Re: [AVTCORE] Suite B Profile for DTLS-SRTP Internet-Draft

"Igoe, Kevin M." <kmigoe@nsa.gov> Tue, 31 May 2011 12:24 UTC

Return-Path: <kmigoe@nsa.gov>
X-Original-To: avt@ietfa.amsl.com
Delivered-To: avt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D1F38E0714 for <avt@ietfa.amsl.com>; Tue, 31 May 2011 05:24:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.134
X-Spam-Level:
X-Spam-Status: No, score=-6.134 tagged_above=-999 required=5 tests=[AWL=0.465, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FFzGFYkURcTP for <avt@ietfa.amsl.com>; Tue, 31 May 2011 05:24:51 -0700 (PDT)
Received: from msux-gh1-uea01.nsa.gov (msux-gh1-uea01.nsa.gov [63.239.65.39]) by ietfa.amsl.com (Postfix) with ESMTP id 7CE8BE06D4 for <avt@ietf.org>; Tue, 31 May 2011 05:24:51 -0700 (PDT)
Received: from MSCS-GH1-UEA03.corp.nsa.gov (localhost [127.0.0.1]) by msux-gh1-uea01.nsa.gov (8.12.10/8.12.10) with ESMTP id p4VCO8rR010019; Tue, 31 May 2011 12:24:08 GMT
Received: from MSIS-GH1-UEA06.corp.nsa.gov ([10.215.228.137]) by MSCS-GH1-UEA03.corp.nsa.gov with Microsoft SMTPSVC(6.0.3790.3959); Tue, 31 May 2011 08:24:08 -0400
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-MimeOLE: Produced By Microsoft Exchange V6.5
Date: Tue, 31 May 2011 08:24:08 -0400
Message-ID: <80F9AC969A517A4DA0DE3E7CF74CC1BB425B19@MSIS-GH1-UEA06.corp.nsa.gov>
In-Reply-To: <4DE4AC77.9050501@ericsson.com>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: [AVTCORE] Suite B Profile for DTLS-SRTP Internet-Draft
Thread-Index: AcwfcC4kJiuhlVKZSjeTuHQ/ihlL6wAG1oEA
References: <4FD125153A070D45BC87645D3B880288025A13CACB@IMCMBX3.MITRE.ORG> <4DE4AC77.9050501@ericsson.com>
From: "Igoe, Kevin M." <kmigoe@nsa.gov>
To: Magnus Westerlund <magnus.westerlund@ericsson.com>, "Peck, Michael A" <mpeck@mitre.org>
X-OriginalArrivalTime: 31 May 2011 12:24:08.0159 (UTC) FILETIME=[A38BA6F0:01CC1F8D]
X-Mailman-Approved-At: Tue, 31 May 2011 11:09:07 -0700
Cc: avt@ietf.org
Subject: Re: [AVTCORE] Suite B Profile for DTLS-SRTP Internet-Draft
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Audio/Video Transport Core Maintenance <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/avt>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 31 May 2011 12:24:55 -0000

Magnus:

  Thanks for your input.  We'll put this under avtcore per your request.
As to allowing keying methods other than DTLS, we have no objections
(obviously) to non-Suite B implementations using them, but in an
effort to maximize interoperability betwixt Suite B SRTP implementations
policy dictates that only DTLS keying will be allowed in Suite B mode.
If another keying methods is used, it is by definition not Suite B compliant.

If you think it would be helpful, we could mention the existence of the MIKEY 
and Security description keying mechanisms, but only with the caveat that their 
use is forbidden when running in Suite B mode.



> -----Original Message-----
> From: Magnus Westerlund [mailto:magnus.westerlund@ericsson.com]
> Sent: Tuesday, May 31, 2011 4:53 AM
> To: Peck, Michael A
> Cc: avt@ietf.org; Igoe, Kevin M.
> Subject: Re: [AVTCORE] Suite B Profile for DTLS-SRTP Internet-Draft
> 
> Hi,
> 
> If I understand this document correctly there are actually three pieces
> to it:
> 
> - The SuiteB Crypto algorithms for SRTP
> - The SuiteB specific DTLS-SRTP procedures
> - Registration of DTLS-SRTP protection profiles
> 
> Thus in light of this document and also the ARIA SRTP registration I
> think we should discuss how to handle SRTP crypto algorithms and their
> connection to the keying mechanisms.
> 
> SRTP has at least three different IETF define ways to be keyed:
> - DTLS-SRTP [RFC5764]
> - MIKEY [3830]
> - Security Descriptions [RFC 4568]
> 
> And to my understanding they are all used somewhere.
> 
> From my perspective as WG chair I wonder if shouldn't require anyone
> that creates a new crypto suit for SRTP to also create the suite
> profiles / identifiers for all of these three keying mechanisms?
> 
> Opinions?
> 
> 
> Secondly, as the part that define the SRTP crypto algorithm needs to go
> through this WG I would recommend the authors to submit their draft
> with
> a new filename that includes avtcore as the second part in the
> filename,
> for example as: draft-peck-avtcore-suiteb-dtls-srtp-00.txt
> 
> Cheers
> 
> Magnus Westerlund
> WG Chair
> 
> On 2011-05-26 19:26, Peck, Michael A wrote:
> > Kevin Igoe and I have submitted draft-peck-suiteb-dtls-srtp-00, Suite
> B Profile for Datagram Transport Layer Security / Secure Real-time
> Transport Protocol (DTLS-SRTP) as an independent submission.  We would
> appreciate any comments.
> >
> > http://www.ietf.org/internet-drafts/draft-peck-suiteb-dtls-srtp-
> 00.txt
> >
> > Abstract
> >
> >    The United States government has published guidelines for "NSA
> Suite
> >    B Cryptography", which defines cryptographic algorithm policy for
> >    national security applications.  This document describes the use
> of
> >    Suite B cryptography with the Datagram Transport Layer Security
> >    (DTLS) protocol, the Secure Real-Time Protocol (SRTP), and the
> Secure
> >    Real-Time Control Protocol (SRTCP) to provide a robust
> architecture
> >    for securing real-time data.
> >
> > Thanks,
> > Mike Peck
> > _______________________________________________
> > Audio/Video Transport Core Maintenance
> > avt@ietf.org
> > https://www.ietf.org/mailman/listinfo/avt
> >
> 
> 
> --
> 
> Magnus Westerlund
> 
> ----------------------------------------------------------------------
> Multimedia Technologies, Ericsson Research EAB/TVM
> ----------------------------------------------------------------------
> Ericsson AB                | Phone  +46 10 7148287
> Färögatan 6                | Mobile +46 73 0949079
> SE-164 80 Stockholm, Sweden| mailto: magnus.westerlund@ericsson.com
> ----------------------------------------------------------------------