Re: [6tisch] Extending CoJP (minimal-security) for non-6TiSCH 802.15.4 networks

Michael Richardson <mcr+ietf@sandelman.ca> Mon, 12 September 2022 08:00 UTC

Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch@ietfa.amsl.com
Delivered-To: 6tisch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7BBE7C1524B3 for <6tisch@ietfa.amsl.com>; Mon, 12 Sep 2022 01:00:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.105
X-Spam-Level:
X-Spam-Status: No, score=-1.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_TEMPERROR=0.01] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7vR-1OLKYKY8 for <6tisch@ietfa.amsl.com>; Mon, 12 Sep 2022 01:00:23 -0700 (PDT)
Received: from relay.sandelman.ca (unknown [176.58.120.209]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A6414C1522A2 for <6tisch@ietf.org>; Mon, 12 Sep 2022 01:00:22 -0700 (PDT)
Received: from dooku.sandelman.ca (unknown [176.61.111.84]) by relay.sandelman.ca (Postfix) with ESMTPS id EF30E1F4C0; Mon, 12 Sep 2022 08:00:18 +0000 (UTC)
Received: by dooku.sandelman.ca (Postfix, from userid 179) id 760AC1A029C; Mon, 12 Sep 2022 09:59:47 +0200 (CEST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Christian =?iso-8859-1?Q?Ams=FCss?= <christian@amsuess.com>, =?utf-8?B?TWFsacWhYSBWdcSNa W5pxIc=?= <malisa.vucinic@inria.fr>, 6tisch@ietf.org
In-reply-to: <YxxnXvHE3WnCt/UO@hephaistos.amsuess.com>
References: <YUcakTFqibo5wEfe@hephaistos.amsuess.com> <102718.1632080924@dooku> <YUhQp3wQ6O3qXp6R@hephaistos.amsuess.com> <618FD3B4-2935-4D9E-9F96-B63454890B50@inria.fr> <YUhoXt7T8bLAU2gZ@hephaistos.amsuess.com> <E4FD542C-3751-4C15-8716-06F9C618C2F9@inria.fr> <YxxnXvHE3WnCt/UO@hephaistos.amsuess.com>
Comments: In-reply-to Christian =?iso-8859-1?Q?Ams=FCss?= <christian@amsuess.com> message dated "Sat, 10 Sep 2022 12:30:54 +0200."
X-Mailer: MH-E 8.6+git; nmh 1.7.1; GNU Emacs 27.1
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Mon, 12 Sep 2022 09:59:47 +0200
Message-ID: <35674.1662969587@dooku>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch/ofldIqgqqXhexO1cPWmPRadsUq4>
Subject: Re: [6tisch] Extending CoJP (minimal-security) for non-6TiSCH 802.15.4 networks
X-BeenThere: 6tisch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Discuss link layer model for Deterministic IPv6 over the TSCH mode of IEEE 802.15.4e, and impacts on RPL and 6LoWPAN such as resource allocation" <6tisch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch>, <mailto:6tisch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch/>
List-Post: <mailto:6tisch@ietf.org>
List-Help: <mailto:6tisch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch>, <mailto:6tisch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 Sep 2022 08:00:25 -0000

Christian Amsüss <christian@amsuess.com> wrote:
    > So before going on with questions about "how would any of this be
    > signaled", my question is:

    > * Do RFCs 9030/9031 allow that a device uses an explicit frame counter,
    > which it increments in its own pace?

They don't say anything about it, I think.
It's an IEEE/802.15.4 issue.

6tisch specifies TSCH mode, which includes the ASN.
(To be clear: Christian is trying to come up with something non-TSCH that can
be used for plain 802.15.4, but which does not use 802.15.9 to do per-pair keying)

    >   * If yes, shouldn't there be more stern words in 9031 about allowing
    > a new key to be used with the same EUI-64 (considering that the device
    > may not get a short identifier)?

The EUI-64 goes into the key schedule.
Different EUI-64s get different keys, even if the counter is the same.


-- 
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-