Re: [Ila] [5gangip] Fwd: New Version Notification for draft-herbert-ipv6-prefix-address-privacy-00.txt

Tom Herbert <tom@quantonium.net> Thu, 22 February 2018 01:52 UTC

Return-Path: <tom@quantonium.net>
X-Original-To: ila@ietfa.amsl.com
Delivered-To: ila@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8D3F312E04B for <ila@ietfa.amsl.com>; Wed, 21 Feb 2018 17:52:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=quantonium-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XCNG-_pFPA_o for <ila@ietfa.amsl.com>; Wed, 21 Feb 2018 17:51:59 -0800 (PST)
Received: from mail-wr0-x232.google.com (mail-wr0-x232.google.com [IPv6:2a00:1450:400c:c0c::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6532A12E049 for <ila@ietf.org>; Wed, 21 Feb 2018 17:51:59 -0800 (PST)
Received: by mail-wr0-x232.google.com with SMTP id v65so8951347wrc.11 for <ila@ietf.org>; Wed, 21 Feb 2018 17:51:59 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=quantonium-net.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=NzO0JjyQr4/fVq5DE+3DBGqB8xQxOgnSC5oMyf7zzC0=; b=0wVA9cnE84ulZJVyF/JOfyzANfbWoamEY7+QTut/OYUnLmcpY5DNcbb0E8BACW8LCi aHXEwtnid/4elTrCmdp8El3bYjhezrrZYaqX8KhSbXLE/BWBN7oyBNr1D3gRx7Ai1+Ks ylHuFScfgRyp78+eg6ljioro97ZbdOw7Rq7S5SvUcaNcSZ93RnfX9UOCsVO8kGeCBTp2 31kAsJlnh1w/OWa+mqZu66KOpKMkTaubIWLGQtJqNg7LytOxom3R5/afVBzo3wrZ0D3M xHtI+MZxDyd/2C5jUoJGHQfUv70uvYONJH7+Nyj3WhQ+1Su0aCFy4/VBVYPAWeO0z3Hb FtMw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=NzO0JjyQr4/fVq5DE+3DBGqB8xQxOgnSC5oMyf7zzC0=; b=tgtXlq1wI/rXQU3f1uiQ91lEI9k8DRDwcS5T08cbzWinvFz1mdROQD0r0smToV2YnE 39GlCHg/M38Cb08Tk2Z4JkLj+a+4zRnHcD9ZfMw02ZM1Z1isNr5KwFtq+TqW7jwXam3r esoz+jwfc11vzhZi04taRgpf/5uQHIi0w7ecg2x5a8PRpIZCgn1yUlcZzm06XU2Ds1fS LBUb0cJdCC6nP5cl/8G944KYdHmf1QFs+Swy999N1OlN2rdBE2wAp5AtrWHtouSANNr9 48DWyujIl3A8LhkJf/JgmzHZPgkhF79c0zpaqX8a/REPhqwTxEaytwGQ5OAtgrAkekOa 38Bw==
X-Gm-Message-State: APf1xPCCdA8DtrMhS+qw8D7ekvaHx/pTQ4sER2pfZR62aoqql5GFskJO Owr7Bq/mF7aWTKCjvnpFOXc1y5ile40u0CoDduK68Q==
X-Google-Smtp-Source: AH8x227MEoUvjtZJcXwa+Qz9aXuzk0StCyGeVAOvge9GwstXKhVZSgUveiEbgGIlEaAMgUFuRcMhtYdlB7JA+r5sIDc=
X-Received: by 10.223.165.67 with SMTP id j3mr3114015wrb.111.1519264317846; Wed, 21 Feb 2018 17:51:57 -0800 (PST)
MIME-Version: 1.0
Received: by 10.223.135.74 with HTTP; Wed, 21 Feb 2018 17:51:57 -0800 (PST)
In-Reply-To: <alpine.DEB.2.20.1802211654010.3478@uplift.swm.pp.se>
References: <151906718318.18731.8986618406430268357.idtracker@ietfa.amsl.com> <CAPDqMeqajavRJ85fUkrdxg1Bjz54kHuWfqbnGgpM7Br7T6MVmQ@mail.gmail.com> <alpine.DEB.2.20.1802211549260.3478@uplift.swm.pp.se> <CAPDqMerU9k4DEQrMi8qyneYB=i=1qnuwRiUf8FQoGrd_QxUmZQ@mail.gmail.com> <alpine.DEB.2.20.1802211654010.3478@uplift.swm.pp.se>
From: Tom Herbert <tom@quantonium.net>
Date: Wed, 21 Feb 2018 17:51:57 -0800
Message-ID: <CAPDqMepCnAniuCFPu+TGPJ=qOO9khXUJw3RECPvPDtU8HEAOxw@mail.gmail.com>
To: Mikael Abrahamsson <swmike@swm.pp.se>
Cc: int-area@ietf.org, ila@ietf.org, 5GANGIP <5gangip@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ila/zfDJvou3VgY9RO1QYUhLi1ahZ_g>
Subject: Re: [Ila] [5gangip] Fwd: New Version Notification for draft-herbert-ipv6-prefix-address-privacy-00.txt
X-BeenThere: ila@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Identifier Locator Addressing <ila.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ila>, <mailto:ila-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ila/>
List-Post: <mailto:ila@ietf.org>
List-Help: <mailto:ila-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ila>, <mailto:ila-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Feb 2018 01:52:01 -0000

On Wed, Feb 21, 2018 at 8:03 AM, Mikael Abrahamsson <swmike@swm.pp.se> wrote:
> On Wed, 21 Feb 2018, Tom Herbert wrote:
>
>> Host are assigned addresses from the space. The goal is that all addresses
>> appear to be randomly assigned in that space. Conceptually, a host could
>> request assignment for inidivual millions or billions of addresses, but that
>> won't scale. The alternative suggested is to assign addresses in blocks
>> using hidden aggregation as described in section 6.2.2.2. Blocks would
>> contain multiple addresses (could be thousands, millions, etc.).
>
>
> This means the host still needs to cycle these blocks over time to maintain
> privacy. Does the scaling still support a host having hundreds of these
> blocks at any given time?
>

Mikael,

Yes, blocks are a finite resource and so would have to have TTL and be
reclaimed. Also, if keys are involved in address creation they would
need expected management and key rotation. Address space should be big
enough to make long TTLs.

The hidden aggregation method is intended to make scaling possible.
Each assigned block results in on entry in mapping system so total
amount of state is num_hosts*num_blocks per host. e.g. in a network of
10M nodes with 100 blocks per host that's 1B entries in the mapping
system-- should be able to scale that. If block size is 2^16 then if
every address is in the mapping system it's 6.5e11-- harder to scale.
Aggregation is needed keep network state reasonable for scaling, but
aggregation that is visible to the outside world exposes information
about network internals of network and potentially PII as discussed in
the draft.

Tom

>
> --
> Mikael Abrahamsson    email: swmike@swm.pp.se