
From anders.rundgren@telia.com  Wed Aug 28 23:53:49 2013
Return-Path: <anders.rundgren@telia.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 964A211E80F3 for <keyprov@ietfa.amsl.com>; Wed, 28 Aug 2013 23:53:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level: 
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OeYj1KXJ24lK for <keyprov@ietfa.amsl.com>; Wed, 28 Aug 2013 23:53:44 -0700 (PDT)
Received: from smtp-out11.han.skanova.net (smtp-out11.han.skanova.net [195.67.226.200]) by ietfa.amsl.com (Postfix) with ESMTP id ABB0C11E80EA for <keyprov@ietf.org>; Wed, 28 Aug 2013 23:53:44 -0700 (PDT)
Received: from [192.168.0.5] (37.250.134.95) by smtp-out11.han.skanova.net (8.5.133) (authenticated as u36408181) id 521DA868000720D7 for keyprov@ietf.org; Thu, 29 Aug 2013 08:53:42 +0200
Message-ID: <521EEFEE.9080302@telia.com>
Date: Thu, 29 Aug 2013 08:53:34 +0200
From: Anders Rundgren <anders.rundgren@telia.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130801 Thunderbird/17.0.8
MIME-Version: 1.0
To: keyprov@ietf.org
X-Enigmail-Version: 1.5.2
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Subject: [KEYPROV] Giving up on XML DSig => JSON
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Aug 2013 06:53:49 -0000

Since Google doesn't support XSD or XML DSig in Android I began looking at other alternatives.
There were none :-( Now there is :-)

https://openkeystore.googlecode.com/svn/resources/trunk/docs/Enveloped-JSON-Signatures.pdf

Comments are welcome!

Cheers
Anders

From simon@josefsson.org  Thu Aug 29 01:35:51 2013
Return-Path: <simon@josefsson.org>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 15D1821E8054 for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 01:35:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level: 
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aBBuRH5rH1qn for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 01:35:50 -0700 (PDT)
Received: from duva.sjd.se (duva.sjd.se [IPv6:2001:9b0:1:1702::100]) by ietfa.amsl.com (Postfix) with ESMTP id 2843121F9FD5 for <keyprov@ietf.org>; Thu, 29 Aug 2013 01:35:49 -0700 (PDT)
Received: from latte.josefsson.org (static-213-115-179-130.sme.bredbandsbolaget.se [213.115.179.130]) (authenticated bits=0) by duva.sjd.se (8.14.4/8.14.4/Debian-4) with ESMTP id r7T8ZiVs001123 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Thu, 29 Aug 2013 10:35:47 +0200
Date: Thu, 29 Aug 2013 10:35:42 +0200
From: Simon Josefsson <simon@josefsson.org>
To: Anders Rundgren <anders.rundgren@telia.com>
Message-ID: <20130829103542.7e22fea3@latte.josefsson.org>
In-Reply-To: <521EEFEE.9080302@telia.com>
References: <521EEFEE.9080302@telia.com>
X-Mailer: Claws Mail 3.8.1 (GTK+ 2.24.10; x86_64-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: clamav-milter 0.97.8 at duva.sjd.se
X-Virus-Status: Clean
Cc: keyprov@ietf.org
Subject: Re: [KEYPROV] Giving up on XML DSig => JSON
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Aug 2013 08:35:51 -0000

You wrote:

> Since Google doesn't support XSD or XML DSig in Android I began
> looking at other alternatives. There were none :-( Now there is :-)
> 
> https://openkeystore.googlecode.com/svn/resources/trunk/docs/Enveloped-JSON-Signatures.pdf

Did you implement JWS or something else?  If the latter, why not JWS?
It seems to be where everyone in the JSON-world is headed.

http://tools.ietf.org/html/draft-jones-json-web-signature-04

/Simon

From anders.rundgren@telia.com  Thu Aug 29 02:54:45 2013
Return-Path: <anders.rundgren@telia.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9AF9921F856A for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 02:54:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.391
X-Spam-Level: 
X-Spam-Status: No, score=-2.391 tagged_above=-999 required=5 tests=[AWL=0.208,  BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G1dHkE2F4oQX for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 02:54:45 -0700 (PDT)
Received: from smtp-out11.han.skanova.net (smtp-out11.han.skanova.net [195.67.226.200]) by ietfa.amsl.com (Postfix) with ESMTP id 26FFD21F9E9F for <keyprov@ietf.org>; Thu, 29 Aug 2013 02:54:45 -0700 (PDT)
Received: from [192.168.0.5] (37.250.134.95) by smtp-out11.han.skanova.net (8.5.133) (authenticated as u36408181) id 521DA8680008DCF3; Thu, 29 Aug 2013 11:54:35 +0200
Message-ID: <521F1A4D.9090502@telia.com>
Date: Thu, 29 Aug 2013 11:54:21 +0200
From: Anders Rundgren <anders.rundgren@telia.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130801 Thunderbird/17.0.8
MIME-Version: 1.0
To: Simon Josefsson <simon@josefsson.org>
References: <521EEFEE.9080302@telia.com> <20130829103542.7e22fea3@latte.josefsson.org>
In-Reply-To: <20130829103542.7e22fea3@latte.josefsson.org>
X-Enigmail-Version: 1.5.2
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Cc: keyprov@ietf.org
Subject: Re: [KEYPROV] Giving up on XML DSig => JSON
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Aug 2013 09:54:45 -0000

On 2013-08-29 10:35, Simon Josefsson wrote:
> You wrote:
> 
>> Since Google doesn't support XSD or XML DSig in Android I began
>> looking at other alternatives. There were none :-( Now there is :-)
>>
>> https://openkeystore.googlecode.com/svn/resources/trunk/docs/Enveloped-JSON-Signatures.pdf
> 
> Did you implement JWS or something else?

I did not use JWS.

> If the latter, why not JWS?

Because JWS is based on in-line signatures of base64-encoded payloads.
This would ruin the readability of the already complex KeyGen2 protocol
and make the switch from XML look bad.

> It seems to be where everyone in the JSON-world is headed.
> 
> http://tools.ietf.org/html/draft-jones-json-web-signature-04

Yes, but these guys only work with comparatively simple authorization systems
like OAuth and OpenID.

In addition, KeyGen2 uses a bunch of non-standard constructs including
SM (Secure Messaging) so having a proprietary signature mechanism seems
like a minor problem.

Cheers,
Anders

> 
> /Simon
> 


From anders.rundgren@telia.com  Thu Aug 29 04:40:05 2013
Return-Path: <anders.rundgren@telia.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A1B2F21F8263 for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 04:40:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.691
X-Spam-Level: 
X-Spam-Status: No, score=-1.691 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_ILLEGAL_IP=1.908, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CP2A-8clgds2 for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 04:39:55 -0700 (PDT)
Received: from smtp-out11.han.skanova.net (smtp-out11.han.skanova.net [195.67.226.200]) by ietfa.amsl.com (Postfix) with ESMTP id 8F07F21F9FF3 for <keyprov@ietf.org>; Thu, 29 Aug 2013 04:39:55 -0700 (PDT)
Received: from [192.168.0.5] (2.68.138.51) by smtp-out11.han.skanova.net (8.5.133) (authenticated as u36408181) id 521DA8680009AC5E; Thu, 29 Aug 2013 13:39:46 +0200
Message-ID: <521F32F3.9030107@telia.com>
Date: Thu, 29 Aug 2013 13:39:31 +0200
From: Anders Rundgren <anders.rundgren@telia.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130801 Thunderbird/17.0.8
MIME-Version: 1.0
To: Simon Josefsson <simon@josefsson.org>
References: <521EEFEE.9080302@telia.com> <20130829103542.7e22fea3@latte.josefsson.org>
In-Reply-To: <20130829103542.7e22fea3@latte.josefsson.org>
X-Enigmail-Version: 1.5.2
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Cc: keyprov@ietf.org
Subject: Re: [KEYPROV] Giving up on XML DSig => JSON
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Aug 2013 11:40:06 -0000

Update: A comparison with JWS was included in the document
as some kind of rationale...

On 2013-08-29 10:35, Simon Josefsson wrote:
> You wrote:
> 
>> Since Google doesn't support XSD or XML DSig in Android I began
>> looking at other alternatives. There were none :-( Now there is :-)
>>
>> https://openkeystore.googlecode.com/svn/resources/trunk/docs/Enveloped-JSON-Signatures.pdf
> 
> Did you implement JWS or something else?

I did not use JWS.

> If the latter, why not JWS?

Because JWS is based on in-line signatures of base64-encoded payloads.
This would ruin the readability of the already complex KeyGen2 protocol
and make the switch from XML look bad.

> It seems to be where everyone in the JSON-world is headed.
> 
> http://tools.ietf.org/html/draft-jones-json-web-signature-04

Yes, but these guys only work with comparatively simple authorization systems
like OAuth and OpenID.

In addition, KeyGen2 uses a bunch of non-standard constructs including
SM (Secure Messaging) so having a proprietary signature mechanism seems
like a minor problem.

Cheers,
Anders

> 
> /Simon
> 


From simon@josefsson.org  Thu Aug 29 04:56:25 2013
Return-Path: <simon@josefsson.org>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4238921F850D for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 04:56:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level: 
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DyWJ+1au7W6k for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 04:56:18 -0700 (PDT)
Received: from duva.sjd.se (duva.sjd.se [IPv6:2001:9b0:1:1702::100]) by ietfa.amsl.com (Postfix) with ESMTP id 9E99C21F8EE6 for <keyprov@ietf.org>; Thu, 29 Aug 2013 04:55:44 -0700 (PDT)
Received: from latte.josefsson.org (static-213-115-179-130.sme.bredbandsbolaget.se [213.115.179.130]) (authenticated bits=0) by duva.sjd.se (8.14.4/8.14.4/Debian-4) with ESMTP id r7TBtcgt005572 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Thu, 29 Aug 2013 13:55:40 +0200
Date: Thu, 29 Aug 2013 13:55:37 +0200
From: Simon Josefsson <simon@josefsson.org>
To: Anders Rundgren <anders.rundgren@telia.com>
Message-ID: <20130829135537.6599b273@latte.josefsson.org>
In-Reply-To: <521F32F3.9030107@telia.com>
References: <521EEFEE.9080302@telia.com> <20130829103542.7e22fea3@latte.josefsson.org> <521F32F3.9030107@telia.com>
X-Mailer: Claws Mail 3.8.1 (GTK+ 2.24.10; x86_64-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: clamav-milter 0.97.8 at duva.sjd.se
X-Virus-Status: Clean
Cc: keyprov@ietf.org
Subject: Re: [KEYPROV] Giving up on XML DSig => JSON
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Aug 2013 11:56:28 -0000

You wrote:

> > If the latter, why not JWS?
> 
> Because JWS is based on in-line signatures of base64-encoded payloads.
> This would ruin the readability of the already complex KeyGen2
> protocol and make the switch from XML look bad.

Why can't you hash the data you want to sign, and then use JWS to sign
the hash?  Then you get readability and don't have to invent something
new.  However, your example blob in the PDF is hardly readable, so I
don't fully follow the argument about readability to begin with.

/Simon

From anders.rundgren@telia.com  Thu Aug 29 05:27:15 2013
Return-Path: <anders.rundgren@telia.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F14221F9DDB for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 05:27:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.691
X-Spam-Level: 
X-Spam-Status: No, score=-1.691 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_ILLEGAL_IP=1.908, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pevxXVRPAhgz for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 05:27:10 -0700 (PDT)
Received: from smtp-out12.han.skanova.net (smtp-out12.han.skanova.net [195.67.226.212]) by ietfa.amsl.com (Postfix) with ESMTP id B9E6921F9DC7 for <keyprov@ietf.org>; Thu, 29 Aug 2013 05:27:09 -0700 (PDT)
Received: from [192.168.0.5] (2.68.138.51) by smtp-out12.han.skanova.net (8.5.133) (authenticated as u36408181) id 521DAB1700060CF6; Thu, 29 Aug 2013 14:26:57 +0200
Message-ID: <521F3E05.7010309@telia.com>
Date: Thu, 29 Aug 2013 14:26:45 +0200
From: Anders Rundgren <anders.rundgren@telia.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130801 Thunderbird/17.0.8
MIME-Version: 1.0
To: Simon Josefsson <simon@josefsson.org>
References: <521EEFEE.9080302@telia.com> <20130829103542.7e22fea3@latte.josefsson.org> <521F32F3.9030107@telia.com> <20130829135537.6599b273@latte.josefsson.org>
In-Reply-To: <20130829135537.6599b273@latte.josefsson.org>
X-Enigmail-Version: 1.5.2
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Cc: keyprov@ietf.org
Subject: Re: [KEYPROV] Giving up on XML DSig => JSON
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Aug 2013 12:27:15 -0000

On 2013-08-29 13:55, Simon Josefsson wrote:

> You wrote:
> 
Hi Simon,

>>> If the latter, why not JWS?
>>
>> Because JWS is based on in-line signatures of base64-encoded payloads.
>> This would ruin the readability of the already complex KeyGen2
>> protocol and make the switch from XML look bad.
> 
> Why can't you hash the data you want to sign, and then use JWS to sign
> the hash?

Such a thing would still require most of what I have done anyway,
wouldn't it?  I mean, "Reference", canonicalization etc.

Existing JSON parsers probably don't support canonicalization since
this hasn't been an issue until now.  By building-in all that from
the beginning you get a cool and rather smallish system as well.


> Then you get readability and don't have to invent something new.

I actually enjoy inventing new things.  Don't you like my brand new octagonic wheel? :-)

To be a bit more serious: I'm not overly convinced that clinging on
to standards always is the best solution.  I have don my clinging
with XML DSig now and it turned out to be a mistake :-(

It is like PKCS #11 and on-line provisioning; it will never work although
the OASIS PKCS11 TC claims that. Why? Because PKCS #11 wasn't designed for
a remote SO and that is a bit hard to add as an afterthought, not to
mention getting all drivers up-to-date.  IMO - Simply undoable.

> However, your example blob in the PDF is hardly readable, so I
> don't fully follow the argument about readability to begin with.

There are blobs but they at least have labels.

Here is the XML version of KeyGen2:

http://webpki.org/papers/keygen2/keygen2.junit.run.html

It is rather pretty (IMO...).  The JSON version will be _almost_
as nice but but only use 1/3 as much code (including third-party
libraries and all).

Cheers
Anders

> 
> /Simon
> 


From anders.rundgren@telia.com  Thu Aug 29 05:44:09 2013
Return-Path: <anders.rundgren@telia.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2A89911E8103 for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 05:44:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.221
X-Spam-Level: 
X-Spam-Status: No, score=-2.221 tagged_above=-999 required=5 tests=[AWL=0.378,  BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id euka41q5ahzG for <keyprov@ietfa.amsl.com>; Thu, 29 Aug 2013 05:44:09 -0700 (PDT)
Received: from smtp-out12.han.skanova.net (smtp-out12.han.skanova.net [195.67.226.212]) by ietfa.amsl.com (Postfix) with ESMTP id 6003811E80FA for <keyprov@ietf.org>; Thu, 29 Aug 2013 05:44:08 -0700 (PDT)
Received: from [192.168.0.5] (2.68.138.51) by smtp-out12.han.skanova.net (8.5.133) (authenticated as u36408181) id 521DAB1700062312 for keyprov@ietf.org; Thu, 29 Aug 2013 14:44:05 +0200
Message-ID: <521F4209.5060101@telia.com>
Date: Thu, 29 Aug 2013 14:43:53 +0200
From: Anders Rundgren <anders.rundgren@telia.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130801 Thunderbird/17.0.8
MIME-Version: 1.0
To: keyprov@ietf.org
X-Enigmail-Version: 1.5.2
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Subject: [KEYPROV] IBM patent on JSON Signatures
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Aug 2013 12:44:09 -0000

http://patents.justia.com/patent/20100185869

This patent doesn't appear to apply to JWS but to my take on JSON signatures:

https://openkeystore.googlecode.com/svn/resources/trunk/docs/Enveloped-JSON-Signatures.pdf

I got this information from the patentee :-(

It is of course a bit reassuring to not be alone with an idea...

Cheers
Anders

From anders.rundgren@telia.com  Fri Aug 30 20:23:06 2013
Return-Path: <anders.rundgren@telia.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A6D611E8111 for <keyprov@ietfa.amsl.com>; Fri, 30 Aug 2013 20:23:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.858
X-Spam-Level: 
X-Spam-Status: No, score=-0.858 tagged_above=-999 required=5 tests=[AWL=-0.833, BAYES_00=-2.599, RCVD_ILLEGAL_IP=1.908, RCVD_IN_DNSWL_LOW=-1, SARE_URI_EQUALS=1.666]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ULmEW0RG4Icy for <keyprov@ietfa.amsl.com>; Fri, 30 Aug 2013 20:23:00 -0700 (PDT)
Received: from smtp-out21.han.skanova.net (smtp-out21.han.skanova.net [195.67.226.208]) by ietfa.amsl.com (Postfix) with ESMTP id F1A8811E8107 for <keyprov@ietf.org>; Fri, 30 Aug 2013 20:22:48 -0700 (PDT)
Received: from [192.168.0.5] (2.68.45.16) by smtp-out21.han.skanova.net (8.5.133) (authenticated as u36408181) id 521DAD6E001463C5 for keyprov@ietf.org; Sat, 31 Aug 2013 05:22:47 +0200
Message-ID: <52216178.4050701@telia.com>
Date: Sat, 31 Aug 2013 05:22:32 +0200
From: Anders Rundgren <anders.rundgren@telia.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130801 Thunderbird/17.0.8
MIME-Version: 1.0
To: keyprov@ietf.org
References: <521ED34C.5020605@gmail.com> <522015DC.9090609@digitalbazaar.com> <5220A2F9.8050505@gmail.com>
In-Reply-To: <5220A2F9.8050505@gmail.com>
X-Enigmail-Version: 1.5.2
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Subject: [KEYPROV] Updated: Re: Giving up on XML DSig => JSON
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Aug 2013 03:23:06 -0000

Hi,
Based on the _extremely_ useful feedback received, I have decided to update the proposed clear-text JSON Signature scheme.

Canonicalization:
- Remove whitespace
- Unescape "strings"
- Sort properties

Signature scope: a JSON Signature signs the object (including possible child objects) it is declared in.

That is, the final XML DSig "leftover", the awkward Reference has been shelved.
I expect the resulting code to be even shorter than today :-)

   {
    "@context": "http://example.com/test-signature",
    "Now": "2013-08-30T07:56:08+02:00",
    "ID": "lADU_sO067Wlgoo52-9L",
    "STRINGS": ["One","Two","Three"],
    "EscapeMe": "A\\\n\"",
    "Intra": 78,
    "Signature":
      {
        "SignatureInfo":
          {
            "Algorithm": "http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256",
            "KeyInfo":
              {
                "SignatureCertificate":
                  {
                    "Issuer": "CN=Demo Sub CA,DC=webpki,DC=org",
                    "SerialNumber": 1377713637130,
                    "Subject": "CN=example.com,O=Example Organization,C=US"
                  },
                "X509CertificatePath":
                  [
                    "MIIClzCCAX+gAwIBAgIG...RBYG3uk9W/uNIHdoyQn19w=="
                  ]
              }
          },
        "SignatureValue": "MEYCIQCCAxLBoPw5h8hW4M...L5t0XscOTPWXE67c1SCT"
      },
  }

The sample shows the new KeyGen2 message structure which has been derived from JSON-LD (@context)

Cheers
Anders
