Re: [Perc] PERC LIte

Sergio Garcia Murillo <sergio.garcia.murillo@gmail.com> Wed, 24 May 2017 19:46 UTC

Return-Path: <sergio.garcia.murillo@gmail.com>
X-Original-To: perc@ietfa.amsl.com
Delivered-To: perc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AC583127599 for <perc@ietfa.amsl.com>; Wed, 24 May 2017 12:46:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.688
X-Spam-Level:
X-Spam-Status: No, score=-2.688 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E4bHmXWS0Auw for <perc@ietfa.amsl.com>; Wed, 24 May 2017 12:46:35 -0700 (PDT)
Received: from mail-wm0-x22d.google.com (mail-wm0-x22d.google.com [IPv6:2a00:1450:400c:c09::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DCF91126C23 for <perc@ietf.org>; Wed, 24 May 2017 12:46:34 -0700 (PDT)
Received: by mail-wm0-x22d.google.com with SMTP id d127so77979832wmf.0 for <perc@ietf.org>; Wed, 24 May 2017 12:46:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:references:cc:from:message-id:date:user-agent :mime-version:in-reply-to; bh=aJyMzHReF/XZEnI2Lpw8+ic9GlURo9m6eIO2dRLhxZU=; b=dWgDIS3luCzCP+B7EtiECoBj8RxF9YfXH78p/Zl/ft/dUC3Kx6fdojZBjX2wAyNgjl xj3bNiOXKE9tlPe+u8nt6wNr2qNcDbAZth474MNRi5b44r+FJocHXLHlpjcWMMSRJ21o Pa85WRCPoUdQ/mtIe1ob6pzAVlylFybAIvWo1WoxAIJ/ermd0GxzFNcng8R5NR0PkQe0 lea6GlUNarifZmQ4KfpDSxbL6VRSZZiCxAGXuntF5wE7pcOh5IRwxqW44kKNmRvCLkzh tUKi/FdqKo8qkTA+0iHM2oS5ZMKcYdj1I80pbwEi6+SGdB/K1lOqkp95ZosVVdoJ+8ip cL/A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:cc:from:message-id:date :user-agent:mime-version:in-reply-to; bh=aJyMzHReF/XZEnI2Lpw8+ic9GlURo9m6eIO2dRLhxZU=; b=nT2ijp2rOQ/YOIKoRo3mHi3H+GetTGrRJ7Q/b9BJozMjjooAMm9FVX0vOMhVwYm4EM +gjIgEo0vd9Ce4bZNE4EaJXm8IqDHXjDArVMLgiRcNa5xKorEpNMc/ZjlCp7QZrkvbbo 5XSfSS6JRFpE5letN9wNlq8uP2Cr7VmY6aoWtXtOVWOWuhSfQ6tEXjJzFTcg0vnGU/FE sWiSp0DfY8csGNRQOdf7geHbUC4xpSvhhLH+l/Tm/l1DlPUJcr9YDEkhqMTVuiEvPc8L d7MbuIT8kIxrBJZ6uPu/iwvSGJJq1VI7KT8CFl2TWe3AfB5+Io7m8e7sxBoBI/6ZggXJ eD8g==
X-Gm-Message-State: AODbwcBPTXKUCpfGYJaTeb/B5iMINuz81mgfeArUONxVqgOOLUBKAdW1 YfJR8BoTbDgMsVKPQKA=
X-Received: by 10.28.174.131 with SMTP id x125mr7138461wme.32.1495655193246; Wed, 24 May 2017 12:46:33 -0700 (PDT)
Received: from [192.168.0.199] ([193.125.41.240]) by smtp.googlemail.com with ESMTPSA id m14sm8281611wmi.2.2017.05.24.12.46.32 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 24 May 2017 12:46:32 -0700 (PDT)
To: Bernard Aboba <bernard.aboba@gmail.com>
References: <9d1552b8-b69f-ac14-e28b-2905bd5e5692@gmail.com> <CAOW+2dtRYXcnzUnP3cZKKNXJ1FxJPwMw3hmb349KpbLJwQD5FA@mail.gmail.com>
Cc: "perc@ietf.org" <perc@ietf.org>
From: Sergio Garcia Murillo <sergio.garcia.murillo@gmail.com>
Message-ID: <1adbb700-b61e-b283-6e29-ff3b5fd0d5ee@gmail.com>
Date: Wed, 24 May 2017 21:46:33 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <CAOW+2dtRYXcnzUnP3cZKKNXJ1FxJPwMw3hmb349KpbLJwQD5FA@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------EB63E0B0D773D8C79D217C24"
Archived-At: <https://mailarchive.ietf.org/arch/msg/perc/Wu-gM6CGl1QmHfCdnDfgtvLsIVY>
Subject: Re: [Perc] PERC LIte
X-BeenThere: perc@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Privacy Enhanced RTP Conferencing <perc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perc>, <mailto:perc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/perc/>
List-Post: <mailto:perc@ietf.org>
List-Help: <mailto:perc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perc>, <mailto:perc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 19:46:38 -0000

Hi Bernard,

Yes, the example API is just the lazy approach I have taken on my 
modified chromium, hardcoding the key to AES-GCM 256 so I didn't have to 
add an object to the IDL and worry about how to retrieve later on the 
c++ code.

The API should allow to set the key and look more like:

*

const pc = new RTCPeerConnection({

mediaCrypto : {

key **: 'VEhJUyBJUyBUSEUgMzIgS0VZIFdJVEggMTIgU0FMVCBET1VCTEUgUEVSQyE=',

suite  : 'AEAD_AES_256_GCM'

}

});*

Anticipating the security comments, I don't expect that to be the final 
API for WebRTC, which IMHO should be a similar mechanism as the one in 
place for IdP (or even integrated with it), but I feel that that 
discussion should take place on the RTCWeb group and not here.

Best regards
Sergio

On 24/05/2017 19:56, Bernard Aboba wrote:
> Thanks for posting this.
>
> Question:  In terms of API support, how is the crypto-algorithm 
> specified?  So far, the proposed API just has the key.
>
> On Wed, May 24, 2017 at 10:11 AM, Sergio Garcia Murillo 
> <sergio.garcia.murillo@gmail.com 
> <mailto:sergio.garcia.murillo@gmail.com>> wrote:
>
>     Hi all again,
>
>     Also to start the discussion about 5), I would like to introduce
>     again my proposal for a "PERC Lite" approach.
>
>     The main objectives and key points of this proposal are:
>
>       * Minimum viable PERC implementation
>       * Minimize impact on both endpoints and MD
>       * OHB is carried in the RTP payload (Encrypted Payload Header).
>       * No changes to the DTLS/SRTP code/api/standards
>       * No RTP E2E Header extensions
>       * RTX/FEC/RED is supported HBH without any change to current
>         standards/implementations.
>
>     Best regards
>
>     Sergio
>
>
>
>     _______________________________________________
>     Perc mailing list
>     Perc@ietf.org <mailto:Perc@ietf.org>
>     https://www.ietf.org/mailman/listinfo/perc
>     <https://www.ietf.org/mailman/listinfo/perc>
>
>