Re: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance

"Paul Ponchon (pponchon)" <pponchon@cisco.com> Thu, 27 October 2022 12:39 UTC

Return-Path: <pponchon@cisco.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A410C1522D7 for <ipsec@ietfa.amsl.com>; Thu, 27 Oct 2022 05:39:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.606
X-Spam-Level:
X-Spam-Status: No, score=-14.606 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=jHtXvg6J; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=GA3ZDFn5
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VNOyJld-i4Dl for <ipsec@ietfa.amsl.com>; Thu, 27 Oct 2022 05:39:24 -0700 (PDT)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4CADBC1522D4 for <ipsec@ietf.org>; Thu, 27 Oct 2022 05:39:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=10892; q=dns/txt; s=iport; t=1666874364; x=1668083964; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=QP7HdUK8aZc2dFV4uW+R8fcupqNtaO2mqbvXeWSIOB4=; b=jHtXvg6JOq/DEGqOXDidT030SIn87GZxwK887gx65HUH/b+dY+zYw6L5 Sb8eH2HCDY692kdb8Qa+D5qLb4KcyeGvd8d4C95qPSTbNR3oYg55trjW+ X0Mb5ka0CDBDJAUYvHaRytcpSXSqDzUO9ytKOP8/qQFG2qQVsrQ6GBq/S Q=;
X-IPAS-Result: A0AnAADZelpjmI0NJK1aHAEBAQEBAQcBARIBAQQEAQFAgTwGAQELAYEpMVJ/Alk6RYgaA4UviBwDlliFHIEsFIERA1UPAQEBDQEBRAQBAYUFAoR4AiU1CA4BAgQBAQEBAwIDAQEBAQEBAwEBBQEBAQIBBwQUAQEBAQEBAQEdGQUOECeFaA2GQgEBAQECARIuAQE3AQQLAgEIGCcHMhQRAgQBDQUIEweCWwGCFlcDDSMDAZ45AYE/AoofeIE0gQGCCAEBBgQEhREYgjoJgT0BgzqFKoNBFYQvJxyBSUSBFUOCZz6EDwESASOEDYIuhCONbIN4BzcDRB1AAws7MgMKUBtYDgkfHA4XDQUGEgMgbgVBDygvZyscGweBDCooFQMEBAMCBhMDIgINKTEUBCkTDy0HI3EJAgMiZQUDAwQoLAMJIAQcByUkPAdYOgEEAwIQIjwGAwkDAiJXgSUmBQMNFyUIBU8ECDoCBQZSEgIKEQMSDwYmSA5KPjkWBidEATQPDhYDYplXgVoNaFEIgTFLlTyKbaFrCoNloGYWqDZdlyYgohqFEQIEAgQFAg4BAQaBZAI2LT5wcBWDIlEZD44gGYNZil51OwIHCwEBAwmKWwEB
IronPort-PHdr: A9a23:DKODexRr64mVGYzhrxcG2XoY9dpso7vLVj580XJvo75Nc6H2+ZPkM QSf4Ph2l1bGUM3d7O4MkOvZta3sGAliqZaMuXwPatpAAhkCj8hFkwkpGsXQD0r9IbbjZDA7G 8IXUlhj8jm7PEFZFdy4aUfVpyi57CUZHVP0Mg8mTtk=
IronPort-Data: A9a23:g4xbN6L55XzN22JWFE+RCZUlxSXFcZb7ZxGr2PjKsXjdYENS0jBWn GIZUGyAPamNMzD3fYp/O96+phtVsJfdztQwSAYd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcIZsCCW0Si6FatANl1EkvU2zbue6WbOs1hxZH1c+En550007wobVv6Yx6TSHK1LV0 T/Ni5W31G+Ng1aY5UpNtspvADs21BjDkGtwUm4WPJinj3eC/5UhN6/zEInqR5fOria4KcbhL wrL5OnREmo0ZH7BAPv9+lrwWhVirrI/oWFih1IOM5VOjCSuqQRr3YEECsJMRXxNihesmuxo9 fhLjZuvHFJB0q3kwIzxUjFRFyV4eKZB4rKCcT60sNeYyAvNdH6EL/dGVR5te9ZGvL8sRzgSr JT0KxhVBvyHr/qux7SwSu5qrs8iN8LseogYvxmMyBmHVal/GMGZK0nMzeFx9gU2h+QVJM7DI OA9bgVfRhLwUQIabz/7D7pnzLv32RETaQZwqUqOqKEf4mXPwkp2yreFGN/eYJ+LSNlbtl2Ro G7L+2HwBFcRPbS30j+U6XarmKnOkD/1cI0XHby8sPVthTW73XAeBhMbUx24pfCikUOkR/pEJ kcJ/Ccy66M18SSDVtDgWzW+p36NogVaUNM4O+479gCLx6z84gWYQGYFJgOtc/QvsMswADctz FLMz5XiBCdkt/ueTnf1GqqoQS2aYCcyElE6NQM/VwonxtzfubweiCrIUYM2eEKqteHdFTb1y jGMiSExgbQPkMIGv5lXG3ia3VpAQbCUE2YIChXrsnGNtVggPdH7D2C8wR2Ks6gffd/xokyp5 iBspiSI0AwZ4XhhfgSkROEAGtlFDN7abWWF2jaD83TdnglBFlaqeYRWpTp5PkosYoAPeCTiZ wnYvgY5CH5v0JmCMP4fj2GZUptCIU3c+TLNDay8gj1mOcIZSeN/1HsyDXN8Jki0+KTWrYkxO I2AbeGnBmsABKJswVKeHrlDj+9zl3hlnTODFPgXKihLN5LDNBZ5rp9YYDOzghwRt8toXS2Mq Y8EbpvWo/mheLygOkE7DrL/3XhTfSRkWvgaWuRcd/WIJUJ9CXo9BvrKqY7NiKQ795m5Ytzgp ynnMmcBkQKXrSSedW2iNCs5AJuxBskXkJ7OFXF2Vbpe8yJ9Md/HAWZ2X8ZfQITLA8Q5k6ElH qFdJ5ncahmNIxyekwkggVDGhNQKXHyWacimZkJJvBBXk0ZcejH0
IronPort-HdrOrdr: A9a23:oj9LAa0M8a29JvHz5T9XYQqjBQxyeYIsimQD101hICG9Lfb3qy n+ppsmPEHP5Ar5AEtQ5expOMG7MBfhHO1OkPYs1NaZLUTbUQ6TTb2KgrGSuwEIdxeOlNK1kJ 0QDpSWa+eAQWSS7/yKmzVQeuxIqLLsncDY5ts2jU0dNz2CAJsQiDuRfzzra3GeMzM2Y6bReq Dsg/Zvln6FQzA6f867Dn4KU6zovNvQjq/rZhYAGloO9BSOpSnA0s+0LzGomjMlFx9fy7Yr9m bI1ybj4L+4jv29whjAk0fO8pVtnsf7wNcrPr3DtiFVEESstu+bXvUjZ1SwhkF2nAhp0idurD D4mWZhAy200QKUQoj6m2qr5+Cq6kdR15ar8y7ovZKkm72+eNr/YPAx3b6wtXDimhMdVZhHod J29nPcuJxNARzamiPho9DOShFxj0Kx5WEviOgJkhVkIMMjgZJq3PoiFXluYd49NTO/7JpiHP hlDcna6voTeVSGb2rBtm0qxNC3RHw8EhqPX0BH46WuonJrtWE8y1FdyN0Un38G+p54Q55Y5/ 7cOqAtkL1VVMcZYa90Ge9ES8qqDW7GRw7KLQupUB/aPbBCP2iIp4/84b0z6u3vcJsUzIEqkJ CES19cvX5aQTOYNSRP5uw+zvngehTJYd228LAs23FQgMyPeIbW
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.95,217,1661817600"; d="scan'208,217";a="6071192"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by alln-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 27 Oct 2022 12:39:23 +0000
Received: from mail.cisco.com (xfe-rcd-003.cisco.com [173.37.227.251]) by alln-core-8.cisco.com (8.15.2/8.15.2) with ESMTPS id 29RCdMFR009966 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Thu, 27 Oct 2022 12:39:22 GMT
Received: from xfe-aln-001.cisco.com (173.37.135.121) by xfe-rcd-003.cisco.com (173.37.227.251) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.9; Thu, 27 Oct 2022 07:39:22 -0500
Received: from NAM12-DM6-obe.outbound.protection.outlook.com (173.37.151.57) by xfe-aln-001.cisco.com (173.37.135.121) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.15 via Frontend Transport; Thu, 27 Oct 2022 07:39:22 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=UDfmh2UFeNap95SqrICKrTuuVZGbXxykPlvxEuar5v226Efp7NI1JDNxFZVbNIQcrrTJW/SjWb5VMgpiVgXbOQk8TUdnPf4SzXcmBYxueiYZeGlfaTy47nY8lYv6Lv8dYSSLlMQ187toqeZqNSR5/49CQs70cV1zcvQNL1K5INIGKJdZwIpUSadP5iK9949HwOxagMLqliz59Rk2JNCR+qMPyaG5oSneBSV7MLcfu92YM+jOUDRMWlqc1T8pdQenV+Z0uN1irdLQ0S+r5+VIbGxdMVRjap80CkEak3/s31TPWntfWOdz3zU268jlBjblxFlVhvlLHil5aEXNM9WwiA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=OfxqMk6k+j29XOAlR6eX9748wAlCDzKKmr7j2g/FF5Q=; b=YQS5N8i39SRkocCfp4P5G7tZqECa732Px+7s/lcMXsWha660rQtoRO5hGklHZXUKFFDVEhtOXOEkCL9FtZNjNAVN/LEHAs+KnRzCzDu6rnejalD8dj+j2zVdVXpP5lQCJAY1jmm35wy6bx3zqnzmLRFKjDHGAYlT6BdBf4FNz/VAVIEuMIcId34AFnqkjREcnh55+iGGj2Qhx3EUJlOgrCyxXEhrLdTfgEyJY4kkgooGp4e66lwVF+Q+m8sYWXlRZdsacTMSh6KobuTJSP0MYotkdwt84el5vrje/Ko3blhD6eln2UdTB1ysTnKgkSrirB3G3pSoeoGvwFwjS/Hthw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=OfxqMk6k+j29XOAlR6eX9748wAlCDzKKmr7j2g/FF5Q=; b=GA3ZDFn5/9A3rhr37WBkR48/dyu/hUPFqlh30y/VnIB5ftRGhnGhW7R1qxZXudTMAlSweY0aSLX5n52TA+z5aIio6rsphHQ+QLdUPmYYsPusVrCZAzSp1+B2zxP8GJu4+9v4kPGEdvwzsq73Gp1Ic3pXJMCnM4o/aLTjbb6yRew=
Received: from DM6PR11MB4531.namprd11.prod.outlook.com (2603:10b6:5:2a5::19) by SJ0PR11MB4862.namprd11.prod.outlook.com (2603:10b6:a03:2de::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5746.28; Thu, 27 Oct 2022 12:39:20 +0000
Received: from DM6PR11MB4531.namprd11.prod.outlook.com ([fe80::80c3:ee31:7f03:49e3]) by DM6PR11MB4531.namprd11.prod.outlook.com ([fe80::80c3:ee31:7f03:49e3%4]) with mapi id 15.20.5723.034; Thu, 27 Oct 2022 12:39:20 +0000
From: "Paul Ponchon (pponchon)" <pponchon@cisco.com>
To: Tero Kivinen <kivinen@iki.fi>, Paul Wouters <paul@nohats.ca>
CC: Steffen Klassert <steffen.klassert@secunet.com>, Valery Smyslov <smyslov.ietf@gmail.com>, Michael Richardson <mcr+ietf@sandelman.ca>, IPsecME WG <ipsec@ietf.org>
Thread-Topic: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance
Thread-Index: AQHY6YZs2qhQym1xgkOprlqrkz8GFq4iLuG/
Date: Thu, 27 Oct 2022 12:39:19 +0000
Message-ID: <DM6PR11MB4531023D4E06E619BAC9935DCB339@DM6PR11MB4531.namprd11.prod.outlook.com>
References: <20221021073714.GP3294086@gauss3.secunet.de> <F84D65B2-9A68-420D-BC55-2A6BD2542246@nohats.ca> <25433.44569.44812.537584@fireball.acr.fi>
In-Reply-To: <25433.44569.44812.537584@fireball.acr.fi>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM6PR11MB4531:EE_|SJ0PR11MB4862:EE_
x-ms-office365-filtering-correlation-id: c656e9be-621f-46be-d7e1-08dab81844db
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: ne0a0M80Me3mxyh7D3Y78af6pj030bEBZSpdYDZKHMaUuE0LDNpK/Q9dbEOZ/qvZmjHrPXg1nPwrObYuOXVbWj27taQXF+U21s9ZMoEDLSnS+rqzQKFgkFUkyu3OCerAFS6XF7Qmx9NUS8d4nPe7GVfk5amwmZN30DgEZ4CqF335By2dR9/ACAFNm+Gg1SUTjE2dpeIZqBq6i4b8dLgg6NzuzSrKpxzrBRKPH41GDQ9KZwFt5RGcSnjjLX3+CGS2CtfxiYLsbaNF6fBHOYMwV/9JhSbzN3WjIli3MZeVEO6eVkXUU44FR4iEhq5cciad7VruaQR5GBj3QtjfHvDRUnwVfBWARi/unb7Mk58vaNiHM+1D7zOV63+WU9iV8UpbCaYsvNiU8Tbb2Ushnsy6eavMh04g9QdYIpbPW2EJ3dSTUAaQJP7TxgytyM8kDn/Vg/IjlpUZD+bqW/fBCOM5/oEsanfEjcNwub+Qyz5WQFyBhXmv/Xzf/NaJiabnbzULxEn1/ucgzMAoEgZ08MnYayLXK03oIU1t2S9OEpwDwATLs0U4VUILCv5mmUE0TfsvNhA6nXokyUrCYS+1n9IDguZFT8jlkzvZeSaPIqWtD3GBIbj/xIVwuxLAAVHiI13V8qDwxZ6YYtgiy4aO6AGnkTNYult97FjVrdK08bfseLkDemfmGDdT3PMT5YeiQYdTpPYr2/0DNOVfGerh3z8HIClXmXmZ+H6m/ThwX5pEvXfyQA4nr/1xoppgoCX9XqLNT8Ie/UsMw8e2/YGcIop8wg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM6PR11MB4531.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(396003)(376002)(136003)(346002)(39860400002)(366004)(451199015)(33656002)(186003)(66446008)(66556008)(64756008)(41300700001)(76116006)(66476007)(478600001)(66946007)(4326008)(2906002)(8676002)(122000001)(38070700005)(71200400001)(38100700002)(54906003)(316002)(91956017)(83380400001)(86362001)(110136005)(55016003)(9686003)(53546011)(6506007)(52536014)(8936002)(7696005)(5660300002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: vwPiU1riXy/kljH6fRTO6nHzpUq+6Bwiq/UNR9pm/lF2OBrwqaIJPAWZCOdsD7H4B8lJaiHuCZD/fJ8sack+ViidfLozBvz7JoI00aYQ6X7D74sRgPnT2v7KefuQDedtBDEYd64Ujt9vGdHXa2vpExnOGSMxrQ6Wdof66aa/M1glcOsL7Xb+JJ5qTJc2ietFbpWoHkeuVw81PNr5YIZKB40ETvWI0MHLoOWr4jPwnh68ntlbJZxTYpCN+4/SN9Icv4Mix2751Qmq2tNKnHK3kpvbghmb5pKl9x4tIlgy0dz7Nxkzx9pfacKjCrfofVBpSMsFI5fLlwCKLNAlEma9HO2egDTW5a1tilTa/Sah8QiUFoG1w4uqV2Rpq0flCA6HihrtBAPN9pQY7FhAfPdOtlhW0m13mrJF+Giikvklgsm4uzPE/Q5ur5aPuIfqOz4jduoIhkKbDsZLN2ju6yHvtexc7dZIZ2IcF36Z/ZKciw0g0wemPV/NqxxtRo3rn6f3va1eaRZscO6w/37suyYLrfuzrTgW8Fs2yXEpHIZ5FRz3N4tLiWpdCo1sSkZuM4e32BlnYj3muYRzGUVxeMFWAhfCIBusckb36ViyCkux8rzC4ZDtcJiNZfloSRpw4htSWuzDhKYSDTjct6AXqWcJrtwko+7EvHmmbwOmgYIs5rC0w9X0PBVdwsPlKFqnbf13KPzQgKkkqLYslSBjhVgYq5TLABoTEQ3xbAw362PgLck36XpXTlewk1qfbORS2h+KRW6eTENdT6cbkSweziCfxXREO9/ghHqRyaMMml1C+vWdH1suUyS2tZp3vtab1dBWsgEfC6oXB6KvZqm0/FuniAcqV6hBC1UxLtveo5uUKawn9Im/ZkpfvIvB3wzmaBNBX+1u8+NSBZIEuRTZfi5VqyQQseauBACPvHS7nkIVSvqQfHgr8KYUYsGPJVhiugMREnsB/7Qx5RyXe2jwD3zXkwVSXRWQwyb+rsORrOKDvCf/XWpGe0qf3s8ASJfXPEUVKZW/RbjWKyvHBQIlNpayRBkSCjxVq84fn3mYmBI0+O4LPxlrJAWKgGzTI/qXgrnKaiYr69W6ljpMs+VQI+5NfS+PTfBy1EZdjTb2iD0xYjDUQv1rPzEIfet0jCaynBmgTLSfEpznFT9m82fSuBnn8ckBTw4wEJgll7Tc71JaFJTLIWfW499gD066zHv2wFeephe9zempm96xOkaLadSwfFw6Ai7w4uudxLKcUFTJKM9EF/bOEWh+j6CrNTFbq0ebVvDm1ukT7Gh6XBjE3XQem+vGqqax8Jx6cxE/E76R5J+Vz9WviWHtj2DHV3YZcp+eZyIkrF8jruh9M5o8uXqYmmIHQsNZbupTlAK5j8MlXiMGy+bU//rp1Ioyfurnk665sLYUC6PEXAESSLEVQWkKS6vZbxIA+nPQDqMKIsk95c4WqJw23hcwbikfRCY/Ui3+k6VBk88Orpo4fFK8rSYbAEscvlZourGQE47CM7HOV+bcRxEew/7LgYxeJLiR89f0St8beTdVjbsaoQMVlOeua/JAnAbVdo2UBXQLFieRMbOTNn5qN8YsUrJx0ZLNnBUxqowx5h75QrklpO0TQyZQnHnO7w0q0RdPPK+XHZCHRVyqfDX8x2uXz1KON3osPux7ZIHKZBBUHfm//02DljbaJQ==
Content-Type: multipart/alternative; boundary="_000_DM6PR11MB4531023D4E06E619BAC9935DCB339DM6PR11MB4531namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM6PR11MB4531.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: c656e9be-621f-46be-d7e1-08dab81844db
X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Oct 2022 12:39:19.9705 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Sys0C6NBUHcVdolZy3tRhVq36UsSARDAUlGpLwgDPqnNesG/afAwJzm7lHd7teJsH7X9xqvzydya6kWjOwu8qg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR11MB4862
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.227.251, xfe-rcd-003.cisco.com
X-Outbound-Node: alln-core-8.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/NPihvu7p9821lx_PgJoU40eGU4A>
Subject: Re: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Oct 2022 12:39:28 -0000

Hi,

Tero Kivinen writes:
> [Replying to this email, but commenting about the others also]
>
> Paul Wouters writes:
> > On Oct 21, 2022, at 03:37, Steffen Klassert <steffen.klassert@secunet.com<mailto:steffen.klassert@secunet.com>> wrote:
> > > Another possibility would be to use the same keymat on all
> > > percpu SAs
> >
> > You cannot do that. You need to ensure unique IVs for AEAD so you
> > would need to subdivide the IV space. You would also still reach max
> > operations on these SAs on different times AND things like FIPS puts
> > an operational max count on the key usage which you can’t do if the
> > key is used by multiple different states.
> >
> > Using different real child SA’s was needed to ensure the
> > cryptographic security properties.


Is this requirement only based on not reusing the same IV on different cores or is there an additional factor I missed?

> This is something that is really a important. The keymat between the
> CPUs can't be same, but we could in theory create a new key hierarchy
> that generates keys for each sub Child SAs for each CPU, but I think
> that will just complicate things more, and having real Child SAs for
> each cpu is the correct solution.

We're are currently facing some scalability issues with using multiple Child SAs and we think it is possible to reuse the same keymat on all the per cpu SAs.

For this to work and respect the uniqueness of the IV, some mechanism would be needed. But that can be implemented without per-packet locks for most ciphers (e.g., by splitting the IV space, or making bulk IV allocations). And we would also ensure that the keymat is used in a FIPS compliant manner.

Would there be any other concerns in reusing the same keymat between multiple SAs ?

> […]

Thanks,
Paul