Re: [T2TRG] dtls resume

Hannes Tschofenig <hannes.tschofenig@gmx.net> Thu, 03 November 2016 19:09 UTC

Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: t2trg@ietfa.amsl.com
Delivered-To: t2trg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9F624129431 for <t2trg@ietfa.amsl.com>; Thu, 3 Nov 2016 12:09:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.598
X-Spam-Level:
X-Spam-Status: No, score=-3.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_SORBS_SPAM=0.5, RP_MATCHES_RCVD=-1.497, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E0dWC6V61HNo for <t2trg@ietfa.amsl.com>; Thu, 3 Nov 2016 12:09:10 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9DE1B1293E4 for <t2trg@irtf.org>; Thu, 3 Nov 2016 12:09:09 -0700 (PDT)
Received: from [192.168.91.155] ([80.92.118.15]) by mail.gmx.com (mrgmx102) with ESMTPSA (Nemesis) id 0MUCTO-1cSKES1Svi-00R2WW; Thu, 03 Nov 2016 20:09:06 +0100
To: Daniel Lux <daniel@seluxit.com>, "t2trg@irtf.org" <t2trg@irtf.org>
References: <1478162371.13408.8.camel@seluxit.com>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <136ca589-91da-b40f-5d22-e846cb7593a4@gmx.net>
Date: Thu, 03 Nov 2016 20:09:04 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.4.0
MIME-Version: 1.0
In-Reply-To: <1478162371.13408.8.camel@seluxit.com>
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="S2tNsmc9MfhVFE6oGwrSGLoiJgPpDrIOo"
X-Provags-ID: V03:K0:t/dGLqnHufKR5OPv4zahjNJVmeZlGVMQwuMQyiQGkSX/WhCaU+D A/H//B+u7QuUdf8HtO2+5mGvwl7wYuMIWyLeXL94OmMm9aQtO7MOcLFY/at3Bh5fgrMbxzC u0RlfH5WI/lBlNz+WDxmQLIXx76Gw/H8j5KauKLgSI3/2tO1AVG6Oe15zB/s8N574NIH3RZ s3+pzcDj2o4EhWs/MHzcQ==
X-UI-Out-Filterresults: notjunk:1;V01:K0:jbRB77xAtCg=:VaumrL93XFRtYYzwqU5xs0 3JccQ56Gsn4bMdUGPucFqx2NxQQF8uN/sD1D1W5CP/q6VYxV78qMMdwVoWWHKewLAeq/4t/Gx 50MMQsJiJ9eWQiMqgDUs9vaBXP+5IFdVZSQbHpgNa5zYwr6vd7vfhPB04qT+nptfqrdK6Icc8 7sBWl/mxHRFez9UbRXnjcL0xaiK9smnMPA1a/tzH/h/sGjZaLuTcv0bLhaMGRXctzNXpJZkyV fo9FeT8yf2j7g+4FxhaBMx2Hgwe5fphHEYiB4XbY7yMJAqmdKy8IhOdLWNFllBpeTht8ZI9qg mQzxoDCXaS2c9AbG3Lk8lkNzlDgdIK34ISD4USeSz7dYRKOe86F7hCY2+K1ifyjafIhIvUF0A aX/ly2ky3TvRsJVzsDKSIkJpR6kkMst2uIugZRUTJkxfbok2WcFNrECq2O7vPDigB/7liZmyV FkmPclSmlOmynjSLo2+qt2rwo41A1IAqTzVKWRHyXFGDNmQx1BEPuoHcXbjENUGbakiNGdIIU lji+/BpX+oC+dsIdgGOc89BeUvCbkfFrgfYzjYzy7/rBgWX9CavXzPpRd3/DpjFiiufGgOx/y ausDb688xyOiU5L3X6jV7RzLqZHoVaFm5IUL08xODN82LnxSGFgvHZNmeEh8bBHiWwgizvPq6 YtHFYqVbIpgtVgYJZdkkM0Y+2ExnwetvdWVP0bge4YWKcnJLV6s5v0XSCDKajKHoUP3o3E2r/ TjZTaD+L3L/0K3TnF1lLOr2WSaxedKAbOymanNZm2uiyCN9TRImDeqbXhuo=
Archived-At: <https://mailarchive.ietf.org/arch/msg/t2trg/hrU-Y9rHO6-psBIfcTdm_gn4FmY>
Subject: Re: [T2TRG] dtls resume
X-BeenThere: t2trg@irtf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "IRTF Thing-to-Thing \(T2T\) Research-Group-in-creation" <t2trg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/t2trg>, <mailto:t2trg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/t2trg/>
List-Post: <mailto:t2trg@irtf.org>
List-Help: <mailto:t2trg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/t2trg>, <mailto:t2trg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Nov 2016 19:09:11 -0000

Section 4 of
https://tools.ietf.org/html/draft-fossati-tls-iot-optimizations-00

Ciao
Hannes


On 11/03/2016 09:39 AM, Daniel Lux wrote:
> During our meeting in Ludwigsuburg at the implementers workshop we
> discussed the DTLS resume problem.
> This problem occurs when a constrained device behind a NAT communicates
> with a server and the NAT changes the
> UDP source port or the IP address of the sending constrained device,
> while the server uses the source address and port number
> to identify the DTLS connection.
> 
> One other solution than adding a parameter to the DTLS records would be
> to construct the IV/NONCE in a way that
> allows the server to identify the session from that information.
> This would mean that we would need to specify a new cipher suite, but
> otherwise it might be an elegant solution.
> Has anybody suggested this kind of solution to the resume problem?
> 
> Kind regards
> 
>   Daniel
> -- 
> Daniel Lux
> Tlf: (+45)-46 922 722
> Seluxit
> Hjulmagervej 32B
> 9000 Aalborg
> Denmark
> 
> 
> 
> 
> _______________________________________________
> T2TRG mailing list
> T2TRG@irtf.org
> https://www.irtf.org/mailman/listinfo/t2trg
>