Skip to main content

Privacy Preserving Verifiable Geofencing with Residency Proofs for Sovereign Workloads
draft-lkspa-wimse-verifiable-geo-fence-04

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors Ramki Krishnan , Ned Smith , Diego Lopez , A Prasad , Srinivasa Addepalli
Last updated 2026-03-01
Replaced by draft-lkspa-rats-verifiable-geo-fence
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-lkspa-rats-verifiable-geo-fence
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

Modern cloud and distributed computing rely heavily on software-only identities and bearer tokens that are easily stolen, replayed, or used from unauthorized locations. Furthermore, traditional methods of location verification - such as IP-address-based geolocation - are easily spoofed via VPNs or proxies and significantly compromise infrastructure security and privacy for *Sovereign Workloads* and high-assurance environments. This document defines a *High-Assurance Profile* designed to solve these challenges through hardware-rooted cryptographic verifiability. A host machine runs a workload identity agent for managing the workload identities on that platform. This proposal replaces implicit trust and spoofable indicators with cryptographically verifiable hardware-rooted evidence of integrity and location for this agent. Critically, this framework prioritizes *Location Privacy* by utilizing Zero-Knowledge Proofs (ZKP), allowing a workload to prove it is within a compliant "Sovereign Zone" without disclosing precise coordinates that could be used for tracking or exploitation. By binding software identities to persistent silicon identities and verified physical residency, this solution establishes a "Silicon-to- Workload" chain of trust. It ensures that sensitive operations are only performed by authorized workloads running on untampered hardware in cryptographically verified, privacy-preserving geographic boundaries, fulfilling the high-assurance requirements of the *WIMSE Architecture* [[I-D.ietf-wimse-architecture]].

Authors

Ramki Krishnan
Ned Smith
Diego Lopez
A Prasad
Srinivasa Addepalli

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)