Re: [Cfrg] Adoption call for draft-harkins-pkex-05
Benjamin Kaduk <kaduk@mit.edu> Wed, 11 April 2018 03:49 UTC
Return-Path: <kaduk@mit.edu>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 39073127023 for <cfrg@ietfa.amsl.com>; Tue, 10 Apr 2018 20:49:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nm8N_puQJ-Pi for <cfrg@ietfa.amsl.com>; Tue, 10 Apr 2018 20:49:23 -0700 (PDT)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3D00C12DA00 for <cfrg@irtf.org>; Tue, 10 Apr 2018 20:49:18 -0700 (PDT)
X-AuditID: 12074423-a4dff70000005c03-d2-5acd85bb384b
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id 50.D2.23555.CB58DCA5; Tue, 10 Apr 2018 23:49:16 -0400 (EDT)
Received: from outgoing.mit.edu (OUTGOING-AUTH-1.MIT.EDU [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id w3B3nEHl009639; Tue, 10 Apr 2018 23:49:14 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id w3B3nAbB022840 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 10 Apr 2018 23:49:13 -0400
Date: Tue, 10 Apr 2018 22:49:10 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Dan Brown <danibrown@blackberry.com>
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, "cfrg@irtf.org" <cfrg@irtf.org>
Message-ID: <20180411034907.GA97291@kduck.kaduk.org>
References: <5ACA0006.4020809@isode.com> <810C31990B57ED40B2062BA10D43FBF501C515B8@XMB116CNC.rim.net> <810C31990B57ED40B2062BA10D43FBF501C5168A@XMB116CNC.rim.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
In-Reply-To: <810C31990B57ED40B2062BA10D43FBF501C5168A@XMB116CNC.rim.net>
User-Agent: Mutt/1.9.1 (2017-09-22)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupkleLIzCtJLcpLzFFi42IR4hRV1t3TejbK4PFmJYsZq4ssun8cZLI4 3ruEyYHZY1bDWnaPyRsPs3mcajYMYI7isklJzcksSy3St0vgyniz6ChrwXXhisMXbzE3MO7j 72Lk4JAQMJE4cRDI5OQQEljMJLF5niqEvZFRYkmXShcjF5B9lUni9qkLrCAJFgFViVNfNjOB 2GwCKhIN3ZeZQWwRAQ2J2SfPsYPYzAKREi8bN4HZwgLWEnveX2AEsXmBdi26NYcRYugyRonD D7cxQSQEJU7OfMIC0awlcePfSyaQ45gFpCWW/+OACGtLLFv4GmwXp4CnxLudP9lAbFEBZYm9 fYfYJzAKzkIyaRaSSbMQJs1CMmkBI8sqRtmU3Crd3MTMnOLUZN3i5MS8vNQiXTO93MwSvdSU 0k2MoBBnd1Hewfiyz/sQowAHoxIPr8bdM1FCrIllxZW5hxglOZiURHnneZyNEuJLyk+pzEgs zogvKs1JLT7EKMHBrCTCe6AUKMebklhZlVqUD5OS5mBREuddvH9vlJBAemJJanZqakFqEUxW hoNDSYJ3UwtQo2BRanpqRVpmTglCmomDE2Q4D9BwB5Aa3uKCxNzizHSI/ClGRSlx3gUgCQGQ REZpHlwvKAVJZO+vecUoDvSKMG8lSBUPMH3Bdb8CGswENPiYzxmQwSWJCCmpBsZehwVJp+cf snZtkr728EWChMv9bTIn65X4P0Y/Tb6ycJ/f5ccBz53+dK0ommvtcUqk0nDz9WqrlofT0044 n4uUiDgyx1raVuXy/9+pW4Ks5RYoCVy2WFCudabhxlanyRecHu53/rP1wwHNtcyON66/a76f WC9rGsx18brf0ei1slPWzl6uUJmnxFKckWioxVxUnAgA3FIBhxwDAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/v5gGUtghYG4pLkP3hFkmy-edbO0>
Subject: Re: [Cfrg] Adoption call for draft-harkins-pkex-05
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Apr 2018 03:49:25 -0000
Noting that I haven't read the draft terribly recently, I nonetheless charge ahead... On Tue, Apr 10, 2018 at 08:46:35PM +0000, Dan Brown wrote: > A third very minor issue (again terminology, and arguably more pedantic): > 3. The PKEX I-D uses the word "trust" often. It seems to me that is not an > equivalent in strength trust to a more conventional public-key certificate > (or a distributed web of trust either). I think this needs clarification in > the draft. I expand on the difference below, in two closely related > sub-issues. I think that we could replace "trust" with "binding between identity and raw public key" to help us understand the intent, though the resulting language from a global search-and-replace would probably be pretty stilted. > 3a. First, if Bob lost his secret password, or has a bad RNG, then Eve may > be able to impersonate Alice to Bob, even if Alice system's is entirely > uncompromised. In regular authenticated key exchange, this type of attack > is called key-compromise impersonation (KCI). I guess KCI applies to every > PAKE, which is fair enough. But PKEX has farther aims than a just PAKE, > kind of a sub-PKI. (Is PKEX a play on PKIX?) But in a PKI, relying parties (I always assumed PKEX was a play on PKIX, even if that was not the author's intention.) > can "trust" public keys, such as code signing keys, without having any > secrets at all to guard. So, in some sense there is lesser degree of trust > provided by a PKI. > 3b. Second, and this issue is an extension of the first (not independent of > it), I would argue that part of "trust" in a public key includes an ability > to trust its use in non-repudiable signed transaction. Because of the KCI > threat, Alice could do PKEX with Bob, sign a message with her key A, then > try to repudiate. Bob will not be able to prove to anybody A is Alice's > key, because he could have generated A himself, as if Bob did a KCI attack > on himself. So, Bob will not be able to trust Alice as much as usual in a > PKI. > > At the moment I don't have a concrete suggestion to correct this > terminology. Also, I forget if PKI spec use the word "trust" or something > else. I think about it as being that a local party has trust that a given raw public key belongs to a particular peer identity. But there's not a huge need to use the word "trust"; we could talk about "confidence that a key belongs to a named party" or similar. -Ben
- [Cfrg] Adoption call for draft-harkins-pkex-05 Alexey Melnikov
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Greg Rose
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Stanislav V. Smyshlyaev
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Dan Brown
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Greg Rose
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Dan Brown
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Benjamin Kaduk
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Dan Brown
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Dan Harkins
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Blumenthal, Uri - 0553 - MITLL
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Dan Harkins
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Richard Barnes
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Dan Harkins
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Richard Barnes
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Dan Harkins
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Richard Barnes
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Blumenthal, Uri - 0553 - MITLL
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Richard Barnes
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Dan Harkins
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Richard Barnes
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Martin Thomson
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Eric Rescorla
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Daniel Harkins
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Christopher Wood
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Eric Rescorla
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Blumenthal, Uri - 0553 - MITLL
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Salz, Rich
- Re: [Cfrg] Adoption call for draft-harkins-pkex-05 Greg Rose