Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Air-gap or network isolated network references #2

Open
SteveLasker opened this issue Sep 8, 2023 · 1 comment
Open

Air-gap or network isolated network references #2

SteveLasker opened this issue Sep 8, 2023 · 1 comment
Milestone

Comments

@SteveLasker
Copy link
Collaborator

Section 3.7. Authentic Software Components in Air-Gapped Infrastructure uses the term "air-gapped" and "off-line". While "air-gapped" is a common term, it's often used to refer to highly isolated environments. While users are embracing cloud environments, they still wish to maintain network isolation, through virtual private networks. Can/should we reword this section to refer to the more common network isolated environments? The subtle difference between network-isolated and air-gapped is a network-isolated environment may enable ingress/egress rules while an air-gapped environment may implement a data-diode that allows content to go into an environment but the environment can never reach out. (diode = one-way)

@SteveLasker SteveLasker changed the title Air-gap or network isloated network references Air-gap or network isolated network references Sep 9, 2023
@OR13
Copy link
Contributor

OR13 commented Sep 12, 2023

It seems worth while to address the isolation levels since each might have different challenges:

  • software isolation (like browsers have for private keys per origin) (same device)
  • hardware isolation TPM / TEE (same device)
  • hardware gapped networks (network of devices)
  • software gapped networks / private clouds ( is there a better word for this ? ) (network of devices)

@SteveLasker SteveLasker added this to the IETF 118 milestone Sep 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants