Re: [Secdispatch] EDHOC Summary

Göran Selander <goran.selander@ericsson.com> Fri, 12 April 2019 11:57 UTC

Return-Path: <goran.selander@ericsson.com>
X-Original-To: secdispatch@ietfa.amsl.com
Delivered-To: secdispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 02F711202A9 for <secdispatch@ietfa.amsl.com>; Fri, 12 Apr 2019 04:57:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.022
X-Spam-Level:
X-Spam-Status: No, score=-1.022 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FROM_EXCESS_BASE64=0.979, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aWToESdg43qJ for <secdispatch@ietfa.amsl.com>; Fri, 12 Apr 2019 04:57:23 -0700 (PDT)
Received: from EUR03-VE1-obe.outbound.protection.outlook.com (mail-eopbgr50063.outbound.protection.outlook.com [40.107.5.63]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C46A1201AF for <secdispatch@ietf.org>; Fri, 12 Apr 2019 04:57:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8ZULul0ziVzRmobcrxDKz7/CaBYO56ohBDu76gUee6Y=; b=bvo92yZdwfKsgA/5Jud2jf2K+PM/o/IWg5dnPULmgNk0FKzcP9bu+TUVCbk+cLGK1F2MeVhY8IL7FJkKk+FwRLgN2ucSTlmZhbNvjPiAr/Dmu6fXuGCPRoVWAkiyajEDYHOtI4ZdIxMupyJ/3duUwF+YrCbijSKgoQymFqix9i8=
Received: from HE1PR07MB4172.eurprd07.prod.outlook.com (20.176.166.25) by HE1PR07MB3067.eurprd07.prod.outlook.com (10.170.244.153) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1792.8; Fri, 12 Apr 2019 11:57:20 +0000
Received: from HE1PR07MB4172.eurprd07.prod.outlook.com ([fe80::c587:c2ec:e227:84fd]) by HE1PR07MB4172.eurprd07.prod.outlook.com ([fe80::c587:c2ec:e227:84fd%4]) with mapi id 15.20.1813.003; Fri, 12 Apr 2019 11:57:20 +0000
From: Göran Selander <goran.selander@ericsson.com>
To: Tero Kivinen <kivinen@iki.fi>, John Mattsson <john.mattsson@ericsson.com>
CC: "secdispatch@ietf.org" <secdispatch@ietf.org>
Thread-Topic: [Secdispatch] EDHOC Summary
Thread-Index: AdTlTpiwSQddzTDHR8ys25qjhhiyAAJEpqUAAB7BU4AAGO0gAAAKvdwAAFJR+IAAIN4XgA==
Date: Fri, 12 Apr 2019 11:57:20 +0000
Message-ID: <C3453F96-8003-4F30-B659-DF3200F1044B@ericsson.com>
References: <359EC4B99E040048A7131E0F4E113AFC01B3311A9F@marchand> <012a4798-fc70-4b5d-b0da-373221c95d38@www.fastmail.com> <721B6044-8DA1-4173-BE73-87D37136DFEE@ericsson.com> <1bfbef5a-027a-460e-b421-fb4c3a82e583@www.fastmail.com> <D7468312-88B4-4546-9D72-8895780A6DD4@ericsson.com> <23727.48301.311217.991808@fireball.acr.fi>
In-Reply-To: <23727.48301.311217.991808@fireball.acr.fi>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.17.1.190326
authentication-results: spf=none (sender IP is ) smtp.mailfrom=goran.selander@ericsson.com;
x-originating-ip: [192.176.1.87]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 4dff74b5-3ca3-4439-8e87-08d6bf3e048d
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600139)(711020)(4605104)(2017052603328)(7193020); SRVR:HE1PR07MB3067;
x-ms-traffictypediagnostic: HE1PR07MB3067:
x-microsoft-antispam-prvs: <HE1PR07MB306712E0CFEC150387BB014FF4280@HE1PR07MB3067.eurprd07.prod.outlook.com>
x-forefront-prvs: 0005B05917
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(346002)(376002)(39860400002)(396003)(366004)(136003)(199004)(189003)(229853002)(68736007)(85182001)(14444005)(305945005)(105586002)(8676002)(81156014)(82746002)(33656002)(6636002)(256004)(6506007)(85202003)(476003)(106356001)(102836004)(6486002)(71190400001)(81166006)(71200400001)(76176011)(5660300002)(6436002)(66066001)(14454004)(7736002)(8936002)(6246003)(11346002)(25786009)(486006)(26005)(446003)(316002)(97736004)(66574012)(186003)(99286004)(3846002)(83716004)(6116002)(4326008)(478600001)(2616005)(110136005)(6512007)(86362001)(53936002)(2906002)(58126008)(36756003)(93886005); DIR:OUT; SFP:1101; SCL:1; SRVR:HE1PR07MB3067; H:HE1PR07MB4172.eurprd07.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: 3544U26JFgwfgxnW8LMGfJHB4/HYKKic7+lAgSyh9pQYI0mQQU83trPbG0vnZhvl5XN2dEt/8W6KXDRHDCx3KGhNLl887LdExGH2sQmY5kLwYwml1KtJufhCGrVvNyqlLaXoM+wtRHxWwljF5pqsKG1U7pxu581q3b91NSDeHMSi35WcEqfzkNL+jc+Hc1jwZ0DRPZGQZ+weZ/M2/IAYVm2cxcX6wGOWIX6qwf4zzYlSIZRhI/Bt4GfIc6pDGK8ByLDE2nEw3IHRKNmkJDnqaV5f30CioslhbsTOhlGh4I5elwbatNd+gNSCoPqsdF5xuPY95/zLPPnai+XZDzWIQ3UNg9alotEO3NP5oYz2KJu7wnpBCYccI5Kmd164rQhHCEt6czsLxUobzl2If7Nu5KGiexzE/CqnDiEAf2llwOE=
Content-Type: text/plain; charset="utf-8"
Content-ID: <14CC837522156443B8BB403345FAF03F@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 4dff74b5-3ca3-4439-8e87-08d6bf3e048d
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Apr 2019 11:57:20.3596 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR07MB3067
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/eYga08ByoYmSsQ4qfgCGmf7zVFQ>
Subject: Re: [Secdispatch] EDHOC Summary
X-BeenThere: secdispatch@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Dispatch <secdispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch/>
List-Post: <mailto:secdispatch@ietf.org>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Apr 2019 11:57:26 -0000

Hi Tero,

On 2019-04-12, 00:16, "Tero Kivinen" <kivinen@iki.fi> wrote:

    John Mattsson writes:
    > constrained some of them are. For the target network technologies
    > LPWAN over LoRaWAN and 6TiSCH over IEEE 802.15.4, the requirements
    > for message size are clear (under 50 bytes).
    
    IEEE 802.15.9 specifies how to use KMPs in IEEE 802.15.4, and it
    provides fragmentation of larger messages, so message size limits are
    not absolute in IEEE 802.15.4 environment. Of course the fewer
    fragments are needed the more efficient the protocol will be, but
    there is no absolute limit that is required.
    
    Some of the PHYs in IEEE 802.15.4 support larger frame sizes (up to
    2048 bytes) and some of them support smaller (smallest are 20-30 bytes
    or so, but that PHY also includes another layer of fragmentation).
    
    The most common maximum frame size is 127 bytes, including header, and
    the header is usually less than 20 octets if no security header is
    used (which normally is not used for key management protocols as there
    is no keys yet). Even with security the overhead is usually about 12
    bytes more, thus the total overhead is around 20-40 bytes. This means
    there is space for around 80-100 bytes of actual frame payload for
    IEEE 802.15.4 in normal cases.
    
    Targetting for 50 bytes is quite pessimistic for IEEE 802.15.4.

[GS] This benchmark provided by 6TiSCH is looking at bootstrapping in a multihop network using the 6tisch minimal security setup with a stateless join proxy, which is how the AKE is planned to be used in this context. The statelessness of the proxy leads to additional overhead in the network.

Göran