ietf-rats-wg / architecture

RATS Architecture
Other
17 stars 10 forks source link

Protect confidentiality of conceptual messages that might contain PII #375

Closed henkbirkholz closed 2 years ago

henkbirkholz commented 2 years ago

In #369 we now explicitly say that "confidentiality protection of Evidence and Attestation Results" is required in some form.

In #370 we now explicitly say that "Many Claims in Evidence, many Claims in Attestation Results, and Appraisal Policies potentially contain Personally Identifying Information (PII)".

See my point already? 😊 Maybe protection of Appraisal Policies is "technically out-of-scope", but expressing this side by side makes a curious impression to me.