[Ace] Re: Plain COSE_Key in draft-ietf-ace-edhoc-oscore-profile

2024-12-16 Thread Marco Tiloca
Hi Christian, Yes, the second form is a correct example while the first form is not compatible with EDHOC, which does not admit "naked" COSE Keys as authentication credentials. In general, the CWT confirmation method (i.e., the 'cnf' type) has to be consistent with an authentication credenti

[Ace] Re: Plain COSE_Key in draft-ietf-ace-edhoc-oscore-profile

2024-12-16 Thread Marco Tiloca
Hi Christian, If I understand correctly, you are proposing the following optimization: * In the EDHOC and OSCORE profile, it can be allowed that 'req_cnf', 'rs_cnf', and 'cnf' specify "COSE_Key" (1) as CWT Confirmation Method. * When doing so, the consumer of 'req_cnf', 'rs_cnf', or 'cnf' mus