05:02:00 RRSAgent has joined #ldsec 05:02:00 logging to https://www.w3.org/2019/09/18-ldsec-irc 05:02:02 Zakim has joined #ldsec 05:02:13 Meeting: Linked Data Security 05:02:17 rrsagent, make logs public 05:02:23 rrsagent, make minutes 05:02:23 I have made the request to generate https://www.w3.org/2019/09/18-ldsec-minutes.html manu 05:06:21 rrsagent, draft minutes 05:06:21 I have made the request to generate https://www.w3.org/2019/09/18-ldsec-minutes.html manu 05:06:50 Chair: manu 05:06:57 present+ 05:06:59 rrsagent, draft minutes 05:06:59 I have made the request to generate https://www.w3.org/2019/09/18-ldsec-minutes.html manu 05:14:02 kiyoto has joined #ldsec 05:17:37 yoshiaki has joined #ldsec 05:28:41 yoshiaki has joined #ldsec 05:34:20 yoshiaki_ has joined #ldsec 05:34:59 yoshiaki_ has joined #ldsec 05:35:56 gkellogg has joined #ldsec 05:36:09 azaroth has joined #ldsec 05:36:19 present+ Rob_Sanderson 05:36:24 scribe+ 05:36:31 bigbluehat has joined #ldsec 05:36:33 present+ Gregg_Kellogg 05:36:41 present+ Benjamin_Young 05:36:42 deiu has joined #ldsec 05:36:47 JoeAndrieu has joined #ldsec 05:36:54 st has joined #ldsec 05:37:11 present+ Joe_Andrieu 05:37:19 present+ Andrei_Sambra 05:37:25 present+ manu 05:37:29 present+ ivan 05:37:38 present+ Ivan_Herman 05:37:38 Dudley has joined #ldsec 05:37:57 manu: Just a handful of slides. (link forthcoming) 05:38:00 present+ Dudley_Collinson 05:38:05 Franck has joined #ldsec 05:38:14 slides: https://docs.google.com/presentation/d/1dn4uotAHXgKIwrPW3dlPArB19NZzxUf_cOSQcSlxb2Y/edit 05:38:37 azaroth has joined #ldsec 05:39:16 … We’ll discuss LD security and whether to push forward at W3C. 05:39:37 … There have been a number of initiatives floating around for 7+ years (jcarroll 2003) 05:39:49 … Why now? 05:40:01 … C14N, proofs, signatures 05:40:24 tpk has joined #ldsec 05:40:26 … I’m co-inventor of VC, JSON-LD, Diigital Bazaar, … 05:40:56 … The VC spec will be a REC in about amonth, and specifies proofs using JWT and LD Signatures. 05:41:12 yoshiaki has joined #ldsec 05:41:15 … The concerns are that there’s no recommended specification of LD sigantures. 05:41:49 … The US Fed Govt through DHS has mandated the use of JSON-LD and VC and DIDs. They want an official standard for LD Sigs. 05:42:04 … (no supprize, but now it’s important). 05:42:11 … Also banks, healthcare, etc. 05:42:16 jc has joined #ldsec 05:42:29 … DID camp needs signatures too. 05:42:55 … Other groups have provenance use cases, graph equaility, etc. 05:43:00 … Also WoT needs signatures. 05:43:22 … (picture of stack) 05:43:28 yoshiaki_ has joined #ldsec 05:43:57 … At the bottom is RDF Dataset C14N, to ensure that different expressions result in the same hash. 05:44:32 … Above, LD Proofs. A digital signature is just one type of proof. (proof of work, stake, elapsed time, …) 05:44:55 … Above that is LD Signatures, and above that Cryptography standards 05:45:35 An example proof mechanism is Equihash which is not a digital proof. 05:46:24 … RDF C14N transforms N-Quads into a canonical serialization 05:46:59 jc_ has joined #ldsec 05:47:05 … There are two mathematical proofs, one by Aiden Hogan, and the most recent by Rachel Arnold and David Longley undergoing peer review. (Aiden’s has been peer reviewed). 05:47:53 ivan: The C14N of an RDF graph has been an open issue. jcarrol and Pat Hayes had an algorithm in 2002, but indicated that it was not complete (there were graphs for which it wouldn’t work). 05:48:14 … For a long time, nothing happened, because there was no proof. 05:48:54 … Aiden published a paper which was complete, and had an implementation (in Java). I implemented in JavaScript, but the paper is not REC quality. 05:49:32 … In parallel, dlongley came out with their algorithm, but it had no proof. manu and I have been discussing for a while. 05:49:38 jc has joined #ldsec 05:50:05 yoshiaki has joined #ldsec 05:50:30 … We expect a peer review of the associated paper, and we’ve discussed on how to put into a REC. Most RECs aren’t mathimatical, and W3C is not equiped to judge mathematics. But, with peer review, we feel we can publish such a REC. 05:50:51 arnod: two papers, are they the same? 05:51:42 ivan: I understand that the two papers are very close. Simple cases plus some esoteric casses. a WG would need to choose between them. 05:52:12 Dudley has joined #ldsec 05:52:24 q? 05:52:40 sander: you mentioned that W3C doesn’t have mathematical capability, but many members do have the expertise. 05:53:12 q+ 05:53:37 ivan: You need different worlds to work together, SemWeb/RDF is one thing, and Crypto people looking at RDF would be difficult to make happen. They’d have to deeply understand things like BNodes. 05:54:08 … Aiden is a mathematician with a SemWeb background, and the other is a combination of mathematician and engineer. 05:54:23 manu: We’re trying to find good review from other universities. 05:54:54 ivan: If we get close to the point where we need to get a charter, we will have to call out university members who’s opinion would be important. 05:55:16 tobias: W3C has said they would incubate? 05:56:06 ivan: For now, there’s an understanding in W3C is that if there is an “official” proof that says the algorithms are okay, that W3C would accept that as input, and we would not have to review. 05:56:28 … We would accept that the community of Crypto people have accepted it. 05:56:46 ack 05:57:05 NJ__ has joined #ldsec 05:57:07 jc has joined #ldsec 05:57:11 q? 05:57:15 ack deiu 05:57:22 yoshiaki has joined #ldsec 05:57:48 Scribe notes that discussion is that it’s not simply JSON-LD. 05:58:09 manu: Is there support to charter a group to handle these specs? 05:58:42 ivan: Need is not just for VC, there is a broad need for signed RDF data. 05:59:29 … We need to understand boundaries of the WG. Obviously, C14N is necessary. What else do we need? 05:59:39 q+ re dependent canonicalizations 05:59:52 q+ to note dependent canonicalizations 05:59:52 … If I compare to XML Sig, it has C14N, a vocabulary, and a further XML serialization. 06:00:07 … We may have to have a vocabulary to describe how to put the data back into LD. 06:00:14 yoshiaki has joined #ldsec 06:00:58 manu: Shows JSON-LD to C14N in N-Quads. (the _:c14nxxx is part of the serialization). 06:01:23 … That gives you a cross-syntax signature. 06:01:55 … The key is that it is syntax/serialization independent. 06:02:31 … LD Proofs are used to express digital proofs. (THere are other types of proofs). 06:03:00 … LD Proofs are a way of attaching a proof to an RDF document. 06:03:40 … (illustrates a proof) 06:04:07 jc has joined #ldsec 06:04:25 … A CuckooCycleProofOfWork2019 could be used to show proof of work. 06:04:53 … comes with domain, proofValue, nonce, and other annotations that are included in the verification of the signature. 06:05:30 … Above proof is LD Signatures. It adds a verification method (e.g., pub key). What matters is the graph, not where the graph is located. 06:05:43 … This is the vocabulary part. 06:06:01 … Proof requires C14N to get hash. 06:06:36 … There aren’t many developer options when picking a signature method. 06:07:30 … LD Cryptosuites are provided pre-packaged suites that bundle the various pieces together in an easy to use type. 06:07:45 yoshiaki has joined #ldsec 06:07:52 q? 06:07:53 q? 06:07:56 ack azaroth 06:07:58 azaroth, you wanted to discuss dependent canonicalizations and to note dependent canonicalizations 06:08:03 q+ ivan 06:08:22 azaroth: isn’t there also a sute of other C14N bits? 06:08:44 manu: There could be, we have a univeral RDF Dataset canonicalization algorithm. 06:09:12 kiyoto has joined #ldsec 06:09:17 azaroth: If we have a JSON literal and the encoding doesn’t canonicalize that, there would be a different hash generated by an algorithm which uses different white space, for examples. 06:09:31 q+ 06:09:38 kiyoto has joined #ldsec 06:09:42 q- 06:09:57 ivan: for datatypes, there are C14N issues. There is one for XML, probably not for HTML. 06:10:55 azaroth: The WG would not consider JSON canonicalization as being in scope. 06:11:02 manu: We don’t go into literals. 06:11:03 JSON Literals in JSON-LD 1.1 (for the curious) https://w3c.github.io/json-ld-syntax/#json-literals 06:11:08 ack ivan 06:11:18 q? 06:11:26 ivan: The signature algorithms shown exist? Who defines them. 06:11:32 kiyoto has joined #ldsec 06:11:46 … My feeling is that we standardize the vocabulary, and C14N, but not the specific methods 06:12:05 manu: Customers need the algorithms to be standardized. 06:12:54 manu: the specs don’t define the encodings, just the vocabulary. 06:13:06 q+ to ask about registries? 06:13:25 scribe+ bigbluehat 06:13:38 gkellogg: the RDF canonicalization does define 3 mechanisms 06:13:52 manu: other things (signature algo, etc) would be out of scope 06:14:00 manu: hashing and signature algorithms are out of scope, but signatures are 06:14:32 azaroth: We are not defining, but we are selecting. THis plays into registries and such, which may need to be updated. 06:14:41 ack azaroth 06:14:41 azaroth, you wanted to ask about registries? 06:14:47 q+ 06:14:54 q- 06:14:55 manu: The CCG is currently in charge of the registry, but could be handed off. 06:15:27 manu: next steps. We still need peer review, then we need to seek a charter 06:16:05 jc has joined #ldsec 06:16:11 ivan: Speaking for myself, if we have the reviews for the algorithms (reconciled). Creating a charter using the algorithms as input that it is doable. 06:16:35 arnod: Why isn’t one peer reviewed algorithm sufficient? 06:16:55 manu: We need two independent proofs. 06:17:48 ivan: We have an implementation of an unproved algorihtm, and no production ready implementation of the one which is reviewed. 06:18:03 … At some point, we will make the bridge to reconcile the two different algorithms. 06:18:04 q+ to talk about IPR 06:18:13 manu: Expectation is that they algorithms converge. 06:19:02 q- 06:19:07 ivan: Aiden’s algorithm is IP free. DB’s has been published to the public domain. 06:20:02 ken: just to clarify that the box at the top defines out to call out to an external crypto library and how to apply them (protocol?) 06:21:41 manu: What remains is if anyone sees issues around formal objections or organizations that may object. 06:21:49 igarashi_ has joined #ldsec 06:22:01 ivan: There will be “the usual” objections. 06:22:04 jc_ has joined #ldsec 06:23:16 tony: I tried to implement this, but couldn’t. Spec is incomplete. 06:23:34 ivan: that’s why the mathematical paper needs to be done, but not that the spec is complete. 06:24:07 tony: I worked on XML C14N and it was a disaster. 06:24:27 jc has joined #ldsec 06:24:55 … The processing time required was a problem, required sender vs receiver C14N. 06:25:21 … Is it going to be fast enough? 06:25:43 ivan: I know Aiden ran his implementation through large LD sets and showed performance. 06:26:04 manu: Depending on the type of graph (poison graphs) it can take 50-100ms to detect an attack. 06:26:32 … In the easiest case, all your doing is sorting, takes about 5-25ms. 06:26:56 … If we put JSON Schema in, it takes 10x longer to do it vs C14N. 06:27:10 … A Base64 encode takes about 1/2 the time. 06:27:23 … It’s on the order of Base64 enode time. 06:28:48 xxx: would it be possible for graph stores to just use canonicalized bnode names? 06:29:02 s/xxx/sander/ 06:29:04 ivan: In theory, but any change throws it off. 06:30:12 manu: You can also canonicalize to a template and reuse at very fast speed. 06:30:55 tony: can I use some XPath like thing? 06:31:19 manu: you could, but it’s likely unnecessary, as we don’t have the same problems. E.G., there’s no nesting. 06:32:00 … You could use framing and JSON pointer. 06:32:07 yoshiaki has joined #ldsec 07:31:35 yoshiaki has joined #ldsec 07:39:00 rrsagent, draft minutes 07:39:00 I have made the request to generate https://www.w3.org/2019/09/18-ldsec-minutes.html manu 07:39:08 rrsagent, make minutes 07:39:08 I have made the request to generate https://www.w3.org/2019/09/18-ldsec-minutes.html manu 07:39:12 rrsagent bye 07:39:15 zakim, bye 07:39:15 leaving. As of this point the attendees have been manu, Rob_Sanderson, Gregg_Kellogg, Benjamin_Young, Joe_Andrieu, Andrei_Sambra, ivan, Ivan_Herman, Dudley_Collinson 07:39:15 Zakim has left #ldsec 07:39:17 rrsagent, bye 07:39:17 I see no action items 07:46:26 RRSAgent has joined #ldsec 07:46:26 logging to https://www.w3.org/2019/09/18-ldsec-irc 07:46:47 Zakim has joined #ldsec 07:48:12 rrsagent, make minutes 07:48:12 I have made the request to generate https://www.w3.org/2019/09/18-ldsec-minutes.html manu 08:27:28 yoshiaki has joined #ldsec 08:28:11 yoshiaki has joined #ldsec 08:33:39 yoshiaki_ has joined #ldsec 08:35:47 jc has joined #ldsec 08:40:17 jc has joined #ldsec 08:40:38 jc has joined #ldsec 08:41:16 gkellogg has joined #ldsec 08:51:14 jc has joined #ldsec 09:04:27 jc has joined #ldsec 09:20:17 jc has joined #ldsec 09:21:59 jc has joined #ldsec 09:28:50 jc has joined #ldsec 09:34:48 yoshiaki has joined #ldsec 09:38:54 yoshiaki_ has joined #ldsec 09:57:30 Zakim has left #ldsec