Re: [Secdispatch] EDHOC

Roman Danyliw <rdd@cert.org> Thu, 28 February 2019 15:27 UTC

Return-Path: <rdd@cert.org>
X-Original-To: secdispatch@ietfa.amsl.com
Delivered-To: secdispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BC62D130EC5 for <secdispatch@ietfa.amsl.com>; Thu, 28 Feb 2019 07:27:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cert.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YJEcnh22Ijea for <secdispatch@ietfa.amsl.com>; Thu, 28 Feb 2019 07:27:26 -0800 (PST)
Received: from taper.sei.cmu.edu (taper.sei.cmu.edu [147.72.252.16]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B3E721271FF for <secdispatch@ietf.org>; Thu, 28 Feb 2019 07:27:26 -0800 (PST)
Received: from korb.sei.cmu.edu (korb.sei.cmu.edu [10.64.21.30]) by taper.sei.cmu.edu (8.14.7/8.14.7) with ESMTP id x1SFRKcZ020525; Thu, 28 Feb 2019 10:27:20 -0500
DKIM-Filter: OpenDKIM Filter v2.11.0 taper.sei.cmu.edu x1SFRKcZ020525
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cert.org; s=yc2bmwvrj62m; t=1551367640; bh=bwzxGTWPuGLFjHhswo9kh5BfCESwtJwMGqVhKVYAkGo=; h=From:To:CC:Subject:Date:References:From; b=i+dd/hX1LO2AWv+2tT1DCzVYDgmc0Csv7hXp9I6xf9CtyIY6nI6ZDM7BObwD80kr7 RxQLLPjyreVQ8POieVcOVjPcqB/JDZ8v7jnWrT1rMKA5IuINyOxV7L71BJMGT/tYTq luldQV1EsT33wRzJFaFQHAHmaDj0mWp314osQf7I=
Received: from CASCADE.ad.sei.cmu.edu (cascade.ad.sei.cmu.edu [10.64.28.248]) by korb.sei.cmu.edu (8.14.7/8.14.7) with ESMTP id x1SFRIRQ019907; Thu, 28 Feb 2019 10:27:18 -0500
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASCADE.ad.sei.cmu.edu ([10.64.28.248]) with mapi id 14.03.0435.000; Thu, 28 Feb 2019 10:27:17 -0500
From: Roman Danyliw <rdd@cert.org>
To: "secdispatch@ietf.org" <secdispatch@ietf.org>
CC: Francesca Palombini <francesca.palombini@ericsson.com>, John Mattsson <john.mattsson@ericsson.com>, Göran Selander <goran.selander@ericsson.com>
Thread-Topic: EDHOC
Thread-Index: AQHUou5Zx1xiDx+jgESY4I5hUyszWqW8B+hAgDmlp4A=
Date: Thu, 28 Feb 2019 15:27:16 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFC01857DD7A7@marathon>
References: <D629D980-C059-474F-B259-2700F2EEAE41@ericsson.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/qYSqRMXLolHWYMtm2hT9-2EBvys>
Subject: Re: [Secdispatch] EDHOC
X-BeenThere: secdispatch@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Dispatch <secdispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch/>
List-Post: <mailto:secdispatch@ietf.org>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Feb 2019 15:27:29 -0000


> -----Original Message-----
> From: Roman Danyliw
> Sent: Tuesday, January 22, 2019 6:10 PM
> To: secdispatch@ietf.org
> Cc: Francesca Palombini <francesca.palombini@ericsson.com>; John
> Mattsson <john.mattsson@ericsson.com>; 'Göran Selander'
> <goran.selander@ericsson.com>
> Subject: RE: EDHOC
> 
> Hi!
> 
> > -----Original Message-----
> > From: Secdispatch [mailto:secdispatch-bounces@ietf.org] On Behalf Of
> > Göran Selander
> > Sent: Wednesday, January 02, 2019 5:56 PM
> > To: secdispatch@ietf.org
> > Cc: Francesca Palombini <francesca.palombini@ericsson.com>; John
> > Mattsson <john.mattsson@ericsson.com>
> > Subject: [Secdispatch] EDHOC
> >
> > We have been advised to ask secdispatch to consider EDHOC:
> > https://tools.ietf.org/html/draft-selander-ace-cose-ecdhe
> 
> [snip]
> 
> > There has been a number of reviews of different versions of the draft;
> > both by people who want to deploy it and by people analysing the
> > security. A formal verification was presented at SSR 2018.
> 
> To save others the search time, I believe this is the reference on a formal
> verification of EDHOC:
> 
> Bruni A., Sahl Jørgensen T., Grønbech Petersen T., Schürmann C. (2018)
> Formal Verification of Ephemeral Diffie-Hellman Over COSE (EDHOC). In:
> Cremers C., Lehmann A. (eds) Security Standardisation Research. SSR 2018.
> Lecture Notes in Computer Science, vol 11322. Springer, Cham
> 
> https://link.springer.com/content/pdf/10.1007%2F978-3-030-04762-7_2.pdf

The following is an alternate reference to this paper that isn't behind a paywall (thanks to one of the paper's authors, Alessandro Bruni):

https://alessandrobruni.name/papers/18-edhoc.pdf

Additionally, the model associated with this paper can be found here:

https://github.com/theisgroenbech/edhoc-proverif

Roman