Re: [AVTCORE] I-D Action: draft-ietf-avtcore-aria-srtp-08.txt

Magnus Westerlund <magnus.westerlund@ericsson.com> Tue, 02 June 2015 14:32 UTC

Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: avt@ietfa.amsl.com
Delivered-To: avt@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B20211ACCF3 for <avt@ietfa.amsl.com>; Tue, 2 Jun 2015 07:32:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x9La425O-bRT for <avt@ietfa.amsl.com>; Tue, 2 Jun 2015 07:32:22 -0700 (PDT)
Received: from sessmg22.ericsson.net (sessmg22.ericsson.net [193.180.251.58]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E86481ACCED for <avt@ietf.org>; Tue, 2 Jun 2015 07:32:21 -0700 (PDT)
X-AuditID: c1b4fb3a-f79ec6d000006dc0-a6-556dbe7385a4
Received: from ESESSHC007.ericsson.se (Unknown_Domain [153.88.253.125]) by sessmg22.ericsson.net (Symantec Mail Security) with SMTP id 88.6A.28096.37EBD655; Tue, 2 Jun 2015 16:32:20 +0200 (CEST)
To: undisclosed-recipients:;
Received: from [127.0.0.1] (153.88.183.153) by smtp.internal.ericsson.com (153.88.183.41) with Microsoft SMTP Server id 14.3.210.2; Tue, 2 Jun 2015 16:32:19 +0200
Message-ID: <556DBE73.3020708@ericsson.com>
Date: Tue, 02 Jun 2015 16:32:19 +0200
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
References: <20150529074920.1366.12700.idtracker@ietfa.amsl.com>
In-Reply-To: <20150529074920.1366.12700.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 8bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrELMWRmVeSWpSXmKPExsUyM+JvrW7JvtxQg6l/+Sxe9qxkt5g8WcCB yWPJkp9MHl8uf2YLYIrisklJzcksSy3St0vgyvg99QFTwVuBinsntjM3MM7h6WLk5JAQMJHY 0zWZCcIWk7hwbz1bFyMXh5DAUUaJsy3t7CAJEQEZibmzH7NCJJYBJeacA+vgFdCWuNHwCqyI RUBFYuf+P4wgNpuAhcTNH41sILaoQJTE1MfrWCDqBSVOznwCZjMLOErsXNQL1issYCPxbOJ9 oJkcQAscJF48dwQJcwKVvJx9lhEkzCxgL/FgaxlEp7xE89bZzCC2ENAFDU0drBMYBWchWTAL oWMWko4FjMyrGEWLU4uLc9ONjPRSizKTi4vz8/TyUks2MQID9eCW31Y7GA8+dzzEKMDBqMTD q8CXGyrEmlhWXJl7iFGag0VJnNezKyRUSCA9sSQ1OzW1ILUovqg0J7X4ECMTB6dUA2Ppragn PUttdd5UJ4o+KuO6sKT/1enZM756qsT6iwjO6FnVH+S5d9Iy1n/dgZO8Yu8rlE2J8Vf8ntXi x+Ik8XHtq0MR7V+E4pm+a5uEaMay9XcGJtc/PHn/0P/yFm3GGzvbi6zKUpN+GCufn7x8M0P+ keJ+xosf83uUF17N3H+1RW91o4vOISWW4oxEQy3mouJEAGKHydE1AgAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/avt/o7uOMQdymLf3oIOXJU0kiku4fao>
Cc: draft-ietf-avtcore-aria-srtp@tools.ietf.org, avt@ietf.org
Subject: Re: [AVTCORE] I-D Action: draft-ietf-avtcore-aria-srtp-08.txt
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Audio/Video Transport Core Maintenance <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/avt/>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Jun 2015 14:32:23 -0000

Hi,

I have reviewed the now split document and have some few comments:

1. Section 4:

    SRTP_ARIA_128_CTR_HMAC_SHA1_80
            cipher:                   ARIA_128_CTR
            cipher_key_length:        128 bits
            cipher_salt_length:       112 bits
            maximum_lifetime:         2^31 packets
            key derivation function:  ARIA_128_CTR_PRF
            auth_function:            HMAC-SHA1
            auth_key_length:          160 bits
            auth_tag_length:          80 bits

What I reacted to is that all of the CTR mode has a maximum_lifetime of 
2^31 packets. Is there a reason for this, or could this in fact use the 
defaults for SRTP, i.e. RTP 2^48 and RTCP 2^31? I do notice that the 
maximum length is a bit inconsistent defined between the key-management 
functions for other SRTP ciphers. I assume this is an old thing, and not 
a result of the split, but I thought it best to bring up. The reason is 
that 2^31 RTP packets are actually not that many, and can force the need 
for rekeying.

I just want to understand if there is a good reason, or if this is 
taking some values, like from DTLS-SRTP for AES, that actually are 
different from the ones in SRTP (RFC3711) for that cipher.

2. Section 4:
    SRTP_ARIA_256_CTR_HMAC_SHA1_32
            cipher:                   ARIA_256_CTR
            cipher_key_length:        128 bits

I assume this should actually say "256 bits"?

3. Remove SRTP_AEAD_ARIA_128_GCM_8

Based on that AES-GCM with 64 bit tags fails to provide the expected 
security, I am of the opinion that the ARIA counter part cipher needs to 
be removed.

Cheers

Magnus Westerlund

----------------------------------------------------------------------
Services, Media and Network features, Ericsson Research EAB/TXM
----------------------------------------------------------------------
Ericsson AB                 | Phone  +46 10 7148287
Färögatan 6                 | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------