[saag] Re: Interests on Initiating the standardization work related to "Zero Trust"

"Aijun Wang" <[email protected]> Fri, 26 Dec 2025 16:16:17 +0800
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Hi, Usama:

As indicated in https://datatracker.ietf.org/doc/html/draft-liu-saag-zt-problem-statement-00#section-5.2, although "zero trust" is mainly used as the marketing buzzword, it also reflects the necessity for the standardization body to define and identify how to achieve this goal and how to interoperate among the different components of the "zero trust" system. 

The use cases defined in this document are just general descriptions. 
For the potential works in "zero trust" WG, I think you should refer to section 5.3 "Gap Analysis" and section 6 "Proposed Scope of Work for the IETF" of this document. 
These are not covered by the SEAT WG, and should be developed in one new WG.

Actually, I think the work within SEAT, and also your referred draft documents can be seen as the cases that enhance the "trustworthiness" in transport layer(specially TLS protocol), which can be also clarified as one part of solution for "zero trust", but not all of them. 

There will be others documents to describe the necessary of the new solutions for "zero trust" in these days.
We encourage also others experts to contribute some documents/thoughts on this topic, to make the "zero trust" concept more touchable, implementable and deployable.

Best Regards

Aijun Wang
China Telecom

-----Original Message-----
From: [email protected] [mailto:[email protected]] On Behalf Of Muhammad Usama Sardar
Sent: Thursday, December 25, 2025 6:25 PM
To: [email protected]
Subject: [saag] Re: Interests on Initiating the standardization work related to "Zero Trust"

Hi Aijun,

I attended side meeting at 123 and gave some feedback. Could you please update me what you did with my feedback? Reading both of your drafts, it seems to have been unaddressed.

Are you aware of SEAT WG [0]? What exactly is the protocol work in your proposal beyond the scope of SEAT? Reading Sec. 5.3 of draft-liu-saag-zt-problem-statement, it is unclear to me which of your requirements cannot be met by the protocol specified in [1*] or at least why it cannot be used as a basis?

Additionally, do you have a real use case that is not covered in [2*]? 
"dynamic security deployment​ in cloud-network​ environments" mentioned by Xuan in the thread is already in [2*]. Telecom network environment in draft-si-saag-zerotrust-promblem seems the same as we have in [2*]. We also have AI agent use case (mentioned in
draft-liu-saag-zt-problem-statement) in [2*].

I believe there is no need to create a new list until the above questions are precisely clarified.

I agree with Richard that Zero Trust is basically a marketing term and trying to define marketing terms is not a good use of IETF time. To support this claim, confidential computing is often presented as "Zero Trust" and we showed [3] that there is HUGE trust base that you still have to trust in these technologies (e.g., Arm CCA and Intel TDX).

-Usama

[0] https://datatracker.ietf.org/wg/seat/about/

[1]
https://tls-attestation.github.io/use-cases-and-properties/draft-mihalcea-seat-use-cases.html

[2]
https://tls-attestation.github.io/exported-attestation/draft-fossati-seat-expat.html

[3]
https://www.researchgate.net/publication/375592777_Formal_Specification_and_Verification_of_Architecturally-defined_Attestation_Mechanisms_in_Arm_CCA_and_Intel_TDX

* Apologies for mentioning the editors' drafts. We will roll out the updates in the corresponding drafts early next year.



_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]