Re: [6tisch-security] agenda for 2014-05-27 6tisch security call

Jonathan Simon <jsimon@linear.com> Tue, 27 May 2014 13:41 UTC

Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 52AAC1A014E for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:41:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.587
X-Spam-Level:
X-Spam-Status: No, score=-1.587 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_MED=-2.3, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eJBLuor1evyR for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:40:59 -0700 (PDT)
Received: from p01c12o148.mxlogic.net (p01c12o148.mxlogic.net [208.65.145.71]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C8D781A014C for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:40:40 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c12o148.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id 4d594835.0.8466.00-250.22587.p01c12o148.mxlogic.net (envelope-from <jsimon@linear.com>); Tue, 27 May 2014 07:40:38 -0600 (MDT)
X-MXL-Hash: 538495d619faf12d-44a58d5ad96382f82ee9f7c57e73973a8f5e42f0
Received: from mail-qg0-f51.google.com (mail-qg0-f51.google.com [209.85.192.51]) by smtpauth1.linear.com (Postfix) with ESMTPSA id 5ACCB740C7 for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:40:35 -0700 (PDT)
Received: by mail-qg0-f51.google.com with SMTP id q107so13814037qgd.24 for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:40:35 -0700 (PDT)
MIME-Version: 1.0
X-Received: by 10.224.30.70 with SMTP id t6mr43233698qac.30.1401198035584; Tue, 27 May 2014 06:40:35 -0700 (PDT)
Received: by 10.229.117.74 with HTTP; Tue, 27 May 2014 06:40:35 -0700 (PDT)
In-Reply-To: <53840205.2070103@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com>
Date: Tue, 27 May 2014 06:40:35 -0700
Message-ID: <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com>
From: Jonathan Simon <jsimon@linear.com>
To: Rene Struik <rstruik.ext@gmail.com>
Content-Type: multipart/alternative; boundary="047d7bdca66a2beebb04fa61d7e1"
X-AnalysisOut: [v=2.1 cv=NZVo1gz4 c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=9iaqTFGLkfwA:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=AxOM2Z2vSZ8A:10 a=BLceEmwcHowA:10 a=MqDINYq]
X-AnalysisOut: [SAAAA:8 a=pGLkceISAAAA:8 a=YlVTAMxIAAAA:8 a=1XWaLZrsAAAA:8]
X-AnalysisOut: [ a=48vgC7mUAAAA:8 a=SyYMxH9GAAAA:8 a=NojvYFcnAAAA:8 a=rWPl]
X-AnalysisOut: [ndbxAAAA:8 a=07xDYRY_YWtYpDXrbQQA:9 a=2847LzV-qUdmLHL5:21 ]
X-AnalysisOut: [a=Ce8NPR-0ha2L2x3A:21 a=QEXdDO2ut3YA:10 a=wUAfXdCGL-oA:10 ]
X-AnalysisOut: [a=G1HyQLfxkfkA:10 a=19wCD08tTksA:10 a=vsVyj9psLt0A:10 a=xE]
X-AnalysisOut: [eETXzOXN8A:10 a=yRLhjdVT-pYA:10 a=uztyEWA5df8A:10 a=qVizmW]
X-AnalysisOut: [-ZYBIA:10 a=p-HxVa_ds0YA:10 a=AeFSex2-gKoA:10 a=QxAq9r8ObN]
X-AnalysisOut: [gA:10 a=ULth79YsAAUA:10 a=MSl-tDqOz04A:10 a=lZB815dzVvQA:1]
X-AnalysisOut: [0 a=xLpt9-x9cSEA:10 a=QV-tR3pPfjiHP0PDIs0A:9 a=tlHEKwvFqhT]
X-AnalysisOut: [X2m9Q:21 a=3LU24-qxkduWaGKp:21 a=JH-OAX8QlGG7W7LQ:21 a=tXs]
X-AnalysisOut: [nliwV7b4A:10]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014052710); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/s_LQeq8urO70A16rYnfEEXyjsts
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: jsimon@linear.com
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 13:41:02 -0000

Rene had asked on a previous call for someone to summarize WirelessHART
joining - here you go.

* One or more devices are sending beacons to advertise the presence of the
network. In WirelessHART, this frame is unencrypted, but authenticated with
a well known key.  The beacon contains the current ASN, which the joining
device uses to synchronize its clock.

* Once the joining node has heard a beacon, it continues listening for
additional beacons for a short specified timeout.

* The joining node encrypts a frame containing some HART specific content,
including a list of beaconing neighbors it heard in the previous steps. The
size of the payload is ~ 60 bytes.  The packet is routed by a "proxy" node
- the joining parent. The frame is authenticated using the well-known key,
and encrypted using a shared symmetric key known only by the node and the
manager.

* The manager responds with a frame containing the run-time link-layer key,
the node's new short address (this takes the place of PAN coordinator
association), and a unicast session key and starting nonce for the manager.
This frame is encrypted with the symmetric key. The payload is ~ 60 bytes,
and is routed to the proxy for delivery to the joining node - the proxy
uses the link-layer well known key on the frame.

* At this point the joining node transitions to using the run-time
link-layer key for all link-layer frames, and the manager unicast session
for end-to-end manager traffic. This ends the initial security handshake.

* Over a number of additional frames, the manager assigns additional
sessions, including broadcast sessions, and a unicast session to the
Gateway (sink for all data traffic), and additional communications
resources, routing information, etc.  There is no explicit transition from
joining to joined - the mote transitions when certain key frames are
received.

* Note that a WirelessHART link-layer frame contains and additional frame
type byte and a 4-byte link-layer MIC, on top of the unsecured 15.4 frame.
A network frame contains an additional 16-40 bytes of addressing, routing,
security and other information.

Hope this help!

Jonathan



On Mon, May 26, 2014 at 8:09 PM, Rene Struik <rstruik.ext@gmail.com> wrote:

>  Hi Michael:
>
> I would like to discuss the outstanding issues I summarized in my email of
> Tue last week, May 20, 2014, 9:45am EDT (see
> http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html<http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkffGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-PspjbppKcvxf5q4rTKYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o>).
> This was also one of the action items at the conclusion of last week's
> 6TiSCH security call.
>
> FYI - the w/HART communication flows were discussed during the 6TiSCH
> security conf call the week before, on Mon May 12, 2014. If one wishes to
> go over this again, that is fine, but I would prefer us giving preference
> to taking on already articulated issues (which were assigned as homework
> assignment to reflect upon) first (i.e., prior to item #4 of the proposed
> agenda).
>
> As another agenda point, I would like us to discuss the frequency of
> future calls (as part of EOB).
>
> Best regards, Rene
>
>
> On 5/26/2014 10:49 PM, Michael Richardson wrote:
>
> To remind, we moved the call from the 26th to the 27th at 10am EDT.
> That's 90 minutes from this email.
>
> 1) notewell.
> 2) intros
> 3) recap of draft-piro-
> 4) wirelesshart -way --- how does the communication work?
> 5) how to summarize all of this to the working group
> 6) how to close this process up?
>
> -- remember that the call is recorded, and the NoteWell applies.
>
> -- The URL to access the webex, which will we use for audio only:
>   https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908 <http://cp.mcafee.com/d/5fHCN0SyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQGmHM0L3-nOQGmHwzMh93o93gUVldTQmjhOgtu7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCmbAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT9OFoCnFZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq879OFoCq8avpKcFBzh1rjPPrz1LmTw7w17>
>
> -- we will resume with the etherpad at:
>    http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security <http://cp.mcafee.com/d/2DRPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs76zB5dAQsCT7DDD6bTdyd9aRw2zVg_oYKrfB3ZzOVLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bnjIyCHssPOEuvkzaT0QSOrodTV5xdVYsyMCqejtPo0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLbVKBTzhOnsDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodJiZvpmK6GwY>
>
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
> if you need more than that to get in, or are having difficulties.
> Please make sure your audio works, and that you mute when not talking.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca> <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -= IPv6 IoT consulting =-
>
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list6tisch-security@ietf.orghttps://www.ietf.org/mailman/listinfo/6tisch-security <http://cp.mcafee.com/d/2DRPoO86QmbEEKnjKOrKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCZKDtxVB_HYMC-C-MNRXBQSnSuvvovv7csJteOaqJNPfaxVZicHs3jr1JwTvAm4TDNOb2pEVdTdAVPmEBC5eBYTu00U9GX33VkDa3JssDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodLWbv>
>
>
>
> --
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
>
> http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd
>
>


-- 
-- 
Jonathan Simon, Ph. D
Director of Systems Engineering
Dust Networks at Linear Technology
30695 Huntwood Ave
Hayward, CA 94544-7021
(510) 400-2936
(510) 489-3799 FAX
jsimon@linear.com

**LINEAR TECHNOLOGY CORPORATION**
*****Internet Email Confidentiality Notice*****
 This e-mail transmission, and any documents, files or previous
e-mail messages attached to it may contain confidential information that
is legally privileged. If you are not the intended recipient, or a
person responsible for delivering it to the intended recipient, you are
hereby notified that any disclosure, copying, distribution or use of any of
the information contained in or attached to this transmission is
STRICTLY PROHIBITED. If you have received this transmission in error,
please immediately notify me by reply e-mail, or by telephone at (510)
400-2936, and destroy the original transmission and its attachments without
reading or saving in any manner. Thank you.