I-D Action: draft-sato-soos-kia-04.txt
[email protected] Thu, 13 Aug 2026 06:35:21 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178662812164.68189.17922112414982110775@dt-datatracker-559c48c7fb-b8xm6> |
Internet-Draft draft-sato-soos-kia-04.txt is now available. Title: Kernel Identity and Attestation for Governing Enforcement Components Author: Tom Sato Name: draft-sato-soos-kia-04.txt Pages: 25 Dates: 2026-08-13 Abstract: This document specifies the Kernel Identity and Attestation (KIA) protocol for the Sovereign Object OS (SOOS) governance architecture. KIA defines the cryptographic identity of the GEC, the trust chain anchoring kernel authority from hardware root through operator root keypair to every signed Event Log entry, the GEC Manifest schema for runtime state attestation, and the Revocation Registry maintenance requirements. KIA is the Layer 0 signing and attestation component on which the audit trail guarantees of draft-sato-soos-gar, the mandate enforcement guarantees of draft-sato-soos-mjwt, and the multi-agent delegation chain of draft-sato-soos-mad all depend. Version -03 adds FROST threshold signing for high-availability GEC keypair deployments, the Cross-Principal Identifier (XPID) for cross-instance federation audit correlation, the XPID cross- instance trust model, and four new Security Considerations (Sections 14.8 through 14.11) addressing FROST nonce reuse, XPID revocation gap, identity takeover via claimed identifier (CVE-2025- 13609 class), and attestation channel binding (CVE-2026-33697 class). This document is the reference specification for the KIA RATS WG presentation at IETF 126 Vienna. The XPID primitive and the CVE-2026-33697 attestation channel binding defense are the primary novel contributions presented to the RATS WG. Version -04 corrects a registry-format mismatch identified by IANA early review (#1456067): the Section 16 request to register XPID_DERIVED and XPID_VERIFICATION_FAILED into the GAR Authority Lifecycle Event Types Registry [I-D.sato-soos-gar] now uses that registry's actual column set (Event Type, Class, Reference) and assigns both entries the newly-defined Class ID (Identity/ Federation event). No new event types, fields, or normative behavior are introduced in -04; this is a registration-format correction only. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-sato-soos-kia/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-sato-soos-kia-04 A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-sato-soos-kia-04 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]