[IPsec] IP host pairing
"Pars Mutaf" <pars.mutaf@gmail.com> Tue, 30 October 2007 16:48 UTC
Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1ImuGT-0002I3-Ai; Tue, 30 Oct 2007 12:48:29 -0400
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1ImuGS-0002Hu-25 for ipsec-confirm+ok@megatron.ietf.org; Tue, 30 Oct 2007 12:48:28 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1ImuGR-0002Hk-Of for ipsec@ietf.org; Tue, 30 Oct 2007 12:48:27 -0400
Received: from wx-out-0506.google.com ([66.249.82.225]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1ImuGL-0002so-9u for ipsec@ietf.org; Tue, 30 Oct 2007 12:48:27 -0400
Received: by wx-out-0506.google.com with SMTP id s8so1826467wxc for <ipsec@ietf.org>; Tue, 30 Oct 2007 09:48:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:mime-version:content-type; bh=6AMq/QThczFXpe2wsFFlSUPg4MBHNNo9G+vDmdXLm8U=; b=GGBxoTtzLnTqWJvaxYtznxcgo1La8Cd7SFlJLz/WMduMFzv0A0IsCPa1WdZivWqEz6xBZQsuE0p7OBUxEqobNiM2XztQw9CpiZItCqzeZ/EbF2mnRqodLHpr0pVKfpqGtZJue/9dDmXrXfa6RlRF4bALG6543AOKjl/uM+c4C2E=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:mime-version:content-type; b=Vamt2CZDg2bE5YC/tS9moGxm5p1kdtBJHpwoEMl0qdu9jSyCf5TGmm+bjtIjwgPg1QH6m3T7l08g6tSMd0aHSBBRbrm+K1jFSyzwr+iWEjoE4RXnpjMIV4CqT/kYef5GOL+aNHxTwk9jfkZnnV/BBuJkUVKlKRGIvUeo6STAJr4=
Received: by 10.70.14.17 with SMTP id 17mr12849739wxn.1193762889936; Tue, 30 Oct 2007 09:48:09 -0700 (PDT)
Received: by 10.70.117.20 with HTTP; Tue, 30 Oct 2007 09:48:09 -0700 (PDT)
Message-ID: <18a603a60710300948s32a0db87lcddfa06470facbb7@mail.gmail.com>
Date: Tue, 30 Oct 2007 17:48:09 +0100
From: Pars Mutaf <pars.mutaf@gmail.com>
To: ipsec@ietf.org
MIME-Version: 1.0
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 41c17b4b16d1eedaa8395c26e9a251c4
Subject: [IPsec] IP host pairing
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============1288826033=="
Errors-To: ipsec-bounces@ietf.org
Dear all,
Comments on the following problem statement would be very much
appreciated.
Regards,
pars mutaf
------------------
IP host pairing problem statement
In the current model of operation (phone number privacy obligates it),
cell phone users exchange their phone numbers upon user contact. This
model is likely to persist in IP telephony, yet under exploited and can be
extended using an IP protocol. Upon their meeting, an "IP host pairing"
protocol can allow two cell phone users to:
1. Exchange their SIP URIs, mobile IPv6 home addresses, and possibly
other information.
2. Establish an IPsec security association using IKEv2.
under user control, i.e. _if accepted_ by the users. For example, one
user will initiate a pairing request, and the target user's phone display
the initiator user's human name and ask for approval.
Since there is user contact, IKEv2 authentication can be less challenging
than the general case. I.e., a global PKI hierarchy is probably not
needed. Solutions like password-based IKEv2 authentication can be applied.
Human name certificates can be applicable, certificate revocation may not
be needed, and human name collisions may not be harmful in this context.
Certificates may be signed by the cellular operators for example, or
PGP-like web of trust solutions may be applicable.
An IP-layer pairing solution can also allow for re-pairing or updating
the pairing state through the Internet. The users may change their
SIP URIs and/or Mobile IPv6 home addresses or other information. The users
will need to update these informations without waiting until their next
meeting. Or, they may need additional information which was not previously
exchanged when there was user contact.
==
Interested people are also welcome to the mailing list for this topic:
(we are 18 people for the moment and need more especially from security
and mobility areas)
https://www1.ietf.org/mailman/listinfo/humanresolvers
_______________________________________________ IPsec mailing list IPsec@ietf.org https://www1.ietf.org/mailman/listinfo/ipsec
- [IPsec] IP host pairing Pars Mutaf