Re: [6tisch-security] slides you presented

Göran Selander <goran.selander@ericsson.com> Thu, 23 February 2017 22:49 UTC

Return-Path: <goran.selander@ericsson.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 22EF1129BCF for <6tisch-security@ietfa.amsl.com>; Thu, 23 Feb 2017 14:49:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.22
X-Spam-Level:
X-Spam-Status: No, score=-4.22 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sBlt63F_6Ys1 for <6tisch-security@ietfa.amsl.com>; Thu, 23 Feb 2017 14:49:40 -0800 (PST)
Received: from sessmg23.ericsson.net (sessmg23.ericsson.net [193.180.251.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 165DD1299A8 for <6tisch-security@ietf.org>; Thu, 23 Feb 2017 14:49:39 -0800 (PST)
X-AuditID: c1b4fb2d-da3ff70000005112-be-58af67003251
Received: from ESESSHC002.ericsson.se (Unknown_Domain [153.88.183.24]) by (Symantec Mail Security) with SMTP id 85.50.20754.0076FA85; Thu, 23 Feb 2017 23:49:38 +0100 (CET)
Received: from ESESSMB303.ericsson.se ([169.254.3.200]) by ESESSHC002.ericsson.se ([153.88.183.24]) with mapi id 14.03.0319.002; Thu, 23 Feb 2017 23:48:32 +0100
From: Göran Selander <goran.selander@ericsson.com>
To: "consultancy@vanderstok.org" <consultancy@vanderstok.org>
Thread-Topic: [6tisch-security] slides you presented
Thread-Index: AQHSjNhj/O61zu/6fEqs5XyYLuNd26F2NsWAgAD9cgA=
Date: Thu, 23 Feb 2017 22:48:31 +0000
Message-ID: <D4D51E37.76BE9%goran.selander@ericsson.com>
References: <D4D2C251.76751%goran.selander@ericsson.com> <f6dbdaf79dc7f3dd5a27eb5d07c39ba1@xs4all.nl>
In-Reply-To: <f6dbdaf79dc7f3dd5a27eb5d07c39ba1@xs4all.nl>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.7.1.161129
x-originating-ip: [153.88.183.154]
Content-Type: text/plain; charset="utf-8"
Content-ID: <665208AAA0E6AD47ADF1784F26F9DA65@ericsson.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrOIsWRmVeSWpSXmKPExsUyM2K7hC5T+voIg2enJS2aVy5it3i0fxWb xbyGy0wOzB5Llvxk8miZs4fZ40TDdvYA5igum5TUnMyy1CJ9uwSujJXfPjMX/JKqmPngJ0sD 4wKpLkZODgkBE4kt7+ewdDFycQgJrGOUWHVvARuEs4RR4m3bTGaQKjYBF4kHDY+YQGwRAVuJ +X/3g9nMAkkSvas+M4LYwgLGEtd+L2LtYuQAqjGRePtSB6LcSuJJ016wEhYBVYm7t4+wgNi8 AhYS8x9fZAcpFxJIl7g0SRskzClgKdHU+osNxGYUEJP4fmoN1CZxiVtP5jNB3CwgsWTPeWYI W1Ti5eN/rCC2qICexPLna6DiShKLbn9mAhnPLKApsX6XPsQYa4lt66dCjVSUmNL9kB3iGkGJ kzOfsExgFJ+FZNsshO5ZSLpnIemehaR7ASPrKkbR4tTi4tx0I2O91KLM5OLi/Dy9vNSSTYzA 6Du45bfuDsbVrx0PMQpwMCrx8H74sS5CiDWxrLgy9xCjBAezkgjv9qT1EUK8KYmVValF+fFF pTmpxYcYpTlYlMR5zVbeDwcGVWJJanZqakFqEUyWiYNTqoHRPn19VqfueqlJP49WZ83xDSpa q+Bw5Lv4i/4txbNj7x8TvNklJK39p1de8m3Rjp0N3AsvhjzrLT9YGPdJsfsVx2WNdbMD3cI2 RU2buZl7acP0wrvqB/e8So5eb9Ledck2gcMyeTKvhdyZd9E+gal5TTO1PA7/5VVxcTBKtrbx 8al/4BBdYaDEUpyRaKjFXFScCADgEgMXugIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/3_38aFAKHkXgXx-S7w10W03UG6I>
Cc: Michael Richardson <mcr@sandelman.ca>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] slides you presented
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Feb 2017 22:49:42 -0000

Hi Peter,

This was the first meeting I participated in this year and I just wanted
to understand the current discussion. The slides were intended for a high
level discussion of functionality without binding to specific protocol,
but, yes, EDHOC and OSCOAP does the job and as far as I understand is in
scope of the minimal security draft.

As for CoMI, it could either take advantage of the established security
for protecting CoMI operations, or in some way be part of the security
solution, which I think Michael was referring to. In the latter case it
needs to be specified how CoMI operations are secured.

Göran


On 2017-02-23 09:41, "peter van der Stok" <stokcons@xs4all.nl> wrote:

>Hi Goran and Michael,
>
>Let me ask very high-level questions about the presented slides.
>Is the diffie-hellman part a replay of the EDHOC draft? or an optimized
>extension, or completely new?
>Is the SK part an OSCOAP scenario?
>
>Will the use of CoMI be described in the minimal security draft?
>
>thanks for answering,
>
>Peter
>
>
>Göran Selander schreef op 2017-02-22 07:53:
>> Before someone slaps my fingers I should disclaim that the message
>> exchange was just a sketch to be able to discuss the number of
>> messages,
>> which party initiates, who encrypts first etc. As we all know security
>> protocols always require a lot of considerations, in this case there is
>> e.g. missing a MAC of the identity of the signing party.
>> 
>> Göran
>> 
>> 
>> On 2017-02-21 17:50, "6tisch-security on behalf of Göran Selander"
>> <6tisch-security-bounces@ietf.org on behalf of
>> goran.selander@ericsson.com> wrote:
>> 
>>> Hi Michael,
>>> 
>>> I edited the presentation during and after the meeting to summarise
>>> some
>>> points made. The protocols are as presented, the annotation I’ve
>>> added.
>>> 
>>> Göran
>>> 
>>> On 2017-02-21 15:48, "Michael Richardson" <mcr@sandelman.ca> wrote:
>>> 
>>>> 
>>>> Can I get a copy posted to the list for the records?
>>>> Thanks.
>>>> 
>>>> --
>>>> ]               Never tell me the odds!                 | ipv6 mesh
>>>> networks [
>>>> ]   Michael Richardson, Sandelman Software Works        | network
>>>> architect  [
>>>> ]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on
>>>> rails
>>>>   [
>>>> 
>> 
>> _______________________________________________
>> 6tisch-security mailing list
>> 6tisch-security@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch-security