ZdCAAVga3VAz3Kh+3bpvHz29u4j2eIcOeWfUuUQPsdx+77rv
mcRXXtmC8a757ncxD1+iDpECcqcVZzDelVdivIgfOnZ03j7zuuuuu/GHN9iU2gqSk7RBK6tF
vXevXkOGDLEussdoSVC4yt2ZdpiUCEYnTTrl3rJH4sWM58W8GUnjq64KyoYP6f31q6/+7ne/
S9H9zGc+E7TrsOdElJ/8xCdmTJseWt59190f//jHRg4fbtfxpz/+0TpCfl4s470UMR440c2/
+x3z1be+8Y3q1asRgN/51rc2rN/wk5/8JISE/b9f/waxejSbAjveb3/725jtnnvuKVuGsh19
/n3nXcC3DpB4sVjBxsl2sLSeG274oZf1oxtvLFKoEBFHsg0aOJA2sW7dehTyg+99nwCc/8w8
rLt7d4SsoBQdPHDA5W7kq/UrX958NpA//clPpkyaFJ7XX+IUBa9ZvcpiUalSJWd+8Yufe4/0
+R//6Edert3NH3//B+fnzpn9/eu+x8LHrNWhfdRnty5db/7dzQ6KFStaqlQpBz/76U+s4wcP
HJw0cSK59K1vftMBU/uNN9yw6rmVa9aspoksXby4QH6mwLzhkd3rB9ddZ80KLOeVEQx5Hn+c
HiHsJrTBeFh9x47t48aOY2nXDDE4c4kZz51wfO1aNQkBhIXErZED+/c/cvjIGVvJmPEG9OvH
X3fLH/8oIqFVq1b0GS9m5PARsNF33XFH7vvvb1Cv7jPPnFY1g5pK139m9pxXX3112bPP2gKx
x9SqWdNXUiJZ5smKe/59D7q3CmK5I2+9xQNBdPzpD384fPgI1RTjURR37dplwKVLl4kYr3v3
LIxHInmvn/zkJzEbQ5GWtsX/8z8f/8Pv/0DHCNO6d89ef1u1aqkHARaBJmgsDvCbd+a8NXLK
pMmB8fhYvFpbxM9+9jMzZ8586+hRQ/VQeZ54gnS1M7zlT382gYm1wDvWAxsS4TNr1syvfvWr
FNpNmzYee/voJWG8SNWMTbhUuHz58nF+WpuEokTaY9++r732Ggq2uGjw29/8Bh0XLlS40FOF
xo8bT6ZhvHvvucci69djb79929/+1qhBzHiPPVayZElbod/+9rd0H4IRw8yZNfuGH/7Q47Rr
165bt+5Urx9eHzEeje5HN9zw+o7tkyZOuuGH16OKTMY7aHnq1DFikvzYLm9eKr3BkDxZGG/t
mtUYj2LpjtScXj17zJ8/z8xDbjA7sf1qz8/pdbNzSOM1NrbNWDdN4FtH3ipSuIi1wBnXDh40
GF8xoowbN55YmzB+PDObBZqoF7x23XXXLlm0mJvXJ7x9HwqdJZ5QDZYwBGrPXLBgweBAThiP
Yd80/uJnP7eg6Pa/wnicdZUqVOzfty/RRJR5+LlxxrIzlJ9Tp6KtUes2jz/yCFNPoSefZLKz
DbUXomHmfeLx+++55+EHHyhVongWVRNOSle8eeXLlitbqvTLmzaNGDacO962J7lFsO7QDEkP
VGtl/fGPf+yAAAxKmhWBpkcR4rjz9amnCvm1U4cOGA95OZ4XbywjGnr8CV/pmfNj/yEevuvO
aP/2zW9886+33oqSbM8MqWmTyLjCrBKuMvV/+P3v//ynPzn585/93F2gwx3f8c/bI9Pf0bf/
cdttvtqxMI1SuV1Cif30p690I8SdPIiDCRMm2ohrHGm2n/50tHVsEhmT7F5wL15lbcs6t++q
ZcYNXEXaXPWF/6tRowat8qc/+TGf/ltHjtx9513snLiOZ4V8u+GGG/51xx3aWIOsoZ733nvv
bdSwodEOHjTI17qxnCeBWYft8ZYsWfLQgw8SmJw6P/zh9XCGzlAR1730Em7MlStXv379vYXF
ixfT3J5f+/zY0WO+8bWrX3t1m/0IzblunXp8sJH0OHnKevrLm36h/x98/3vDhgy1xuknvMEw
/kzjynN01zKly7iEUIpcVnNm2w6w6onq5DtlD/vHP/7x8MMP79u3n6pJrLmWfmg5sI1kFi5e
vDgWcS0VhsXBIBs2aGjHMWrkKHa1a7/73WJFi8nR/OUvfXHJokVI9Jvf+EaFCuXJTLLOpvHv
f/ubBciON4iWQAPJMaqmVFvr+/Xrd813vst6BJjlzMZNZ4ccX6BxxS3ZAJh9Md7G9etNk72s
dTSb5fTU3j17atWoQdvs368/QUdjHD923LgxY7t37fbEo4/16tnLDpjUpnNnIayYc9bPmTnr
1a1bEcrkiROrValii5jaLIwe7z36yKM0qN/f/DtK7MQJE6MZOXmS6YLW7n1gJC3tCiypqJCk
kujCcsXOHhlFTv0H0gUNiRikT4Y+Ga8xmLn+/e9+h23sNo8fP0am5c2Td9SokWHSeRSQoAW1
RPHiwYPPKmMppQVYF/XDfkhJ++Mf/mBxpXlqsPWVLV48gYYWkwcJkpPZ84FcD+jt3nvu7dun
L/Jykt7VsH59BEFeZZvb8+O8k6dsd2vWqFmmTBnvi0IY6AWJoHVCb8yoUXjg5z//ueelyJFv
brRi+YqKFSsxhjVv3gwcp1evXjNmzAz384y2RowrWo6MzSFt2rTlzrELbdq0KdXLbNNrSpcq
jb6Z3CxPFDANoAvsAL3KLp0716hZ004s2SzR9umBQ4cMiZTPgwebNWuGl8Lz+mvRsR/zRiwT
4ydMwPyWLZYSYkqfNiMeiOOX8QPgnvT2pnhTV65cpQOLSPv2Hdgdhg0bzt5o9SS6Vz5na7Ky
YsWK7dq2a9q0mS+nTp4YNmxo5cqV586d26RJ02ARwUulSpVs2aI5FjJ7xhC2nYnCmbxBJ9nh
2Jm4o5cvX4ZaQD4YKfiHdu7cddYXd+GMN2rkCM9pO2TG+/XpQzcI+JIsH9qzrVqgVK+qZ4/u
S5csYSgfO2Yswg3nWVCQfhbGMzKq4+yZszp16EiVJbgtwEwj2ZuFTuyUCJlwHCGLjx9PlqXw
Nfzk48WEg6AuZsdYnnFh7BqJrzrt9c6Yej6tlMspk4Fb4saZ3Ub++miNDOexPVMNs0TcQ4aV
KBpqpgNdJ8k4Q4vw9UK57mTq06VOTnIXB5Re3kJrfGaD03OV2syDhDiSM06mTGY0pbGqknxQ
aXwy4yniB8qYRi/Fw3oXqSSYiiXIJKSM9kmz5InCGV1mecbk/SYHJzIHGRxd2T/ZZyk1f0Jq
e2/8bAve6YfKmMNMensnxPyFM97oUSObNGw4aOCANatXYyFCL9ipsjLe668PHjjA4rRg3ryh
Q4dWLF/e1q5e3ToWcraKFcuWPb92DRGRnfEisjtxgnmDJ501zBJr09+hfcSrZ9wiepWR3yKF
QDOwIGG9DCQb+zair5nH0fnIG5wZphS3cybTaXoiK946/JTKAKk3DbfMaKCnTIdK8s7sdkDG
f/Ob3/zPxz8ePGkp98q4NpXlkmdMHuFs7/t8zp3hBs4YZ+QGP33ezpxxclkmHj1pk9F7ZsvM
Z8zwFWUAieKOwin/S+YhzHP0Y+bf1DPJcWr7cDJz6s71aPFbzHiEjDd4+sKMyYxXtvCM8WsO
RynPknqD0/fNPJs8Vvxc5+tKT52qcNMwK9kf5mIYb0STBg1sABg/+vbuQ1PasX171oX51Enb
6B7du61du2bJ4iV0D1av4sWK534oN92M089+w1aYNynVgR5GqSsrIhvM1MmT165ebXfets3Z
GO98aO+cbc4hTM4qbcKUZZ+45GTWu8XtOSHs3Ig7bqjwdBc98EvWQdhRx+p5+vM+zcDFMN4o
sqtf374vb9o8fOgwaiToY3Z6YlRo3KD++LFjJk2YaBNFarEWCH+gNDLiUbvpkFx8z8zNsseL
hJgOqZqCD2wbJowf53bAIqkSL2gyWT6xKHv3JSqs08m1Z7kkFqRZnyhDrGUsDUGlJCoTXora
x4tw6gt0jl4wfuzYZUuXXjzW8ZKTRliUz2fSLvmtP7IdXjjjzZo1i0fO7o6Jn1zCVCReNhTv
qZ2vvzH06aeZJWV5GD9u3HPPrWCoFezHz8bzvmTxInFmAVR9pg4ZEf3uXbsF+DVt3Hj5smep
alUqVZaeLGmGUN566whQKLACRJx/0f9ff8NW0xJ+Pm/Utg0yo0XzFnrI3p6tr3jRYpCWYJ8Z
N7UTO3Vq5vTpDRvU50WwdWbCejh3boYZXgoGJCsFW47gpuyyI3V1OJ+xpdt8uGfgwhnvpRdf
tGGjZLKckntVK1WGLcimap7avXNnm9atGJHZLZk07QnFH4wYPnzqlEnMaM/MmQPCUrlChSyq
Jqai+SyYP09L1iHBdazD3AlgRwnjOXj22We5azm+v/+979/wwxt++hPW8p+wPmfdB57tHWoD
z816TgPs0L79GZfEu8ED+w/w7TA3c9QGPSwe1X969+x19113Pf/883//298pzLkffIiVuU2r
Vjf/9ndQS4zXwXvx4aab9NNd5AxcIOPZtRAIsGAd2rWN4NETJ/bt1WvksGEg3ll4jx8PQgUQ
wVatXp3anTq0nzVj+qwZM8SniwmaOmnStMmTy5YqlYrVjLekkcmLnXfixEmECfNuuzZtuCX4
W1IZD1CLP5S/FSry+ut/wOuNi8ZPiNCG4RPUp3DM4JYchzMEJgt7rvtzrVq5KiiHqXKJD5SR
nRvQEpN6vl+fvgBQrOr/uO0f856ZB3ixcOHC3j17Yjnu6V/8/BfBX3+RLyZ9+Yd7Bi6Q8QKN
Mkvy0tDWGC25E3r16EmyZaE5+h/n2/wFCwYNGkQWsX/CxYEOtG/Tlpth3JgxrNhdO3cJ+Npk
rh2/+MKLTRs3nT59OifysqXPRpCxevXejhDrGa0i5nz7bcIQcAyUjDMN1/3zn/90hhWUX5GM
1fTwkUP82pHR9QDZvA+wYMaM6Ry7RiKGCMNjpNdf3xFQzgsWzHeeXxV4JUBPOHO576iRTViA
ZkcgL+VvwRpvu+22alWr0YS5vAsXKgTnTYCDlYJZ7ty1K0H0fbipJ/10FzwDF8V406dOg9Vi
q+QlB03gN0wiwRMRQeJhMHEMUPDQJ3yRi+3rnn8eAA9Kk1bmQxcNEi/1s2fvXszTulVLTmeQ
P7Z4PsNEiMVSMXrqcAlNVYwCkMRS1ov//IfqG8D+jnfv3oU3YAi2bttmt/blL38ZWpIL+9NX
fgrAh5aoZfC589sKSvDVBzrp0KHDv/zlLwU6XHvtNeGk2KJFcTwbvzAMDe824QZ8LNo92l/u
3MlRy88bocMu+IWkL/xozMCFM575sQsSWQdrv3DBQqSPjnUnxiR8jsrRc+zY9ldf4zSHwo/5
oQ/XeWAVYTUCTMMxYRLhvk+eDFfF/44GnyZLyboXX6SsVixfAWIzizh1iX7hG/9yyy0YI8lH
OGDAAF/hVLS3KED04UlGIJLQpg4CS0YZ64ULBSx+/H8+PmvGTKoj5gTvgquIIi3mz+eWxHga
61zyeVApfYK8ZFkgsn+9rFwFHw0yznlPeeGMFywNZAvjXpVKlbgHunfp2kUIXdu2Hdu3jw/a
AUbyH1SqUKFzhw7du3QRU2eb17VTpy6dOrVs1kxcpgP/BA3Vr1vHgWtdqLEDpk6XQ8oBKHVo
115wQ3auCxIPCAhL/O63v2MFDWwwcOBAZ4SWOBa7ASKMozIZ79uEHkSSn/D2vffe94lPfILH
AtzUJaVKlEwYiWYKF0sGBldHk0YRUDOEJuS895we8WU2AxfOeIHoyROM0axxYzF1AszBncFZ
alStWrJYcdgUdsiSJYqTV+wiUoxxxLVo1hSXVqxQ3p4NrlrqB9wovV+F8uVEo8vCAjztwJap
fNmyMtuKCxbhDvgXAo5SZy+IRKBHGHAIY3HWCc9AtWKSggUKOmNrx/KZMJ4wEPbPkOKFQBYV
ivHIW+nMXAKV5nyYFPKQpcSFIdhPUJIGHirNeJcZDefI4VwU4wXeY9IUEsrMwJjO9gjNLEpN
zPi0KVMdkCQTxk9wnsSgjjKW3HfPPYLBxRAJNxRiSLUTAFq3Th0ijspXl+WzY0cxfngAZzYS
zFi/PvuHG2X18J44CZ4pegM/PFmwIMuJVWDXrt3YyW7QSeGYrqI3iuYWBRMkHsZjBQ3xYIHx
/vcT/wtC2bB+FAPONBJyfjLb4NjAeHzfacbLkdR9GQ/6Yhkv5r1TjRs1Jgrq1a3HrMevBRVF
HEWwzMaN+bKLFC4s8teBXH033nCj8BPmeDEX4tA3btwApSnEi+4HPoYnwcapdrff9neARior
BmYtlEkhOx4FMzCifupTnxRl873rrrWRu1702HXXiR9l5Rdf97Uog8DDbiTQTiiKZAc8H1/5
ylfiCL0Mxrvrrjvxm+Xg2aXP/t///Z9jO7q77767RrXqkaj88Y9lTAlRtqJX/Er8piXeZUzP
OWZol4DxdCHEA2JDkIHkFrAsQoDhbhkwJ44bB8zRo2vXIYMHyXriQIRbrH+W+MY3vl63Vi0h
RXJptmjalK+MRte+TRueCciPAX37yWUiaqNkyRJCE95pd4dp+bgF2tA2JbqQSuhrX/uquFtG
mqJFikoJwV5SoEAB2YfkPhAwwhopPYGgSRKPNkniiQoVqC+oxC369O4jJyet9cpPXVmyRMk3
3zwoQwTx+EKcwkyGGFbNd9pq5pgXnh7o5TEDl4DxgpWFIle2dJnmzZsjX3Aqhkr1Ejq1b1+m
ZKmunbrI605vnD51CiVT2pnyZcpiBtksbJzq162HY/3jKO/TsydoGBu9/EhqLURxbjHRv9Nc
SQYvLdTpj+Pt2wW5eCoBLMRvCKySzUGzYGt9fcfrYGU0yeNxrBAOZF8NAU1hy2ozKdAJPEAM
DCeBzjkJPCNbi2eEGk1jGi8P0s3Zo7gEjBcmIOK9ba8KJcRLHHpt2rQWB2R3JIpRRL1/XNJQ
woKgBQLLsCBHC1w1kWV/JcUFBJYNGKEnmR+/vA2eXNROnluvS6wpWQ7CeLJ8AuI5nEwc3Emb
yDNxZs3opJPgHkhtmbPfeXr0l8EMXDLGC2HUZAtZx1ApE96A/v1BsZIb0DzlgChfpsyTBQqo
RpLniTyMnPIOLJgXGet95JKQb4cuV61K1Tq1a2/bGqUGuwymKD2E9Axc+hm4ZIyXyD3cItIH
DlNFBF4v6BNGS0Dn3Xv2+NuwXv0QF8MKKlWE8jcRimXaNJ43fMiAoaIQeFeI/730j5vuMT0D
l8cMXGLGS0DJ9k7SYJJd0kKxpjSoX89XyWSLFy0yacL4qZMnVShXntuAVGzauBEHoH8ay/YX
cmCmue7yII/0KP5bM3CJGc8wQxR9YB6aJy8f/zhnQ/Wq1TgY+MS5B2r4r3JlTvOqVSqrSaIc
lwwuIuoyWC4leP+/9dzpftMz8IHOwKVnvNTHSQwSUJ2SK4p2le5TZJ0SsIIS4EXomcrHnbZb
XE4JET7Q95K++Yd8Bv67jJeksnkn82OmiEvnHfiQ01n68bLMwH+X8dLTnZ6B9AycdQbSjJcm
jPQMfAAzkGa8D2DS07dMz0Ca8dI0kJ6BD2AGPpKMF2w+mZ/zmfX31PhdO0y9eXbkZzgTRWOk
ZD4+V5+Z+Zsv7SDf9SnSDS5mBnI242VHY57PXCDULBe+61WXFqgZYOXJJwvvqScQygBHjBRV
s36XD7R3AjJVGyCN4X63Cbssfs/BjGfoEpCJJFDDxUeKlMT/fu5k95oJVgLR7tipk7ydIhIC
DPqdPn5dvWZNz569xDGcu+V5vlIDWLN6jVwZ3bt1X71qZZY+fVVnr3jxElteeeW8bnfqpIrN
hvf88y8YQMoacbqkxHkOLN3sfZuBHMx4KEwAqwKOii0LxpPWUshcVAg6qFyZJXgcJEIgZIuQ
4EwyCFnJfvXrX//gB98XOBsQaoFkIx0vviTjZCxNVFFWhW9BnE43yKLkwHGYxDNOuntSR+WM
WhnRANSjEkAo0k8JVaWJw02TSkO+CtuXSDcpc5tUPgoqaBhYUnbHVxVdRB7iPceyYsvYLWGh
XqU5DWWHo/7T4IT3javO40Y5m/EmTpz46U9/pkOHjmKO7vxXVEoS9jr1kYjBKNleZmklxA0L
qoghupdmQq22lzdvUhA8cNHevXtCEuhUPsSD5OquXTvXrn1exs5Enkj+Jy1nKr85Vv8tFLIy
87hFbbTdu/YEvTF5F9JVSMJ7y5/+BCAu6yGJnSDsDr75piSBcoS2adNGVC9MuQhj5cdSxyMD
m7sEXtW/TG6ORQkKXAxh9YraWVNCugqRh4Lyk6Lt50EP6Sbv0wzkbMZTAfiqL1wV6qdLMi0a
XeoHRRQ6deoo64TUg+o0pJZN10w9a/wp5C9hIQc4UCDS9773vWu+e43KktgMyrRixQq9evZU
JlL6sxUrlovKFeCLGYoUKdy9e/e//vWvxKZKLC6H9q5Vq5a6hJLJ537oIdyC4nPdd79q7IqD
Fi9WLMTmxlLq5JEjb/38pz8V6r569ZrTYvP48c6dOunwW9/6drkypQ3v61+7OveDD6ru4kYy
d5LkkkpJhJEvTx55QQUZlyhWTP4YgcUwd5s2bVLYUZZeqXu///3vKT4uf+GggYOUQZUlTVpR
9d+tGmmZ9z5x1Xnc5sPAeKHcHBnw6KOPUgiVDZMB6ZOf/MQd/7yjR48eGC8p3aORDLyf/MQn
1CVPpJCDfn37OVm3Tl3JNr/whf+rXKmiSPZrr/nu16++WtXyBfPnhwy5KJtodfBArlwSY197
zTWqr7BnPPrIw5/8xCeFIFavVv3jH/+YMoCkaL06dWfOnKXqqqroI4ZnVPQOeqngep1IAwMr
HmSsYoNXfvJTTxV8UuXuaVOnafCpT35SNaUuXbpKgla7dm3Z5tVzJ6uxk+f62BVXVK9eQ5Jf
Bd+HDx9uYPJ/eljppG6++feSO+XJk2fK5CmVKlV2F0XGW7RoIaY+bXc5D454n5p8mBjvP2qs
KyA+/5l5aj5ffbWK25EOqSxoQnC+ivdD06rUZzBeJAVOPProI6ovBKVOaW+UunHDevJHnukg
lDCeXCxKN6qy4kCKNCextxzvbx48IKyesMWBG+NkSnZofnVepRZK41VXXdWkcZQGNxJ48Rpw
7NjbzCo33vBD7KcT8vbJgk/qYf++DLy4pGxqNrwYB+Cr7S6HmtxnNrHKEjnTrl27r3z5SwKv
rA62uPICW2vcpWfPnn4lLV3L2uRY9hqrg7ymqXd/nygrfZtzzsCHgfGYWBAWmlZ73gIvhYQg
9x/dcOOBffsz9MlTGVusQJfIXXhuJCIzjSKqnP/5z3+Wy8zJwk899aMf3Sj3EsZTuzyD8fr1
y2S8ufKOKccZGO+mm26SEwnj/eRHP4qDel/A8HL4CryQRRffyu1px2XnmZB+YoORWub+++77
8he/+NILL+bO/fBvf/tbwjncDuMRtspq40kGmEJPPRUYz4LiV0kTv/XNb0iJv2nTxm9945tN
mzSWoA3jqVTuV1U+pc1evSra48ntfc13viNxcHjYNC9cPjPwYWC8efPmI6xhQ4dR6iRaJ0/y
5817w/U/3LN7DyqP0hYpdRJ/NGPHJxBQuaRjEY3LOX/0aJlSpSXefHnzywTSH/7w+7/+9dZX
trwsXyCKPyvjqeXgvLydzCSB8X584402cljl61+/WqVbumgkA48fW7Vq5Re/+MWmKRLPSfUk
QreyHhqMjEw1alT/3Oc+F1JWR4zXurXx2E8eOXLkhz+8PmE8i4JfW7Vs+c1vfF0WpsB4zZo2
SWU8aRaxuiVAyy1btmhQpnSa8S4fjssYSc5mPDsi4uuvf/ubRJ0sCtgAsSK4B+6//+qvfVUq
aHn7ZNGcOmVqEDiB94TCf+ELX7jh+uvt3277+9+nTJqocAIr4q9/9evb/n7b5z73WXwlv5hU
gY89+kjgBNYUN1q0cFHY49kKOkmgsce4S+7cD3FoOOAAkM+ziZj6GjVtGnPlyvWnP/5R+9o1
a4YBUDTfOnpU1m2bwwceeMBmjFDl+mCTNE7M9uCDD1WrUkXCqOBOOHT4kAd5/NFHidNvf/tb
IUVvwwYNlHRWHWXd+nWf+fSnpfpUJ8xdOnXqHD1dr16Ob/nzLSqHSvL7y5t+oe6KwkZvvnno
sqO+j/CAcjDjRX7t1avLly//1JNP2iMxLXJhoTx03LdvX5aSw4cPod1ixUvIlptpVMwogrdk
yRKZJvLlzVumTJmQoX3pkiWly5QhWzjBfN2/b7/k1gMHDoom6NSpRYsWlStXzsZJ/s9y5crL
FoOJevfu3ahRY0qgBBb16tU/fOiwnLlVqlRRBkwy3BbNmxmXHNgMnqHPsMezFRQK7KcCBQr2
6N6dwyNTFK9ma3niiTzdu3aTSLtq1ap6s+1knlGDRQJCObVlpqEvsr5UrVKN319hzWrVqqki
ZmDlK1ScN3++rrgWWrVspX9Zfd1UGaZiRYs1atgoLpT77jiYjzAvvK+PnoMZLwvwKoim4DtP
jsNBIu7iqWVXzJr8L0tXiWxMlZOOQ82jjM5jX3y4Y3KQfTazDCD49pOTKWPOejK6XVzMPdtd
Mu6LiVNulzGwgBA4PciUeyWmnfeVvtI3e4cZyMGM54kCICP5JM8YzoSv72RUOPdVSedJJ6kd
huPkLllud8avmbfJMv/Z736Wx3mHu5zrdpmPnPrUqe3TjHCZzEDOZrzMScyE88d5ls49s7Ek
OXviwFAUNsiZiA1SOzpxdgY+U5ZGl4QJvbC3G+RbKt8GGXthvSVXpfYQS9ywZFxst9lHFeT5
eRpPo3m+yAfLyZfnYMYLalXMJxnFzVNddmd9KciCnVAi97MSDaZl6oTw0HOis6WSLzY4gxmh
yQ4dCkBKn5DS9+jRt0DMLmA3hR/Azdhgjx59O1Bwklz0+LsFKZxDpgW7bpZBBlY0d5eWdJN5
i5Ljv8MKmDHUeInxXJd2ADmotxzMeIYu/bsqPw5e27Zt5MiRGStuCj1loUgvm9Fvfpy7OnlJ
QcI4M3bM2LJlynAqRILr5MlevXoqmB54+9CbB2vWqLEmNpkmOiFoJQxXEhWhKkP//v1nz5rZ
qWOnpNlZNcwst05t075t29WrVrmcfaV69erlyparUaPmwhicfVaqSgafNIjQ1plNiTWrABvp
nrgsWXhMZiR2I3lMzd5Zx5mI3NN3jKYoQ7s++zD8GkmwE6Bt3bt1MxWhWap+Hs6E/ScLsLLy
qswT6HGb00tA/MoybhIdXerV4TJhzhzMeN4fFOWwYcMcrF29mjkxxazwH2rMGV8zzQwd2rdX
F8VPQeVKbcNEmdRIQQ4lixd/KNcDwavO38BTFy5MPvsP7GeHJD/DGX48BlI2RgX9UpvFq39W
m0pQa8MnlSKV5gRDcRICUywSg+2Lz78AL5baONFmk5PPPPPMCy9EjrvsHzRdpnTpBPzN3aLP
uXPnrl+/HtLgrFOUejI1BiI5HwaQxZATfuUyZUNOFqPs42FP5tv0yM8tXx6gQhmTQPU9ccac
ZJmfy4RhLtUwcjbjATEHZti6ZUsokrx27RoHEF4onS9B4T4FjJT88ZxDnh4CzIXspPcM5G55
htKEhLT245l//ON2QOdDh4CJT1HzlLYtVrjIizFBk5PFihThxHPVwAEDXeK+Rw4dIiGbNWuu
OBmfOAwXMSUdfdPGjV0yccIEjgTgSb3Fmt6pdevWqT0GWaLw2PbtO/r169+sWTM98+D79O7Z
S4F1qLckGogDoGbNmkYCitm7V2+IcEU2ZSilD/MouESue9VdDB7MTb0xGG6xF9DhilhzpZBy
XO2G91SBAkHi+bRs0Tx1+bBqqJ7rcaZMnkT2zJgxs0uXLk0aN546dVrTpk1HjBjBf6j8k3ir
nj17jBo5yvysX7/hjTdeBwQ1FRz3oS6Np2ioEsaYsaIlxowZy5uiTevWrT2vmoRmHgZ9/Ljx
O19/49FHHgHdduHE8RN4VlauWKGUd9u2bT2Xik5eh/cFgkPfBtCrV68e2PdpCXipqP4y6CeH
M16PHhxxFDz0V6N6dZuZmjWqL126lMyZO2f22jWrVSnqipQ6d/YWoftR8MO5c8+cPiNQ4YRx
413F+6wi9IplyytUqICybRTDm27epInqYoMHDrRjaVCvXtu2bZC4gs9g1oLcSpUsaWnX26hR
o/jxlPJbv2FDsaJFpk6Z3LJ5c5KTgrdi+Yry5crjk9Dh2tVrli97dvCgwfh/1apV4pjokGTm
ooULJ0+ajDQXLlx0/733GXO8LpzikYO6tr/DLerAvPzylnJlyr7x+uuulX57wfwF4h6sC5gN
0UNI099g06wOHdp3oAh07NABt4wfPz7XffeFrMH4X83QLS9vCeuOvwL5pPQGDADIVtUMB5ol
K8uDDzwAzlr4qULLly2/9S9/GTd2bNHCRejVVjRTQWxWr1YtWo969hTN6NdHcudetHixsocW
l7x58ryyZYvGvKkrn1u5bcuWObNnqZgtOmnDunWtW7cSh4Eb8z7++I7XtoOzzZhuwO29Jrgf
RUsVG9W5laVooUKehVj+UNpgcjrjdcc5EydN4j1HuC+9+MJDDzyABIXwwDELz1F+CCwLir9P
r17oA61079o1YTyiaVG8fVK62RIuvGD9+nW+hl2HIipCSJX1e27Fii5xmQegUChKQkybIUOe
dgv4LMoVE0uNaAe42r0wXpvWrYiRpwoWhFp+5OFH4mJjERR7z569cG21a9dRBX41aRzXW+cc
VzJJjaTFixZFEql58xXLl6cwXjWi28Ixa0a0WACg7Nq5U6Q5BrMXjW8XgXKQOEf53j17H3zg
wU6dO4uHsvRUqVgxCDq3c5UDXcHQIPqE8dxu7uzZvpooSb7bt2urHwjPRvUbOFmnZk2kryq9
Y8vX4oULYdAUuLeiQc84CbNqVmnXVA9fmzVpGuEQSpZc/uwy/JzQlqXNSzG2DRs2KBplzHTR
EsWKLlqw0AriwmiJqV5j+fJloVvIoeHDhls+OnboGJaMJKLyMpBVl2YIOZ3xeii57sVs2bwZ
HYPzI3cUbBexbdurVStXUbeoV4+ezZs2xVpjRo/REouKQI/kXUQoTYT8OOjTp09c46Hl889H
dTAD4ylstH7dOu3xtj5Rw/Rp05FmYDzhORivdu1aGI8hVJsMxpscM17/ARaC5cuXr1m7lh2V
ukipU5hFvomhQ4ay06xa+Zy7h1tPGDcOPwcLCjVvxbJlWRiPNJg5Yzp5VblSZbqfZPj169XT
Zt/+/YSneHYYmvnz52G8fHnzzJkzd8WKFQBlFcqWjRjv1KmK5cqJMAyP3LF9h4DwDh86ZFC8
RTnFjNeOVCf6LEmmgPoAc1eubFk6uQr1JDPgTq0aNaSrSBhPKv6pU6d4Cp24iq2rdMkStsTl
SpdW/dNJJRCB4BYvXkJXN59DBj89bep0ANfiRYsuWbS4Tq1a2hi5NWXF8mUe31cQ9rHxy/Jy
K5YvB/j24bOw5GzG69ShA7LzhtauXmWZP3L4kIrQY8eOmzNn9tZXtqrCZ9OCRqtbpNeuLVu2
7IwZM/55++30yUB2djIVCY2pU9lRtmx5GcosWBRjxjtRvUoVYT5UtVtvuQW5d+3WbdLESRiV
MjZt2lS6mQiAu++6i/Ylao5eR1oWK1x4wrixlDEaoOKbtCb/mBDYcWzkShYvMWH8BMTtdkgz
ADi7dOo8dtQosbyRfjVt2t9uvXXZ0qUx451EjuwiMN842bpgVJUrVcLSipm5+7atVLjZQn7b
t21H4tE2d+/ehR/69+s/b94zIoawa/v27QcPHqTEvP1neK6tW7fBqhmzqaDaPfPMPHFStqYl
ihWn1EGWkdgUh9o1a5gBxQynTJla+MknBUlAfs+bO4eSSQCSe+Da5u3BXLlEA5oiMln/BrZw
wULMbxMrWMmiYAJ6dO9mxZk/f/6/77rTRprMr1O7Di0gz+OP7XzjdcqzXZyWdolUaOuXfhg8
Bw0Y4OmETRbMn4+4jhnvQ6Vy5mDG8yps53CUA+YTlISyrNYtmregpciqYLPEQgDfGCwco0aN
FlBDY6RrhU0XKUT+MGYKnGOnmz17Djt4+IlWNnPGTK9cLDnCcvLZZ5996aV13j5SYyBhGGRI
wIrdunbDdSLfhPkISF+37qUgEl2Ojok4VhDCSqcvvvCiMtQDBgw01Fdf3Yaw3IcNEwNoMHjg
IMF77CUqchqAreabhw5ZGt4+dgxSFFc7iSXQqBxJrvUULVu2tDti15HsqEWLlhs2bIRWpTC3
atXKGYKCqta5c5cRw4YdOhhbjOJ93Yb1G8RGNW3SFOLUyfA4OjQDwiNog0L4bWbNgOAmSw8r
CFMHcaeCvFgkthn9WCMYThTTtsS8tG4dY4n2Otm69ZWxY8dQHQ8ePEA7ZXbasH4dZcE4hw0d
ynwiSNLwbJLhV60pONBusFu3bpCufsVqfBI0BTrLwAH9CUD7z2gVjLyCaca7NFruxfZyNhzj
acRjlhUlC0IyZq0zai/7GsRgGFZG+0x3Q3J5oN3wyeKxSAFyngZwRs0yP8mFp3vIhJVmsdpn
ONDjeyV3yfII2Xs7x5nEMJh9HlIGkzF7wcmS2jLJCpM5RWdBlqZ6F7Iv52cdW+pkJpdk91KE
7FUXSy6X2fU5W+JdZpOZHk56Bs53BnI244WlMDyDv/+NdfG8nEjvgOTM/hKMMAMReib67Hxf
17u1o6clYiQW25dOUMT5qoMwjKc6gqWE40QipaoM7zbSj/rvOZjxImTgsSi5nWc4cvhIAApe
SlIL4XMAlJlozOzE4tY+4dbnRUoxgIad8xwpn0Of59XbmY3CTlL/zDkh7V8MXr2Ans5ySUaw
VZxEmCE3mvaTMqYd0f2xY8cxYvxconwjS+alueWHupcczHgBlGxbz5gmHlQmr8R+EA4CBWec
jMD4Z5yMfsgkkYTQkwszcsyePMkAGNIohJkKxJCx0mceMJ8wHjCuhPMZvUUwwwBFPM1FbJvA
GdBtsgwi3+R2qaPN6OJsMUEBpZ3cInNIp/tnfhRcW6tWTaCZZc8uCyDIlIfKGH/2543Dfc/F
7R6Njy6a6qpVx4we/eqrrzVu2Ei0LjOmK3kO1LiHs6lZs4Zmad5710UjBzOeoUNISIk3e/Zs
tjKZS84EQJ6BwwxaEBRI9l0+MRkLh+NhLlIrKyDFjRs2nC4WHRN+zF0Z3fCYAXIxq0iORBSk
dp6p8sX6WCa78kZwasGy6DbcNwnbTa6dMGHCypUrU7six7MPO+PNRewSc2PMj107dwFzEboO
xsUgmfJ2U0N44+CjTANSKmDVc51VdOtH5l9wNu51YLfXXnuVvZEbAGhG6he99ezenbN029at
7psYjd+V+D7KDXIw43nfDOuSWCZEiWgGDRhYpWrV3r37HH377aefHgLhIWPCqBEjYa840y3M
cICcXc2aN2fdrlql6jPPzMUwjPi0MokkeAIgs6Smrle3Hm8SdPLokchr6759e1u0bFGrVm2+
JmEQfG4w+ERcseLF//WvO3E+vziQNN8G1JVkDbyCL7zwYrt27bnRIdpwV5hoRvmypcsEGyZX
Ne+WA64tcrtJk6Zt2rR9Ye3zd999N+Al2z1HWeUqVYYNG+7K0aPHcJPobeTIUXXq1DVgcBl4
EYiZkLrChx+iQrnyQQ8MH+tRl85denTvsWPH6zzgnpcj0Ug4SPRPUXRrDhjhFJ4XkitSHUMs
YmYPiYQ3G+pMJD0DAwG7hK98DOXKlnFt8utHmaPO89lzNuNhKlnDYrmBlE/xDpUvWxbFYwzw
rkKFCtG7+HaLFi4Mc8hxDOj477vvHj92HLAvyCVvFXyTNZs/2n6Ok7pr5058g8CNWKhK5SpL
Fi/hXwawhF8BziBDZKpdumQpkQKECc4CRgzvAh8t1R9S1icHF6xww/r1YankJuKnKl2ylFCA
RMh07tTZ7dQ/AVXhsufyMmYAK5UPeL2xE5TzyBEjXFizeg1eNU5zmaQrV66M1qGN9UnMQoE8
PWhw6VIljYTHMkhX4+Gdc2DwHGikK6aSahrcxIVgJc57XoPx+Dz4ADe84YSYrE3AAIQYn57L
9cbDKdxB4plEVjds0PD5taejoghtqVy6du2q/arnVsLKOjBmrsjZs2afW2s9T9L8cDfL2YyH
Vp59NgPn4cVDPwyPBSBHMEhHvbp16J8L5y/o1qWLkyWLF/NVPAHUv8zNI0cMf/Pgm+XLlFa9
AJoR40lSBPW7bNmzUBra8+pOmzKldq0oHK5i+fJJqAuEIfRJ7ty5582dC5gClmkSixQqTGpF
AMW4aoIIicGDBgYEI7h9iPSJfcCRrLMdhbDhLyaCpkyZ0qFdO7gtTAuo7VeLBeCVWz/84EO2
jlKhLVq0MGStxYEtmjXXpnKFiuDaoGc4n8pK3YwYYOWqgOR6bfv2jh07YoaNGzcEMKSFwNLj
oG+fvqCVXNjQBWRUtapVwFwAXPwEMSOeIEgt0ljaX0tA4EN/HYen8DW4+PbvP2AAAGh0yxAa
4om6dumapFT7cHPORT5dzmY82wxbi0TDGdCvX8h4CQMFMIUa1r30EjgFxsMMJYsVI5QwHigW
/iRVYD6gojAevnLV9OnTevXoQRSgS19VCALdYE4gScqWKqWyl5PPrXgOdtGODriJXgrKGKCP
gPwEkRgCE8qiiCKHPj0kpHZu0gT8MuCeMwwzjjEerVI8IY6dNjWKbNq2bWvZMmVF2UgyLawB
OLNK5UrSh23dtk3RH1wEo+zXls1bIHxISLAsWiGciicNMwAUTrp6HMe2ZDHmez2hGo2hUSPA
SAc0zxnTpoO/gNFE4M+KFa0drVtGz2t9oW068AjgY8IvILaC7HKSug5ikkx1OLCQlS9bThAQ
/Tlgr23zwMqTh71I6vwQX56DGc+6Kw4I2M/mR6wXzSpCSxYtKmyMQkX+UNIYJKOok3btAK+e
zJ9fcQ9qJ+Ai/oTWlTzTV0GiwJODBw/Ony+/JNBUTUod0rH8Q3VCZgLv2klWqlDRBgnErHSp
UsTUww/lxqgLFiwsXqz42jVr8z2RBy4Z9kpyS4AskmrihImdOnTUj3BvgwkEjSswqruDO9tb
zpg+TdkgLI3oGWkMHnga4llsgQgAjya2TVwfM73dncD5WKlr4MFJb2OzaxXWoDxQIHR/NS5S
uPBo4Q6t2xCSJCSkuPNw4bZ/IP+lSpSkb7OFkI1AniJ94dGo3/aQ1atWE0aQdBVYK5C+kZtq
wFGg6nHjxi1cYCzP2OtaDlh9NbMdtYKYeboAqGp84SXyY3xImS8HM17AFqlZ1a9fX2YMUdi+
KpwgqjJKanDq1Lxn5gpPhVoUFcZ2ggPZJ2logkRffPFFOx+bHNs8+5nVq1d16NCBGAQRtPvC
J6QKsbNl88u6xRiWfVYNbZCySBlCxoZQYBty7NWrN7aBzHQM2ElRpPFKaiAsdeXKVZhEEKBq
dcEHsHvXbtB7Ymfzps1GawtHAut8/vwFbdu2U3VMG/BuDYgOGE7PhVvkcdEJeKf+RXB7cBuz
lSufAxPt06c3QRfkUtAAlyxaRFZ369ZVnmmTYz2KvJHHjsFG4gpD0obMpwaDU5PYrP8Vylc0
5kmTJodOEmZLpfloqnfvxmYqNwgFZGSKZmzYcA6MYJ59dslS97XrE5KX2s+HlHEu9rFyMOMl
pJboP6mQwiABsvwUnjb5KRycFQOZ5WTYRGX/pE5flkQSoXEqyDO6XYqPQ6g7AcKtl9ptAhk9
Y/DvkMbi9NPFZBB4JvsgA7onOZ/l0UClGVTDr+dgmHMgRWP80BkOj3DmYmnzQ319zma8nPtq
zLtNXefOnXfv2nlmIsH3+5nYReWcjtj2PME37/cAP5z3SzPeB/Zes8irD2QciWs+QtsdT8uo
9+8lpBnv/Zvr9J3SM5DMQJrx0sSQnoEPYAbSjPcBTHr6lukZSDNemgbSM/ABzECa8T6ASU/f
Mj0DacZL00B6Bj6AGUgz3gcw6elbpmcgzXhpGkjPwAcwA2nG+wAmPX3L9AykGS9NA+kZ+ABm
IM14H8Ckp2+ZnoEczHhxmscMMH5I7hhCb97rS4WZDLMQgIuOU+H277W3828f7hINOyOO4fSl
IVDg3J8kniCjcQhNCBkv40+YkPiJMrJZJ8EZyU9JCEVSFDI1ju7MsImMyQkhF8ktUoeadBs1
eIfohIxHzoyWOOszhnGeT3xD8qbC857njL3b1L4fv+doxjsugaRMOwoehPcktDQqzfMeP+Lo
JIOQux9QWIidIL04LewJGUfE1L1T6EBCxO/xbqebG3AIKfQ3yTLkZyvHoWgw70hGgR/kL1Ip
QfomyQX90YnAQtmZMugvypwbLUzCC50PS5IDl8R3PPHWkWjqhCbs2bM7JErcs3uvZ08YSdj7
jtdff3Xbq8IRpb2QXdRESQkTzU9mHIObRj9l1pR3awUbBPueIywoZHPzV4LAqBTz2RbKI6rP
HDoUErqde3rdyPOLAIwm8JwgbzdSP1C5lQt+X5f2whzMeN6KkiCFCxcpX768mjvmRSEuQdln
ov5Px6Elj5p6gAIkhhg3Zkwo6dy8aZP1L70Ueli6eHHd2nVioZqZqTqOxQ5SMdBxdJz5axLz
FjFPyoqeiKZIIsWfRFxYo5VFkU9JHGo476/g1Hx58qKSs5Kdk35Sk0z6oxrVqklmMWTw4Pnz
5rujNCoSioWrYu49JEGLHBOK9QiWlQRNLgwJHUJ2DPHjhQsXln9T7LmvIoNKlyotq8XmzS+H
B1RJS+2X2nXqlChRQj4YZ6Q2Gz92rIygoorDg8ho5hYh2UT4KLckv2DqY2al1xMnhSM3adRY
foCe3Xsk61d007ipg0mTJgmxdZyljkKsz2Smr86czEOHolJ7wurDTSPxHmVJy3jvyd39pNRu
wwb1w7u7tFx0Ab3lbMYLOeeIK7m3vH605aVaBRFEyE0kdlu0NbKTalptGhOuio3zcS7naJmX
EkKWPqm+oguPH1ezTra8kKlOqhW14MK6G9ggfFSl079mqhxbm8PqLhDbT/v37Uu4S/0gvzqJ
evQfsu6RTqFlLO2itV8AePWqVTrG6YZcK/+SxJsPP/RQKKyV5Y0GaabmkdQS+MqodCv1g1QU
0YAXLmwYF5TMYOAZM2vXrOUWEq5MnKh82Fi50qSZqVi+whtv7JR/dvLEqFyZgXhezC+4XslI
SdNCD+5ltP6akwH9+jspnp1AM11uahyRgD1yBMWHUuYmXz9SV+jBGwlBydnVPyeV1FMQk9Q1
53oIExjl84z0jKiQ4N69+6gbo0eNxn6+xm9nj+eVsjp5F5HUlUj32DGZF4sWLqTCkZ/27tsb
K9sIIJreAwf2hzGEN67iZ4P69dKMdwHLxBmXmE35C6QeMbOWZNXhlFaUXESevFo1a6urLNeY
1H0Ki1etVk3qFOWOK1WsJNlJqxYtJUeRztkbVU1WZjuqZs8ePWlRsnFpQ0qowuU91aldS+eq
z+lNTgdZfVSQrFatuvSYbVq1/sMf/oA4QqJOmQUlcZHQWvE3SVz69elrRVfRynIg54ocKtu3
vybZniRIJJWsE15/RGsxN0pRERjPZ9SIEf379lXQTycJC4WfgiClK6q8l5o8V5EwCSw0UNFS
TdbQ2EdmJDUDpSSUr0VWmKaNm4Q8ufILyq0iA0WD+g0krUDrMlyE0sqknPRHFqkgE5yRu1Yi
I6wlHYb0FmHOlYyVRUJ9eckpLAFS11A0ypevgLFNmhTD7qgs4e7dewIDJ0MKfbq7BIcmPzCh
rKS4i1yVf0lqDPM5YcLEAf0HFCxYUBHZpc8+a3klq/M8kWf9upeGPP10hQoVpcawQjVp3ERi
JSl0S5coIfWTZlKqCuo/8tYRiVUVnY5qa0s3HKeiqVSpcolixcx/SO59scR30dfnbIknKdgT
jz/x5JNPNmsSZbZq07pNvz59LN5UUDm/VCr2RjGVcseoTQlLqY1e3rzl3rvvlgTJu5w+daqc
JbNnziI6MJu/UdHWoUPkyUOyVE2aiaRjRJAstxUrlKdrPVXgSbLIvkKbGtVrWEddSNkjHCSH
xhV66N2zR8F8+W0nsJZ8gZhZs2NH30aO8rXIfSLlHiZKDANy+6mwafwouE6t2mR1tSqVSYNA
H74qE42BQ+72TZs216xZK17Io0IRDtq1aZsnTx6FKQsWKFi/Xn2XHIlqJ0RqcMkSJf/fb35D
vURrmPmlFyMt2pDGjBqFQ3AsQmzbuo1nlKEoqJdlS5ci2SI+jzvv2qWzTDAOqH/9+kVZKnCm
CntPFsj/zNw5tpSFCz2Fc0yC/bAMn1RN+UtlH5UwSh7BaJwnT3quSZMmWhnDE/krd8uTBQvK
oSYHXKsWzTdt3HDHP26nvCycPx/34u2e3bpT/vv37xfeoIQuMhpa7yxnJtYyKjna448+Kukb
SViiaFF7UfMvMWmp4sXVpldfVvFtSdaktLHLxefyXHl98jgaUprxLmrdiFZf5Ua7dpN6VeYv
mpIcRCqJSuq65eXNqEeWS6RJF6JxeT1jxoxWAN3uR6lXKopMW7Z2gwYOkM6ImiR7LD3KCrp5
40aqqWoMC+fPsxVR1TH3Q7mbNm1WuFAhRRLpdWQdBpOtCK0bg0xbJFggTYmrH3n4YTk7EZbz
XraRyDOp6KQslI8+/EjtWrXUHmgoU1hmfRUXSs2E2hy0bdO2atVqhC1VU1KjIB+sDldccYWF
IFAMc0iF8hVcHudgjxp0aNe+b99+iHhklIEvSr9ZrVpV2fgIfyPctHGT7KOSiNKyQs5pOyvF
n4MUOnb8mOxpshjGtZ2lEjtcoVyUri/6Lb5X9WpVg248beq0wYOj1NG1atRcv36DdKO7d+4k
ssuWKW3XJ0116HDNmjVkjgMZqCRfDCc9nUfo27t3xM+ZezNZp3DF5s2baMKG59WYW3J42dJn
B/bvp8w19Vj604h1T5zUZt2LL9FuHnzgAVkGZVKTetAW14pmybPHw3gjRgwnAx+4PxfhLJep
h2VzkiLR17pxweeN6zeEEtNpxrtYxkNDiMacyq4Z8md6YWafUkfJrFq5UmQ76drVrlob/IAC
vKeqFSsxYsppOX7cWGqkjF00N/obxtOPVJxv7NxZQzmO+fMaNWgwYfw4RPnmm4cOxkVV9UO9
JLJY0uSx9tW2SlXUtavXlCxRwg4K71GfnJcXjG4TLrH8Y0V0tmr1qsM0uSgzV/RJrClKk2um
7rG0fOq8/uWWW9wl2HAYFSWcJaAsGWHfZdl+Ji46Gz6SF6JCB1jOoqNz+iHpLb2f3KHO+5XU
tdAQtr7Wr1sXe4RryZMK5ctZODz+sbeP4l5LQxBKfu3bu0+oEe9DZ+vff4CDMqVKrd+wgagk
1mybCRP6BR4IzVavWa0EswNSS20TBzpT+hxTydUZKdjRJ8PIVKZUaZk5ZWcsX6YsPqGTV65Y
ycj79O5F37ZQhpkk8IcNifIUW0qsj8yqllEagc3qgf0HPG+ZUiWlVLXAUV9NjvRNqtWSvQS4
bYOnsxOJ52dZtGlPG1cuiu3ihVPuV6nUbc/oHl6YysNegL2HN03BkHOWQvj4Y4/LZCklprIK
FmbWDUqLNyd565hRo627pCWZwDxDqWNIWPfii6+/sZNiJnlk3dq1WR3Z+qKq3IMGIg70pLFc
sfrPlzcvC2SDevWdl41PyXXcpZ/evXrTyuyC6I0SUBIINDELBIlE3EkFL5Ulug6Gh4gxZsyU
4jJhJAdVK1UKxqFEPjiOWsfqn61agXz5KYoeH/V36tB+aqzU0cQ8e9KPgsaFnnrKgIsULqLW
NLovUbwEg1CdWrVw7zNz5lIWlExo37YtUrRm2Z3KqDtz5ozQA6lu6iQvpKiTyXaMZL6Huutf
/6Lu1qheTRZ3/dDeLXOutQzhwCWLF4WEtj169AwSL8seD08/v/Z59lL8Zj3yq+LYD+TKRQex
ajxZoGB0bfcexKORFC9aTIp+Sqkq87LQSwFM0bXBk5rNg5PVrFk8D9RL2RatHfJk57rv/pjx
mq5eufLAwQMVypbDqHazkhRbGW1D9J+WeBfJeiet0CNGjLQuBlMEFUj9ILttTIi1qKCUfsV3
hg8fMXnylI0bqX6bvWDrPdcTQqRKIeVZs2exgqgr8NZbR5Xz3r9/H3cg4tCnv7qVqdZ+Q4ER
Ak25Dx2+eehNQ6d5yodp48SAqdkLz6+VSRZXUJ+wmeyuVFbjkQyXuT961LhKOCmEaJJ3H+wl
EmwmcxHl+Vy1yvbpbPQRmf/ci3mDP0AaX5TnqVhuULAkogaT9KMZ48eQIUNtdwMvrVmzdsTI
kbt2RuXEJH72UDNnzjIhhBLzCTvTM1G6segT7fcOHpRp0/RqRvvVP51NNls7KJZh02WG5cx+
bsUK+gLiHjt2rLoRJs2qpzG3xGvbtgX5lvrx1XThEzMZKxEnvaOQXt4uMVS091pf3vwyFXfi
xEkyoCqDYdiS1StJz/eowAMlxcbPezRLVlJjsAQsW7bMhFhq2V3pI5HJ9OhR6wV92DFXkzdI
nblYmrtE1+dg40qqNMiyssZrWkoKyxRpEq5Krj2zslesAmUa9MJFqQt2SjcZtofkzFnzYZ7R
PsW5Fw0ghR5Dsyxn3tHwdmbyzOT9JeNMJYxkAIHtU0abJQ3m6WycyeVZKIOim/I4mbXHYqUx
Ow0lg8nuToi4OqWj1JZZJjx7t6nzmepeP+sYkrechU4uEeNcbDc5m/Eu9unT16dn4AOagRzM
eBbLZPRBOwoC6lLOZOYtguk/rLJZbhCt2SnFYrNInowLM4Esrk0VO6niNFEss8jYLG0iQGnS
W1yJ/Ayxlu3howk5w5OWkez9vc5SIo6S580+1Umb0HmQOUGSx6PIQKWeqUecgYzNuCS+PExd
xtPFVplU8Z78FCpsJhpH7IS/pDTwXmfq/NrnZMY7fpxxcssWxRG2ej0HDhxUEOHSTrqXGpAT
sQUyep1gK1lqptIJbTDsKjOoTZVwu59Dh8LXBJpoJ7bjte0xnOKg3SZkhjH7avuhyMGGjRtY
U5JLbOE2bNjI4geWoQ3XCD+4j32XF+Z2Nqs2OTjQ3mzbtlc3bFivOOtZnz1GyBzne1SyyxgS
pMj5kUdGK0NVOMVGLjx7BAw6cCAq457Sizb2xgyOYRjhjRheJuNFLGQ36CnswWxVudftM5l4
wzzYHJoFM2OEoddQKzce+UZmEvMMPrpp8+bDbx6KqDae54ALDcgyW2VTcekX3/c0U+fdOAcz
nilmqCxQoACsCazjunUvhepwyaoZjkmEQAepP6WKytS5ymJrdgksCNe58wiCAZBlLwJ2pIC5
tOGLZ0EN/b999K08jz/OPZg5jKikEeM7uytfBXplZgRe4dTmxEdMjgEs9PB8XGndYI6+fZQR
r06dOmXKlKlapTLjQblyZSFu6tevhzIxKkc8MynPHuMNFEjevHlq166lxhBTx1nsMXFNJYUs
QXaAeEKxsWha4k+4Y/T3zD1laj/hF2WG2HK13LtnjzEbQ2ob/WGApwoW7NGtW+jfje6+8061
BMMtNN7+2nYGZC+rR7fuVpAWzZt5BP4DDIMhlWoyh0yj/EChZxeqjlKkUCHNmG2xPb8O2IqZ
dIlnZyKGEIAo0nLRosWKGbHfqj2YEMB5c8EH0DBnM556yEyall44abYvrlXIzEgURNrYKedB
+EFEYmo+xueDaKK3EpePVXkHXDPWTML6Gq+cQb+JpYSWjGBPFSjA4a6BGIg+vftwWwErhVcb
tB1m6wL58sVglIhW+KYfffhhjuCEppVibtUy8inrMwYiRmOAseKWcEmtWrWA9AMnJO8/0C4X
Ip+BS/Ati2tykjfZsRKtHhlqhA09/HRW8tEtaczUHiBabkO0sg1akAio0C3RQTQlAtOsRDOT
oSJGz6gSYJ5HH2vXJipbCQ4CjRlVoowrwifzAOf5+COPdOvcOQyGizXXvfc+M3t2Mg9gesEd
J5ri6FtH98NVxvg1dcswlRqd4cIgVONhHyxetCgfaXTy2DFOF04Lx1FVtvETeGUxeVRbs0oV
r4mnbu2aNdtffY3v4aww1w+At855y5zNeKRHcKBXr16DLbtA/ny1atYCwmShZmeP5EyFCtxK
bx48wDmrUhwX9sJ4DSYh8SpGpUEFig+KzYwZylYtdQbtOetaLxicivvBSbKOeAp8kvAqMATg
RQSJOHWKpZ6rmi+R6zkm8ij+BU1wJXNeE1YJbXFgQDBpYJ3u3r370qVLUjknNIM+4zcH91WC
jz+NX85JhcSqVKqs8BjAGvs7lGapUqVZ+XftysB2ZhHvboHTVN4MHhdAFsLKs4tRgLHi4Nqz
ew9NwTKUcL4DZQBVBQuPQEo3atBQnc0O7TOcjZwf0KfJUqGN9U5XADrd4yqZ3Bgtm7ckIWdn
egWxfdmyZUBPpkyZZM6jQcbhHcFJyNOdN29eJQq5ExJG5QUh3HhKleNzkqfE2+TM4OLHaSbc
JDhP4sGaQagErDaVRNG11Mm83FgujCeHM16PHqWjaoktOUxfevGFwk89ZTvUqWMnPiLeapAO
OgxZBPFQIF9e72zunLla8sMiRE68ShUqzJsXvdRkpz5s+PA5szNAIZzOMGj2TlGlxZgqufgq
la/A+5QQh57xGJcgwIqTsKMLFixQjxaAJuqWpH3r6EMPPIDhjYpqRMKAGloa/nXHHevXrder
oIGBAweWKF4c80TdZm6QOAA5fMkiG6rRI0ciUGUrLS7aAEz97re/LV+uLJFjm9S/Xz8162hx
RERQIHm0Bw0cZCsVhwedNAlPPPYYqlUxE4DOP15paiGOov268OlBg1yVaoYB++IfD/w/bOgw
/jF4zgQXpta5KuoJ42kD0wyGCnwXqk+bDY44LLFg3rzQCdfl7X//O7CBn1q2bOV2XkeRIoWB
4/bt248DKedQRDz+bhQumTFt2q233NKlSxfaKfyDMwKXbv7tb82VZRFWRl1eJ7naoXA9CICO
Pv9w880BqHR58lsyqhzPeDVr1qRu2QhZv4MONnTokJHDh9uPzZsblapE0JDQ9WrXpmpGK3GL
FlMnTwKVUBQOzYnKCeQO0QurlS9/vmLFiou7EdngQBktQBNUy6VrpiLGq1AhqJq+gkrnzZMX
TkW19IIFCgBM5H7oIVqQJRk+m/pkli3DDz34IIe4S4gaVIWRoF4QKPBkYm/k66cyhSUgiCxA
DRU2HSQxaQplUi89jnEK/rXkI7hAo6HzZXE5eB+AG9hIkPxAf0ailDRmo2F6EIoiafn4o4/x
Pnv8m37xC0IvuvXxEyJqBw8aDORx/3331YCfbtvWQz2cOzcfOgBa8WLFAn4a4yUSz1chObly
5YJxIzltPufMmQPdakkqWqQIHGmIh8J4ue6/H07aMfgIaCUtkWlEYGGIRQwf8U1hJxkdT5qM
Dx2wCVFeQGHtUe0dDI+4BoUNwDfAIC1FMFN26tdvkDfPE8xI4cEv50/OZjwY6UBePiB5ETWw
uAwcOGrkCLssaAdfMQ8oE5Cetw5WInATjIvwQRDEEUNZWOnhLQirunXrQUELlmFJGzNmTFQV
uUGDu+++O6hA9CUlvyPTYhy1ybo4bNhwberUqY2qFi9eMnDAwN59ehcrVgzFJOEFkPIQzy5n
PEiWc2AL28UQFuRDAQY7jqg/7KxOnoRTiwo4xyFnoQ2lC/W3Ugx5bCQbx40dg3UTksXqNjm+
Ghi8OAlJ4kER6M0eD60LHfAroCblmTRjtCDxdFi0cJFhQ6OtVwhTMkVMGsWLl6BtstzQZgd4
qN69WTUee/QxS4aW1i97vNB5vB7tJ6ysbqVKlbIAqWXta+/evXLnzq2ZWdKG/blkyZK0DA9I
/qsNGEYOj0JHTZ5C1I99e/hqd0fERQcvvqASPXEdxjl92nT6vP02DdPX2lHQUwb0lApqHtwr
dcN8ebJfzma8Xj17jB0zOrwnaK9Qu9yajbZodHQzWigwJ+t8zWrVAb5QFZ3Ei8EDUIt4EjmG
lxQ6oaAmqmY4s3XrKxbXcEwpgg+0ZcowK2T60yiNtosJ9YDVU958Dd2CUJIVjRo2omjZaFnR
O3ToWKhQIbApVGi9V9O4VKmS6DW6JCreesomqljRIqxEemCTJFHhpMlnazwiwyp0SyBJ+z2B
diSAzuG5Q4qHLHu8iPH2G3aFsMezKgm9o28XyC+uZy5IKv4sVbIUiZF6LVmHSZInip9iUbfO
0f7NBzbVGpekWkiaUfYE4yRfgSotYck8AH2VK1OO7AJ8hSZjLnYX4ExbNc8IrWpmPKOY+qAw
W3GaNW4irI51F9SOUs1oqWB14UKFCepXX32VZdhCCZ7qwWkxwLelS5acMSPCml6ezJY6qhzM
eKj21ddeQ0+BYmDWoxQpJ07s2LH9jTeiRADIl34Cx4iWvTZaH20zorC4CPjkKVMIIpEjYTqC
LXPH9h0Qj8G6Gc6Tb9Sz8NUL1qe/Wd6rbqNbZ35sooiUMKqQQGn16jWsKThWz4gG2jNE6MQS
ZpWvhpdCLicobzwHBuVyEQDMKoLiUGSgaY3Jeaq1Y3XJp02bTrsL9snsBBebUt8Kj+9XEl4k
m8gJC5PIJmZAV3GgGXMiJTws76idYWJn9ZMbKc4e1gVTDU1JPmahJLalCP4afzSz3oVY2PAh
vYULG6ox0DPtt6M68ps3G4ApJV1BQ4NETXowBpZbQXfhwe0bx0+YCIubOQ+bpk6dRp671/r1
68yJZchPOcF/npONKymJseL3Gn+SXVMqeDL8mqwxWX5KKCMxsaTSUyoqJfSTnbhDgo/TFBZG
kvIJYwsnU4+zf40vyoBrZHo6znVJ0ttZB5Y6pAyBlg3BmsxYlgFn0daS6T091TGiIPtjvtM8
pK7xqccZbJn5JKlskzxdWALOMXWnW0bzl0auZCfS9Jn0DKRnIEe7E876+s4qtc4io86mkATn
+RkyJEYYhjOpP1EUQuN3IqHkkosZZJo+P8QzkIP3eGd9K1QSWxf/zmHXOvrWW7bmGcn54n18
0FEDa7HCrX3+ed5bEKegv9m6MKPbAs6YPoPrwh4yoBbfifF0yJDDCmLbmJofNhmwQdrC2WVd
/sa3DzHpf7CPlrMZL2Xbdhqn//TTTwe7c8xOpzcGSWOmF5462MuQC1Azlr3Qnj2aoa9xo4YM
bsAuTI6YBO6EV4oFnJlUtGW3rl1eBLOMWSqDac/cQ+pHFgYG1WRfl+w6kjFI4yPj0OkGHywV
pO/+vs9ADma8iGdi0xk8brAQbHt1Gx/xsCFDnh78tLBxDm7cAZEo5Jm5TBuNiTt2wt17MN1e
TgXJMzmvubm279jBssdCPf+ZeTiNKRwaA8SRI5v7wWfylKmSJsGOuTDOWxzJPKZCljfH7nLo
8GEeYSbQ3Xt261b2LrbNKINDDBzzZsNcGwOMr6RMI4YNjwXv0Q8+19z7TnbpG+ZgxkOv0FLl
ypWHHfEiBw4YwIErzaOTeZ/IU7VqFeikyBfUrBlJVbx4cRlQgI/gvzZu2sixK5vlX2+9Fe+1
bNni9zf/XoIGPi7/eCCkypk4YeL9997L7ydjUpfOnSQO4Em//fbbpUtp2iTKJxkJq1P/ASuT
GdYRcJkERDxyNWrWBONgKBejoPOKFStyeERcFzOexpzCXTp37t2zl5Qt0Plc2AaZ1jk/aqyY
UxnPuNHrUwUKBlAIoAmpFXLxQ7s3b9rMDqxSpUpbt2yRlgfWkRe7dKmSXNIA7zKIyP8FMMX3
ChIpb7E2OpHoVnJleaxs88TCgXqSk9WqVMVpoDAEY+sYnl+2dGnJ0oOWSAWV/8cBNNOi2Fk8
Y9p0OZdopFHeruPHuKrlUwqN9QBXEVUFOHUK0AMUAwBaqiwyMGwm05+PzgzkVMYLMoQjWDiJ
FNHgVLBUgb4BxKLceBE8ql4E4GzcGD6LqQOhO1mhbNk5c2djHjpnzHivUB2rx4xH3EmJi9Pk
gcM2sqqCwsAHSwoowSOAYuu4BwBrGXXCvcSqdI0DYVq3ar1s6VLgKeBdQa7u2L5dlBxaQthp
U6P86j4ghe3btAnHVocA/JXzC8Y6zXgfHZYLT5qDGS+ghwkxsEOSqnSJkiG3PugwQL0DYGWM
B7m7dPESMqpl8xYeWA5Glkk4SRfWrVP3tde22+5RQbUXgikAh2pKTI0fO44SmPeJJwCa2rRt
K/BHviqRYJrhyZUrngvTh/F0G/FzhQoyTwtKCGhMEq91XIRAHjuBambZjhRqXjhpcN9rKSWZ
A7E/bLBpxkszHvDTtddee8Wtt96KQMPyHD6X1T7EYEDpJaWVLBkKmdTq2LEjbbN71279+/WX
MNOAYflBpaLkykuXCleV6hz1V6lUUeQBqcX0Iic09K3AH8hJqGKX4C6cIMEjeKRiA5C44FGY
Z+zo0WvWrpXpmX1EgmqAr9mz59jgMZPA4LvR3XfdBbIklTpjZteu3aZOnRKCaOSulKFdRoOn
nx7CCkqiijETmtCrZ69JEybojVjmV0gzXprxcgbjeU+AjIIjxYABXkbrwslTjPhEDd8A6HME
vNyxg1gTSCLOUkESRkvbQtZOqHzmRJdjV1vEkLpD5E6IA1Aoz0n7QDGjYbkRJKql9ObYLAKI
viqkJToOFWrs0BYtWoh7FZojHl24YOFCv8aZRU6wrEBy+mzdGoEYiTtgaE5C5wUZgTtu377D
lvKjRnbp583BqqaXl0jj+PgMGGL4NXm8VIdbuCq5PGkTqCGLkE8AK2d12WVpn3ptfIvTSbJS
73jmsC8vVSLNEu/PDORsxnt/5ih9l/QMXPIZyMGMd56wzOxTFm9YMyK7L4eNaxCA7wRAy/KY
voZ3ltRDPjtNnAk6Df0HFeCsKNN33WSee5CXnC4/9B3mYMbzbpYtWy6vUcI8iQUoOcj+/jQW
GGoPFkfuvR6Fk3+gL9l4hNvZN77TKGBKhYTbpkaPGYO2wWVgYqK0lpkg7ezP66HUalQ55OWX
N6uywJcYb1Zfj/JhZkOZAuLYKvOvvNMy5LxtsL1uFi39A525nH3zHMx4iKBZ0yZRfoTMj/JU
IcW/g7h2+elPwJSFp4XknD51GmMMt4GkfdH5zEC7ZDoyY/ZOB3R7zxmiJlPmRMaSk6nZrDM2
mUnLhEwDh5y5zTu9I+W3UEU5yOHTci8TZcrkw7UYJeTL3JfCo6m5lfp0MppED5gZER9+4tnv
3r0HV6dEZkp/GKp8M+r1hV8Dj4Vj7scK5cpivDNHmHoHNdNHuC87kDXLD2pNhoLVOZv8P7jR
52zGU3VNcishycePvQ2DIv+U5Hxy4xQvXkzCPLZEpsXVa9ZESTgkxoyqdUcVt9XiYsEXcCAB
GQKKQJfHjqmJB4epJDrz4yG5igUl7NoVYTJPnFAfWGQ6OSFHy062yrhouISqfnIlAlabJi5D
o0TOZoPRj58UFla7izMd54SMmu7omKFVOjC5H6XE4pZg3pT1QGIyFxJlADeJjUeGwlWrVovp
VoKPTz+OSY9YRfrAkOCAT9+v7iKdCd8GDKrjUAuJKVU6CZnzpE6RlcSA9+7Z7Xk5UdTc4TUJ
1SfNlXEaAyeK3oTnO3mQBfiNndJym65169dp76TBw52q1KM3hm+w1aefHhzVOr8Myhp/cOxz
4XfO2YwHrSIBifLWXTt3ARC55Za/cLUpaHjLLbeEBGFAm9Wj/MT1uRMgUVCpnLZ8dzhBklaV
2WSMlRcE/cFh+lUmr/vuuUeZO7Qr8xxwCWkg52yUDnDrVkWbpd9CjqNHjxoSZ/gy8T169ChX
tpwkKMDZfHTWAv4JiLCyZctyl1euVNG9otSA+/Yjbn6IRQsXkFdr1z7fpGkT2VflIDEGGACZ
nsmoqHH8oXzCl0n1JSFn+bJlIcsgUSdMGO8nydQsHIBplStXIb2hdv7yl7/ECQ5fhBZQh10e
Md6RO+64Q+Yy2ZnuvfdeTPXs0iUywEoPY7TyC4HLSFgGOOrCjRvWgwpUr1ZdAb1Vq1YpQKmu
rdybUVKTOnXAXC09JnbihPGm4p577sH55kHVctrs5bBJvnDy/+CufEfGy58/P8JN1TYutyk2
NimGZJImpmhTXG1y/vB3m0y5vgkjnAZvqZmVfuHCRSFXCroPBcf9BNglozMyIhlyP/jgnNmz
nh48qG3r1nLOyeEhPzSwGFHTplWrXj16Eq0YMs9jjxFTZGZAqBBxvPa41LF0Q/37RlXCBeMp
m4r96GalS5biMDR1SjHjH7FIdlM6DBMLU0ogG4l8hFguPEX4SUag4XFwEymsN6kyn3/hBWxg
n+avx1RqPGR0pWRKOEsiEbkyqamjkC9PHntXEDlZUlaufE6dR8147WU3mjZlqjLikXq5b7+R
h6TLBw7sl2aTDJ8xY6YM0PJhmgQ7OreQH0ViMnVhZROcOWM6AFDPnlFv1jWLVFrVvGDOzc54
NKCbbrrpiqpVqwL+XuaMR7ysWPEcCIsCvDRJ9U0RLoUQWIwWJKnrvLlzPYJ4BVlxwrMIsSPi
qIING9SXT5LWhIvgXYQSYUiJruCtmzRuBEs5eOBAVYXJrihT6vLl7dq0AcvEWoIhZJgO2fIk
DnJ56Pm1ba/Cdnbu2Im0UcnZmTgZbv0AZONFV80U89t0yfnpDFEmJ6SD9u3bcf1TFKFqMG3o
DbmHxKwYT0QFvVcaNfEWBq9SsfNMMmQUw4m9Wf26Uf4yCq+MmrVq1yarqakGuWH9Biq3NOna
k2x8/ThfAV05wmTgVrs43ItOThrj/HnPPEMaW18sBDLf1qsjT/spD+i83mbNmCFTU7euUW8k
/JLFZ2S/vmAS/GhemJ3xFLumpFwhg2/RokUvc8aT2hUpSAlesVx52zDYMcv2kbeOUNuwnxgc
ATgegUBApgwDTtLTGFRgo6mp2M+mS+o7mqS48pLFi8u3aeNmyS+YL7/U1IhVSnBKJjYr/ORT
UgOKbn/iscfJKM1syeS9kkIzlCUI9nr64fBhQ/2VcJrEK1tabfG3jTBUAnCJVJz6sUwApilR
4BKiiXFFmrAKRNCu3YapK3FG3bp09atr6caGR+IRxX169ZZkNrw2m668efJs2fKyXK6ygHk0
WDn1ekg8GjV0uASb4pjIbUH0+EfPAZ0zsP8AS0OZ0qVkE/NVOQcrl9mZPWumNcjKMmTQYJEZ
AjU8ZqMG9a1fJJ7UzoI8BF65pEXLlhL+Ofhoss3FP3V2xgscd0VAjl3mjCcv+nPLlrEcEHFY
TpSd1OLibiz79jlq7lj7baLwGIrv1bM3/VBouaXdvmh4DKSOFu+2bUNx+qqVq7ZqFSGbyTGp
pnUrSK9gwYKRyDp1Cn+iYDOO1iWTtSHs3iNKV96vbx85p7Foz+7dataoKREtD4fErOqJlyhW
nJa4bes2iE28JOxdks98efJaDkaNGvXE4483btzIMCSEJPEwHouFyKahQ4fRgXfu3GV7ZgXB
xpLwYlTWlyaNGotdAlUjOYkgkRlgop6XJJRJmtosV6xtWMECBUl+T6rAyNKlz9oysP2SY0aL
c+gyZUqXkb1X2maZKsUZCi+kJ9u7UoNpBzQFYVDuiJNZj9q0aknM6g3oVLSUxzd7xi+TvI3i
5bYBuXiWeH96yM54xB2hd4WXdPPNN1svE9673KYYKdOR6E5WcTF1NnUkwPoNG3x1nkyzq0G1
dkchpSSDJFMe6cQJwOgXWeTi2CI2TFXv4t4OImL9RKa/3XvYF0kbPUdugxMnXCjVioOouDYi
PfLWGzsjNKb5YZthtECpLIohyTnepvup0SF1vN5wkZa4RVJkmzSWHssERlq1ehWZaTCYnPSL
IKbHjslFaYemE4MJedfd2rVUSrfWf1zL6Di9kYWGePdePDg902aS0SXq8ODBuKzfgWich9/y
q0+cJ+aE/wkLJMPDa2Ud4WkwFXL1unVczTxqSWzqwSDdSD+GZ0rDjLH6CunwK65Oavq9P8T6
YbpLFsbzpq666ip/I8aTzJxp7rJlvGBbT/xRiVcqOWC0nD49Y2uXnAzaUXioxHCf5WSYlHM3
S9pkX7pwvs1bq1atK1aoGDaZqb2lKhFZ5jal2RkJocP55Eapw07tOXUkyeSkOvdSM9CkdpLl
eVMHnDEJmR7CZE6yDObDxBLvz7NkIZuE1yLGw3+0TRj/8CYuN4l37gkK/rdIvr2/nyj38/Hj
FHVxQ2SCeSNC3wXe9f6OMH23y2EGUhkvldEixvMRrHnfffflUMYLw34nDOR/a/ZjKGQiyoKa
+n6P4b/1bOl+L9kMpDJeqmqZwXgIiKWFvSXHSbxLNkPpjtIz8F+YgYTxmFEEnYeqmj6nGc8p
9pYs0ehn3aikT6ZnID0D72kGbEmYMJPd3BmM5wvrlp8lin1PnaYbp2cgPQPnmAGyDlvhvdQ2
pyVeOEvuPfLII1xAmDA9m+kZSM/AxcwAbrKvo2GmyrqsqmbqDYDI2Dldk2a/i5n39LUf5RmA
Z7jxxhs56pJ93bkkXvIblnMNZx9rJ6OLvR8P7Ed5HtPPnp6Bc89A7FuabadGZ7zyyiuFH2RR
L8+L8ZJGPA0MnsQl9lXqPv1Jz0B6Bs46A5REbILr8N5ZpVwq4/1/9BckHFTJneYAAAAASUVO
RK5CYII=
--------------040702090607050002070706--

--------------070008070200070909030307--

