[homenet] Follow-up on HNCP security / trust draft

Steven Barth <cyrus@openwrt.org> Thu, 20 November 2014 09:30 UTC

Return-Path: <cyrus@openwrt.org>
X-Original-To: homenet@ietfa.amsl.com
Delivered-To: homenet@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E91A31A0149 for <homenet@ietfa.amsl.com>; Thu, 20 Nov 2014 01:30:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.978
X-Spam-Level:
X-Spam-Status: No, score=-0.978 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_MISMATCH_ORG=0.611, HOST_MISMATCH_NET=0.311] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Hgi4q1RmUCqh for <homenet@ietfa.amsl.com>; Thu, 20 Nov 2014 01:30:49 -0800 (PST)
Received: from chi.subsignal.org (cxd-2-pt.tunnel.tserv11.ams1.ipv6.he.net [IPv6:2001:470:1f14:ed::2]) by ietfa.amsl.com (Postfix) with ESMTP id 25C131A012D for <homenet@ietf.org>; Thu, 20 Nov 2014 01:30:49 -0800 (PST)
Received: from [IPv6:2001:470:52f9:0:fef8:aeff:fe3f:44b3] (unknown [IPv6:2001:470:52f9:0:fef8:aeff:fe3f:44b3]) by chi.subsignal.org (Postfix) with ESMTPSA id E8D41126077 for <homenet@ietf.org>; Thu, 20 Nov 2014 10:31:02 +0100 (CET)
Message-ID: <546DB4C6.8030401@openwrt.org>
Date: Thu, 20 Nov 2014 10:30:46 +0100
From: Steven Barth <cyrus@openwrt.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Icedove/31.2.0
MIME-Version: 1.0
To: "homenet@ietf.org Group" <homenet@ietf.org>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/homenet/HrmgV-u4aHz21XrnQTYak8xTIG0
Subject: [homenet] Follow-up on HNCP security / trust draft
X-BeenThere: homenet@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <homenet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/homenet>, <mailto:homenet-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/homenet/>
List-Post: <mailto:homenet@ietf.org>
List-Help: <mailto:homenet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/homenet>, <mailto:homenet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Nov 2014 09:30:54 -0000

Hello Everyone,

unfortunately the presentation of the security and trust draft was bit 
rushed in Hawaii.

I intent to merge that draft with the main HNCP one if there are no 
blocking objections.
So if you have some time please review it so we can get any issues or 
unclarities out of the way soon.


Here is a quick outline of the draft's contents:

* Threats to homenet border determination (with focus on automatic 
algorithm)
* Threats to HNCP payloads (multicast, unicast)
* Ways to secure the unicast channel
* 3 security models: PSK, PKI, Trust Consensus
* Details about the Trust Consensus Mechanism
* Means to bootstrap Trust Relationships
* Dealing with additional (routing) protocols (lack of) security features


Please see the slides for a short content summary.
http://tools.ietf.org/agenda/91/slides/slides-91-homenet-6.pdf

And the full draft for reference.
http://tools.ietf.org/html/draft-barth-homenet-hncp-security-trust-01



Cheers,

Steven