Delegated Authenticated Authorization Framework (DCAF)
draft-gerdes-ace-dcaf-authorize Stefanie Gerdes, Olaf Bergmann, Carsten Bormann {gerdes | bergmann | cabo} @tzi.org IETF-94, ACE Meeting, 2015-11-02
1 / 27
Delegated Authenticated Authorization Framework (DCAF) - - PowerPoint PPT Presentation
Delegated Authenticated Authorization Framework (DCAF) draft-gerdes-ace-dcaf-authorize Stefanie Gerdes, Olaf Bergmann, Carsten Bormann { gerdes | bergmann | cabo } @tzi.org IETF-94, ACE Meeting, 2015-11-02 1 / 27 Review Comments Renzo:
1 / 27
◮ Improved readability. ◮ Removed inconsistencies. ◮ Clarified definitions of CBOR keys. ◮ Clarified handling of Ticket Request Messages. ◮ Improved description of Nonces.
◮ Also support COSE. ◮ Address Server-Initiated Token Request (“Pull”). ◮ Adress piggy-backed protected content in SAM Information
◮ Use a resource to store tokens (DCAF-COSE). ◮ Bind an authorization token to the security context between C
2 / 27
3 / 27
4 / 27
5 / 27
6 / 27
7 / 27
8 / 27
9 / 27
10 / 27
11 / 27
12 / 27
13 / 27
14 / 27
15 / 27
16 / 27
17 / 27
18 / 27
19 / 27
20 / 27
21 / 27
22 / 27
23 / 27
24 / 27
25 / 27
◮ Opaque for the client, no semantic restrictions ◮ mandatory -> good interoperability ◮ All known DTLS libraries pass it to the application to
◮ Client and server must support this extension. ◮ Needs to define a new SupplementalDataType or a new
◮ Derivation of master-secret from supplemental data is not
26 / 27
27 / 27