Depending on the use cases covered, there can be additional
requirements. An exemplary subset is illustrated in this section.
Here starts to talk about “additional requirements”, but I wonder there is no other places in this draft talking about requirement, so what are the basic requirements?
Perhaps we should introduce a dedicated section "(Basic) Requirements", describing basic requirements, such as:
"Integrity": The information provided by the Attester MUST be integral. This may be achieved by means of a digital signature over the attestation evidence.
"(Attester) Authentication": The information provided by the Attester MUST be authentic. The Attester should authenticate itself to the Verifier. This may be an implicit authentication by means of a digital signature over the Attestation Evidence, which does not require additional protocol steps.
Based on https://mailarchive.ietf.org/arch/msg/rats/okJriJPpapmZgeOfjbVGVP57bQk/
Here starts to talk about “additional requirements”, but I wonder there is no other places in this draft talking about requirement, so what are the basic requirements?