Date: Wed Mar 07 2007 - 16:55:18 EST

Date: Wed Mar 07 2007 - 16:55:18 EST

Gee - I got bagged out for suggesting that the dereferencing mechanism obviated the concern about temporal and identity integrity for location information quite some time ago. Must be OK now. Dereferencing does remove the concerns with respect to knowing that the location really does apply now (temporal) and that it is applicable to a specific end-device (identity) - which addresses the main replay concerns. The other component of location dependability is the "source identity". That is, that the LIS operator is a recognised and trusted access operator. This can be achieved by some independent certificate exchange process - or it could be achieved just by having the dereferencer request a signed location anyway; that would be the same process for the LIS on the northbound and southbound interfaces. Cheers, Martin ________________________________ From: Andrew Newton [] Sent: Thursday, 8 March 2007 5:39 AM To: Brian Rosen Cc:; 'Marc Linsner' Subject: Re: [Geopriv]WGLCondraft-ietf-geopriv-l7-lcp-ps-00(PIDF-LOdigitalsignatures) On Mar 7, 2007, at 1:32 PM, Brian Rosen wrote: I'd guess we would be better off just using a location reference though. That's an interesting thought. The channel security of the dereference means that you don't have to sign the location to trust it. -andy

