[saag] Re: Proposal for Discussion: The Secure Internet – Embedding Trust into the Protocol Layer
Eric Rescorla <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CABcZeBOxmkZi5VUPhGGEma1Kc=pVQ1NxV1Htz0=yS-o7oZkXzA@mail.gmail.com> |
On Mon, Aug 18, 2025 at 7:07 AM Thi Nguyen-Huu <[email protected]> wrote: > Dear SAAG members, > > I’m writing to follow up on my earlier outreach regarding *The Secure > Internet* architecture. After further reflection and community feedback, > I believe this initiative is best introduced through a *BOF (Birds of a > Feather)* session rather than a standalone Internet-Draft. > Typically the Internet-Draft is the basis on which the community determines (1) whether a BOF is warranted and (2) whether the WG should be chartered. At the end of the day, the IETF publishes specifications as RFCs, and so the I-D serves as some indication of what specification will eventually be published. > > The *Secure Internet (SI)* enables what legacy architectures deemed > infeasible — and what users have long dreamed of: > > - *No user action*: No passwords, no MFA, no friction. > - *Protocol-native protection*: Cryptographic defense against session > hijacking and adversary-in-the-middle (AitM) attacks. > > > > SI proposes a new trust model for the Internet — one that replaces static > credentials and certificate-based authentication with *policy-bound > cryptographic keys anchored in hardware*, available only when *organizational > trust conditions* are met. This enables *non-interactive, mutual > authentication* via mTLS without certificates, transforming how endpoints > and services establish trust. > > Given the architectural scope — spanning transport security, endpoint > identity, and trust enforcement — SI does not fit neatly into existing > working groups. It introduces foundational concepts such as: > > - *Live Key*: A dynamic identity signal tied to verified user presence > and device integrity. > - *LIM/TIM (The Identity Machine)*: A system that governs Live Key > availability based on policy. > - *MagicEndpoint*: A trusted channel between endpoint and IdP, > enabling continuous identity signaling. > > I believe a BOF is the right venue to: > > - Explore the feasibility of a new working group > - Discuss technical foundations and deployment models > - Align with existing standards (TLS, FIDO2, RATS) > - Define a roadmap for multiple RFCs under the Secure Internet umbrella > > This may or may not be true, but nevertheless, an I-D is the right place to lay out this argument. -Ekr _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]