[IPsec] Re: ESP's use of dummy packets?
Csaba Kiraly <kiraly@dit.unitn.it> Thu, 29 November 2007 22:37 UTC
Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1Ixs0y-0005d8-6f; Thu, 29 Nov 2007 17:37:48 -0500
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1Ixs0w-0005cZ-Kc for ipsec-confirm+ok@megatron.ietf.org; Thu, 29 Nov 2007 17:37:46 -0500
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1Ixs0w-0005bs-9o for ipsec@ietf.org; Thu, 29 Nov 2007 17:37:46 -0500
Received: from mail4-out.unitn.it ([193.205.206.45]) by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1Ixs0v-0006VT-12 for ipsec@ietf.org; Thu, 29 Nov 2007 17:37:45 -0500
Received: from mail4-out.unitn.it (unknown [127.0.0.1]) by mail4-out.unitn.it (Symantec Mail Security) with ESMTP id 2FC36153F0E; Thu, 29 Nov 2007 23:37:43 +0100 (CET)
X-AuditID: c1cdce2d-abbcbbb000001013-30-474f3f3605c6
Received: from dit.unitn.it (brenta.dit.unitn.it [193.205.194.4]) by mail4-out.unitn.it (Symantec Mail Security) with ESMTP id DDEB4EAC88; Thu, 29 Nov 2007 23:37:42 +0100 (CET)
Received: from [192.168.1.102] (host210-105-dynamic.7-79-r.retail.telecomitalia.it [79.7.105.210]) (authenticated bits=0) by dit.unitn.it (8.12.11.20060308/8.12.11) with ESMTP id lATMbfD4019669 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 29 Nov 2007 23:37:42 +0100
Message-ID: <474F3F37.1030905@dit.unitn.it>
Date: Thu, 29 Nov 2007 23:37:43 +0100
From: Csaba Kiraly <kiraly@dit.unitn.it>
User-Agent: Thunderbird 1.5.0.13 (Windows/20070809)
MIME-Version: 1.0
To: Joy Latten <latten@austin.ibm.com>
Subject: [IPsec] Re: ESP's use of dummy packets?
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: AAAAAA==
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 3e15cc4fdc61d7bce84032741d11c8e5
Cc: ipsec@ietf.org
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org
> Joy Latten wrote: > > RFC 4303 introduces the use of dummy packets within ESP. > Section 2.6 states, > A transmitter MUST be capable of generating dummy packets marked > with this value in the next protocol field, and a receiver MUST be > prepared to discard such packets, without indicating an error. > > However, it is not clear to me whether an IPsec/ESP implementation > MUST > use this feature. That is, it MUST send out dummy packets at random > intervals or in a way to shape the traffic. I interpreted the > above statement to mean that an implementation must only have the > capability. > > > That's correct. > You had better be able to discard them if the other end sends them, > though. > Which means you'll have to test that. Which means that you'll have to > find a way to generate them in your lab... so it means that you'll > wind up having to implement it anyway. > > Dear Joy, If you need dummy generation in Linux, we have an open source implementation in the kernel for our Traffic Flow Confidentiality protocol. I'm quite sure it can easily be transformed into an RFC 4303 compliant one. Since this list is not intended to discuss implementations, I'm just pointing you to http://minerva.netgroup.uniroma2.it/discreet/wiki/TfcProject and of course feel free to contact me directly for a patch. I would also like to take the occasion to say that we have made some efforts to extend the Traffic Flow Confidentiality capabilities of IPsec. In our research we were trying to create a separate TFC security protocol, which goes beyond the limited TFC capabilities that were already included in ESPv3. We have included support for size modifications such as padding (with explicit payload size information), fragmentation and aggregation. It also supports packet re-timing, as well as dummy generation and discarding. Finally, the choice of the masking algorithm combining one or more of these basic tools is handled separately. Of course these are just initial steps, and the same ideas can be imagined as part of ESP as well. If there is still interest in the list for TFC, I would be really glad to discuss ideas! Best regards, Csaba _______________________________________________ IPsec mailing list IPsec@ietf.org https://www1.ietf.org/mailman/listinfo/ipsec
- [IPsec] ESP's use of dummy packets? Joy Latten
- Re: [IPsec] ESP's use of dummy packets? Stephen Kent
- [IPsec] Re: ESP's use of dummy packets? Michael Richardson
- [IPsec] Re: ESP's use of dummy packets? Csaba Kiraly
- [IPsec] Re: ESP's use of dummy packets? Stephen Kent
- Re: [IPsec] Re: ESP's use of dummy packets? Csaba Kiraly