[TLS] Request for Technical Review and IETF Venue Guidance: Zero Trust Transport Layer Security (ZTLS)

sripad karthik <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <CAC4a+jBOUR=HThm1q4_62Q8R58not8ANHeeRZObp0B1o4YrVMw@mail.gmail.com>
Dear TLS Working Group Chairs and Participants,

I am writing to introduce my proposed Internet Draft, *“Zero Trust
Transport Layer Security (ZTLS),"* and to seek technical feedback regarding
its applicability and potential discussion within the IETF.

ZTLS proposes a security architecture at the transport communication layer
that extends the traditional authenticated-session model with continuous
identity validation, device and network context verification, evolving
cryptographic state, session-level trust evaluation, and secure recovery
mechanisms.

The objective is to investigate whether transport security can incorporate
continuous Zero Trust verification rather than relying primarily on
authentication performed during initial session establishment.

I am the sole author and contributor of this work.

I would particularly appreciate feedback regarding:

   1. Whether the ZTLS problem statement is relevant to the scope of the
   TLS Working Group.
   2. Whether the proposed mechanisms could be considered as a TLS
   extension, a complementary protocol, or a separate transport-security
   protocol.
   3. Whether existing TLS 1.3 mechanisms already provide equivalent
   functionality.
   4. Whether the proposal overlaps with existing IETF work.
   5. What security analysis, formal specification, interoperability
   testing, or implementation experience would be required for further
   consideration.

I would greatly appreciate guidance from the working group regarding the
appropriate technical direction and IETF venue for this work.

Thank you for your time and consideration.

Best regards,
Thanks and Regards
Sripad Rama Hebbar
https://www.linkedin.com/in/sripadrh/

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.