is that your best ?16 Apr 2021 23:12
average at best but to lay to rest an earlier post. As you have a poor take on Andrbea's research and knowledge I took the liberty of running the attached past my two tech mates and they agreed with what was posted and one friend even ran it past a more qualified tech mate of his who specializes more in this field. He agreed as well. So guess I put their knowledge above yours.Suggest anyone has doubts read the below :
Good find SW (post 928)
FIDO's proposed standard
It sounds even better now IMO ..... as the free-for-all 'no profit motive' argument of ellipses ..... is neatly sidestepped for the lifetime management part that KeyScaler would do (that part is 'out of scope' says FIDO)
see part 2.3.2.
"For example, a Management Agent may send a Public Key Cryptography Standards (PKCS#10) Certificate Signing Request (CSR) to the Management Service in a Device ServiceInfo key-value pair, which can use a certificate authority (CA) to provision a X.509 certificate, trusted by itself, and send that certificate back to the Management Agent in PKCS#7 format, all using an Owner ServiceInfo key-value pairs.
The flows of ServiceInfo information between the Owner and the Management Service, and between the Device and the Management Agent, are OUTSIDE THE SCOPE of this document."
/// (the keywords.. for DA .. are in capitals)///
quoting FIDO again:
"The following sections define these protocols
It is expected the βfinal stateβ protocol (BOTTOM RED ARROW in the diagram) may be a pre-existing protocol between a Management Agent and Management Service that exist INDEPENDENTLY of FIDO Device Onboard. FIDO Device Onboard serves to provide credentials rapidly and securely so that the pre-existing software is able to take over and operate as if it were manually configured. FIDO Device Onboard is not used further by the device or owner unless the owner wishes to re-provision the device, such as to effect another ownership transfer."
***
So DA can charge what it likes IMO ... (for use of its policy-driven Device Management Platform)
***
My take:
In this diagram Keyscaler is the Management Agent/Management Service
The old notations devised by Intel (Ownership Voucher + Rendezvous Service) are still in place.
Quoting FIDO again:
"3.4.6.5. Rendezvous Server Verification of the Ownership Voucher
The FIDO Device Onboard protocols do not supply the Rendezvous Server with a mechanism for determining the trust of the Ownership Voucher. It is desirable for the Rendezvous Server to be able to trust one or more of the keys in the Ownership Voucher. This implies using a back channel to supply public material to the Rendezvous Server by cooperating supply-chain entities.
These mechanisms are OUTSIDE THE SCOPE of this document."
Https://fidoalliance.org/specs/FDO/fido-device-onboard-v1.0-ps-20210323/fido-device-onboard-v1.0-ps-20210323.html
andrbea
2 Jul '20 - 16:32 - 208526
A current Intel web page has a video sho