|
| 1 | +# Requirements for HTTPS/WSS in Local Network |
| 2 | + |
| 3 | +This section outlines functional and non-functional requirements of HTTPS/WSS usage in local network represented in [UseCases.md](UseCases.md). |
| 4 | + |
| 5 | +Functional requirements consist of device discovery, device authentication, certificate issuance, and certificate management and lifecycle. |
| 6 | + |
| 7 | +Non-functional requirements address user experience and security aspects of HTTPS/WSS usage in local network. |
| 8 | + |
| 9 | +## <a name=“functional-requirements”></a>Functional Requirements |
| 10 | + |
| 11 | +### <a name=“terminology”></a>Terminology |
| 12 | + |
| 13 | +A device is in the same local network as the user agent (UA), capable of HTTPS/WSS server, compliant with [certificate grant and issuance](#certificate-grant-and-issuance) and [certificate management](#certificate-management), and notifies the UA of the capability during [device discovery](#device-discovery). |
| 14 | + |
| 15 | +A device delegate is in the public IP address network, has the certificate issued for the device, and relays messages between the UA and the device. Device discovery through the device delegate is out of scope. |
| 16 | + |
| 17 | +### <a name=“device-discovery”></a>Device Discovery |
| 18 | + |
| 19 | +- The UA shall be able to discover the presence of devices in the same local network. |
| 20 | +- The UA shall be able to obtain the endpoint URL of the device which has the scheme `https:` or `wss:` and its compliance with [certificate grant and issuance](#certificate-grant-and-issuance) and [certificate management](#certificate-management). |
| 21 | + |
| 22 | +### <a name=“device-authenticaion”></a>Device Authentication |
| 23 | + |
| 24 | +- The UA shall authenticate one of the [discovered](#device-discovery) device selected by the user. |
| 25 | +- The UA shall authenticate one of the devices registered in the device delegate selected on the web application. |
| 26 | +- The UA shall ask the user to input information such as PIN code or passphrase when the device requests to do so, and notify the device of the information, so that the UA and the device or the device delegate can properly authenticate with each other. |
| 27 | +- The UA shall only expose the interface to the authenticated device to web applications. |
| 28 | +- The UA shall initiate [certificate grant and issuance](#certificate-grant-and-issuance) procedure when the device or the device delegate is authenticated successfully. |
| 29 | +- The UA shall be able to authenticate the device or the device delegate automatically without the user’s grant when it has been authenticated once and its certificate has not been expired or revoked yet. |
| 30 | + |
| 31 | +### <a name=“certificate-grant-and-issuance”></a>Certificate Grant and Issuance |
| 32 | + |
| 33 | +#### <a name=“local-network-certificate”></a>Certificate for Local Network |
| 34 | + |
| 35 | +- The device shall be able to have at least one of the following types of TLS server certificates so that an origin of the connection with the device becomes [potentially trustworthy](https://w3c.github.io/webappsec-secure-contexts/#potentially-trustworthy-origin) in a certain period: |
| 36 | + - a self-signed certificate explicitly granted by the user (*TODO: consider whether this item is appropriate or not in terms of security*) |
| 37 | + - a self-signed certificate granted on the web application’s origin explicitly by the user |
| 38 | + - a certificate issued by a private certificate authority for devices (device CA) explicitly granted by the user |
| 39 | +- The device shall be able to verify whether or not the certificate is either granted by the user or properly issued by the device CA. |
| 40 | +- The web server shall be able to provide the UA with a hint about the certificates to be granted on the web application’s origin. |
| 41 | +- The device CA shall automatically issue a certificate for the device when the user grants and the device requests. |
| 42 | +- The device CA shall verify certificate issuing request from both the device and the UA before issuing a certificate to the device. |
| 43 | +- The certificate shall have a reasonably short expiration period. |
| 44 | + |
| 45 | +#### <a name=“certificate-for-delegate”></a>Certificate for Device Delegate |
| 46 | + |
| 47 | +- The device delegate shall be able to have a TLS server certificate issued by the publicly trusted certificate authority (public CA) through an automated procedure so that an origin of the connection with the device becomes [potentially trustworthy](https://w3c.github.io/webappsec-secure-contexts/#potentially-trustworthy-origin). |
| 48 | +- The public CA shall automatically issue a certificate for the device delegate when the user grants and the device behind the device delegate requests. |
| 49 | +- The certificate shall have a reasonably short expiration period. |
| 50 | + |
| 51 | +### <a name=“certificate-management”></a>Certificate Management |
| 52 | + |
| 53 | +- The UA shall ask the user if the user grants the renewal of the certificate when the certificate is expired during [device authentication](#device-authentication), [certificate grant and issuance](#certificate-grant-and-issuance), or communication with the device. |
| 54 | +- The UA shall be able to revoke the certificate when the user decides to do so. |
| 55 | +- The certificate issued by the device CA shall be able to be revoked by the device CA when necessary. (Note that the root CA can revoke the ceritficate issued by it through OCSP.) |
| 56 | + |
| 57 | +## <a name=“non-funcational-requirements”>Non-Functional Requirements |
| 58 | + |
| 59 | +### <a name=“privacy-and-security></a>Privacy and Security |
| 60 | + |
| 61 | +- [Device authentication](#device-authentication) and [certificate grant and issuance](#certificate-grant-and-issuance) should prevent passive network eavesdroppers from learning messages related to authentication or certificate passed between the UA and the device. |
| 62 | +- [Device authentication](#device-authentication) and [certificate grant and issuance](#certificate-grant-and-issuance) should prevent active network attackers from impersonating a device and observing or altering data intended for the UA. |
| 63 | + |
| 64 | +### <a name=“user-experience”></a>User Experience |
| 65 | + |
| 66 | +- The UA should minimize user’s interaction for authentication as much as possible. |
| 67 | +- The procedure of [certificate grant and issuance](#certificate-grant-and-issuance) should be automated as much as possible so that the user’s interaction can be minimized. |
0 commit comments