<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc SYSTEM "rfc2629-xhtml.ent">
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<?rfc toc="yes" ?>
<?rfc symrefs="yes" ?>
<?rfc sortrefs="yes"?>
<?rfc compact="yes" ?>
<?rfc subcompact="no" ?>
<?rfc iprnotified="no" ?>
<?rfc strict="no" ?>
<rfc xmlns:xi="http://www.w3.org/2001/XInclude"
	docName="draft-card-drip-arch-00" category="info" 
	ipr="trust200902" obsoletes="" updates="" submissionType="IETF" 
	xml:lang="en" tocInclude="true" symRefs="true" sortRefs="true" 
	version="3">
  <!-- xml2rfc v2v3 conversion 2.37.1 -->
<front>
	<title abbrev="DRIP Arch">Drone Remote Identification Protocol 
	(DRIP) Architecture</title> <seriesInfo name="Internet-Draft" 
	value="draft-card-drip-arch-00"/> <author fullname="Stuart W. 
	Card" initials="S." surname="Card"> <organization>AX 
	Enterprize</organization> <address>
	  <postal>
		<street>4947 Commercial Drive</street>
		<city>Yorkville</city>
		<region>NY</region>
		<code>13495</code>
		<country>USA</country>
	  </postal>
	  <email>stu.card@axenterprize.com</email>
	</address> </author> <author fullname="Adam Wiethuechter" 
	initials="A." surname="Wiethuechter"> <organization>AX 
	Enterprize</organization> <address>
	  <postal>
		<street>4947 Commercial Drive</street>
		<city>Yorkville</city>
		<region>NY</region>
		<code>13495</code>
		<country>USA</country>
	  </postal>
	  <email>adam.wiethuechter@axenterprize.com</email>
	</address> </author> <author fullname="Robert Moskowitz" 
	initials="R" surname="Moskowitz"> <organization>HTT 
	Consulting</organization> <address>
	  <postal>
		<street/>
		<city>Oak Park</city>
		<region>MI</region>
		<code>48237</code>
		<country>USA</country>
	  </postal>
	  <email>rgm@labs.htt-consult.com</email>
	</address>
	</author>
    <date year="2020"/>
    <area>Internet</area>
    <workgroup>DRIP</workgroup>
    <keyword>RFC</keyword>
    <keyword>Request for Comments</keyword>
    <keyword>I-D</keyword>
    <keyword>Internet-Draft</keyword>
    <keyword>HIP</keyword>
    <keyword>DRIP</keyword>
<abstract>
<t>
	This document defines an architecture for Drone Remote 
	Identification Protocol (DRIP) Working Group protocols and services 
	to support Unmanned Aircraft System Remote Identification (UAS 
	RID), including its building blocks and their interfaces, all to be 
	standardized.
</t>
</abstract>
</front>
<middle>
<section numbered="true" toc="default"> <name>Introduction</name>
<t>
	Many safety and other considerations dictate that UAS be remotely 
	identifiable. Civil Aviation Authorities (CAAs) worldwide are 
	mandating UAS RID. The European Union Aviation Safety Agency (EASA) 
	has published <xref target="Delegated" format="default"/> and <xref 
	target="Implementing" format="default"/> Regulations. The United 
	States (US) Federal Aviation Administration (FAA) has published a 
	Notice of Proposed Rule Making (<xref target="NPRM" 
	format="default"/>). CAAs currently promulgate performance-based 
	regulations that do not specify techniques, but rather cite 
	industry consensus technical standards as acceptable means of 
	compliance.
</t>
<t>  
	ASTM International, Technical Committee F38 (UAS), Subcommittee 
	F38.02 (Aircraft Operations), Work Item WK65041 (UAS Remote ID and 
	Tracking), is a Proposed New Standard <xref target="WK65041" 
	format="default"/>. It defines 2 means of UAS RID. Network RID 
	defines a set of information for UAS to make available globally 
	indirectly via the Internet. Broadcast RID defines a set of 
	messages for Unmanned Aircraft (UA) to transmit locally directly 
	one-way over Bluetooth or Wi-Fi. Network RID depends upon Internet 
	connectivity, in several segments, from the UAS to the observer. 
	Broadcast RID should need Internet (or other Wide Area Network) 
	connectivity only for UAS registry information lookup using the 
	directly locally received UAS ID as a key.
</t>
<t>
	<xref target="WK65041" format="default"/> specifies 3 UAS ID types. 
	Type 1 is a static, manufacturer assigned, hardware serial number 
	per ANSI/CTA-2063-A "Small Unmanned Aerial System Serial Numbers" 
	<xref target="CTA2063A" format="default"/>. Type 2 is a CAA 
	assigned (presumably static) ID. Type 3 is a UAS Traffic Management 
	(UTM) system assigned UUID <xref target="RFC4122" 
	format="default"/>, which can but need not be dynamic. The EU 
	allows only Type 1; the US allows Types 1 and 3, but requires Type 
	3 IDs (if used) each to be used only once. <xref target="WK65041" 
	format="default"/> Broadcast RID transmits all information in the 
	clear as plaintext, so Type 1 static IDs enable trivial correlation 
	of patterns of use, unacceptable in many applications, e.g. package 
	delivery routes of competitors.
</t>
<t>
	An ID is not an end in itself; it exists to enable lookups and 
	provision of services complementing mere identification.
</t>
<t>
	Minimal specified information must be made available to the public; 
	access to other data, e.g. UAS operator Personally Identifiable 
	Information (PII), must be limited to strongly authenticated 
	personnel, properly authorized per policy. <xref target="WK65041" 
	format="default"/> specifies only how to get the UAS ID to the 
	observer; how the observer can perform these lookups, and how the 
	registries first can be populated with information, is unspecified.
</t>
<t>
	Although using UAS RID to facilitate related services, such as 
	Detect And Avoid (DAA) and other applications of Vehicle to Vehicle 
	or Vehicle to Infrastructure (V2V, V2I, collectively V2X) 
	communications, is an obvious application (explicitly contemplated 
	in the FAA NPRM), it has been ommitted from <xref target="WK65041" 
	format="default"/> (explicitly declared out of scope in the ASTM 
	working group discussions based on a distinction between RID as a 
	security standard vs DAA as a safety application). Although dynamic 
	establishment of secure communications between the observer and the 
	UAS pilot seems to have been contemplated by the FAA UAS ID and 
	Tracking Aviation Rulemaking Committee (ARC) in their <xref 
	target="Recommendations" format="default"/>, it is not addressed in 
	any of the subsequent proposed regulations or technical 
	specifications.
</t>
<t>
	The need for near-universal deployment of UAS RID is pressing. This 
	implies the need to support use by observers of already ubiquitous 
	mobile devices (smartphones and tablets). UA onboard RID devices 
	are severely constrained in Size, Weight and Power (SWaP). Cost is 
	a significant impediment to the necessary near-universal adoption 
	of UAS send and observer receive RID capabilities. To accomodate 
	the most severely constrained cases, all these conspire to motivate 
	system design decisions, especially for the Broadcast RID data 
	link, which complicate the protocol design problem: one-way links; 
	extremely short packets; and Internet-disconnected operation of UA 
	onboard devices. Internet-disconnected operation of observer 
	devices has been deemed by ASTM F38.02 too infrequent to address, 
	but for some users is important and presents further challenges. 
	Heavyweight security protocols are infeasible, yet trustworthiness 
	of UAS RID information is essential. Under <xref target="WK65041" 
	format="default"/>, even the most basic datum, the UAS ID string 
	(typically number) itself can be merely an unsubstantiated claim.
</t>
<t>
	IETF can help by providing  expertise as well as mature and 
	evolving standards. Existing Internet resources (business models, 
	infrastructure and protocol standards) should be leveraged. Host 
	Identity Protocol (HIPv2) <xref target="RFC7401" format="default"/> 
	and its Domain Name System (DNS) extensions <xref target="RFC8005" 
	format="default"/>, together with the Registry Data Access Protocol 
	(RDAP) and the Extensible Provisioning Protocol (EPP), can 
	complement emerging external standards for UAS RID. This will 
	facilitate utilization of existing and provision of enhanced 
	network services, and  enable verification that UAS RID information 
	is trustworthy (to some extent, even in the absence of Internet 
	connectivity at the receiving node). The natural Internet 
	architecture for DRIP described herein addresses requirements 
	defined in a companion DRIP Requirements document.
</t>
</section>
<section anchor="terms" numbered="true" toc="default"> <name>Terms and Definitions</name>
<section numbered="true" toc="default"> <name>Requirements Terminology</name>
<t>
	The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", 
	"SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", 
	and "OPTIONAL" in this document are to be interpreted as described 
	in BCP 14 <xref target="RFC2119" format="default"/> <xref 
	target="RFC8174" format="default"/> when, and only when, they 
	appear in all capitals, as shown here.
</t>
</section>
<section numbered="true" toc="default"> <name>Definitions</name>
	<dl newline="true" spacing="normal">
	<dt>$SWaP</dt>
		<dd>
			Cost, Size, Weight and Power.
		</dd>
		<dt>AAA</dt>
		<dd>
			Attestation, Authentication, Authorization, Access Control, 
			Accounting, Attribution, Audit.
		</dd>
		<dt>ABDAA</dt>
		<dd>
			AirBorne DAA. Also known as "self-separation".
		</dd>

		<dt>AGL</dt>
		<dd>
			Above Ground Level. Relative altitude, above the variously 
			defined local ground level, typically of an UA, typically 
			measured in feet.
		</dd>
		<dt>CAA</dt>
		<dd>
			Civil Aviation Authority. An example is the Federal 
			Aviation Administration (FAA) in the United States of 
			America.
		</dd>
		<dt>C2</dt>
		<dd>
			Command and Control. A set of organizational and technical 
			attributes and processes that employs human, physical, and 
			information resources to solve problems and accomplish 
			missions. Mainly used in military contexts.
		</dd>
		<dt>CS-RID</dt>
		<dd>
			Crowd Sourced Remote Identification. An optional DRIP WG 
			service that gateways Broadcast RID to Network RID, and 
			supports verification of RID positon/velocity claims with 
			independent measurements (e.g. by multilateration), via a 
			SDSP.
		</dd>
		<dt>DAA</dt>
		<dd>
			Detect And Avoid, formerly Sense And Avoid (SAA). A means 
			of keeping aircraft "well clear" of each other for safety. 
		</dd>
		<dt>E2E</dt>
		<dd>
			End to End. 
		</dd>

		<dt>GBDAA</dt>
		<dd>
			Ground Based DAA. 
		</dd>
		<dt>GCS</dt>
		<dd>
			Ground Control Station. The part of the UAS that the remote 
			pilot uses to exercise C2 over the UA, whether by remotely 
			exercising UA flight controls to fly the UA, by setting GPS 
			waypoints, or otherwise directing its flight.
		</dd>
		<dt>GPS</dt>
		<dd>
			Global Positioning System. In this context, misused in 
			place of Global Navigation Satellite System (GNSS) or more 
			generally SATNAV to refer generically to satellite based 
			timing and/or positioning.
		</dd>
		<dt>HI</dt>
		<dd>
			Host Identity. The public key portion of an asymmetric 
			keypair from HIP. In this document it is assumed that the 
			HI is based on a EdDSA25519 keypair. This is supported by 
			new crypto defined in <xref 
			target="I-D.moskowitz-hip-new-crypto" format="default"/>.
		</dd>
		<dt>HIP</dt>
		<dd>
			Host Identity Protocol. The origin of HI, HIT, and HHIT, 
			required for DRIP. Optional full use of HIP enables 
			additional DRIP functionality.
		</dd>
		<dt>HHIT</dt>
		<dd>
			Hierarchical Host Identity Tag. A HIT with extra 
			information not found in a standard HIT. Defined in <xref 
			target="I-D.moskowitz-hip-hierarchical-hit" 
			format="default"/>.
		</dd>
		<dt>HIT</dt>
		<dd>
			Host Identity Tag. A 128 bit handle on the HI. Defined in 
			HIPv2 <xref target="RFC7401" format="default"/>.
		</dd>
		<dt>Limited RID</dt>
		<dd>
			Per the FAA NPRM, a mode of operation that must use Network 
			RID, must not use Broadcast RID, and must provide pilot/GCS 
			location only (not UA location). This mode is only allowed 
			for UA that neither require (due to e.g. size) nor are 
			equipped for Standard RID, operated within V-LOS and within 
			400 feet of the pilor, below 400 feet AGL, etc.
		</dd>
		<dt>LOS</dt>
		<dd>
			Line Of Sight. An adjectival phrase describing any 
			information transfer that travels in a nearly straight line 
			(e.g. electromagnetic energy, whether in the visual light, 
			RF or other frequency range) and is subject to blockage. A 
			term to be avoided due to ambiguity, in this context, 
			between RF-LOS and V-LOS.
		</dd>
		<dt>MSL</dt>
		<dd>
			Mean Sea Level. Relative altitude, above the variously 
			defined mean sea level, typically of an UA (but in FAA NPRM 
			Limited RID for a GCS), typically measured in feet.
		</dd>
		<dt>NETDP</dt>
		<dd>
			UAS RID Display Provider. System component that requests 
			data from one or more NETSP and aggregates them to display 
			to a user application on a device. Often an USS.
		</dd>
		<dt>NETSP</dt>
		<dd>
			UAS RID Service Provider. System component that compiles 
			information from various sources (and methods) in its given 
			service area. Usually an USS.
		</dd>
		<dt>Observer</dt>
		<dd>
			Referred to in other UAS RID documents as a "user", but 
			there are also other classes of UAS RID users, so we prefer 
			"observer" to denote an individual who has observed an UA 
			and wishes to know something about it, starting with its 
			ID.
		</dd>
		<dt>PII</dt>
		<dd>
			Personally Identifiable Information. In this context, 
			typically of the UAS operator, Pilot In Command (PIC) or 
			remote pilot, but possibly of an observer or other party.
		</dd>
		<dt>RF</dt>
		<dd>
			Radio Frequency. May be used as an adjective or as a noun; 
			in the latter case, typically means Radio Frequency energy.
		</dd>
		<dt>RF-LOS</dt>
		<dd>
			RF LOS. Typically used in describing operation of a direct 
			radio link between a GCS and the UA under its control, 
			potentially subject to blockage by foliage, structures, 
			terrain or other vehicles, but less so than V-LOS.
		</dd>
		<dt>SDSP</dt>
		<dd>
			Supplemental Data Service Provider. Entity that provides 
			data allowed and presumed useful but neither required nor 
			standardized as an option in UTM, such as weather. Here 
			used to enable CS-RID.
		</dd>
		<dt>Standard RID</dt>
		<dd>
			Per the FAA NPRM, a mode of operation that must use both 
			Network RID (if Internet connectivity is available at the 
			time in the operating area) and Broadcast RID (always and 
			everywhere), and must provide both pilot/GCS location and 
			UA location. This mode is required for UAS that exceed the 
			allowed envelope (e.g. size, range) of Limited RID and for 
			all UAS equipped for Standard RID (even if operated within 
			parameters that would otherwise permit Limited RID).
		</dd>
		<dt>UA</dt>
		<dd>
			Unmanned Aircraft. Typically a military or commercial 
			"drone" but can include any and all aircraft that are 
			unmanned.
		</dd>
		<dt>UAS</dt>
		<dd>
			Unmanned Aircraft System. Composed of UA, all required 
			on-board subsystems, payload, control station, other 
			required off-board subsystems, any required launch and 
			recovery equipment, all required crew members, and C2 links 
			between UA and control station.
		</dd>
		<dt>UAS ID</dt>
		<dd>
			Unique UAS identifier. Per <xref target="WK65041" 
			format="default"/>, maximum length of 20 bytes.
		</dd>
		<dt>UAS ID Type</dt>
		<dd>
			Identifier type index. Per <xref target="WK65041" 
			format="default"/>, 4 bits, values 0-3 already specified.
		</dd>
		<dt>UAS RID</dt>
		<dd>
			UAS Remote Identification. System for identifying UA during 
			flight by other parties.
		</dd>
		<dt>UAS RID Verification Service</dt>
		<dd>
			System component designed to handle the authentication 
			requirements of RID by offloading verification to a web 
			hosted service.
		</dd>
		<dt>USS</dt>
		<dd>
			UAS Service Supplier. Provide UTM services to support the 
			UAS community, to connect Operators and other entities to 
			enable information flow across the USS network, and to 
			promote shared situational awareness among UTM 
			participants. (From FAA UTM ConOps V1, May 2018).
		</dd>
		<dt>UTM</dt>
		<dd>
			UAS Traffic Management. A "traffic management" ecosystem 
			for "uncontrolled" UAS operations separate from, but 
			complementary to, the FAA's Air Traffic Management (ATM) 
			system for "controlled" operations of manned aircraft.
		</dd>
		<dt>V-LOS</dt>
		<dd>
			Visual LOS. Typically used in describing operation of an UA 
			by a "remote" pilot who can clearly directly (without video 
			cameras or any other aids other than glasses or under some 
			rules binoculars) see the UA and its immediate flight 
			environment. Potentially subject to blockage by foliage, 
			structures, terrain or other vehicles, more so than RF-LOS.
		</dd>
	</dl>		
</section>
</section>
<section numbered="true" toc="default"> 
<name>Entities and their Interfaces</name> <t>
	Any DRIP WG solutions for UAS RID must fit into the UTM system. 
	This implies interaction with entities including UA, GCS, USS, 
	NETSP, NETDP, Observers, Operators, Pilots In Command, Remote 
	Pilots, etc. The only additional entities introduced by DRIP WG are 
	registries, required but not specified by the regulations and <xref 
	target="RFC7401" format="default"/>, and optionally CS-RID SDSP and 
	Finder nodes.
</t>
<t>
	UAS RID registries hold both public and private information. The 
	public information is primarily pointers to the repositories of, 
	and keys for looking up, the private information. Given these 
	different uses, and to improve scalability, security and simplicity 
	of administration, the public and private information can be stored 
	in different registries, indeed different types of registry.
</t>
<section numbered="true" toc="default"> <name>Private Information 
Registry</name>
<t>
	The private information required for UAS RID is similar to that 
	required for Internet domain name registration. This facilitates 
	leveraging existing Internet resources, including domain name 
	registration protocols, infrastructure and business models. This 
	implies a further derived requirement: a DRIP UAS ID MUST be 
	amenable to handling as an Internet domain name (at an arbitrary 
	level in the heirarchy), MUST be registered in at least a 
	pseudo-domain (e.g. .ip6 for reverse lookup), and MAY be registered 
	as a sub-domain (for forward lookup).
</t>
<t>
	A DRIP private information registry MUST support essential 
	Internet domain name registry operations (e.g. add, delete, update, 
	query) using interoperable open standard protocols. It SHOULD 
	support the Extensible Provisioning Protocol (EPP) and the Registry 
	Data Access Protocol (RDAP) with access controls. It MAY use XACML 
	to specify those access controls. It MUST be listed in a DNS: that 
	DNS MAY be private; but absent any compelling reasons for use of 
	private DNS, SHOULD be the definitive public Internet DNS 
	heirarchy. The DRIP private information registry in which a given 
	UAS is registered MUST be locatable, starting from the UAS ID, 
	using the methods specified in <xref target="RFC7484" 
	format="default"/>.
</t>
</section>
<section numbered="true" toc="default"> <name>Public Information
Registry</name>
<t>
	The public information required to be made available by UAS RID is 
	transmitted as clear plaintext to local observers in Broadcast RID 
	and is served to a client by a NETDP in Network RID. Therefore, 
	while IETF can offer e.g. <xref target="RFC6280" format="default"/> 
	as one way to implement Network RID, the only public information 
	required to support essential DRIP functions for UAS RID is that 
	required to look up Internet domain hosts, services, etc.
</t>
<t>
	A DRIP public information registry MUST be a standard DNS server, 
	in the definitive public Internet DNS heirarchy. It MUST support 
	NS, MX, SRV, TXT, AAAA, PTR, CNAME and HIP RR types.
</t>
</section>
<section numbered="true" toc="default"> <name>CS-RID SDSP</name>
<t>
	A CS-RID SDSP MUST appear (i.e. present the same interface) to a 
	NETSP as a NETDP. A CS-RID SDSP MUST appear to a NETDP as a NETSP. 
	A CS-RID SDSP MUST NOT present a standard GCS-facing interface as 
	if it were a NETSP. A CS-RID SDSP MUST NOT present a standard 
	client-facing interface as if it were a NETDP. A CS-RID SDSP MUST 
	present a TBD interface to a CS-RID Finder; this interface SHOULD 
	be based upon but readily distinguishable from that between a GCS 
	and a NETSP.
</t>
</section>
<section numbered="true" toc="default"> <name>CS-RID Finder</name>
<t>
	A CS-RID Finder MUST present a TBD interface to a CS-RID SDSP; this 
	interface SHOULD be based upon but readily distinguishable from 
	that between a GCS and a NETSP. A CS-RID Finder must implement, 
	integrate or accept outputs from a Broadcast RID receiver. A CS-RID 
	Finder MUST NOT interface directly with a GCS, NETSP, NETDP or 
	Network RID client.
</t>
</section>
</section>
<section numbered="true" toc="default"> <name>Identifiers</name>
<t>
	A DRIP UAS ID MUST be a HHIT. It SHOULD be self-generated by the 
	UAS (either UA or GCS) and MUST be registered with the Private 
	Information Registry identified in its heirarchy fields. Each UAS 
	ID HHIT MUST NOT be used more than once, with one exception as 
	follows.
</t>
<t>	
	Each UA MAY be assigned, by its manufacturer, a single HI and 
	derived HHIT encoded as a hardware serial number per <xref 
	target="CTA2063A" format="default"/>. Such a static HHIT SHOULD be 
	used only to bind one-time use UAS IDs (other HHITs) to the unique 
	UA. Depending upon implementation, this may leave a HI private key 
	in the posession of the manufacturer (see Security Considerations).
</t>
<t>
	Each UA equipped for Broadcast RID MUST be provisioned not only 
	with its HHIT but also with the HI public key from which the HHIT 
	was derived and the corresponding private key, to enable message 
	signature. Each UAS equipped for Network RID MUST be provisioned 
	likewise; the private key SHOULD reside only in the ultimate source 
	of Network RID messages (i.e. on the UA itself if the GCS is merely 
	relaying rather than sourcing Network RID messages). Each observer 
	device MUST be provisioned with public keys of the UAS RID root 
	registries and MAY be provisioned with public keys or certificates 
	for subordinate registries.
</t>
<t>
	Operators and Private Information Registries MUST possess and other 
	UTM entities MAY possess UAS ID style HHITs. When present, such 
	HHITs SHOULD be used with HIP to strongly mutually authenticate and 
	optionally encrypt communications.
</t>
</section>
<section numbered="true" toc="default"> <name>Transactions</name>
<t>
	Each Operator MUST generate a "HIo" and derived "HHITo", register 
	them with a Private Information Registry along with whatever 
	Operator data (inc. PII) is required by the cognizant CAA and the 
	registry, and obtain a certificate "Cro" signed with "HIr(priv)" 
	proving such registration.
</t>
<t>
	To add an UA, an Operator MUST generate a "HIa" and derived 
	"HHITa", create a certificate "Coa" signed with "HIo(priv)" to 
	associate the UA with its Operator, register them with a Private 
	Information Registry along with whatever UAS data is required by 
	the cognizant CAA and the registry, obtain a certificate "Croa" 
	signed with "HIr(priv)" proving such registration, and obtain a 
	certificate "Cra" signed with "HIr(priv)" proving UA registration 
	in that specific registry while preserving Operator privacy. The 
	operator then MUST provision the UA with "HIa", "HIa(priv)", 
	"HHITa" and "Cra".
</t>
<t>
	UA engaging in Broadcast RID MUST use "HIa(priv)" to sign Auth 
	Messages and MUST periodically broadcast "Cra". UAS engaging in 
	Network RID MUST use "HIa(priv)" to sign Auth Messages. Observers 
	MUST use "HIa" from received "Cra" to verify received Broadcast RID 
	Auth messages. Observers without Internet connectivity MAY use 
	"Cra" to identify the trust class of the UAS based on known 
	registry vetting. Observers with Internet connectivity MAY use 
	"HHITa" to perform lookups in the Public Information Registry and 
	MAY then query the Private Information Registry, which MUST enforce 
	access control policy on Operator PII and other sensitive 
	information.
</t>
</section>
<section anchor="IANA" numbered="true" toc="default"> <name>IANA Considerations</name>
<t>
	It is likely that an IPv6 prefix will be needed for the HHIT (or 
	other identifier) space; this will be specified in other drafts.
</t>
</section>
<section numbered="true" toc="default"> <name>Security Considerations</name>
<t>
	DRIP is all about safety and security, so content pertaining to 
	such is not limited to this section. The security provided by 
	asymmetric cryptographic techniques depends upon protection of the 
	private keys. A manufacturer that embeds a private key in an UA may 
	have retained a copy. A manufacturer whose UA are configured by a 
	closed source application on the GCS which communicates over the 
	Internet with the factory may be sending a copy of a UA or GCS 
	self-generated key back to the factory. Compromise of a registry 
	private key could do widespread harm. Key revocation procedures are 
	as yet to be determined. These risks are in addition to those 
	involving Operator key management practices. 
</t>
</section>
<section numbered="true" toc="default"> <name>Acknowledgments</name>
<t>
	The work of the FAA's UAS Identification and Tracking (UAS ID) 
	Aviation Rulemaking Committee (ARC) is the foundation of later ASTM 
	and proposed IETF DRIP WG efforts. The work of ASTM F38.02 in 
	balancing the interests of diverse stakeholders is essential to the 
	necessary rapid and widespread deployment of UAS RID.
</t>
</section>
</middle>
<back>
<references> <name>References</name>
<references> <name>Normative References</name>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml"/>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.7401.xml"/>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.7484.xml"/>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8005.xml"/>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml"/>
</references>
<references> <name>Informative References</name>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.6280.xml"/>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml3/reference.I-D.moskowitz-hip-hierarchical-hit.xml"/>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml3/reference.I-D.moskowitz-hip-new-crypto.xml"/>
	<xi:include href="https://xml2rfc.tools.ietf.org/public/rfc/bibxml/reference.RFC.4122.xml"/>
	<reference anchor="CTA2063A" target="">
	<front>
		<title>Small Unmanned Aerial Systems Serial Numbers</title>
		<author>
			<organization>ANSI</organization>
		</author>
		<date month="09" year="2019"/>
	</front>
	</reference>
	<reference anchor="WK65041" target="">
	<front>
		<title>Standard Specification for Remote ID and Tracking</title>
		<author>
			<organization>ASTM</organization>
		</author>
		<date month="09" year="2019"/>
	</front>
	</reference>
	<reference anchor="Delegated" target="">
	<front>
		<title>EU Commission Delegated Regulation 2019/945 of 12 March 2019 on unmanned aircraft systems and on third-country operators of unmanned aircraft systems</title>
		<author>
			<organization>European Union Aviation Safety Agency (EASA)</organization>
		</author>
		<date month="03" year="2019"/>
	</front>
	</reference>
	<reference anchor="Implementing" target="">
	<front>
		<title>EU Commission Implementing Regulation 2019/947 of 24 May 2019 on the rules and procedures for the operation of unmanned aircraft </title>
		<author>
			<organization>European Union Aviation Safety Agency (EASA)</organization>
		</author>
		<date month="05" year="2019"/>
	</front>
	</reference>
	<reference anchor="NPRM" target="">
	<front>
		<title>Notice of Proposed Rule Making on Remote Identification of Unmanned Aircraft Systems</title>
		<author>
			<organization>United States Federal Aviation Administration (FAA)</organization>
		</author>
		<date month="12" year="2019"/>
	</front>
	</reference>
	<reference anchor="Recommendations" target="">
	<front>
		<title>UAS ID and Tracking ARC Recommendations Final Report</title>
		<author>
			<organization>FAA UAS Identification and Tracking Aviation Rulemaking Committee</organization>
		</author>
		<date month="09" year="2017"/>
	</front>
	</reference>
</references>
</references>
</back>
</rfc>
