Re: [rtcweb] Consensus call regarding media security

Bernard Aboba <bernard_aboba@hotmail.com> Thu, 29 March 2012 12:54 UTC

Return-Path: <bernard_aboba@hotmail.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 429C321F8AC9 for <rtcweb@ietfa.amsl.com>; Thu, 29 Mar 2012 05:54:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.127
X-Spam-Level:
X-Spam-Status: No, score=-102.127 tagged_above=-999 required=5 tests=[AWL=0.472, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uIl3ypT+2WTd for <rtcweb@ietfa.amsl.com>; Thu, 29 Mar 2012 05:54:11 -0700 (PDT)
Received: from snt0-omc3-s1.snt0.hotmail.com (snt0-omc3-s1.snt0.hotmail.com [65.55.90.140]) by ietfa.amsl.com (Postfix) with ESMTP id 9591521F8A7B for <rtcweb@ietf.org>; Thu, 29 Mar 2012 05:54:11 -0700 (PDT)
Received: from SNT0-P5-EAS23 ([65.55.90.135]) by snt0-omc3-s1.snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675); Thu, 29 Mar 2012 05:54:10 -0700
X-Originating-IP: [130.129.20.41]
X-Originating-Email: [bernard_aboba@hotmail.com]
Message-ID: <snt0-p5-eas23A4F74F9163E475BCDDCF93480@phx.gbl>
References: <4F732531.2030208@ericsson.com> <BLU169-W80FA8377288974CAF4716F93480@phx.gbl> <4F745719.5090709@ericsson.com>
Content-Transfer-Encoding: base64
From: Bernard Aboba <bernard_aboba@hotmail.com>
Content-Type: text/plain; charset="utf-8"
In-Reply-To: <4F745719.5090709@ericsson.com>
Date: Thu, 29 Mar 2012 14:54:42 +0200
To: Magnus Westerlund <magnus.westerlund@ericsson.com>
MIME-Version: 1.0 (1.0)
X-OriginalArrivalTime: 29 Mar 2012 12:54:10.0035 (UTC) FILETIME=[08B65C30:01CD0DAB]
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>
Subject: Re: [rtcweb] Consensus call regarding media security
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Mar 2012 12:54:12 -0000

There are a number of potential variants:

a. DTLS-SRTP with IdP (Eric's proposal)
b. DTLS-SRTP as used with SIP (e.g. w/RFC 4474)
c. DTLS-SRTP-EKT
d. DTLS-SRTP with PKI (could be used in government or high security settings)

These variants differ in their potential use cases, security properties and interoperability with existing implementations. 

On Mar 29, 2012, at 14:35, "Magnus Westerlund" <magnus.westerlund@ericsson.com> wrote:
> I hope someone that knows the details can elaborate on this. I thought
> DTLS-SRTP has a core that you will need to implement. Then there is
> clearly a question of crypto algorithms to be supported. But that also
> applies to SRTP where we also need to select which crypto suites that
> are to be implemented if any in addtion to the MITM. The WG will need to
> select these details as part of the next steps.
> 
> Cheers
> 
> Magnus Westerlund
> 
> ----------------------------------------------------------------------
> Multimedia Technologies, Ericsson Research EAB/TVM
> ----------------------------------------------------------------------
> Ericsson AB                | Phone  +46 10 7148287
> Färögatan 6                | Mobile +46 73 0949079
> SE-164 80 Stockholm, Sweden| mailto: magnus.westerlund@ericsson.com
> ----------------------------------------------------------------------
>