[saag] Re: Proposal for Discussion: The Secure Internet – Embedding Trust into the Protocol Layer
"StJohns, Michael" <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CANeU+ZAYJ11sSV=4LDr5z2hJgEkF2h_JPdA78RWKP0VQ5LnmWQ@mail.gmail.com> |
Hi Thi - I suggested submitting an ipr statement because the presentation of the idea seemed to imply some win magic ownership of some IPR. Glad to hear this is free and clear. Thanks - Mike On Wed, Aug 13, 2025 at 20:08 Thi Nguyen-Huu <[email protected]> wrote: > Thanks, Michael and Rich. > > > > Sorry we did not do this before. Please see if this is good. Thanks. > > --- > > > > IPR Holder: Thi Nguyen-Huu > > Document(s): Letter_Secure_Internet_IETF_W3C.docx (and any revisions) > > And attached the revised Letter_Secure_Internet_IETF_W3C_5.docx > > > > > > Patent Information: > > The IPR holder is not aware of any patent or patent application that > covers or may cover the technology described in the above-referenced > document. > > > > Additional Notes: > > This declaration is made in good faith in accordance with the IETF IPR > policy defined in RFC 8179. > > > > Submitted by: Thi Nguyen-Huu, CEO of WinMagic Corporation > > Date: 11 August 2025 > > > > Cheers > > > > *Thi Nguyen-Huu | *CEO > > > > Tel: +1 905.502.7000 x 3288 | Toll Free: 888.879.5879 > > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > [email protected] | www.winmagic.com > > > > *WinMagic Corp.* | 11-80 Galaxy Blvd. > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > > Toronto, ON > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > | > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > M9W 4Y8 | > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > Canada > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > | www.winmagic.com > > <http://www.facebook.com/WinMagicInc> <https://twitter.com/winmagic> > <http://www.linkedin.com/company/winmagic> > <https://www.winmagic.com/blog/> > > [image: A person holding a phone and typing on a computer AI-generated > content may be incorrect.] <https://winmagic.com/en/secure_internet/> > > > > *From:* StJohns, Michael <[email protected]> > *Sent:* Wednesday, August 13, 2025 1:06 PM > *To:* Thi Nguyen-Huu <[email protected]> > *Cc:* Paul Wouters <[email protected]>; [email protected]; Sergei Nikitin > <[email protected]> > *Subject:* Re: [saag] Re: Proposal for Discussion: The Secure Internet – > Embedding Trust into the Protocol Layer > > > > You don't often get email from [email protected]. Learn why this is > important <https://aka.ms/LearnAboutSenderIdentification> > > CAUTION:This email originated from outside of the organization. Do not > click links, open attachments or respond unless you recognize the sender > and know that the content is safe. > > > > Hi - it would be helpful if you could make an IPR declaration similar to > what the IETF uses for its documents, but by email. The amount of > encumbrance will play heavily into whether this gets any traction with the > IETF community. > > > > Thanks - Mike > > > > > > > > On Wed, Aug 13, 2025 at 09:56 Thi Nguyen-Huu <thi.nh= > [email protected]> wrote: > > Thank you, Paul. > > > > 1. I am replying and add [email protected]. I will resend to [email protected] > as well. Thanks. > > > > 2. Just a comment: our idea to eventually omit the certificate can be > an option for the future. It’s not essential for the Live Key and mTLS. > > > > > > Cheers > > > > *Thi Nguyen-Huu | *CEO > > > > Tel: +1 905.502.7000 x 3288 | Toll Free: 888.879.5879 > [email protected] > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g>| > www.winmagic.com > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+%0D%0A+Toronto,%0D%0A+ON+%0D%0A%7C+%0D%0AM9W+4Y8+%7C+%0D%0ACanada?entry=gmail&source=g> > > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+%0D%0A+Toronto,%0D%0A+ON+%0D%0A%7C+%0D%0AM9W+4Y8+%7C+%0D%0ACanada?entry=gmail&source=g> > > > > *WinMagic Corp.* | 11-80 Galaxy Blvd. > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > > Toronto, ON > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > | > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > M9W 4Y8 | > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > Canada > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,%0D%0A+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > | www.winmagic.com > > <http://www.facebook.com/WinMagicInc> <https://twitter.com/winmagic> > <http://www.linkedin.com/company/winmagic> > <https://www.winmagic.com/blog/> > > [image: A person holding a phone and typing on a computer AI-generated > content may be incorrect.] <https://winmagic.com/en/secure_internet/> > > > > *From:* Paul Wouters <[email protected]> > *Sent:* Tuesday, August 12, 2025 12:39 PM > *To:* Thi Nguyen-Huu <[email protected]> > *Subject:* Re: Proposal for Discussion: The Secure Internet – Embedding > Trust into the Protocol Layer > > > > You don't often get email from [email protected]. Learn why this is > important <https://aka.ms/LearnAboutSenderIdentification> > > CAUTION:This email originated from outside of the organization. Do not > click links, open attachments or respond unless you recognize the sender > and know that the content is safe. > > > > > > Hi Thi, > > > > The Security Area Directors were forwarded this email. > > > > Begin forwarded message: > > > > *From: *"Thi Nguyen-Huu via RT" <[email protected]> > > *Subject: Proposal for Discussion: The Secure Internet – Embedding Trust > into the Protocol Layer* > > *Date: *August 11, 2025 at 3:51:53 PM PDT > > > > > > *Subject:* Proposal for Discussion: The Secure Internet – Embedding Trust > into the Protocol Layer > > > > Dear IETF and W3C Working Group Members, > > > > I’m writing to propose a discussion around a new architectural model we > call *The Secure Internet*—a vision that reimagines how identity and > trust are established online by embedding them directly into the transport > layer. > > the appropriate venue to discuss such items would be the SAAG mailing list > of the IETF. > > > > At the core of this model is a cryptographic identity signal called the *Live > Key*, derived from the user presence, security posture and anchored in > TPM hardware. This signal is long-lived, non-exportable, and accessible > only when specific security conditions are met—such as active user’s OS > login, full disk encryption, and up-to-date system patches. These > conditions are *policy-defined*, allowing organizations to enforce > dynamic, context-aware trust requirements beyond simple user presence. > > Furthermore, the Live Key enables *mutual TLS (mTLS)* without requiring > client-side certificates. > > you will likely run into big resistance for the significant privacy risks > associated with this proposal. but as I said, the proper discussion venue > within the IETF for this would be the SAAG mailing list. > > > > Paul, on behalf of the SEC Area Directors > > > > > > > > > > Instead, the client registers its Live Key directly with the server, > similar to the FIDO model. This simplifies trust establishment, eliminates > the need for certificate authorities, and enables personalized, > cryptographically assured sessions. > > The Secure Internet aligns with the goals of both *TLS* and > *WebAuthn/FIDO2*: > > - It complements mTLS by enabling certificate-less client > authentication. > - It enhances FIDO2 and Passkeys by offering a transport-level trust > mechanism that can eliminate user interaction and additional policy-defined > signals check while maintaining strong assurance. > - It inherently satisfies and exceeds *NIST FAL3-level assurance* without > tokens, or channel binding. The architecture can eliminate the need for > federated authentication entirely. In this model, the identity provider > (IdP) evolves into a real-time, CA-like trust authority—capable of > informing the relying party (service provider) when a previously registered > public key is no longer trusted. > > *Importantly, this model does not require changes to existing standards—at > least not initially.* It builds on them, offering a new way to express > identity and trust natively within the protocol layer. In the future, > optional client certificates may be considered as part of evolving > standards. We believe this approach could be of interest to working groups > focused on TLS, OAuth, WebAuthn, and identity federation. > > We would welcome the opportunity to present this concept, share open > specifications, and explore how it might align with ongoing efforts across > both IETF and W3C. > > Thank you for your consideration. > > > > PS. The same text is in the attachment. And for more info on our website > please visit: https://winmagic.com/en/secure_internet/ > > > > Sincerely, > > > > *Thi Nguyen-Huu | *CEO > > > > Tel: +1 905.502.7000 x 3288 | Toll Free: 888.879.5879 > [email protected] > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g>| > www.winmagic.com > > > > *WinMagic Corp.* | 11-80 Galaxy Blvd. > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > > > <https://www.google.com/maps/search/80%0D%0A+Galaxy+Blvd.+%0D%0A+%0D%0A+Toronto,+ON+%0D%0A+%0D%0A%7C+%0D%0AM9W+4Y8+%7C+%0D%0ACanada?entry=gmail&source=g>Toronto, > ON > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > > <https://www.google.com/maps/search/80%0D%0A+Galaxy+Blvd.+%0D%0A+%0D%0A+Toronto,+ON+%0D%0A+%0D%0A%7C+%0D%0AM9W+4Y8+%7C+%0D%0ACanada?entry=gmail&source=g> > | > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > M9W 4Y8 | > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > Canada > <https://www.google.com/maps/search/80+Galaxy+Blvd.+%0D%0A+Toronto,+ON+%7C+M9W+4Y8+%7C+Canada?entry=gmail&source=g> > | www.winmagic.com > > <https://www.google.com/maps/search/80%0D%0A+Galaxy+Blvd.+%0D%0A+%0D%0A+Toronto,+ON+%0D%0A+%0D%0A%7C+%0D%0AM9W+4Y8+%7C+%0D%0ACanada?entry=gmail&source=g> > > > > > > > > > > > > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] > > _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
image006.png
(image/png, 2 KB) - not displayed
image005.png
(image/png, 222.4 KB) - not displayed
image010.png
(image/png, 217.3 KB) - not displayed
image002.png
(image/png, 1.3 KB) - not displayed
image007.png
(image/png, 1.9 KB) - not displayed
image004.png
(image/png, 1.4 KB) - not displayed
image003.png
(image/png, 1.4 KB) - not displayed
image001.png
(image/png, 1.4 KB) - not displayed
image008.png
(image/png, 2 KB) - not displayed
image009.png
(image/png, 2 KB) - not displayed