[Lake] FW: New Version Notification for draft-ietf-lake-edhoc-09.txt

Göran Selander <goran.selander@ericsson.com> Mon, 23 August 2021 13:39 UTC

Return-Path: <goran.selander@ericsson.com>
X-Original-To: lake@ietfa.amsl.com
Delivered-To: lake@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BBD143A18AE for <lake@ietfa.amsl.com>; Mon, 23 Aug 2021 06:39:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.553
X-Spam-Level:
X-Spam-Status: No, score=-2.553 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.452, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UZrJZrAm-Igv for <lake@ietfa.amsl.com>; Mon, 23 Aug 2021 06:39:47 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2079.outbound.protection.outlook.com [40.107.20.79]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BD0CE3A18B7 for <lake@ietf.org>; Mon, 23 Aug 2021 06:39:47 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=M+DExLcKXSCupK/Xm5r1Yoyt3y0vIMI2KBJq+ejKbS2dcTrPgxOceHMNOyK6TJ5DNWfcR81D62c5PKocuN2HrVB/kT+iab3f8xEu606L5zD4/KDf7OVcPRSFEmuR5cK0uj5TAjABB0yRA7jIJMcI4V0NvjqSkAl1gF/mBX/WiQyi2Rvtnw7a/dj2YbiM4gntabfEw++8xmF5I6lCXPeQzJDYx0PbyLKTJpZU2VQF5xpC0fiP8r67XKWKW8jBwFdfEwb+Wc1XAOF2ec/hRS3CFi6ow1M1Sb0nvjAL3zxUYaRV4EjLvKvM62QQ/DjEEhlx2M9CSIV80RyEdXN2NDbM3A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=D+8aQzfik68YlFuRjng2LEzeu1I0JUV8GXHNs+RAxWY=; b=RDOfkD4ddDwcr5cjklqKSW16jmwLAER8gJD2HseNKgz8CsvH8QYZZqjwjUmy+Zpl+aTnR+ktGXcQEE1H2vfxvN3i7BUys3iXBFQbiKEkf/S7MzUayls6rYczvXHZggc08Ez0isc466sWw5LqTKOoUIHNDCYKeM+jS35FPLTFUWmwL2ZJpQ3bCBfqv8tU694MBA1GXyQcjQ9POP0UOx+DMAURKa6Qh6i9VurutJRD8c4iMvN1FXyorg3ZUXtfwWr+OURcu0SoNx2bEeu53s1WDzOVm1AW3lnkv+C5Ik46hyQ4PHlP42gjrrrHM9I2fbzaIz1AeIqgsIitXsWpPg7RdQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=D+8aQzfik68YlFuRjng2LEzeu1I0JUV8GXHNs+RAxWY=; b=SoQBh2ZN6Ktvy3dwpuUvC0tDMLP2FyMLgM47cNx98ZKSoMepCaIRMEJ3zTZyoZXG8cxdT1e0B5icqO9Shn17RnRQePyM56IBBl95Je2AMg/Qz7IdG10uyT0yq0kzjeaoPx3uvVsb6gfvWfsjECPkLRhJtcgpL24LKOBEkVpsygw=
Received: from HE1PR07MB3500.eurprd07.prod.outlook.com (2603:10a6:7:31::20) by HE1PR0701MB2331.eurprd07.prod.outlook.com (2603:10a6:3:73::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4457.8; Mon, 23 Aug 2021 13:39:44 +0000
Received: from HE1PR07MB3500.eurprd07.prod.outlook.com ([fe80::a141:8e66:ce19:813d]) by HE1PR07MB3500.eurprd07.prod.outlook.com ([fe80::a141:8e66:ce19:813d%7]) with mapi id 15.20.4457.012; Mon, 23 Aug 2021 13:39:44 +0000
From: Göran Selander <goran.selander@ericsson.com>
To: "lake@ietf.org" <lake@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-lake-edhoc-09.txt
Thread-Index: AQHXmByVkCkgCJXKpE2MWULjgHLA16uBOfcA
Date: Mon, 23 Aug 2021 13:39:44 +0000
Message-ID: <EE5CA284-CBE3-467E-961D-33451CCC9FFB@ericsson.com>
References: <4fb4dc84-2bd4-4525-89ee-585ad5362cb0@AM5EUR02FT027.eop-EUR02.prod.protection.outlook.com>
In-Reply-To: <4fb4dc84-2bd4-4525-89ee-585ad5362cb0@AM5EUR02FT027.eop-EUR02.prod.protection.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.52.21080801
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 463b6dae-4560-425c-907e-08d9663b77b4
x-ms-traffictypediagnostic: HE1PR0701MB2331:
x-microsoft-antispam-prvs: <HE1PR0701MB2331A6A3F7E39D036A84EADAF4C49@HE1PR0701MB2331.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: DMu6r9+IMFZKBoiUR/EsmmPZwsubLJV9ECgPwLo+/o9YZ2rN40Zjlj5QDHDofBqUPPiqYhR7cXy03iYYR521tgAZ0vVKZmhknhW/QXe1K/ioQjQ1A0LrpvzGIoBDDqKYD3EJn2xfdtwKmvMc57X1bL5EfzXhihYNccTrZvgd2X8h6vRNA8umH0lJEi473p0R4UTyxA4MHVaW3pv46MYhKbKXa/HmCIUr4EmmxqrvgLxug5NZ+yQ9g5RIFkAfvCMY/fU4I6IdsP0YJIo4INfmWSAyKwd+Xx/Dgn4M4TWAaZJ+Vd35U4UWm35c7eZHbImqBkY9vp2h5H6ZNq0xYwgQEgs+lX21SfsjmUa5T+rPU3Ac8IMv6MEB9hqLWgnFch24bhXTalFuboGGJGy+95r5h/OeuhiYfzpGphBiSoWrmS5QvFsj+Ze1DHnWDUT1Su35OKXLV9ghH3oorvWdp5UfNjbXZVA0gi2/UYsPAGyVczG1kMS9xX2/6oonxFpV4SsSEWjhiV4M0BlGiMuYvdTgpvO7nn89A/D1wKGTiKJtraXjnGCR4R8x69UyvHyyoEtLADI5mfpacdjunuluxfQn9DX6/r1NpUSdoJ3QqTndzYfGjs79eSwIsCTODdfA9d7rpnTXbv1fyD3xkv3xSHkfCD3rQolRa3Cd56s0Lh4mDjtHz78RqV1XQU0ewNsKNPsdUvhJSxpAZD4rI8AV8f80W12aj734PHZ4gMzsmvG+zeu4d/jJIV2/5cvlSRHEfJvQHhCWX/0CqbLFPZIl5UJkeaWa7Z/qQzM+54ATYSyRf54pDZPeNZv/RLz5tFWNwhBzcm/ArSQKxFEt1dOKdlLZiOmGVK3/1DSSYO6DPgD2U5bLyo57AcrSdRJlJt3BFeP4GmbYgEKfl304hvW02G2B6u6q/LB585ErY+SWHptGfRYsB+sDcvL4IcZMeZ+0GS7whNrxgOPzO7G49XSzWmZ2hw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR07MB3500.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(71200400001)(316002)(6916009)(85202003)(6512007)(33656002)(83380400001)(122000001)(38100700002)(5660300002)(6506007)(38070700005)(186003)(15650500001)(86362001)(66556008)(8676002)(8936002)(66946007)(66476007)(76116006)(66446008)(6486002)(64756008)(66574015)(2906002)(26005)(2616005)(508600001)(966005)(36756003)(85182001)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: aNGpd1deJJeL28lV5zmCCiQdrY72JenYUzIMIWakBDPxAJc6tV3YU22eN5q2xq+v/Vd5zOXsDaUaAd3ayFG3UQqsTLVdDnUL+umE59jf36RcalaBL4v+yXSdOVF+kAW23Fex3hgnhfhDSocEY50rU2lCsFoQVlzvlP77vo1H3TVoR0Md/+oYw3A/mgXau4MyKKO1CpYQYy/s+SE9Gwm08TbuE96XIXyL59YZxZrboawO0LW1IPEsBCc8V2DQG3vYF7fvUnK8CvW3hUAeLZh1vHz2o/9pkHYZ+dKNrz7NQzRu1Fck6p0tTi58pHeaYfo1dRcxXBMLVYCWkO0YTyUFiUZJX6zlkdbApjm3sqRJr+X5+R6pVdVLDsoOdZwH4v+8AKFp0tTFwwsaG2LsTIc5BA96/tIiMq1MJRY4Fr67ZL3aN+PpYfvLxcMC2mF/2QIeqaGu8unNlFgtOoa1mVOt9vbeYAEOLAvqYxoLItppAE/RQfVLNLT74BdJ6mkjOqO4ZfxorzPjPJXUziBy5hW9c/aA/CD0sOfvCba7AZp9oheqGG++BfIBCiFgV32SZPLdpYM0PiU39XlOZz0g9wrEA2b2pT1UFlZDPLggDXB1wp1HFgnMnuHibfhunmO7mH0nqbXB3s4ws8Ovvg+764+htHMr6tzSMJUHgoq80JMGFcFJgL5ew30aG/fKMesgy7a/Sfu91QcT9xX8J5GTTu5TiFatp/9BMg1zzO264U7OH8lKfO9tVzkFEqTNOuQ4Gw5f2cbc8OE/OyntoQ7j2VGAC+98cH/Hp1NreIKvcUkyo5YO9qjmjNtddrTzpTqw3MHbHWos+K8XS2o9GtoHeZIQgk/l55SdN70CsD4p4j7VNPNsgwe0xOyAXKht4bNLBxj2+haewvdAjm4dGGM+3GdJm5LRZAouNhxmqqvNqQ46O+nCDwGvR1f5AzFieNGW/oyBwBAxcN2aVJPrUiU+kR1+95AXRbuu5XoOHhcyuSiAh22XuGXfowmIsh0LBeWd/uYoWpsLJTqFqYS022xcRHjQ26cf1Xfi1wzVtGs1uQ3IUeccd16wiYAO76z9e3vW9feRfEqnlOJk581+32q8s1MzBKqRiSAasJwGUnnB0xGTR0NccA1c/y96JQVKm44IYpQK1j0plkh3cqK3m2W4o3/W/O3O2dkGmYKExhZQVMwz1vn4Qo30Ad5z8A9WQs27sDjzoIup76yvFvDCkhooXcbjFlVIUJhqBlW39Fj9LCmPTV8k/0lI6pDbchNL9XfFTuTVpWkJnFY5uhCjLL/T5NfBjKB3OlqPppIpV0vi8eNxoPIBZfS9czVUItcP7uDkTEQlVwSQE5HtZ4WNPIm/F1Ltxw==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <8B9D739FE8011E429B34D67DD04A770A@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR07MB3500.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 463b6dae-4560-425c-907e-08d9663b77b4
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Aug 2021 13:39:44.5572 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 3UvBPX6CBRz322HYY9MR31q7+cKUBcnPVsk3BluVH/2N83MZIvSCcSi0HD+gDjXjN5CeJlLmw5bMHqNQ3aF976rllYm7WvmIP1selTdETTA=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0701MB2331
Archived-At: <https://mailarchive.ietf.org/arch/msg/lake/0Av46wf3UCicYCvPhmUV1-1-l-U>
Subject: [Lake] FW: New Version Notification for draft-ietf-lake-edhoc-09.txt
X-BeenThere: lake@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Lightweight Authenticated Key Exchange <lake.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lake>, <mailto:lake-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lake/>
List-Post: <mailto:lake@ietf.org>
List-Help: <mailto:lake-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lake>, <mailto:lake-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Aug 2021 13:39:54 -0000

Hello LAKE,

Following the plan from IETF 111, we have now submitted -09 addressing the major issues recorded to date. We think this is a good version for continued testing and security analysis.

The main changes compared to -08 are listed in the change log, details in the diff, here are the highlights:

* MAC_2 and MAC_3 are now generated with EDHOC-KDF instead of COSE_Encrypt0.  This change was straightforward with an update to the KDF now supporting an optional general “context” field. 

* A new parameter "EDHOC MAC length" is added to the cipher suite.

* G_Y and CIPHERTEXT_2 of message_2 are now combined into one CBOR bstr. 

* The key identifier ‘kid’ is extended to also support CBOR ints, making ‘kid2’ introduced in -08 redundant. This change was based on feedback from the COSE WG [1]. One potential next step is to move all COSE-related IANA registrations from this draft to a separate COSE draft and make an informative reference.

* The prepended byte used to distinguish message_1 in a CoAP setting is now of CBOR simple type “true” (0xf5), avoiding potential confusion with "null".

* More details on the use of different credentials, in particular CWT and UCCS.

* External authorization data is now defined as a sequence of “(type, content)”. (An IANA register for different types was already in -08.)

* Updated message size examples.

This version also has some updated security considerations + a few of restructured sections, a number of clarifications and editorials.

One thing we know has been of good use to implementers is appendix D with its test vectors and detailed transcript printouts. We have not had time to update those yet but plan to do so soon. Meanwhile we removed all content from appendix D which reduced the number of pages by 25, addressing one of the open issues (#142). We propose to put the updated transcript printouts in a separate draft in the same github repo, and replace appendix D with an informative reference.

Next steps also include closing github issues, many of which have been resolved in -09.

Any comments are welcome!


Göran

[1] https://mailarchive.ietf.org/arch/msg/cose/qGngdte4s3SEZEKM-xBEoXYUgKc/


On 2021-08-23, 14:44, "internet-drafts@ietf.org" <internet-drafts@ietf.org> wrote:


    A new version of I-D, draft-ietf-lake-edhoc-09.txt
    has been successfully submitted by Göran Selander and posted to the
    IETF repository.

    Name:		draft-ietf-lake-edhoc
    Revision:	09
    Title:		Ephemeral Diffie-Hellman Over COSE (EDHOC)
    Document date:	2021-08-23
    Group:		lake
    Pages:		75
    URL:            https://www.ietf.org/archive/id/draft-ietf-lake-edhoc-09.txt
    Status:         https://datatracker.ietf.org/doc/draft-ietf-lake-edhoc/
    Htmlized:       https://datatracker.ietf.org/doc/html/draft-ietf-lake-edhoc
    Diff:           https://www.ietf.org/rfcdiff?url2=draft-ietf-lake-edhoc-09

    Abstract:
       This document specifies Ephemeral Diffie-Hellman Over COSE (EDHOC), a
       very compact and lightweight authenticated Diffie-Hellman key
       exchange with ephemeral keys.  EDHOC provides mutual authentication,
       forward secrecy, and identity protection.  EDHOC is intended for
       usage in constrained scenarios and a main use case is to establish an
       OSCORE security context.  By reusing COSE for cryptography, CBOR for
       encoding, and CoAP for transport, the additional code size can be
       kept very low.




    The IETF Secretariat