Re: [Ila] [5gangip] Fwd: New Version Notification for draft-herbert-ipv6-prefix-address-privacy-00.txt

Tom Herbert <tom@quantonium.net> Thu, 22 February 2018 04:12 UTC

Return-Path: <tom@quantonium.net>
X-Original-To: ila@ietfa.amsl.com
Delivered-To: ila@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B74B124B0A for <ila@ietfa.amsl.com>; Wed, 21 Feb 2018 20:12:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=quantonium-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gMQ_iMSew0AM for <ila@ietfa.amsl.com>; Wed, 21 Feb 2018 20:12:50 -0800 (PST)
Received: from mail-wr0-x243.google.com (mail-wr0-x243.google.com [IPv6:2a00:1450:400c:c0c::243]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 95AD6127869 for <ila@ietf.org>; Wed, 21 Feb 2018 20:12:50 -0800 (PST)
Received: by mail-wr0-x243.google.com with SMTP id l43so9184126wrc.2 for <ila@ietf.org>; Wed, 21 Feb 2018 20:12:50 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=quantonium-net.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=D/uI1n+ynl+jWVY+0Z25teeeK1RHHF9SgAksNpPoa6Y=; b=bmsYZQ9UHaHVw4otT6XcIGYPsOXTQwpyPRfIRZSSfy7VvWilRajN4ZwXc0bPB0Pzwm Ldqd8PYbsYIZ37oBRvofgly6UatI/1M8Puut03PQr55KhISYxCWvhWWIvMua2FgQMwkk Yl927RUizuGRXtDQe5+nAnGSxHw70MRtIM4IBAmUD/m+Hx7V8Wij1NHfBREnTzSFG+NT Svlku6dPCZH5gwYyH1NmpYz5vcRDwumFx4Zl3FLHFbYe/qJou6blNJnGK6SkQKDk9JeT 6O8iB4a5oXEHgD5S9+XPcs0h7Kt/x9RXzrVzKdQ7b5Azh1cw4MWQ2qvs2m2nZb1aNQmc YXgA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=D/uI1n+ynl+jWVY+0Z25teeeK1RHHF9SgAksNpPoa6Y=; b=pXDfRC2CsosXWkn5f5nhFBGirpIuZh6DiB1rl40m37oiFGmdqxdyRwOwAgHeUh84ju ro02QjCidkg1wfaIx4sXN7pkWtbg6I+J/llyNYTtX4RBvdKeEVznHNCa5lNcWDNBygad HIWDx5NzEWZ/0QPtCFX7NCAHfKmMB0xzGbWgTuygjbPSw5fzfwgH362S7OHreZY0SViI PffgNqdH7/N2Vn6sHsTViwHxfbYqACMsMlmj/Xu3VpchjGM+vPHgIkOfEh+C10vfBdhH HKezurQCjKAabKf4pz7xWsp1gRewjWpospaUzryyMorT7Mwd5t3uQ9IgIEWRTcR1UAAW k8lw==
X-Gm-Message-State: APf1xPA6gAm0pG18aexihpPj+rBOGMziPINehzJi3AKuhCR19nXDohaS F1pKxLrsjgvNB39us8212ur/cBeoBzUlkil2ZoxOWQ==
X-Google-Smtp-Source: AH8x227P8FTUmiskXE5j+jfd53peSiLgnmY618EDUMw1aGKWwr7V17YctCDxu42d8QbNPv/z2MVjUJI8dS3jhtbkAMo=
X-Received: by 10.223.131.133 with SMTP id 5mr4469372wre.153.1519272769070; Wed, 21 Feb 2018 20:12:49 -0800 (PST)
MIME-Version: 1.0
Received: by 10.223.156.210 with HTTP; Wed, 21 Feb 2018 20:12:48 -0800 (PST)
In-Reply-To: <CAKD1Yr3p0P3zC_QFzQrGKAh+0eO3-rTG6_ZkWsO36dFHmk8rfQ@mail.gmail.com>
References: <151906718318.18731.8986618406430268357.idtracker@ietfa.amsl.com> <CAPDqMeqajavRJ85fUkrdxg1Bjz54kHuWfqbnGgpM7Br7T6MVmQ@mail.gmail.com> <alpine.DEB.2.20.1802211549260.3478@uplift.swm.pp.se> <CAPDqMerU9k4DEQrMi8qyneYB=i=1qnuwRiUf8FQoGrd_QxUmZQ@mail.gmail.com> <alpine.DEB.2.20.1802211654010.3478@uplift.swm.pp.se> <CAPDqMepCnAniuCFPu+TGPJ=qOO9khXUJw3RECPvPDtU8HEAOxw@mail.gmail.com> <CAKD1Yr3p0P3zC_QFzQrGKAh+0eO3-rTG6_ZkWsO36dFHmk8rfQ@mail.gmail.com>
From: Tom Herbert <tom@quantonium.net>
Date: Wed, 21 Feb 2018 20:12:48 -0800
Message-ID: <CAPDqMepfxaPLu=K-tpXbGpfZ9q1H3VT5-58R1PD2hS7rU3Vs_g@mail.gmail.com>
To: Lorenzo Colitti <lorenzo@google.com>
Cc: Mikael Abrahamsson <swmike@swm.pp.se>, ila@ietf.org, int-area@ietf.org, 5GANGIP <5gangip@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ila/GvMO2Dw8ylW_Mdghx0GI-Nx3AGA>
Subject: Re: [Ila] [5gangip] Fwd: New Version Notification for draft-herbert-ipv6-prefix-address-privacy-00.txt
X-BeenThere: ila@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Identifier Locator Addressing <ila.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ila>, <mailto:ila-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ila/>
List-Post: <mailto:ila@ietf.org>
List-Help: <mailto:ila-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ila>, <mailto:ila-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Feb 2018 04:12:52 -0000

On Wed, Feb 21, 2018 at 7:38 PM, Lorenzo Colitti <lorenzo@google.com> wrote:
> On Thu, Feb 22, 2018 at 10:51 AM, Tom Herbert <tom@quantonium.net> wrote:
>>
>> The hidden aggregation method is intended to make scaling possible.
>> Each assigned block results in on entry in mapping system so total
>> amount of state is num_hosts*num_blocks per host. e.g. in a network of
>> 10M nodes with 100 blocks per host that's 1B entries in the mapping
>> system-- should be able to scale that.
>
>
> I have a fundamental problem with the assertion "should be able to scale to
> 1B mapping entries" given that a) current routing hardware capabilities are
> three orders of magnitude away from that, and b) anyone on the Internet can
> mount a state exhaustion attack on the mapping system simply by originating
> a packet to any IPv6 address in the domain.
>
The complete mapping system is not required to be stored in a single
device it is sharded. So if a single device hold 10M entries, then 100
devices are required with some multiplier needed for redundancy and
load. The numbers are not out of line with numbers of routers that are
deployed in large provider networks today. However, scaling into the
future especially with vast numbers of IoT devices, like the 1T
devices projection, will require more work (but even without this work
on scaling is still needed).

> Personally I don't think this work should progress until we have line of
> sight to a system that can actually do that.

I would think that a major part of the work is to implement a mapping
system and identifier/locator protocol and to demonstate the scaling
properties. This is work currently in progress.

Tom