Re: [Iotops] I-D Action: draft-ietf-iotops-security-protocol-comparison-04.txt

John Mattsson <john.mattsson@ericsson.com> Mon, 04 March 2024 17:34 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: iotops@ietfa.amsl.com
Delivered-To: iotops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 78E5AC15793B for <iotops@ietfa.amsl.com>; Mon, 4 Mar 2024 09:34:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uRaxe8OT6JkA for <iotops@ietfa.amsl.com>; Mon, 4 Mar 2024 09:34:19 -0800 (PST)
Received: from EUR03-AM7-obe.outbound.protection.outlook.com (mail-am7eur03on2080.outbound.protection.outlook.com [40.107.105.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 86F8AC165518 for <iotops@ietf.org>; Mon, 4 Mar 2024 09:34:19 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=FLs3qijQPfnakESj7F67LM475/FFpTlWbecsYOHtmVgulb8DkqVYUrgvXNkg59jLYLl68pJEy2eQo/IUI7TVtwLZKsizd/dIlx6IvQzaFGJI3C34ak8ia43eZj5GtJYkhEvgyfUbzOKU761dmrfEpXYoO9OUrDJFiXG05EYsotWrkqOxpvX0UWqtd0+/1sCDzRs57PS459Uyt/CS/xCJrXh0I8AQ6wLlOpswL81tEZEVp27CqFWN8IFpymv/3nPcHEdKLp88QrRFrpL1VJBSLdGNAcJGf1XXl3g7WS685b0B5mSdKnoL0/q4CJOayX+xw+esMFCUQnHb07H2mlar9A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=iKk8IulKJKJxnF5gRCO/gTXdbTmLLFUEiG9/govGBgI=; b=EzN/vywNJYMzUar6WH+D1mpl2sjxfUrLnSoLJlEUctwGGesPapvF8h+a1v0dIq8zvACaQChmfZkVXHVcrT2KPf9qVDZElnTo73TFiRfwjk3biQSj/Rcx5+PxObWmjBP0Ucdb6E7Knsh0oy9FGYY+7y4xFiPnH8pPbMw68xn0dcUzn3V0EzCMUgfXJFFCh1002vJVoE0ltcm4mgrMXgqs7570AtESrRH6bXLR5OWfFZGNyfj/35mpquEVRDewV3ptinw7Kl+FXZhJb6yVlKYOjY14Ncuo7w1ZmY9It+7ht6sEne/PCFeJKAkJjTXgMqbwf/B/HV6gv7CfUzen/HVhqQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=iKk8IulKJKJxnF5gRCO/gTXdbTmLLFUEiG9/govGBgI=; b=EW2FStthqCDPy5GF6MS3NGZyh/u3SJ+NrBOj23/LGzxZUdkT9C8UT2BcvE5DapXQ+AYxbhiFBHUvqvYnY0QWt0E4HDC2g1KIWYQM6TOPfhJalsAJ66S7F4OBksSE14MQv5Ectrd2DaHPVZbKgzg01uAGcn1RDN20ZI3+32CHB66ZGZ3gZrG4OaqCjjSrV7N01IuZ2ZpBzjaANA0BGmgU1b9hQMOPSI3k55p3O8nVv4DTzvKRsrKCXhdk0Ho4qPjWCleMrhg0n6jSSNJUL+pUmQVXR4IbXrVZbb5n+T8j3NEjZWAujJ7wSRAwTHfl2yox8CnVS3Htd09af9ajxGaD7A==
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com (2603:10a6:150:114::10) by DBBPR07MB7418.eurprd07.prod.outlook.com (2603:10a6:10:1e0::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7339.38; Mon, 4 Mar 2024 17:34:16 +0000
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::b0d0:9785:585a:9568]) by GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::b0d0:9785:585a:9568%4]) with mapi id 15.20.7339.035; Mon, 4 Mar 2024 17:34:16 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: "iotops@ietf.org" <iotops@ietf.org>
Thread-Topic: [Iotops] I-D Action: draft-ietf-iotops-security-protocol-comparison-04.txt
Thread-Index: AQHablouF+rarjhOEkS8Axqh0+pGFA==
Date: Mon, 04 Mar 2024 17:34:16 +0000
Message-ID: <GVXPR07MB9678EFCD59792FD5AAD5F22589232@GVXPR07MB9678.eurprd07.prod.outlook.com>
References: <170957086926.43395.7700466175182950217@ietfa.amsl.com>
In-Reply-To: <170957086926.43395.7700466175182950217@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVXPR07MB9678:EE_|DBBPR07MB7418:EE_
x-ms-office365-filtering-correlation-id: 8ca0fa25-1577-4d97-a9ba-08dc3c7150d1
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: FAGc+WeXe9bUoNxBB02WcmzMfsrrDncuGyuz22O/cjJj8TrQkel4m6zRd23Ouj1hmbvCGqtKul/rXLWIwt9lfbaOQwQguJrOd4b73h9y3TsOq9+yb18n5gLSV+HrQIJ1PXmyW/84E4kAOGRL1EBa4TfpJtZJ4weAHkydDy5c/SeWVkuYBnw7e3p2ocJJC1s9agq/d6KHrrFmSDim1we7AzlRz+aOrvSU5D5iJScS+qdER7RnBTwEiWV3fvDspcManNQzs4uIic4o8F8AJAr9yb8mhYF0GVTgWJVybUA5EZXLduT4FLMDZowCwHHxoL39cIgtXZbM22yTNNgfSSc3NKBQ9ynotoucri4XNEfMw6auJsa6opwG9CSZsjsfLw6PwSSVN/P8TXcMyE/doNI4HBBhLS7GeYDIXdhXnFlwN0bo+anH1918vTlUyZ3Y2qRXq5RFD1pnRkfjDEVOEqJJlNhJj9OGvAyzQOaAIN3Sg89GR5g2bWeoAK3hjp/C2pXKYihyRyY8U8NgZSCECd4iNqxEdOhLaOpbGDZo+OhR8wcXFLU5q59A3gTbaUCfeOuxWWBIYUck9jEwSiIMcbOw7OwfpldD6Ocf1YdQP+wXpcWuJqnDi4+A5zpuGRKKlsiyN58BwKBfe9fKYTnDSezifaYsrKH+Y1Vp0FipjM1EGX47Y84CvDbSyTGGPNrX7Mfx
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVXPR07MB9678.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376005)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: FVNpBxECPLJBfCDfzISUenOBviJWznkTtwR1OFeWClwLpjcGTj4XillW9c1U8uruuMxK08uPVMHVRPSQtzEYm4x0bgUMw4ikw1hA+qzB0Vp3NLMjmH7Vtl2whKAoINPwsgYJFrJwXsnnm2/ntwAn9bzNjGd2ebj6rTdKjtleOU1zOGyAC2vGQq71tryA7i9sda04Q4JmoUKxfDb2kECwrTc4oWr3TI2JHrwK3dt+ara4Cuj9woVd5kFJBX187P0rlLOI0r9ThKB630A7oPAEkb2MhsqHgM5fishNlEIbgLIEGViQVuFDaCYrYe6P7u1ncBC5UGP6vGevRbR4c1qfWSZhkDUfZfl7QQmfTIZsiXpSjr03RvbbaVxwFaDJnQVE01qyb3Rmiwv5TF6EWolJ2pVkumrjyy83TkjLjH4Cp01PRBrjyUqMRmCACo1Kkf25BbmiEAR82Njm9zZhFbm5ixqhMmlaQjGxj/wImAbBcj7FrC8JOCQeANAhzr+yIckEEtl3hoabYFtKFz6F3iedmXO0hHHBOeOshdOzHxHe9v3IHzqnH4NBD2dGmKVhWwpXUeV6AYBNljKEHG+9XCt7QvElJ+NsjSmOktNE9v2BXgF3rFqD1vbF528jHTvB/Z3eUyifO5SSJPYF0ROCzF7CqsVz2tLKu5VqEGgVyA5DKN1lHSDQNEGAXFssRrFca23qPBlOFzi709uSn3waZHgO2/CWB08Aa+rW19wqdPHjaB6gaoV2uapcuR7hXcFfn15T2T2X/rpO7VskxSwYo34oZCiWq591b7zqpgI+Z6I3xHMMbnzWM2ifuDMhB6l2UDvouGQZd5NPcpsQg4VkV4dT54eLfMn8kRA5ewwqQ6y4+vDMIWMKGKxXbJ9fV5lg7kkjsuyFz0tItG2vwi9MHbGbKrkAfKBUEO5OsTtGF18y5vx/9ih8+JldgD2mSL3GvVpciGe66wv+lMoqjxhzWFXQ0ySMuSGH+90bkvGl7GpZSg3x0+wt89IsbUA3OLXjr/BuZKj+R77j7bzGaRZ0fQwk2cv6Hr/CfzdQ3R5aU+sJ4YKyK0YC2IfR4WwFPonpdcO2tzq8nElIEiR9wc8kEHnKmcDqzpYvIBaX+8525Ql5Vt9QoFFEovDD1CdzLFFQHDFVgQ2tIe5iEsCuh31u+r0h/IAlrqM3alY8L3j0QT7u0SeNMeiCVwIa2zGbfzUVayie08JcV1goGqhl+MUbI0Qt/2eoJSHA0/b+OFJg9pmjCNnJvuQE8SmHwD9bDcDeIgloYm7M3Et2QW8sUt2/UTVixj1dllIoLI8urXGENcZj6fQcHlAJD3yCvXOrXvJ/fx6NWJrX0Ao4DCfALtNvjwpPRjMWZQHVrztQ4+Avs1ZYZP6sLy5yNxeS9p/+KZtGuofdnEND+JLjHW6HXfUapmlSAQHlN+mrc2Ce/ryHWwVkbpyEqP41AliK6DC6kdN03DGxFhkGrzMFc819QoSWTcAizEWSnp2u007qP78hTaLILoEg7Y2R/H2UlhMWoU0AI+FrmNNSfgLbwSKDlytIztvBf1o1sqfHsSG+pU7tac6+EcJ5ZBFzsCCdyzFjWg5c18mxkp37MFyiA09nMHaQNSspJVEqg4SascwZ2BfiaOuKrow=
Content-Type: multipart/alternative; boundary="_000_GVXPR07MB9678EFCD59792FD5AAD5F22589232GVXPR07MB9678eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVXPR07MB9678.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8ca0fa25-1577-4d97-a9ba-08dc3c7150d1
X-MS-Exchange-CrossTenant-originalarrivaltime: 04 Mar 2024 17:34:16.4587 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: FgerSLOh9xm+UiC9n+WR6DTyA9272iHexRVdJ0qeOffUZV2OciCgfOsJv9UVKeKLzUxFdlKdlIPpoW0nbxc9baE17ujY1tS+000cZSHHdGc=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBBPR07MB7418
Archived-At: <https://mailarchive.ietf.org/arch/msg/iotops/l7XD8RzSGCEP45T7X4j9uRiRdv4>
Subject: Re: [Iotops] I-D Action: draft-ietf-iotops-security-protocol-comparison-04.txt
X-BeenThere: iotops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IOT Operations <iotops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/iotops>, <mailto:iotops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/iotops/>
List-Post: <mailto:iotops@ietf.org>
List-Help: <mailto:iotops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/iotops>, <mailto:iotops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Mar 2024 17:34:23 -0000

Hi,

We have submitted version -04 of draft-ietf-iotops-security-protocol-comparison. We think -04 addresses the comments in the iotdir early review. Additional changes can be found in the new change log.

Changes from -03 to -04:

   *  Added change log

   *  Updated to cTLS-09, which seems relatively stable.

   *  Explained key and certificate identifiers.

   *  Added a paragraph to introduce the section on underlying layers.

   *  Added text explaining the difference between AKEs and protocols
      for protection of application data.

   *  Added reference to RFC 7250, RFC 9547, and "Performance Comparison
      of EDHOC and DTLS 1.3 in Internet-of-Things Environments".

   *  Editorial changes.



Changes from -02 to -03:



   *  Security considerations linking to the security considerations for

      the protocols as well as newer recommendations and best practices.



   *  Moved "EDHOC Over CoAP and OSCORE" subsection to appendix.



   *  References for the algorithms.



   *  Editorial changes.

Cheers,
John Preuß Mattsson

From: internet-drafts@ietf.org <internet-drafts@ietf.org>
Date: Monday, 4 March 2024 at 17:47
A new version of Internet-Draft
draft-ietf-iotops-security-protocol-comparison-04.txt has been successfully
submitted by John Preuß Mattsson and posted to the
IETF repository.

Name:     draft-ietf-iotops-security-protocol-comparison
Revision: 04
Title:    Comparison of CoAP Security Protocols
Date:     2024-03-04
Group:    iotops
Pages:    54
URL:      https://www.ietf.org/archive/id/draft-ietf-iotops-security-protocol-comparison-04.txt
Status:   https://datatracker.ietf.org/doc/draft-ietf-iotops-security-protocol-comparison/
HTML:     https://www.ietf.org/archive/id/draft-ietf-iotops-security-protocol-comparison-04.html
HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-iotops-security-protocol-comparison
Diff:     https://author-tools.ietf.org/iddiff?url2=draft-ietf-iotops-security-protocol-comparison-04

Abstract:

   This document analyzes and compares the sizes of key exchange flights
   and the per-packet message size overheads when using different
   security protocols to secure CoAP.  Small message sizes are very
   important for reducing energy consumption, latency, and time to
   completion in constrained radio network such as Low-Power Wide Area
   Networks (LPWANs).  The analyzed security protocols are DTLS 1.2,
   DTLS 1.3, TLS 1.2, TLS 1.3, cTLS, EDHOC, OSCORE, and Group OSCORE.
   The DTLS and TLS record layers are analyzed with and without 6LoWPAN-
   GHC compression.  DTLS is analyzed with and without Connection ID.



The IETF Secretariat