[IPsec] Re: ESP's use of dummy packets?

Csaba Kiraly <kiraly@dit.unitn.it> Thu, 29 November 2007 22:37 UTC

Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1Ixs0y-0005d8-6f; Thu, 29 Nov 2007 17:37:48 -0500
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1Ixs0w-0005cZ-Kc for ipsec-confirm+ok@megatron.ietf.org; Thu, 29 Nov 2007 17:37:46 -0500
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1Ixs0w-0005bs-9o for ipsec@ietf.org; Thu, 29 Nov 2007 17:37:46 -0500
Received: from mail4-out.unitn.it ([193.205.206.45]) by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1Ixs0v-0006VT-12 for ipsec@ietf.org; Thu, 29 Nov 2007 17:37:45 -0500
Received: from mail4-out.unitn.it (unknown [127.0.0.1]) by mail4-out.unitn.it (Symantec Mail Security) with ESMTP id 2FC36153F0E; Thu, 29 Nov 2007 23:37:43 +0100 (CET)
X-AuditID: c1cdce2d-abbcbbb000001013-30-474f3f3605c6
Received: from dit.unitn.it (brenta.dit.unitn.it [193.205.194.4]) by mail4-out.unitn.it (Symantec Mail Security) with ESMTP id DDEB4EAC88; Thu, 29 Nov 2007 23:37:42 +0100 (CET)
Received: from [192.168.1.102] (host210-105-dynamic.7-79-r.retail.telecomitalia.it [79.7.105.210]) (authenticated bits=0) by dit.unitn.it (8.12.11.20060308/8.12.11) with ESMTP id lATMbfD4019669 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 29 Nov 2007 23:37:42 +0100
Message-ID: <474F3F37.1030905@dit.unitn.it>
Date: Thu, 29 Nov 2007 23:37:43 +0100
From: Csaba Kiraly <kiraly@dit.unitn.it>
User-Agent: Thunderbird 1.5.0.13 (Windows/20070809)
MIME-Version: 1.0
To: Joy Latten <latten@austin.ibm.com>
Subject: [IPsec] Re: ESP's use of dummy packets?
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: AAAAAA==
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 3e15cc4fdc61d7bce84032741d11c8e5
Cc: ipsec@ietf.org
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org

> Joy Latten wrote:
>
>     RFC 4303 introduces the use of dummy packets within ESP.
>     Section 2.6 states,
>     A transmitter MUST be capable of generating dummy packets marked
>     with this value in the next protocol field, and a receiver MUST be
>     prepared to discard such packets, without indicating an error.
>
>     However, it is not clear to me whether an IPsec/ESP implementation
>     MUST
>     use this feature. That is, it MUST send out dummy packets at random
>     intervals or in a way to shape the traffic. I interpreted the
>     above statement to mean that an implementation must only have the
>     capability. 
>
>
> That's correct.
> You had better be able to discard them if the other end sends them, 
> though.
> Which means you'll have to test that. Which means that you'll have to 
> find a way to generate them in your lab... so it means that you'll 
> wind up having to implement it anyway.
>
>   

Dear Joy,

If you need dummy generation in Linux, we have an open source 
implementation in the kernel for our Traffic Flow Confidentiality 
protocol. I'm quite sure it can easily be transformed into an RFC 4303 
compliant one.

Since this list is not intended to discuss implementations, I'm just 
pointing you to
http://minerva.netgroup.uniroma2.it/discreet/wiki/TfcProject
and of course feel free to contact me directly for a patch.

I would also like to take the occasion to say that we have made some 
efforts to extend the Traffic Flow Confidentiality capabilities of 
IPsec. In our research we were trying to create a separate TFC security 
protocol, which goes beyond the limited TFC capabilities that were 
already included in ESPv3. We have included support for size 
modifications such as padding (with explicit payload size information), 
fragmentation and aggregation. It also supports packet re-timing, as 
well as dummy generation and discarding. Finally, the choice of the 
masking algorithm combining one or more of these basic tools is handled 
separately.

Of course these are just initial steps, and the same ideas can be 
imagined as part of ESP as well. If there is still interest in the list 
for TFC, I would be really glad to discuss ideas!

Best regards,
Csaba



_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec