[Iotsi] IoT Security

Russ Housley <housley@vigilsec.com> Tue, 22 March 2016 15:06 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: iotsi@ietfa.amsl.com
Delivered-To: iotsi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E5DC712D87A for <iotsi@ietfa.amsl.com>; Tue, 22 Mar 2016 08:06:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level:
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x3_Avf9ow1go for <iotsi@ietfa.amsl.com>; Tue, 22 Mar 2016 08:06:13 -0700 (PDT)
Received: from odin.smetech.net (x-bolt-wan.smeinc.net [209.135.219.146]) by ietfa.amsl.com (Postfix) with ESMTP id C3D4A12D9F4 for <iotsi@iab.org>; Tue, 22 Mar 2016 08:06:05 -0700 (PDT)
Received: from localhost (ronin.smetech.net [209.135.209.5]) by odin.smetech.net (Postfix) with ESMTP id CE6F8F2406A for <iotsi@iab.org>; Tue, 22 Mar 2016 11:06:05 -0400 (EDT)
X-Virus-Scanned: amavisd-new at smetech.net
Received: from odin.smetech.net ([209.135.209.4]) by localhost (ronin.smeinc.net [209.135.209.5]) (amavisd-new, port 10024) with ESMTP id dzX6uCh0RA8a for <iotsi@iab.org>; Tue, 22 Mar 2016 10:52:30 -0400 (EDT)
Received: from [192.168.2.100] (pool-108-51-128-219.washdc.fios.verizon.net [108.51.128.219]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by odin.smetech.net (Postfix) with ESMTP id 78A889A4004 for <iotsi@iab.org>; Tue, 22 Mar 2016 11:06:05 -0400 (EDT)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Message-Id: <52B6085F-DF7A-40A9-8556-82EA62EDDB50@vigilsec.com>
Date: Tue, 22 Mar 2016 11:04:33 -0400
To: iotsi@iab.org
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/iotsi/e_5seCMJkjut9w4kLsk32csnfDo>
Subject: [Iotsi] IoT Security
X-BeenThere: iotsi@iab.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Internet of Things Semantic Interoperability Workshop <iotsi.iab.org>
List-Unsubscribe: <https://www.iab.org/mailman/options/iotsi>, <mailto:iotsi-request@iab.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/iotsi/>
List-Post: <mailto:iotsi@iab.org>
List-Help: <mailto:iotsi-request@iab.org?subject=help>
List-Subscribe: <https://www.iab.org/mailman/listinfo/iotsi>, <mailto:iotsi-request@iab.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Mar 2016 15:06:14 -0000

At the workshop we talked about gateways that translate the syntax while preserving the semantics.  It was very clear how one might provide confidentiality and integrity for connections to the gateway, but no one had any suggestions for end-to-end confidentiality or integrity.  As requested at the workshop, I am starting this tread to resume that discussion.

Russ