14:48:17 RRSAgent has joined #prov-xg 14:48:17 logging to http://www.w3.org/2010/05/07-prov-xg-irc 14:48:19 RRSAgent, make logs world 14:48:19 Zakim has joined #prov-xg 14:48:21 Zakim, this will be 98765 14:48:21 ok, trackbot; I see INC_PROVXG()11:00AM scheduled to start in 12 minutes 14:48:22 Meeting: Provenance Incubator Group Teleconference 14:48:22 Date: 07 May 2010 14:48:50 Zakim, this will be inc_provxg 14:48:50 ok, olaf; I see INC_PROVXG()11:00AM scheduled to start in 12 minutes 14:51:59 SamCoppens has joined #prov-xg 14:52:00 Agenda: http://lists.w3.org/Archives/Public/public-xg-prov/2010May/0001.html 14:52:19 chair: Yolanda Gil 14:52:30 Scribe: Olaf Hartig 14:52:38 ScribeNick: olaf 14:52:50 rrsagent, make logs public 14:53:11 raphael has joined #prov-xg 14:54:34 ivan has joined #prov-xg 14:54:40 pgroth has joined #prov-xg 14:55:10 hi ivan 14:55:32 Irini has joined #prov-xg 14:56:03 pmissier has joined #prov-xg 14:56:23 INC_PROVXG()11:00AM has now started 14:56:30 +??P0 14:56:48 + +1.310.560.aaaa 14:57:06 +??P2 14:57:59 Yolanda has joined #prov-xg 14:58:23 thank you Olaf for scribing! 14:58:28 smiles has joined #prov-xg 14:58:34 +??P7 14:58:35 + +49.308.937.aabb 14:58:45 zakim, who is on the phone? 14:58:45 On the phone I see ??P0, +1.310.560.aaaa, ??P2, ??P7, +49.308.937.aabb 14:58:53 afreitas has joined #prov-xg 14:59:00 michaelp has joined #prov-xg 14:59:00 Zakim, ?P2 is pgroth 14:59:00 sorry, pgroth, I do not recognize a party named '?P2' 14:59:07 Zakim, ??P2 is pgroth 14:59:07 +pgroth; got it 14:59:09 +??P3 14:59:14 + +30281039aacc 14:59:15 zakim, +1.310.560.aaaa is really me 14:59:15 +Yolanda; got it 14:59:17 + +1.614.764.aadd 14:59:29 + +49.300.aaee 14:59:46 Zakim,+30281039aacc is Irini 14:59:46 +??P9 14:59:46 +Irini; got it 14:59:52 zakim, aabb is olaf 14:59:52 +olaf; got it 14:59:59 zakim, ??P9 is really me 14:59:59 +smiles; got it 15:00:03 zakim, dial ivan-voip 15:00:03 ok, ivan; the call is being made 15:00:04 +Ivan 15:00:18 +??P12 15:00:21 zakim, ??P0 is SamCoppens 15:00:21 +SamCoppens; got it 15:00:33 -??P7 15:00:38 zakim, ??P1 is pmissier 15:00:38 +pmissier; got it 15:00:41 + +1.619.223.aaff 15:00:50 +??P5 15:01:02 jcheney has joined #prov-xg 15:01:09 JimM has joined #prov-xg 15:01:23 zakim, ??P12 is pmissier 15:01:23 I already had ??P12 as pmissier, pmissier 15:01:59 Mark has joined #prov-xg 15:02:03 Christine has joined #prov-xg 15:02:41 +??P13 15:02:44 did not find US tel # on site for today... 15:02:59 +??P15 15:03:14 Zakim, ??P13 is JimM 15:03:14 +JimM; got it 15:03:29 Yolanda: we want to learn more about security related issues in our use cases 15:03:30 +??P14 15:03:43 zakim, ??p15 is me 15:03:43 +jcheney; got it 15:03:51 Yolanda: new members ... 15:03:59 me 15:04:13 dgarijo: from UPM 15:04:32 yolanda - pls fwd the US bridge tel # - is not on site 15:04:49 dgarijo: student project on provenance 15:05:14 paulo: what provenance projects? 15:05:22 Bridge US: +1-617-761-6200 (Zakim) Bridge UK: +44.117.370.6152 Bridge FR: +33.4.89.06.34.99 Conference code: 98765 15:05:31 tlr has joined #prov-xg 15:05:35 zakim, call thomas-781 15:05:35 ok, tlr; the call is being made 15:05:36 +Thomas 15:05:45 zakim??? ? 15:06:06 + +1.518.608.aagg 15:06:36 DeborahMcG has joined #prov-xg 15:06:51 tlr: most of the time we will be going through list of sec.issues in the use cases 15:07:21 srry zakim...518-608-2244 does not work 15:08:06 this is mark sartor 15:08:22 tlr: associating message with identity 15:08:34 Mark: were you able to get on the phone? 15:08:48 no...do not have correct US bridge # 15:08:54 tlr: ivan's signature assoc. with message -> conclude message was signed by ivan 15:09:09 +1-617-761-6200 then conference code 98765 15:09:41 + +1.609.936.aahh 15:09:47 ok, am in.... thx 15:10:46 tlr: complicated about RDF: mixing data 15:11:11 tlr: what of these piece are reliable? 15:11:23 aahh...Mark 15:11:38 tlr: early work by J.Carroll 15:11:55 tlr: efficient canonicalization 15:12:10 tlr: only for a subset of RD graphs 15:12:40 tlr: blank nodes are a big issues 15:13:14 tlr: signatures give useful additional information about the data 15:13:54 tlr: what annotations can be made to graphs and subgraphs? 15:15:21 tlr: discussion ... 15:15:38 how about the overhead metadata (size and BW issue) related to this? what portion of the original data size.. 15:15:55 Yolanda: can one be reliably rely on having a signature forever? 15:16:35 tlr: associating signature to everything not useful 15:16:40 this won't scale 15:16:49 s/signature/public key/ 15:17:07 what about backing out problems...e.g., when we find out that the provenance was incorrect/bad (bad character...) 15:17:12 cert.authority is a 3rd party I trust 15:18:15 call this transferred provenance..perhaps we can use this as a secondary level 15:18:18 tlr: relying on another party to verify the binding between the key and the party assoc. with it 15:18:34 paul: i have to step out for a min, can you take on? 15:18:55 tlr: CAs allow for hierarichal structures 15:19:04 my view is that we assign provenance to data, and to relationships (which may affect the data); should handle differently? 15:19:21 tlr: hence only a small amount of authorities required 15:19:35 sure 15:20:06 need to assign levels of trust...i trust "person" 50%... 15:20:33 tlr: issues: don't trust "old" key 15:21:01 tlr: ... based on outdated algorithms 15:21:40 time may change things in relationships between entities (thereby trust); how do we acccount for this 15:22:14 q+ 15:22:14 any questions? 15:22:46 +1 to that 15:23:35 JimM: comment: electr.signatures relevant for records also as a timestamp 15:23:55 JimM: sign series of pages - hierarchy of signings 15:25:40 JimM: learning from attacks on electronic records for RDF 15:26:50 tlr: how express signature semantics ? requires work 15:27:11 q+ 15:28:22 tlr: library community has worked on these issues 15:28:35 JimM: difference with RDF is OWA 15:29:05 q- 15:29:11 JimM: RDF has not a hierarchy that can be facilitated 15:29:37 smiles: complication with provenance .. 15:30:35 smiles: experiment data cannot always be signed 15:30:49 smiles: b/c the potential signer is not available anymore 15:31:22 smiles: experiment results are based on lots of input 15:31:25 q+ 15:31:40 smiles: only some of which are relevant (for signing / provenance) 15:32:06 tlr: make statement on your own data - the data you have available 15:32:14 q+ 15:32:39 tlr: don't rely on signatures of others 15:33:19 tlr: what does is the semantics of the provenance metadata - what does it mean? (signatures are just a tool) 15:34:31 tlr: sign a summary statement instead of the whole data 15:35:18 I think it is always straight forward to have a third party sign subsets if the originator signs the'whole thing' - 15:35:36 jimM, right -- if the consumer trusts that third party ;-) 15:35:37 I read Newton's notebook and he said "F=ma" 15:35:41 yep 15:36:01 Mark: once we find signatures and have a trail of provenance - what if the signature sources are gone? 15:36:30 tlr: that's an issue 15:36:51 tlr: if the priv.key is public - everybody could have created the signatue 15:37:11 i'm back paul, tnx 15:37:13 only the public ey is needed to verify sigs, so the private key could be lost w/o causing trouble 15:38:04 tlr: be prepared for these possibilities if you want reliable provenance information 15:38:31 ack smiles 15:38:34 great 15:38:36 ack mark 15:38:36 It can get lost without causing trouble. It can't be disclosed without causing trouble. ;-) 15:40:13 that's why we need provenance, no? 15:40:25 +1 :-) 15:41:18 tlr: to trust provenance statements a security system is required 15:41:49 tlr: that system must be more complex 15:41:57 s/must/will/ 15:42:49 identity of what? 15:42:59 person or the thing being signed? 15:43:09 person 15:43:12 pgroth: some sort of identity other than using signature 15:44:01 signatures don't eally identify a person - it is their posession of something (key material in this case) that is the ID part 15:44:11 tlr: other measures are possible 15:44:18 signature is the way to bind that ID to this purpose applied to those bits 15:44:31 tlr: but signature provides a binding that an attacker cannot game with 15:44:47 for the latter purpose, there aren't many good options. 15:45:12 For ID, you can actually combine user/password, cryptocard, etc. with signatures to make managing them 'easier' 15:45:22 i guess then openid has this on the end 15:46:25 JimM: signature is a binding mechanism - not aware of other good mechanisms 15:48:30 tlr: openId let's me proof to another Website that I have access/conrol to another Web site 15:48:47 thanks! 15:49:22 JimM: similar to grid authority mechanism 15:50:16 Yolanda: Thomas please go through the use cases 15:50:19 http://www.w3.org/2005/Incubator/prov/wiki/Security_issues_in_provenance_use_cases 15:50:48 tlr: review? or discussion? 15:50:57 Yolanda: 1st use case 15:51:24 Yolanda: anonymized statements 15:52:19 Shiboleth - an examle of an authority that will sign a statement about your qualifications w/o giving your name/all info known about you 15:53:01 tlr: hash a string 15:53:08 attach that hashed string to the message 15:53:20 if someone wants you proof ownership 15:53:31 tlr: show the string 15:55:31 tlr: there is cryptography mechanisms that let's you do this 15:57:03 Yolanda: is a notarization service differnt from ... ? 15:58:34 tlr: these services may publish hashes of signatures and attach these to other signatures 15:58:44 tlr: so that the chain cannot be broken easily 15:58:56 q? 15:59:13 nope 15:59:16 that's from before 16:00:03 DeborahMcG has joined #prov-xg 16:00:27 -??P5 16:00:56 Yolanda: how to handle the issues that are raised? 16:02:51 -raphael 16:03:00 -Yolanda 16:03:00 zakim, drop me 16:03:01 Ivan is being disconnected 16:03:01 -pmissier 16:03:01 -Ivan 16:03:02 -Thomas 16:03:02 -??P14 16:03:04 -smiles 16:03:04 jcheney has left #prov-xg 16:03:05 -JimM 16:03:07 -pgroth 16:03:07 ivan has left #prov-xg 16:03:09 - +1.609.936.aahh 16:03:11 - +1.619.223.aaff 16:03:13 -michaelp 16:03:15 -Irini 16:03:17 - +1.518.608.aagg 16:03:19 -??P3 16:03:21 -olaf 16:03:23 -jcheney 16:03:25 -SamCoppens 16:03:27 INC_PROVXG()11:00AM has ended 16:03:29 Attendees were +49.308.937.aabb, pgroth, Yolanda, +49.300.aaee, raphael, Irini, olaf, smiles, Ivan, michaelp, SamCoppens, pmissier, +1.619.223.aaff, JimM, jcheney, Thomas, 16:03:32 ... +1.518.608.aagg, +1.609.936.aahh 16:04:34 rrsagent, set log public 16:04:45 rrsagent, draft minutes 16:04:45 I have made the request to generate http://www.w3.org/2010/05/07-prov-xg-minutes.html olaf 16:04:58 trackbot, end telcon 16:04:58 Zakim, list attendees 16:04:58 sorry, trackbot, I don't know what conference this is 16:04:59 RRSAgent, please draft minutes 16:04:59 I have made the request to generate http://www.w3.org/2010/05/07-prov-xg-minutes.html trackbot 16:05:00 RRSAgent, bye 16:05:00 I see no action items