[IPsec] Re: Dictionary-based key exchange (for mobile users)

"Pars Mutaf" <pars.mutaf@gmail.com> Wed, 05 December 2007 16:40 UTC

Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1IzxIM-0002fX-41; Wed, 05 Dec 2007 11:40:22 -0500
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1IzxIL-0002cX-Ay for ipsec-confirm+ok@megatron.ietf.org; Wed, 05 Dec 2007 11:40:21 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1IzxIK-0002Zg-U9 for ipsec@ietf.org; Wed, 05 Dec 2007 11:40:20 -0500
Received: from nz-out-0506.google.com ([64.233.162.233]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IzxII-0002QY-KB for ipsec@ietf.org; Wed, 05 Dec 2007 11:40:20 -0500
Received: by nz-out-0506.google.com with SMTP id n1so2621422nzf for <ipsec@ietf.org>; Wed, 05 Dec 2007 08:40:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; bh=Orp0yL9icvkOvz5DpsqkdoqmhsbJtkGHaCpPH6I7B5c=; b=DY9RZLy8QuknGVWnSbMXuoe9VI5b1dSm0hDOOsNOa4t0ls20VSSNEKCs4OH37+lexn0MuF9sZ8ke35j6jxj3CLdi4xtST6TzgSv3loFcZptHfwjunqttppRaosMYz/9gCysxi+VjkJoWmR2bGo3wKYWbgmVOt3Q9/cmYVQ40Ak0=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=UXZzw1DBhH2A9UCxkF191zIeizGDk60Sg2A58Lx4xw6JsKbTSxECCR8Lq8p1Bm8el8IxZsa2adaYK0BynuPBvlCLuNmQlu0JR6By8HNp9b0wmDce9rnwJmOPaLyr+MP9UDNLgK6vJOg7wxhC9Mj7TkIq+6WhbUwP5Ok/PJw7tvo=
Received: by 10.142.106.18 with SMTP id e18mr1057240wfc.1196872817012; Wed, 05 Dec 2007 08:40:17 -0800 (PST)
Received: by 10.70.117.20 with HTTP; Wed, 5 Dec 2007 08:40:16 -0800 (PST)
Message-ID: <18a603a60712050840t59b19641l2e40113ef72ca24c@mail.gmail.com>
Date: Wed, 05 Dec 2007 17:40:16 +0100
From: Pars Mutaf <pars.mutaf@gmail.com>
To: ipsec@ietf.org
In-Reply-To: <18a603a60711161050i3f8130c2q1316a2876472fb16@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
References: <18a603a60711161050i3f8130c2q1316a2876472fb16@mail.gmail.com>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 52f402fbded34a6df606921f56b8bdd8
Subject: [IPsec] Re: Dictionary-based key exchange (for mobile users)
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org

Hello,
An implementation can be found below (using TCP transport
because future extension is possible for exchanging a large
dictionary). It supports GTK word completion with mouse and
keyboard.

http://code.google.com/p/vke/

Michael Richardson and Nicolas Williams suggested
changing the name to something like Verbal Key Exchange.

Thanks,
pars

On Nov 16, 2007 7:50 PM, Pars Mutaf <pars.mutaf@gmail.com> wrote:
> Hello,
> I would very much appreciate some feedback on the following
> draft (very short). Thanks in advance.
>
> Regards,
> pars
>
> --------cut here ---------
>
>
>
>
> Network Working Group                                           P. Mutaf
> Internet-Draft                                     Institut National des
>                                                       Telecommunications
> Expires: May 19, 2008                                  November 16, 2007
>
>
>                      Dictionary-based Key Exchange
>                          draft-mutaf-dke-00.txt
>
> Status of this Memo
>
>    By submitting this Internet-Draft, each author represents that any
>    applicable patent or other IPR claims of which he or she is aware
>    have been or will be disclosed, and any of which he or she becomes
>    aware will be disclosed, in accordance with Section 6 of BCP 79.
>
>    Internet-Drafts are working documents of the Internet Engineering
>    Task Force (IETF), its areas, and its working groups.  Note that
>    other groups may also distribute working documents as Internet-
>    Drafts.
>
>    Internet-Drafts are draft documents valid for a maximum of six months
>    and may be updated, replaced, or obsoleted by other documents at any
>    time.  It is inappropriate to use Internet-Drafts as reference
>    material or to cite them other than as "work in progress."
>
>    The list of current Internet-Drafts can be accessed at
>    http://www.ietf.org/ietf/1id-abstracts.txt.
>
>    The list of Internet-Draft Shadow Directories can be accessed at
>    http://www.ietf.org/shadow.html.
>
>    This Internet-Draft will expire on May 19, 2008.
>
> Copyright Notice
>
>    Copyright (C) The IETF Trust (2007).
>
> Abstract
>
>    A dictionary-based key exchange protocol is proposed.  Two mobile
>    host users that physically meet each other can use this protocol to
>    authenticate each other.  PKI nor certificates are not needed.
>
>
>
>
>
>
>
>
> Mutaf                     Expires May 19, 2008                  [Page 1]
>
> Internet-Draft        Dictionary-based Key Exchange        November 2007
>
>
> Table of Contents
>
>    1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . . . . 3
>    2.  Protocol description  . . . . . . . . . . . . . . . . . . . . . 3
>    3.  Security considerations . . . . . . . . . . . . . . . . . . . . 3
>    4.  IANA considerations . . . . . . . . . . . . . . . . . . . . . . 4
>    5.  Conclusion  . . . . . . . . . . . . . . . . . . . . . . . . . . 4
>    6.  Informative References  . . . . . . . . . . . . . . . . . . . . 4
>    Author's Address  . . . . . . . . . . . . . . . . . . . . . . . . . 4
>    Intellectual Property and Copyright Statements  . . . . . . . . . . 5
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
> Mutaf                     Expires May 19, 2008                  [Page 2]
>
> Internet-Draft        Dictionary-based Key Exchange        November 2007
>
>
> 1.  Introduction
>
>    A dictionary-based key exchange protocol is proposed.  Two mobile
>    host users that physically meet each other can use this protocol to
>    authenticate each other.  PKI nor certificates are not needed.
>
>
> 2.  Protocol description
>
>    The proposed protocol is briefly described below:
>
>
>           Initiator              MitM                 Responder
>
>                      Request RSA public key PK
>            ----------------------------------------------->
>                                   PK
>          | <--------------------------------------------
>       T  |
>          | <========== Read 40-bit fingerprint ============
>    human verification
>    of 40-bit fingerprint
>
>            -----------------{secret key}PK --------------->
>
>    where
>            PK: a one time RSA public key
>            ===: voice channel, i.e. responder user tells the fingerprint
>                 to initiator user through oral communication.
>            MitM: Man in the Middle
>
>                                  Figure 1
>
>    The octets of the fingerprint will typically be mapped to a
>    dictionary of easy to pronounce and type well-known words.  For
>    example, with a dictionary containing 256 words, each octet can be
>    represented with one word in the dictionary, and only 40/8=5 words
>    need to be checked.
>
>    In T time units, MitM has to find a PK' giving the same fingerprint
>    as PK, and returned it to the initiator before PK. 2^40 is large
>    enough to assume that the attacker cannot reasonably succeed.
>
>
> 3.  Security considerations
>
>    TBD.
>
>
>
>
> Mutaf                     Expires May 19, 2008                  [Page 3]
>
> Internet-Draft        Dictionary-based Key Exchange        November 2007
>
>
> 4.  IANA considerations
>
>    None.
>
>
> 5.  Conclusion
>
>    This document described a dictionary-based key exchange protocol.
>    The idea of human verification of a public key fingerprint is not
>    new.  A 40-bit fingerprint is normally too short and considered
>    insecure (See for example [SB].).  In the proposed protocol, however,
>    the fingerprint is used to authenticate a one-time public key that is
>    used to exchange a secret key and possibly other material.
>
>
> 6.  Informative References
>
>    [SB]  McCune, J. and J. McCune, "Seeing is Believing", Proceedings of
>          the IEEE Symposium on Security and Privacy, Oakland, CA. May
>          2005.
>
>
> Author's Address
>
>    Pars Mutaf
>    Institut National des Telecommunications
>
>    Email: pars.mutaf@gmail.com
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
> Mutaf                     Expires May 19, 2008                  [Page 4]
>
> Internet-Draft        Dictionary-based Key Exchange        November 2007
>
>
> Full Copyright Statement
>
>    Copyright (C) The IETF Trust (2007).
>
>    This document is subject to the rights, licenses and restrictions
>    contained in BCP 78, and except as set forth therein, the authors
>    retain all their rights.
>
>    This document and the information contained herein are provided on an
>    "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS
>    OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY, THE IETF TRUST AND
>    THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS
>    OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF
>    THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED
>    WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
>
>
> Intellectual Property
>
>    The IETF takes no position regarding the validity or scope of any
>    Intellectual Property Rights or other rights that might be claimed to
>    pertain to the implementation or use of the technology described in
>    this document or the extent to which any license under such rights
>    might or might not be available; nor does it represent that it has
>    made any independent effort to identify any such rights.  Information
>    on the procedures with respect to rights in RFC documents can be
>    found in BCP 78 and BCP 79.
>
>    Copies of IPR disclosures made to the IETF Secretariat and any
>    assurances of licenses to be made available, or the result of an
>    attempt made to obtain a general license or permission for the use of
>    such proprietary rights by implementers or users of this
>    specification can be obtained from the IETF on-line IPR repository at
>    http://www.ietf.org/ipr.
>
>    The IETF invites any interested party to bring to its attention any
>    copyrights, patents or patent applications, or other proprietary
>    rights that may cover technology that may be required to implement
>    this standard.  Please address the information to the IETF at
>    ietf-ipr@ietf.org.
>
>
> Acknowledgment
>
>    Funding for the RFC Editor function is provided by the IETF
>    Administrative Support Activity (IASA).
>
>
>
>
>
> Mutaf                     Expires May 19, 2008                  [Page 5]
>
>


_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec