Re: [quicwg/base-drafts] GREASE the packet type octet (#311)

ekr <notifications@github.com> Tue, 06 June 2017 15:19 UTC

Return-Path: <bounces+848413-a050-quic-issues=ietf.org@sgmail.github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 667F8128B8E for <quic-issues@ietfa.amsl.com>; Tue, 6 Jun 2017 08:19:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.801
X-Spam-Level:
X-Spam-Status: No, score=-4.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vgIMtciL1YxC for <quic-issues@ietfa.amsl.com>; Tue, 6 Jun 2017 08:19:03 -0700 (PDT)
Received: from o9.sgmail.github.com (o9.sgmail.github.com [167.89.101.2]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20B4512702E for <quic-issues@ietf.org>; Tue, 6 Jun 2017 08:19:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=NECF4TK1aDk0EbqY39E+7fckguI=; b=tn6HAwNT6Ouiqg4s s/pLAmXto+D8hRUDlEG637OfO9UuImQf6EensIDHbD8ckIALshaOsP9q6ysILSxY 01DYXZUllz85nBZlY1AWGnYMAE6szI7FrOqEu/vP39K9Om/KJpIaS6YPi5Ln+Hfb 2AV9aTIYwKhsYtHpveFZ/OL3Pto=
Received: by filter1158p1mdw1.sendgrid.net with SMTP id filter1158p1mdw1-30467-5936C7E5-AA 2017-06-06 15:19:01.983510974 +0000 UTC
Received: from github-smtp2a-ext-cp1-prd.iad.github.net (github-smtp2a-ext-cp1-prd.iad.github.net [192.30.253.16]) by ismtpd0006p1iad1.sendgrid.net (SG) with ESMTP id DtYIGmL0Tnq4ZUd5CB-nHQ for <quic-issues@ietf.org>; Tue, 06 Jun 2017 15:19:01.885 +0000 (UTC)
Date: Tue, 06 Jun 2017 08:19:01 -0700
From: ekr <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4ab15032c33eb035fa23809c5c621110c4008c6f3e592cf00000001154e89e592a169ce0c62bcd7@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/311/306519885@github.com>
In-Reply-To: <quicwg/base-drafts/issues/311@github.com>
References: <quicwg/base-drafts/issues/311@github.com>
Subject: Re: [quicwg/base-drafts] GREASE the packet type octet (#311)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5936c7e5c35c2_4bce3fc022a75c34869ca"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: ekr
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak1pxcYE4BqqGOJZQFxC5qCbQnJ2OZxtnooZwq cSM+ZNUffAv/HJAfworMmyTeMWJC+WYoTS64ic/2dylws2vuqc2e6lO14cWoAVJKhZoXsiKqYoFy/t M/Triio35hk/+13xtfVCDdoyS2GboZGhBOsJA3qfys8wK7XHOa9LZB1xOw==
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/oz-4i1fcpBigLMw6_LxKsTGIol8>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Jun 2017 15:19:09 -0000

@huitema points out that we might want to have a keyed permutation because any static permutation is easily degreased. The observation here is that you can have a key that's shared across all of the connections, because we're not really worried about the middlebox connecting to the server and extracting the key for the transformation. With that in mind, here's an alternate keeed proposal.

```
1. Server generates a key K_static which it uses for all connections.
2. Packet has type P and last byte T
3. The server delivers K_static in its first flight.
4. For every packet, you compute P' = P ^(PRF(K, T) & 0x7f) where
    K = 0 for initial packets
    K = K_static for other packets.
```


-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/311#issuecomment-306519885