Re: [AVTCORE] Suite B Profile for DTLS-SRTP Internet-Draft

Magnus Westerlund <magnus.westerlund@ericsson.com> Tue, 31 May 2011 08:53 UTC

Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: avt@ietfa.amsl.com
Delivered-To: avt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 48158E0706 for <avt@ietfa.amsl.com>; Tue, 31 May 2011 01:53:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.27
X-Spam-Level:
X-Spam-Status: No, score=-106.27 tagged_above=-999 required=5 tests=[AWL=0.329, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T1vBDB1BVluq for <avt@ietfa.amsl.com>; Tue, 31 May 2011 01:53:13 -0700 (PDT)
Received: from mailgw10.se.ericsson.net (mailgw10.se.ericsson.net [193.180.251.61]) by ietfa.amsl.com (Postfix) with ESMTP id 7054FE06D3 for <avt@ietf.org>; Tue, 31 May 2011 01:53:13 -0700 (PDT)
X-AuditID: c1b4fb3d-b7c17ae00000262e-2a-4de4ac785047
Received: from esessmw0247.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw10.se.ericsson.net (Symantec Mail Security) with SMTP id 30.54.09774.87CA4ED4; Tue, 31 May 2011 10:53:12 +0200 (CEST)
Received: from [127.0.0.1] (153.88.115.8) by esessmw0247.eemea.ericsson.se (153.88.115.94) with Microsoft SMTP Server id 8.3.137.0; Tue, 31 May 2011 10:53:12 +0200
Message-ID: <4DE4AC77.9050501@ericsson.com>
Date: Tue, 31 May 2011 10:53:11 +0200
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.17) Gecko/20110414 Thunderbird/3.1.10
MIME-Version: 1.0
To: "Peck, Michael A" <mpeck@mitre.org>
References: <4FD125153A070D45BC87645D3B880288025A13CACB@IMCMBX3.MITRE.ORG>
In-Reply-To: <4FD125153A070D45BC87645D3B880288025A13CACB@IMCMBX3.MITRE.ORG>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-Brightmail-Tracker: AAAAAA==
Cc: "avt@ietf.org" <avt@ietf.org>, "kmigoe@nsa.gov" <kmigoe@nsa.gov>
Subject: Re: [AVTCORE] Suite B Profile for DTLS-SRTP Internet-Draft
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Audio/Video Transport Core Maintenance <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/avt>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 31 May 2011 08:53:14 -0000

Hi,

If I understand this document correctly there are actually three pieces
to it:

- The SuiteB Crypto algorithms for SRTP
- The SuiteB specific DTLS-SRTP procedures
- Registration of DTLS-SRTP protection profiles

Thus in light of this document and also the ARIA SRTP registration I
think we should discuss how to handle SRTP crypto algorithms and their
connection to the keying mechanisms.

SRTP has at least three different IETF define ways to be keyed:
- DTLS-SRTP [RFC5764]
- MIKEY [3830]
- Security Descriptions [RFC 4568]

And to my understanding they are all used somewhere.

>From my perspective as WG chair I wonder if shouldn't require anyone
that creates a new crypto suit for SRTP to also create the suite
profiles / identifiers for all of these three keying mechanisms?

Opinions?


Secondly, as the part that define the SRTP crypto algorithm needs to go
through this WG I would recommend the authors to submit their draft with
a new filename that includes avtcore as the second part in the filename,
for example as: draft-peck-avtcore-suiteb-dtls-srtp-00.txt

Cheers

Magnus Westerlund
WG Chair

On 2011-05-26 19:26, Peck, Michael A wrote:
> Kevin Igoe and I have submitted draft-peck-suiteb-dtls-srtp-00, Suite B Profile for Datagram Transport Layer Security / Secure Real-time Transport Protocol (DTLS-SRTP) as an independent submission.  We would appreciate any comments.
> 
> http://www.ietf.org/internet-drafts/draft-peck-suiteb-dtls-srtp-00.txt
> 
> Abstract
> 
>    The United States government has published guidelines for "NSA Suite
>    B Cryptography", which defines cryptographic algorithm policy for
>    national security applications.  This document describes the use of
>    Suite B cryptography with the Datagram Transport Layer Security
>    (DTLS) protocol, the Secure Real-Time Protocol (SRTP), and the Secure
>    Real-Time Control Protocol (SRTCP) to provide a robust architecture
>    for securing real-time data. 
> 
> Thanks,
> Mike Peck
> _______________________________________________
> Audio/Video Transport Core Maintenance
> avt@ietf.org
> https://www.ietf.org/mailman/listinfo/avt
> 


-- 

Magnus Westerlund

----------------------------------------------------------------------
Multimedia Technologies, Ericsson Research EAB/TVM
----------------------------------------------------------------------
Ericsson AB                | Phone  +46 10 7148287
Färögatan 6                | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden| mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------