Re: [T2TRG] [TLS] ITDA - IoT Device Authentication
Sankalp Bagaria <sankalp.nitt@gmail.com> Mon, 18 February 2019 01:38 UTC
Return-Path: <sankalp.nitt@gmail.com>
X-Original-To: t2trg@ietfa.amsl.com
Delivered-To: t2trg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B1461130E86 for <t2trg@ietfa.amsl.com>; Sun, 17 Feb 2019 17:38:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SS-0PTzdDdao for <t2trg@ietfa.amsl.com>; Sun, 17 Feb 2019 17:38:07 -0800 (PST)
Received: from mail-ot1-x342.google.com (mail-ot1-x342.google.com [IPv6:2607:f8b0:4864:20::342]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E9FE2130E9C for <T2TRG@irtf.org>; Sun, 17 Feb 2019 17:38:06 -0800 (PST)
Received: by mail-ot1-x342.google.com with SMTP id m1so25712783otf.5 for <T2TRG@irtf.org>; Sun, 17 Feb 2019 17:38:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=zIheLh3CCN4aD8aviI8TqKeETE6GNpc3FhQyW3Nvrfw=; b=m/SWN4QmIE4vkC+1exyB9jvz9soy/a9us8yXNHSEjUaEEZwy/abu5e2N2d/AukaF2k NBTdFm5TMsCMj+607l3i6ZHqJ5YSKAlM5RxPbKatQwnqZpbmCQ5RWrygNv2uVbapJxEd s8lNevLOP/fLPxKXCKOs86psAgAR/k8Ra5A5fDOdAhT27XWk3Fdx3oOglZ33tlFywHpx Q2ppKzDPpZWf6qKeOtpskVVWfwiH7P0TUhZvNwNvN+hhru1ZTnYLwuM3oOhbDQRGUGBC Q3KjELQ6Z3rvI5o96tUIF3oUHERtxW8zXBWimH13zzlm/ypa1QeoX7LJbDCExWHAw1DF /orw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=zIheLh3CCN4aD8aviI8TqKeETE6GNpc3FhQyW3Nvrfw=; b=rzpq2lP0ouHv974Apt7SBRMjLvewONsZoC7klUqDX81KXwjdpGUxSdnc6QeLuUYqdN 0Udx98N7ix0K1ouWEp6txUx3Nwrcg3uzrnQFdTXQc1k907/EgtJrAk2c87v4nQRRl/IK KD7ENzefi2u1rLnqO22mBrfqjW0UXVGnuGekT7cFUH5BA67sbYDZ0lYnhVd2xOebm7MJ sBJ3FhTnzYMmsTNsYPlQtrjkmdyxdl06N+iLdByvtddaqM1/4RTd9OxmHiGZq4iPTjJF R+sLtkkh/Ry/gxrsGIegjaQKBpTfXm08TPUcDtNETd5LrfZOojFXTLldyId6HsJGrrS/ td2A==
X-Gm-Message-State: AHQUAuaf36mz+EG215xoZ/bUrygcKW+tE67DNuBJ1umbkbZL8WkTz56r KaXF+9sCU8pOm4aToT7GKCHxPGx8IA5T+5APqgs=
X-Google-Smtp-Source: AHgI3IYmmlaxzph/GYzyBZFRm+uY/EU3CWuSssQyX3kDuaXygDoYwYE9HBZnxwo2UB2uUbauv7Bg09bxAUUPu/8o2Io=
X-Received: by 2002:a9d:130:: with SMTP id 45mr12925383otu.355.1550453885900; Sun, 17 Feb 2019 17:38:05 -0800 (PST)
MIME-Version: 1.0
References: <CAPZZOTgmiDVxJmEYq7J6amgCaWrdcBHDjww=ZjrVd0m-5nbsjg@mail.gmail.com> <1550365230138.15157@cs.auckland.ac.nz> <DBF8D4B0-0E1E-4C97-9923-B88FBC7AE823@akamai.com>
In-Reply-To: <DBF8D4B0-0E1E-4C97-9923-B88FBC7AE823@akamai.com>
From: Sankalp Bagaria <sankalp.nitt@gmail.com>
Date: Mon, 18 Feb 2019 07:07:53 +0530
Message-ID: <CAPZZOTgh9ODmZOBeUrk85xzYSe-jmeQ46JXd_+ZkrRXCmgVx1g@mail.gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Cc: Peter Gutmann <pgut001@cs.auckland.ac.nz>, tls@ietf.org, "T2TRG@irtf.org" <T2TRG@irtf.org>
Content-Type: multipart/alternative; boundary="0000000000001c1b210582212d38"
Archived-At: <https://mailarchive.ietf.org/arch/msg/t2trg/qQuJmLaEoGCGq-YuSoahIOpQ5B0>
Subject: Re: [T2TRG] [TLS] ITDA - IoT Device Authentication
X-BeenThere: t2trg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IRTF Thing-to-Thing Research Group <t2trg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/t2trg>, <mailto:t2trg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/t2trg/>
List-Post: <mailto:t2trg@irtf.org>
List-Help: <mailto:t2trg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/t2trg>, <mailto:t2trg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Feb 2019 01:38:11 -0000
Hi, Servers are usually more secure and can store challenge/ response pairs for all clients it connects with in Oracle. Remote IoT devices can be attacked physically and keys retrieved from them. To prevent this, costly and complex tamper proof cryptographic circuitry is used. PUF provides a cheaper alternative to complex and expensive cryptographic circuitry. As keys need not be stored at the IoT device. When PUF receives a challenge from server, it calculates response and sends it to server. Thanks and Regards, Sankalp Bagaria.. On Mon 18 Feb, 2019, 12:20 AM Salz, Rich, <rsalz@akamai.com> wrote: > I would also be concerned about adding a "new" scheme that easily > functions as an oracle. > > On 2/16/19, 8:01 PM, "Peter Gutmann" <pgut001@cs.auckland.ac.nz> wrote: > > Sankalp Bagaria <sankalp.nitt@gmail.com> writes: > > >We propose that the server is authenticated using X509 certificate in > a TLS > >1.3 like protocol. The Server sends 32-byte Challenge. Client replies > by > >sending 32-byte Response. > > Something very similar to this already exists in the form of > CHAP/MSCHAP over > PEAP/EAP-TLS/EAP-TTLS. It's supported by every Radius server and vast > numbers > (probably billions) of clients. To compete against this huge > installed base, any > new proposal would have to be pretty spectacular... > > Peter. > > _______________________________________________ > TLS mailing list > TLS@ietf.org > https://www.ietf.org/mailman/listinfo/tls > > >
- [T2TRG] ITDA - IoT Device Authentication Sankalp Bagaria
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Peter Gutmann
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Sankalp Bagaria
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Salz, Rich
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Sankalp Bagaria
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Salz, Rich
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Sankalp Bagaria
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Salz, Rich
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Sankalp Bagaria
- Re: [T2TRG] ITDA - IoT Device Authentication Paul Lambert
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Eliot Lear
- Re: [T2TRG] ITDA - IoT Device Authentication Sankalp Bagaria
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Sankalp Bagaria
- Re: [T2TRG] [TLS] ITDA - IoT Device Authentication Salz, Rich