Markdown Version | Transcript | Session Recording | Session Materials
SPICE
Summary
The SPICE Working Group met at IETF 126 to discuss the group's charter scope, the registration path for Global Unique Enterprise (GLUE) Identifiers, updates on the Selective Disclosure CBOR Web Token (SD-CWT) specification, the progression of the OpenID Connect claims registration, and the potential adoption of the SPICE Architecture draft. The agenda was adjusted at the start of the meeting to address the charter scope first to accommodate Area Director Roman Danyliw's schedule.
Key Discussion Points
1. Charter Discussion
Presenter: Heather Flanagan
Slides: Charter Discussion
The working group discussed the ongoing block on the SPICE charter due to concerns regarding the scope of "data structures useful for commerce and trade." To resolve this, proposed text was introduced to narrow the scope by focusing on adapting existing claim values or claim names consistent with the conventions of COSE/JOSE and ensuring automatic machine conversion capabilities.
- Discussion:
- Michael Richardson queried the boundaries of the term "adapt," asking whether it strictly referred to machine-readable format changes (e.g., date formats). Rohan Mahy clarified that the intent is to maintain semantic consistency (such as converting shipping manifests or waybills into a format consistent with CBOR Web Tokens) without redefining the underlying semantics established by external organizations.
- Roman Danyliw questioned whether the working group is intended to act as a general claims registration hub for other industries' verticals or if the scope is narrowly bounded.
- Orie Steele and Michael B. Jones noted that the group should only adopt work where sufficient working group expertise exists. Orie Steele stated in the chat that "adapt" means making claim values or names consistent with COSE/JOSE conventions and expressed comfort with a narrow charter listing specific drafts, rechartering later as necessary.
- Martin Vigoureux asked if the working group would prefer to explicitly list active drafts in the charter rather than using general text. Henk Birkholz and Brent Sundell voiced support for more general text to allow future work to fit in without the friction of frequent rechartering.
- Poll:
The chairs ran a poll to gauge consensus on the charter language:
- Would you like to see the general text, as proposed (yes) or do you think that would be unacceptable (no; because you want a specific list of drafts instead)?
Result: yes: 26, no: 0, no_opinion: 11 (total: 57)
- Would you like to see the general text, as proposed (yes) or do you think that would be unacceptable (no; because you want a specific list of drafts instead)?
2. Global Unique Enterprise (GLUE) Identifiers
Presenter: Brent Sundell
Slides: GLobal Unique Enterprise (GLUE) Identifiers
Brent Sundell presented the background and status of the GLUE specification. The draft aims to define a namespace prefix enabling the lookup of metadata for organizational identifiers. After passing Working Group Last Call (WGLC), the draft encountered issues during IESG review because the URN designated experts determined that GLUE does not satisfy the strict persistence and uniqueness properties required of a URN scheme (as identifiers can sometimes be reassigned or authorities can dissolve).
- Discussion:
- Ted Hardie (invited to provide expertise on URI/URN registrations) explained that URNs require absolute uniqueness over time with no reassignment. He noted that registering GLUE as a URI scheme is structurally viable but cautioned that a centralized registry not managed directly by the issuing authorities risks falling out of sync or suffering from identifier collisions (such as the abbreviation "IRS" denoting tax authorities in both the US and Portugal).
- Phillip Hallam-Baker and Pamela Dingle argued that absolute uniqueness over time is functionally impossible in the real world (e.g., business acquisitions or domain changes like pets.com). They asserted that having a standardized, distinguishable identifier is better than none.
- Ted Hardie suggested that if the working group pursues a URI scheme, the syntax should be updated to allow full URI capabilities, including percent-encoding, to support internationalization and non-ASCII characters. Alternatively, the registry could use IANA-assigned serial numbers to maintain ASCII compliance.
- Michael B. Jones and Brent Sundell requested to keep moving forward with registering GLUE as a URI scheme using the current draft structure.
- No objections were raised by the working group against proceeding with the URI scheme registration.
3. Update on SD-CWT
Presenter: Rohan Mahy
Slides: Update on SD-CWT
Rohan Mahy provided an update on the SD-CWT specification. WGLC has concluded, and there are currently no open issues in the GitHub repository.
- Key Updates:
- An interop test rig was developed during the IETF 126 Hackathon, successfully passing tests with an implementation by Beltrum. Orie Steele committed to providing a second implementation to verify cross-compatibility.
- Normative changes since version -07 include:
- Added validation guidelines for nested claims.
- Added key context in AEAD encrypted disclosures.
- Clarified the nonce length of the AAD (and that the AAD is empty).
- Clarified how CBOR tags are treated with respect to nesting.
4. OpenID Connect Standard Claims Registration for CBOR Web Tokens
Presenter: Michael B. Jones
Slides: OpenID Connect Standard Claims Registration for CBOR Web Tokens
Draft Context: draft-ietf-spice-oidc-cwt
Michael B. Jones reported that draft-ietf-spice-oidc-cwt is complete, having resolved shepherd reviews in March and finished WGLC late last year. The next step is for the Area Director to perform the write-up and progress the draft to IETF Last Call.
5. SPICE Architecture
Presenter: Brent Sundell
Slides: SPICE Architecture IETF 126
Brent Sundell presented the structural outline for the proposed SPICE Architecture document, seeking feedback on its components (terminology, actor descriptions, and flow diagrams) and requesting working group adoption.
- Discussion:
- Nicola Twerit asked whether the draft would define explicit properties, guarantees, and security assumptions for actors. Brent confirmed that it would.
- Nick Doty emphasized the need to describe privacy and security considerations and the differences between presentation flows (e.g., native app wallets versus web-based backends).
- Henk Birkholz suggested explicitly documenting standard flow scenarios, such as the passport model and background check model.
- Martin Vigoureux pointed out a procedural issue: the draft was incorrectly uploaded directly with an IETF WG name prefix rather than as an individual submission, and it has since expired.
6. Any Other Business (AOB)
Phillip Hallam-Baker introduced a proposal to use DNS domain names as user identifiers for federated authentication, referencing Blue Sky's implementation.
- Discussion:
- Orie Steele pointed out that the current SPICE charter explicitly excludes general-purpose key discovery from its scope.
- Michael B. Jones and Justin Richer noted historical lessons from OpenID 2.0, emphasizing that end-users generally resist treating themselves as URIs or domain names.
- The chairs concluded that the topic is out of scope for SPICE but suggested it could be a suitable topic for an IETF side meeting.
Decisions and Action Items
- Charter: The chairs will submit a Pull Request (PR) containing the general scoping text approved by the working group in the session poll.
- GLUE Identifiers: The authors will consult with IANA staff (Amanda and team) regarding the registry design, with the intent of progressing the draft as a URI scheme registration.
- draft-ietf-spice-oidc-cwt: Co-chair Christopher Inacio to transition the document status in the Data Tracker to initiate the AD write-up.
- Architecture Draft: Brent Sundell to resubmit the architecture document under an individual draft name (e.g., draft-zundel-spice-architecture) so the WG can formally initiate an adoption call on the mailing list.
Next Steps
- SD-CWT: Complete interoperability testing among the three target implementations (Rohan Mahy, Beltrum, and Orie Steele).
- Architecture: Initiate a formal call for working group adoption on the mailing list once the individual draft is uploaded.