Location by Reference Requirements

Hannes Tschofenig <[email protected]>
Newsgroups gmane.ietf.sip,gmane.ietf.geopriv
Message-ID <[email protected]>
Hi Andy,
Hi Jeroen,

Andrew Newton wrote:
> 
> On Jul 25, 2006, at 7:21 PM, Jeroen van Bemmel wrote:
> 
>> For location-by-reference, you'd probably want some additional  
>> requirements:
>> - URL must be valid for a limited amount of time
Ok.

Should it be end point controlled or should the end point be informed 
about the lifetime?

>> - URL must be cryptographically hard to guess

must contain a random,non-guessable component.

>> - URL must not contain any information that identifies the user /  
>> device / AoR

more difficult if you consider that a PIDF-LO contains identity 
information.

>> - for whatever transport protocol is used: response must be marked  as 
>> 'no cache'
Sounds reasonble.


>> - user must be able to remove the information at the URL, ie  explicit 
>> invalidation

Difficult with the SIP based approach we are discussing.
Simpler with the Geopriv-L7 approach being discussed.

>> - user must be able to verify correctness of the issued information  
>> (ie user can access the URL himself)


Difficult with the discussed SIP-based mechanism since the user does not 
ever see the URI.

>> - user must be able to control who accesses the URL, both upfront  and 
>> history of accesses (for a reasonable period)

This has been subject for a long discussion with no conclusion.

>> - there must be explicit consent before a proxy would insert user  
>> location
That's not what some of the use cases indicate.

Nice requirements; maybe something for the Geopriv L7 design team.

> 
> 
> Please tell me that you are merely suggesting guidelines and  
> considerations by operators and are not suggesting 2119 language for  
> these?  Because just like you'd never get agreement on the intended  
> duration or accuracy or confidence of location-by-value, you'd never  
> get agreement on these.

Well, some of these requirements are actually protocol capabilities. 
With some other stuff I agree with you, Andy.

> 
>> For the latter point: except for emergency scenario's, the UAC  should 
>> include some flag in the INVITE saying "proxy: please append  
>> location". You'd probably also want some feedback (eg proxy or UAS  
>> adding a header to the response saying 'this is the URL that I  
>> appended/got'

This is in fact interesting. I haven't seen these requirements so far.

> 
> 
> Just thinking out loud here, but maybe the rule should be that  proxies 
> never append a Location header except for emergencies.

The problem is that the IETF cannot enforce this. Once you have a 
solution for adding location-by-reference by a proxy it can do it.

Ciao
Hannes

> 
> -andy
> 
> _______________________________________________
> Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
> This list is for NEW development of the core SIP Protocol
> Use [email protected] for questions on current sip
> Use [email protected] for new developments on the application of sip
> 
> 


_______________________________________________
Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [email protected] for questions on current sip
Use [email protected] for new developments on the application of sip
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.