[saag] Request for guidance regarding E2E security over Diameter
<lionel.morand@orange.com> Thu, 26 March 2015 16:24 UTC
From: lionel.morand@orange.com
To: "saag@ietf.org" <saag@ietf.org>
Thread-Topic: Request for guidance regarding E2E security over Diameter
Date: Thu, 26 Mar 2015 16:24:25 +0000
Cc: "dime-chairs@tools.ietf.org" <dime-chairs@tools.ietf.org>
Subject: [saag] Request for guidance regarding E2E security over Diameter
Hi, As currently specified, the Diameter Base protocol (RFC6733) only offers transport level protection between neighboring Diameter peers, using either TLS/TCP, DTLS/SCTP, or IPsec as last resort. However, no mechanism has been defined to ensure E2E security for data (in the conveyed (in the form of Attribute-Value Pairs (AVPs)) in Diameter messages between two endpoints. Early 2000, at the beginning of the work on Diameter, CMS (Cryptographic Message Syntax) was identified as solution to provide AVP-level E2E security but this work was not completed due to lack of deployment interest (at least at that time) and the foreseen complexity of the developed solution for Diameter. Due to the renewed interest for E2E security over Diameter, mainly for inter-domain signaling in the mobile network environment, the DIME WG has decided to reactivate the work on E2E security for Diameter. The first step is almost completed, with a document (draft-ietf-dime-e2e-sec-req-02) defining the requirements for an AVP-level E2E security solution. The second step will be work on the specification of such mechanism. An early proposal was to derive a solution from JOSE, encapsulating JOSE objects for integrity protection and AVP encryption. It is however expected that other mechanisms could be proposed as candidate solutions. And we know already that there are existing discussions on alternative to JOSE (e.g. COSE). Whatever the proposed solution(s),the DIME WG has not (and will not have) the expertise required to evaluate and select the more appropriate security mechanism for E2E security over Diameter. We are therefore interested by any guidance and support from SAAG regarding the development of a solution for E2E security over Diameter, based on the requirements collected in draft-ietf-dime-e2e-sec-req-02. Regards, Lionel
