[saag] New I-D: draft-yossif-psea-01 — Post-Session Execution Assurance (authority gap at execution time)
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
--===============2141730172632145260== Content-Type: multipart/alternative; boundary="Apple-Mail=_8DD6EFF6-9B85-4B2A-8CC3-99DE2AD64F60" --Apple-Mail=_8DD6EFF6-9B85-4B2A-8CC3-99DE2AD64F60 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 List, I have submitted an Informational Internet-Draft defining a security = model for verifying human authority at execution time: draft-yossif-psea-01 Post-Session Execution Assurance (PSEA): A Security Model for = Verifying Authority at the Moment of Action https://datatracker.ietf.org/doc/draft-yossif-psea/ The problem statement: session-based security conflates authentication = (who logged in) with execution authority (who is approving this specific = action right now). In banking, healthcare, government, and critical = infrastructure, this gap enables fraud and unauthorized execution within = technically valid sessions. PSEA defines five requirements that an implementation must satisfy to = close this gap: 1. Authority validated at the moment of execution, not at login 2. Human presence demonstrated, not inferred from prior authentication 3. Execution approval bound to a verified device state 4. Cryptographic proof independent of session tokens or bearer = credentials 5. Proof generation independent of network connectivity The model is intentionally agnostic to biometric modality, cryptographic = scheme, and attestation mechanism. It defines what must be proven, not = how. A reference specification is maintained at = https://github.com/yuthent/psea-spec and includes: - Formal P/S/E/A tier definitions - JSON Schema for the proof token - STRIDE-based threat model - OpenAPI 3.0 verification contract - RFC 6979 deterministic test vectors (20 vectors, 4 tiers) - Reference verifiers in Python and TypeScript The draft explicitly distinguishes PSEA from MFA, continuous = authentication, session hardening, risk-based authentication, and Zero = Trust =E2=80=94 each of which addresses a different problem. I am seeking technical review and critique, specifically: - Whether the problem definition is sound and the gap is genuinely = unaddressed by existing models - Whether the five conformance requirements in Appendix B are = technically sufficient - Whether the threat model in the reference spec correctly = characterizes the attack surface - Whether this warrants a dedicated BOF or fits within an existing WG = charter Mohamad Khalil Yossif Yuthent [email protected] https://yuthent.com/psea =09 Mohamad Khalil Yossif CEO =E2=80=93 Yuthent Founder =E2=80=93 SwiftCrew, MK Digital, MK Electronics =20 T: +972 50-931-1103 <tel:+972509311103> E: [email protected] <mailto:[email protected]> W: yuthent.com <https://yuthent.com/> = <https://www.linkedin.com/in/mohamad-khalil-yossif-4b9781163/> =20 <https://yuthent.com/> This email may contain confidential or sensitive information. If you are = not the intended recipient, any review, use, disclosure, distribution, = or copying is prohibited. If you received this message in error, please = delete it immediately. --Apple-Mail=_8DD6EFF6-9B85-4B2A-8CC3-99DE2AD64F60 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"content-type" content=3D"text/html; = charset=3Dutf-8"></head><body style=3D"overflow-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;"><div><p = style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><span style=3D"font-family: = Helvetica; font-size: 12px;">List,</span></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">I have submitted an = Informational Internet-Draft defining a security model for verifying = human authority at execution time:</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> = </span>draft-yossif-psea-01</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>Post-Session Execution = Assurance (PSEA): A Security Model for Verifying Authority at the Moment = of Action</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> = </span>https://datatracker.ietf.org/doc/draft-yossif-psea/</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">The problem statement: = session-based security conflates authentication (who logged in) with = execution authority (who is approving this specific action right now). = In banking, healthcare, government, and critical infrastructure, this = gap enables fraud and unauthorized execution within technically valid = sessions.</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">PSEA defines five = requirements that an implementation must satisfy to close this = gap:</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>1. Authority validated at = the moment of execution, not at login</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>2. Human presence = demonstrated, not inferred from prior authentication</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>3. Execution approval = bound to a verified device state</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>4. Cryptographic proof = independent of session tokens or bearer credentials</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>5. Proof generation = independent of network connectivity</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">The model is intentionally = agnostic to biometric modality, cryptographic scheme, and attestation = mechanism. It defines what must be proven, not how.</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">A reference specification is = maintained at https://github.com/yuthent/psea-spec and = includes:</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- Formal P/S/E/A tier = definitions</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- JSON Schema for the = proof token</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- STRIDE-based threat = model</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- OpenAPI 3.0 verification = contract</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- RFC 6979 deterministic = test vectors (20 vectors, 4 tiers)</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- Reference verifiers in = Python and TypeScript</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">The draft explicitly = distinguishes PSEA from MFA, continuous authentication, session = hardening, risk-based authentication, and Zero Trust =E2=80=94 each of = which addresses a different problem.</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">I am seeking technical = review and critique, specifically:</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- Whether the problem = definition is sound and the gap is genuinely unaddressed by existing = models</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- Whether the five = conformance requirements in Appendix B are technically = sufficient</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- Whether the threat model = in the reference spec correctly characterizes the attack = surface</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica"><span = class=3D"Apple-converted-space"> </span>- Whether this warrants a = dedicated BOF or fits within an existing WG charter</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; = min-height: 14.0px"><br></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">Mohamad Khalil = Yossif</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px Helvetica">Yuthent</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px = Helvetica">[email protected]</font></p> <p style=3D"margin: 0.0px 0.0px 0.0px 0.0px"><font face=3D"Helvetica" = size=3D"3" style=3D"font: 12.0px = Helvetica">https://yuthent.com/psea</font></p> </div><br><br><div> <table dir=3D"ltr" cellpadding=3D"0" cellspacing=3D"0" border=3D"0" = style=3D"direction: ltr !important; unicode-bidi: embed; font-family: = Arial, sans-serif; font-size: 14px; color: #000000; max-width: 600px; = width: 100%; border-collapse: collapse; text-align: left;"> <tbody> <tr> <td style=3D"padding: 10px 0; text-align: left;"> <table dir=3D"ltr" cellpadding=3D"0" cellspacing=3D"0" = border=3D"0" width=3D"100%" style=3D"direction: ltr !important;"> <tbody><tr> <td valign=3D"middle" style=3D"font-family: = Arial, sans-serif; text-align: left;"> <table dir=3D"ltr" cellpadding=3D"0" = cellspacing=3D"0" border=3D"0" style=3D"direction: ltr !important;"> <tbody><tr> <td style=3D"padding-right: 15px; = text-align: left;"> <img = src=3D"https://yuthent.com/public/assets/profile.jpg" width=3D"60" = height=3D"60" alt=3D"Mohamad Khalil Yossif" style=3D"display: block; = border-radius: 50%; width: 60px; height: 60px; border: 0;"> </td> <td style=3D"font-family: Arial, = sans-serif; line-height: 1.2; text-align: left;"> <div style=3D"font-size: 18px; = font-weight: bold; color: #002b5c;">Mohamad Khalil Yossif</div> <div style=3D"font-size: 13px; = color: #333333; margin-top: 2px;">CEO =E2=80=93 Yuthent</div> <div style=3D"font-size: 11px; = color: #777777; margin-top: 2px;">Founder =E2=80=93 SwiftCrew, MK = Digital, MK Electronics</div> </td> </tr> </tbody></table> </td> <td align=3D"right" valign=3D"middle" = style=3D"text-align: right;"> <img = src=3D"https://yuthent.com/assets/logo.png" width=3D"90" height=3D"90" = alt=3D"Yuthent Logo" style=3D"display: inline-block; width: 90px; = height: 90px; border: 0;"> </td> </tr> </tbody></table> </td> </tr> <tr> <td style=3D"border-top: 1px solid #d9d9d9; font-size: 1px; = line-height: 1px;" height=3D"1"> </td> </tr> <tr> <td style=3D"padding: 10px 0; text-align: left;"> <table dir=3D"ltr" cellpadding=3D"0" cellspacing=3D"0" = border=3D"0" width=3D"100%" style=3D"direction: ltr !important;"> <tbody><tr> <td style=3D"font-family: Arial, sans-serif; = font-size: 13px; color: #333333; line-height: 1.5; text-align: left;"> <strong>T:</strong> <a = href=3D"tel:+972509311103" style=3D"color: #002b5c; text-decoration: = none;">+972 50-931-1103</a><br> <strong>E:</strong> <a = href=3D"mailto:[email protected]" style=3D"color: #002b5c; = text-decoration: none;">[email protected]</a><br> <strong>W:</strong> <a = href=3D"https://yuthent.com" style=3D"color: #002b5c; text-decoration: = none;">yuthent.com</a> </td> <td align=3D"right" valign=3D"middle" = style=3D"text-align: right;"> <a = href=3D"https://www.linkedin.com/in/mohamad-khalil-yossif-4b9781163/" = style=3D"text-decoration: none;"> <img = src=3D"https://cdn-icons-png.flaticon.com/512/174/174857.png" width=3D"24"= height=3D"24" alt=3D"LinkedIn" style=3D"border-radius: 4px; border: = 0;"> </a> </td> </tr> </tbody></table> </td> </tr> <tr> <td style=3D"border-top: 1px solid #d9d9d9; font-size: 1px; = line-height: 1px;" height=3D"1"> </td> </tr> <tr> <td style=3D"padding-top: 10px; text-align: left;"> <a href=3D"https://yuthent.com" style=3D"text-decoration: = none;"> <img = src=3D"https://yuthent.com/public/assets/banner.jpg" width=3D"600" = alt=3D"Yuthent =E2=80=93 Verify the Human" style=3D"display: block; = width: 100%; max-width: 600px; border: 0;"> </a> </td> </tr> <tr> <td style=3D"padding-top: 10px; font-family: Arial, = sans-serif; font-size: 10px; color: #888888; line-height: 1.4; = text-align: left;"> This email may contain confidential or sensitive = information. If you are not the intended recipient, any review, use, = disclosure, distribution, or copying is prohibited. If you received this = message in error, please delete it immediately. </td> </tr> </tbody> </table> </div> <br></body></html>= --Apple-Mail=_8DD6EFF6-9B85-4B2A-8CC3-99DE2AD64F60-- --===============2141730172632145260== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2FhZyBtYWls aW5nIGxpc3QgLS0gc2FhZ0BpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IHNhYWctbGVhdmVAaWV0Zi5vcmcK --===============2141730172632145260==--