Forward Secrecy

Ben Laurie <ben@algroup.co.uk> Thu, 24 February 2005 16:49 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA14329 for <openpgp-archive@lists.ietf.org>; Thu, 24 Feb 2005 11:49:25 -0500 (EST)
Received: from above.proper.com (localhost.vpnc.org [127.0.0.1]) by above.proper.com (8.12.11/8.12.9) with ESMTP id j1OGIKLh044445; Thu, 24 Feb 2005 08:18:20 -0800 (PST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.11/8.12.9/Submit) id j1OGIKKG044444; Thu, 24 Feb 2005 08:18:20 -0800 (PST)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from mail.links.org (mail.links.org [217.155.92.109]) by above.proper.com (8.12.11/8.12.9) with ESMTP id j1OGII2e044424 for <ietf-openpgp@imc.org>; Thu, 24 Feb 2005 08:18:19 -0800 (PST) (envelope-from ben@algroup.co.uk)
Received: from [193.133.15.218] (localhost [127.0.0.1]) by mail.links.org (Postfix) with ESMTP id 7F22733C9A for <ietf-openpgp@imc.org>; Thu, 24 Feb 2005 16:18:05 +0000 (GMT)
Message-ID: <421DFDC3.3080404@algroup.co.uk>
Date: Thu, 24 Feb 2005 16:16:03 +0000
From: Ben Laurie <ben@algroup.co.uk>
User-Agent: Mozilla Thunderbird 1.0 (Windows/20041206)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: OpenPGP <ietf-openpgp@imc.org>
Subject: Forward Secrecy
X-Enigmail-Version: 0.89.6.0
X-Enigmail-Supports: pgp-inline, pgp-mime
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
Content-Transfer-Encoding: 7bit

This I-D has been through WG last call back in 2001 or so. At that 
point, something went wrong and it got sat on. Unfortunately, I didn't 
have time before the deadline to convert it to the new format, but it 
now is, and I'd like to try to introduce it as a work item for the WG. 
I'll send it to the I-D editor, but in the meantime, its available here:

http://www.links.org/dnssec/draft-brown-pgp-pfs-04.html
http://www.links.org/dnssec/draft-brown-pgp-pfs-04.txt

Forward Secrecy Extensions for OpenPGP

"The confidentiality of encrypted data depends on the secrecy of the key 
needed to decrypt it. If one key is able to decrypt large quantities of 
data, its compromise will be disastrous. This memo describes three 
methods for limiting this vulnerability for OpenPGP messages: reducing 
the lifetime of confidentiality keys; one-time keys; and the additional 
use of lower-layer security services."

Comments, please!

Cheers,

Ben.

-- 
http://www.apache-ssl.org/ben.html       http://www.thebunker.net/

"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff