Return-Path: <dyork@voxeo.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
 with ESMTP id 90F0E3A67E2; Tue, 14 Jul 2009 13:27:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[AWL=-0.000,
 BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id db3gDZjUuEQ9;
 Tue, 14 Jul 2009 13:27:13 -0700 (PDT)
Received: from voxeo.com (mmail.voxeo.com [66.193.54.208]) by core3.amsl.com
 (Postfix) with SMTP id 6A7BF3A67D3; Tue, 14 Jul 2009 13:27:12 -0700 (PDT)
Received: from [66.65.229.48] (account dyork HELO pc-00148.lodestar2.local) by
 voxeo.com (CommuniGate Pro SMTP 5.2.3) with ESMTPSA id 49415385;
 Tue, 14 Jul 2009 20:16:18 +0000
Message-Id: <53ADC9B8-F9D2-4B27-A6D8-96B507911343@voxeo.com>
From: Dan York <dyork@voxeo.com>
To: Roni Even <Even.roni@huawei.com>
In-Reply-To: <05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com>
Content-Type: multipart/alternative; boundary=Apple-Mail-146-859920856
Mime-Version: 1.0 (Apple Message framework v930.3)
Date: Tue, 14 Jul 2009 16:16:16 -0400
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>
 <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>
 <05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com>
X-Mailer: Apple Mail (2.930.3)
X-Mailman-Approved-At: Wed, 15 Jul 2009 08:14:53 -0700
Cc: speechsc@ietf.org, 'Saravanan Shanmugham' <sarvi@cisco.com>, rai@ietf.org
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>,
 <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>,
 <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 20:27:14 -0000

--Apple-Mail-146-859920856
Content-Type: text/plain;
	charset=US-ASCII;
	format=flowed;
	delsp=yes
Content-Transfer-Encoding: 7bit

Roni,

The current text at http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3 
  is:
------
12.3. Media session protection
Sensitive data is also carried on media sessions terminating on MRCPv2  
servers (the other end of a media channel may or may not be on the  
MRCPv2 client). This data includes the user's spoken utterances    and  
the output of text-to-speech operations. MRCPv2 servers MUST support  
SRTP for protection of audio media sessions. MRCPv2 clients that  
originate or consume audio similarly MUST support SRTP. Alternative  
media channel protection MAY be used if desired (e.g. IPSEC).
------

Based on your comments and the srtp-not-mandatory draft (which was  
just revised to http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03 
  ), my understanding would be that you are advocating something more  
like this:

------
12.3. Media session protection
Sensitive data is also carried on media sessions terminating on MRCPv2  
servers (the other end of a media channel may or may not be on the  
MRCPv2 client). This data includes the user's spoken utterances    and  
the output of text-to-speech operations. MRCPv2 servers MUST support a  
security mechanism for protection of audio media sessions. MRCPv2  
clients that originate or consume audio similarly MUST support a  
security mechanism for protection of the audio.
------

Is that an accurate summary of your feedback?  Would that text be  
acceptable?

Regards,
Dan

On Jul 9, 2009, at 4:56 PM, Roni Even wrote:

> Eric,
> My comment is that in this case in AVT we say that you do not need to
> mandate SRTP but mandate a security mechanism that can be  not only  
> SRTP but
> in a different layer like ipsec. This is why I gave a reference to the
> srtp-not-mandatory draft
>
> Roni
>
>> -----Original Message-----
>> From: Eric Burger [mailto:eburger@standardstrack.com]
>> Sent: Thursday, July 09, 2009 11:28 PM
>> To: Roni Even
>> Cc: Saravanan Shanmugham; Daniel Burnett; speechsc@ietf.org;
>> rai@ietf.org
>> Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19
>>
>> The reality is that NO ONE has implemented any security to date. The
>> GENART reviewer raised the same issue, and so far the work group has
>> the same response: MRCPv2 (the speechsc work group) is not planning  
>> on
>> figuring out which of the seven key exchange mechanisms to use in
>> SIP.  We are counting on the community publishing something, and
>> people using it.  After all, we are the "using SIP for media resource
>> control" work group, not the "media resource control work group using
>> something like SIP for control."
>>
>> Does this work for you?
>>
>> On Jul 7, 2009, at 3:40 PM, Roni Even wrote:
>>
>>> [snip]
>>>
>>>
>>> 18.   In section 12.3 the suggestion is to use SRTP as the mandatory
>>> interoperability mode. If the reason for mandating SRTP is for a
>>> common mode you should also decide on a key exchange mechanism. I
>>> suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-
>> not-mandatory-02
>>> for discussion on media security.
>
>
> _______________________________________________
> RAI mailing list
> RAI@ietf.org
> https://www.ietf.org/mailman/listinfo/rai

-- 
Dan York, Director of Conversations
Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com
Phone: +1-407-455-5859    Skype: danyork

Join the Voxeo conversation:
Blogs: http://blogs.voxeo.com
Twitter: http://twitter.com/voxeo  http://twitter.com/danyork
Facebook: http://www.facebook.com/voxeo









--Apple-Mail-146-859920856
Content-Type: text/html;
	charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

<html><body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =
-webkit-line-break: after-white-space; =
"><div>Roni,</div><div><br></div><div>The current text at&nbsp;<a =
href=3D"http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-1=
2.3">http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3=
</a> is:</div><div><pre><font class=3D"Apple-style-span" =
face=3D"Helvetica" size=3D"3"><span class=3D"Apple-style-span" =
style=3D"font-size: 12px; white-space: =
normal;">------</span></font></pre><pre><font class=3D"Apple-style-span" =
face=3D"Helvetica" size=3D"3"><span class=3D"Apple-style-span" =
style=3D"font-size: 12px; white-space: normal;">12.3.  Media session =
protection&nbsp;
   </span></font></pre><pre><font class=3D"Apple-style-span" =
face=3D"Helvetica" size=3D"3"><span class=3D"Apple-style-span" =
style=3D"font-size: 12px; white-space: normal;">Sensitive data is also =
carried on media sessions terminating on
   MRCPv2 servers (the other end of a media channel may or may not be on
   the MRCPv2 client).  This data includes the user's spoken utterances
   and the output of text-to-speech operations.  MRCPv2 servers MUST
   support SRTP for protection of audio media sessions.  MRCPv2 clients
   that originate or consume audio similarly MUST support SRTP.
   Alternative media channel protection MAY be used if desired (e.g.
   IPSEC).</span></font>
</pre></div><div>------</div><div><br></div><div>Based on your comments =
and the srtp-not-mandatory draft (which was just revised to&nbsp;<a =
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03">h=
ttp://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03</a> ), my =
understanding would be that you are advocating something more like =
this:</div><div><br></div><div>------</div><div><pre><font =
class=3D"Apple-style-span" face=3D"Helvetica" size=3D"3"><span =
class=3D"Apple-style-span" style=3D"white-space: normal; ">12.3. Media =
session protection&nbsp;</span></font></pre><pre><font =
class=3D"Apple-style-span" face=3D"Helvetica" size=3D"3"><span =
class=3D"Apple-style-span" style=3D"white-space: normal; ">Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances &nbsp; =
&nbsp;and the output of text-to-speech operations. MRCPv2 servers MUST =
support a security mechanism for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support a =
security mechanism for protection of the =
audio.&nbsp;</span></font></pre></div><div>------</div><div><br></div><div=
>Is that an accurate summary of your feedback? &nbsp;Would that text be =
acceptable?</div><div><br></div><div>Regards,</div><div>Dan</div><div><br>=
<div><div>On Jul 9, 2009, at 4:56 PM, Roni Even wrote:</div><br =
class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite"><div>Eric,<br>My comment is that in this case in AVT we =
say that you do not need to<br>mandate SRTP but mandate a security =
mechanism that can be &nbsp;not only SRTP but<br>in a different layer =
like ipsec. This is why I gave a reference to the<br>srtp-not-mandatory =
draft<br><br>Roni<br><br><blockquote type=3D"cite">-----Original =
Message-----<br></blockquote><blockquote type=3D"cite">From: Eric Burger =
[<a =
href=3D"mailto:eburger@standardstrack.com">mailto:eburger@standardstrack.c=
om</a>]<br></blockquote><blockquote type=3D"cite">Sent: Thursday, July =
09, 2009 11:28 PM<br></blockquote><blockquote type=3D"cite">To: Roni =
Even<br></blockquote><blockquote type=3D"cite">Cc: Saravanan Shanmugham; =
Daniel Burnett; <a =
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;<br></blockquote><=
blockquote type=3D"cite"><a =
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><br></blockquote><blockquote =
type=3D"cite">Subject: Re: RAI review of =
draft-ietf-speechsc-mrcpv2-19<br></blockquote><blockquote =
type=3D"cite"><br></blockquote><blockquote type=3D"cite">The reality is =
that NO ONE has implemented any security to date. =
The<br></blockquote><blockquote type=3D"cite">GENART reviewer raised the =
same issue, and so far the work group has<br></blockquote><blockquote =
type=3D"cite">the same response: MRCPv2 (the speechsc work group) is not =
planning on<br></blockquote><blockquote type=3D"cite">figuring out which =
of the seven key exchange mechanisms to use =
in<br></blockquote><blockquote type=3D"cite">SIP. &nbsp;We are counting =
on the community publishing something, and<br></blockquote><blockquote =
type=3D"cite">people using it. &nbsp;After all, we are the "using SIP =
for media resource<br></blockquote><blockquote type=3D"cite">control" =
work group, not the "media resource control work group =
using<br></blockquote><blockquote type=3D"cite">something like SIP for =
control."<br></blockquote><blockquote =
type=3D"cite"><br></blockquote><blockquote type=3D"cite">Does this work =
for you?<br></blockquote><blockquote =
type=3D"cite"><br></blockquote><blockquote type=3D"cite">On Jul 7, 2009, =
at 3:40 PM, Roni Even wrote:<br></blockquote><blockquote =
type=3D"cite"><br></blockquote><blockquote type=3D"cite"><blockquote =
type=3D"cite">[snip]<br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote =
type=3D"cite"><br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote =
type=3D"cite"><br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote type=3D"cite">18. &nbsp;&nbsp;In section 12.3 =
the suggestion is to use SRTP as the =
mandatory<br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote type=3D"cite">interoperability mode. If the =
reason for mandating SRTP is for =
a<br></blockquote></blockquote><blockquote type=3D"cite"><blockquote =
type=3D"cite">common mode you should also decide on a key exchange =
mechanism. I<br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote type=3D"cite">suggest you look at<a =
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-">http://tools.ietf=
.org/html/draft-ietf-avt-srtp-</a><br></blockquote></blockquote><blockquot=
e type=3D"cite">not-mandatory-02<br></blockquote><blockquote =
type=3D"cite"><blockquote type=3D"cite"> for discussion on media =
security.<br></blockquote></blockquote><br><br>___________________________=
____________________<br>RAI mailing list<br><a =
href=3D"mailto:RAI@ietf.org">RAI@ietf.org</a><br>https://www.ietf.org/mail=
man/listinfo/rai<br></div></blockquote></div><br><div =
apple-content-edited=3D"true"> <span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; -webkit-border-horizontal-spacing: =
0px; -webkit-border-vertical-spacing: 0px; color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; -webkit-text-decorations-in-effect: none; =
text-indent: 0px; -webkit-text-size-adjust: auto; text-transform: none; =
orphans: 2; white-space: normal; widows: 2; word-spacing: 0px; "><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">--&nbsp;</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">Dan York, =
Director of Conversations</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">Voxeo =
Corporation<span =
class=3D"Apple-converted-space">&nbsp;</span>&nbsp;&nbsp;<a =
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Phone: +1-407-455-5859&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;&nbsp;&nbsp;</span>Skype: =
danyork&nbsp;<span class=3D"Apple-converted-space">&nbsp;</span></div><div=
 style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Join the Voxeo conversation:</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Blogs: <a =
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 12px/normal Helvetica; =
min-height: 14px; ">Twitter: <a =
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a> &nbsp;<a =
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a></div><d=
iv style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 12px/normal Helvetica; =
min-height: 14px; ">Facebook: <a =
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a></=
div></div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
12px/normal Helvetica; min-height: 14px; "><br =
class=3D"khtml-block-placeholder"></div><br =
class=3D"Apple-interchange-newline"></span></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"> </div><br></div></body></html>=

--Apple-Mail-146-859920856--
