I-D Action: draft-geng-acme-sm2dualcert-rotation-00.txt

[email protected]
Newsgroups gmane.ietf.announce
Message-ID <178456667159.193024.7971261663046575351@dt-datatracker-d4d6ff9d9-fsx7d>
Internet-Draft draft-geng-acme-sm2dualcert-rotation-00.txt is now available.

   Title:   ACME STAR Extension for SM2 Dual-Certificate Automated Key Rotation
   Authors: Feng Geng
            Panyu Wu
            Guilin Wang
            Xin Chen
   Name:    draft-geng-acme-sm2dualcert-rotation-00.txt
   Pages:   53
   Dates:   2026-07-20

Abstract:

   The SM2 dual-certificate system, specified in [GMT.0034-2014],
   employs a dual-certificate architecture in which each entity holds
   both a signature certificate and an encryption certificate.  The
   encryption private key is generated and escrowed by the Key
   Management Center (KMC).

   This document defines an *ACME Profile* that adapts the core protocol
   of [RFC8555] to the specific deployment scenario of SM2 dual-
   certificate management in the ShangMi (SM) ecosystem.  Building upon
   the dual-certificate foundation framework defined in [I-D.geng-acme-
   sm2dualcert-extension], this document defines a STAR extension for
   the ACME protocol that enables *synchronized short-term automatic
   renewal* of SM2 dual certificates.  The signature certificate follows
   [RFC8739] (ACME STAR) for automatic renewal with the same key pair;
   the encryption certificate achieves automated key rotation with a
   fresh key pair per epoch based on *Asynchronous Remote Key Generation
   (ARKG)* [Frymann2020].

   This extension establishes a *unified ARKG seed chain key derivation
   system*: the KMC holds a seed seed_kmc and derives all encryption
   certificate key pairs (pk_i, sk_i) for all epochs via the ARKG
   algorithm, enabling stateless, lightweight KMC operations.  On this
   basis, this extension provides *two private key delivery modes*:

   *  *Mode A (ARKG Envelope Delivery)*: delivers sk_i to the client via
      a digital envelope, fully inheriting the envelope mechanism of the
      base framework.

   *  *Mode B (ARKG Offline DH Derivation)*: the initial private key is
      obtained via envelope delivery; subsequent private keys are
      derived offline by the client, providing key insulation security
      properties.

   Both modes share the same ARKG cryptographic infrastructure,
   differing only in the final delivery mechanism of the private key.
   Deployers may choose according to their requirements, with full
   compatibility and coexistence achieved through ACME directory object
   negotiation.

   *Document Positioning*: This document is intended for the *specific
   SM ecosystem* as a practical guide and interoperability reference,
   and does not seek to become a general Internet standard.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-geng-acme-sm2dualcert-rotation/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-geng-acme-sm2dualcert-rotation-00.html

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.