I-D Action: draft-geng-acme-sm2dualcert-rotation-00.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178456667159.193024.7971261663046575351@dt-datatracker-d4d6ff9d9-fsx7d> |
Internet-Draft draft-geng-acme-sm2dualcert-rotation-00.txt is now available.
Title: ACME STAR Extension for SM2 Dual-Certificate Automated Key Rotation
Authors: Feng Geng
Panyu Wu
Guilin Wang
Xin Chen
Name: draft-geng-acme-sm2dualcert-rotation-00.txt
Pages: 53
Dates: 2026-07-20
Abstract:
The SM2 dual-certificate system, specified in [GMT.0034-2014],
employs a dual-certificate architecture in which each entity holds
both a signature certificate and an encryption certificate. The
encryption private key is generated and escrowed by the Key
Management Center (KMC).
This document defines an *ACME Profile* that adapts the core protocol
of [RFC8555] to the specific deployment scenario of SM2 dual-
certificate management in the ShangMi (SM) ecosystem. Building upon
the dual-certificate foundation framework defined in [I-D.geng-acme-
sm2dualcert-extension], this document defines a STAR extension for
the ACME protocol that enables *synchronized short-term automatic
renewal* of SM2 dual certificates. The signature certificate follows
[RFC8739] (ACME STAR) for automatic renewal with the same key pair;
the encryption certificate achieves automated key rotation with a
fresh key pair per epoch based on *Asynchronous Remote Key Generation
(ARKG)* [Frymann2020].
This extension establishes a *unified ARKG seed chain key derivation
system*: the KMC holds a seed seed_kmc and derives all encryption
certificate key pairs (pk_i, sk_i) for all epochs via the ARKG
algorithm, enabling stateless, lightweight KMC operations. On this
basis, this extension provides *two private key delivery modes*:
* *Mode A (ARKG Envelope Delivery)*: delivers sk_i to the client via
a digital envelope, fully inheriting the envelope mechanism of the
base framework.
* *Mode B (ARKG Offline DH Derivation)*: the initial private key is
obtained via envelope delivery; subsequent private keys are
derived offline by the client, providing key insulation security
properties.
Both modes share the same ARKG cryptographic infrastructure,
differing only in the final delivery mechanism of the private key.
Deployers may choose according to their requirements, with full
compatibility and coexistence achieved through ACME directory object
negotiation.
*Document Positioning*: This document is intended for the *specific
SM ecosystem* as a practical guide and interoperability reference,
and does not seek to become a general Internet standard.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-geng-acme-sm2dualcert-rotation/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-geng-acme-sm2dualcert-rotation-00.html
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]