JOSE Working Group @ IETF 116

630 - 800 UTC (1530 - 1700 local time)
Pacifico Yokohama: G316

Agenda

Admin and Agenda Bash (Chairs - 5 minutes)

Newly-reconsitited JOSE

First meeting after a BoF in Phladelphia IETF!

Charter review (Chairs - 10 minutes)

https://datatracker.ietf.org/wg/jose/about/

History of JOSE: what's been done and what that's lead to
- signing, encryption, etc.
- JSON Web tokens and other things that are adopted everywhere

New context: applications that want to preserves privacy
- existing structures don't support constructs that we need

Current charter recap

Chairs requested to review the charter and suggest milestones.

JSON Web Proof Drafts (Mike Jones - 30 minutes)

JSON Web Proofs
https://datatracker.ietf.org/doc/draft-jmiller-jose-json-proof-algorithms/

JSON Proof Algorithms
https://datatracker.ietf.org/doc/draft-jmiller-jose-json-proof-algorithms/

JSON Proof Token
https://datatracker.ietf.org/doc/draft-jmiller-jose-json-proof-token/

Background

BoF @ philadelphia meeting in July
- discussed json web proofs
- showed json-based container format for ZKP

Overview of the above three specs

JSON web proof algorithms:

Originally bord in OIDF SIOP WG, incubated in DIF applied crypto WG,
interest from W3C VC WG.

Design Consideratons

selective disclosure: multiple payloads, so that subset can be disclosed

unlinkability:
proof of knowledge: want to account for multiple algs like BBS,
ZkSNARKs, while also supporting currently available techniques like MAC.

working with cryptographers

Comparison of JWP and JWS

JWS has three parts: header, payload, signature

JWP: looks a lot the same!

if a payload is omitted (not disclosed), placeholder concurrent tildes

proposal: adopt jmiller drafts as starting points

Discussion

mike prorock: this is a good set of building blocks to start. Thanks
Jeremie for the slides.

mike jones: credits to CFRG for taking up algorithms for BBS

Orie: excited for new work, especially URL safe representation part of
it; and BBS and what it can do for privacy

Tobias: supports the works, also having worked on BBS

mike prorock: in addition to BBS, lots of work on the lattice side,
still early but looks real

Brent Z: support bringing in these work items; volunteering to help
write

Orie: comment to add to what mike P said; lattice proofs have different
hardness problem

Adoption (chairs)

chairs run poll, also humming: no opposed, strong in favor
will be circulated on the list for final confirmation

X.509 Certificate Extended Key Usage (EKU) for Javascript Object Signing and Encryption (Migault - 10 minutes)

https://datatracker.ietf.org/doc/draft-reddy-lamps-jose-eku/

document submitted for LAMPS

Way Ahead and AOB (Chairs - 5 minutes)

milestone defined today:

use-case doc

scope of the WG

tooling: GH?

virtual interims

No other AOB. meeting ajourned.