Re: [TICTOC] Please Comment on Practical Solutions for Encrypted Synchronization Protocol

Tal Mizrahi <talmi@marvell.com> Sun, 11 March 2012 09:24 UTC

Return-Path: <talmi@marvell.com>
X-Original-To: tictoc@ietfa.amsl.com
Delivered-To: tictoc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6807321F8455 for <tictoc@ietfa.amsl.com>; Sun, 11 Mar 2012 01:24:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ySOXjQ-BKikp for <tictoc@ietfa.amsl.com>; Sun, 11 Mar 2012 01:24:06 -0800 (PST)
Received: from galiil.marvell.com (galiil.marvell.com [199.203.130.254]) by ietfa.amsl.com (Postfix) with ESMTP id 9543F21F8454 for <tictoc@ietf.org>; Sun, 11 Mar 2012 01:24:05 -0800 (PST)
From: Tal Mizrahi <talmi@marvell.com>
To: Cui Yang <cuiyang@huawei.com>, "tictoc@ietf.org" <tictoc@ietf.org>
Date: Sun, 11 Mar 2012 11:24:00 +0200
Thread-Topic: [TICTOC] Please Comment on Practical Solutions for Encrypted Synchronization Protocol
Thread-Index: Acz8E0iUW5Z05eDtRseAiVHAxMBZUgDVAA3Q
Message-ID: <74470498B659FA4687F0B0018C19A89C017E97229D9C@IL-MB01.marvell.com>
References: <8CC0CB0BCAE52F46882E17828A9AE2161A032B90@SZXEML508-MBS.china.huawei.com>
In-Reply-To: <8CC0CB0BCAE52F46882E17828A9AE2161A032B90@SZXEML508-MBS.china.huawei.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_74470498B659FA4687F0B0018C19A89C017E97229D9CILMB01marve_"
MIME-Version: 1.0
Subject: Re: [TICTOC] Please Comment on Practical Solutions for Encrypted Synchronization Protocol
X-BeenThere: tictoc@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Timing over IP Connection and Transfer of Clock BOF <tictoc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tictoc>, <mailto:tictoc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tictoc>
List-Post: <mailto:tictoc@ietf.org>
List-Help: <mailto:tictoc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tictoc>, <mailto:tictoc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 11 Mar 2012 09:24:08 -0000

Hi Yang,

A couple of comments:

1.       The assumption in the draft is that one-step timestamping is not accurate. However, it is basically a question of implementation. It is possible to perform one-step timestamping and to perform constant-latency-encryption/decryption. Furthermore, there are existing products that do exactly that.
There are a few academic papers that deal with the accuracy of encrypted PTP, for example see A. Treytl, B. Hirschler, "Securing IEEE 1588 by IPsec tunnels - An analysis".

2.       If I understand the goal of this draft correctly, it appears to be presenting the motivation for draft-xu-tictoc-ipsec-security-for-synchronization. If this is indeed the case, you may want to consider integrating the two drafts.

BR
Tal Mizrahi.

From: tictoc-bounces@ietf.org [mailto:tictoc-bounces@ietf.org] On Behalf Of Cui Yang
Sent: Wednesday, March 07, 2012 5:35 AM
To: tictoc@ietf.org
Subject: [TICTOC] Please Comment on Practical Solutions for Encrypted Synchronization Protocol

Hi, all,

I have posted a new draft that discusses the practical solutions for encrypted synchronization protocols.

Since we have discussed a lot on this problem, and the security requirement of synchronization also noted that confidentiality may need protection, especially in case that the confidentiality protection is mandatory. Synchronization should be available when the traffic is encrypted. The influences by the encryption are explained, and several possible solutions have been discussed.
The URL is below, please review and comment.

    Title      : Practical solutions for encrypted synchronization protocol
Author(s)  : Y. Cui,
M. Bhatia,
D. Zhang
Filename   : draft-cui-tictoc-encrypted-synchronization-00.txt
Pages     : 10
Date      : Mar. 1, 2012
   This informational document analyzes the accuracy issues with time
   synchronization protocols when time synchronization packets are
   encrypted during transmission. In addition, several candidate
  solutions on such issues are introduced.

A URL for this Internet-Draft is:
http://datatracker.ietf.org/doc/draft-cui-tictoc-encrypted-synchronization

Thanks,
Yang

==================

Yang Cui,  Ph.D.

Huawei Technologies

cuiyang@huawei.com<mailto:cuiyang@huawei.com>