[hiprg] Adding Identity privacy to HIP DEX
Robert Moskowitz <rgm@htt-consult.com> Wed, 06 April 2011 00:18 UTC
Date: Wed, 06 Apr 2011 02:19:12 +0200
From: Robert Moskowitz <rgm@htt-consult.com>
To: "hiprg@irtf.org" <hiprg@irtf.org>
Subject: [hiprg] Adding Identity privacy to HIP DEX
I faded early this evening and woke up in the middle of the night (hey, I am in Stockholm right now, it is 2am) with perhaps a wild idea that may make some sense. I forfeited Identity privacy and PFS in DEX with moving the HI to ECDH and that ECDH exchange as the extent of the public key crypto in DEX. Here is my thought. The Initiator has TWO ECDH key pairs. One is the HI, the other is an identity privacy key (IPK?). I2 uses the IPK on the 'outside' with the HI encrypted for an 'inner' ECDH protected exchange. The responders HI is still exposed. It is ASSUMED that this is acceptable and that the Initiator has some mechanism to validate this HI to avoid a DH MITM. I don't know if this is worth the effort to flesh out. I have lots of other work to do on HIP-bis, HIP-DEX, core, and some Verizon projects. So I am asking here if others see Identity privacy as important enough to persue it?
