Re: [tsvwg] I-D Action: draft-ietf-tsvwg-rfc4895-bis-02.txt

John Mattsson <john.mattsson@ericsson.com> Sun, 10 March 2024 06:29 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: tsvwg@ietfa.amsl.com
Delivered-To: tsvwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5CB83C14F5E5 for <tsvwg@ietfa.amsl.com>; Sat, 9 Mar 2024 22:29:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ztnh13FMo-MW for <tsvwg@ietfa.amsl.com>; Sat, 9 Mar 2024 22:29:22 -0800 (PST)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2069.outbound.protection.outlook.com [40.107.22.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6E062C14F5E4 for <tsvwg@ietf.org>; Sat, 9 Mar 2024 22:29:22 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=bgOR2dXPAWPQ5IH+93FZ1BaGmxphxTEyGm9WtRVaIntyiScmcSQAa60SqWE1qgwioGRErNa66fa65V6gCC6WSvUXKd+VE1tKVZBJXQu4F0yo9RGphg7mCE2teoRtF4U2o4LHau3yjlidVn9WHyf/m4RA5EbZEC5Nb6ifM3albR579enfav79cwGJMjqKncbwtKZp7r1pbF5+EIuc57jkvcIw6gCCLFsQwdyx6oo98VwEqMs0bqLW8ogge9tqJF5Hf32fF4egJGM9xg5D6cUdIwyuYD2OP55PIOJgMCA45++MWX5bx45vC65Gthp/MhWioJAOqkN9jqsdDbnJmPaVhQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=BoSPmMjgwGO6igfC2bgDidwFAGEEhQUjnUM4OtSRerc=; b=UKDUTHfskCkXN0Sba4volP2/xP3RdMR2E2ol/QJXEPeEM/4zHqgOiVU1GXJAk7Mop6gJsLHe9XCEJzo+aPdZQ8MzcLaHBX2S9hoXJl6Ix7L3VNNE6D+tb9TY/Od2cSwo2keMMkkWB4NF9eySSTqUqzhM9dNlsNhAaFUDpPMmm+6TltI8/sPEO9oWewYdRS9USgzNOd4MXu9/37O8edSfucI6HkVRMRC9opjkjy4DNWPGzTJO5UsMq9x7KlMTWNLYjRQmD68U8ooG5ZgLb45evvKcT5D55soGzrXKm5xmhDVR4YMpatCQUzb6hl0EWETgBF3mxtu+9xpYDBYPGMZ5Fg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=BoSPmMjgwGO6igfC2bgDidwFAGEEhQUjnUM4OtSRerc=; b=Qt4p2ODKEveEhFKA+4jN+xO9BW/Gnb6tMw9gnext2e69Y2J1pxC8MeXeMd22n0n5jlwWV5g4h2NEx8B+Yk6YpOp26b6aNHHkpUMRxJq2UrNbSedTHk5i4SA2b7b97tQFoD6tQJfHfEcUhPGy4U3Kqm2tubp+BKeMKETyDxmQn5BSzOqL2q4ER02xt+6FW+R+cvxOTrZDOiChT/2uYBas3zBmQQgy0AItaovucYWn8AJKAt68d3+uLL5FYUUfaEUytzV+UNvmXyGYyEn6J8A6RS2+7XnLC44kjXsuUsWgwUi1+yD1nYB2UkYTEQAGYkryEsGPbSepJrxKuCh4sgeOww==
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com (2603:10a6:150:114::10) by AS4PR07MB8532.eurprd07.prod.outlook.com (2603:10a6:20b:4eb::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7362.33; Sun, 10 Mar 2024 06:29:19 +0000
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::b0d0:9785:585a:9568]) by GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::b0d0:9785:585a:9568%4]) with mapi id 15.20.7362.031; Sun, 10 Mar 2024 06:29:18 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: "tsvwg@ietf.org" <tsvwg@ietf.org>
Thread-Topic: [tsvwg] I-D Action: draft-ietf-tsvwg-rfc4895-bis-02.txt
Thread-Index: AQHacrMKaIeIKbPA20mkpTrI/dJyyg==
Date: Sun, 10 Mar 2024 06:29:18 +0000
Message-ID: <GVXPR07MB96786EE4554285EA327565B389252@GVXPR07MB9678.eurprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVXPR07MB9678:EE_|AS4PR07MB8532:EE_
x-ms-office365-filtering-correlation-id: 9291eaf6-5cc4-4993-6288-08dc40cb6a71
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: aCNOMIxL4WOZ5ZnU++/1xTk09KVVaUcie6/KM1i3LSnwHJ5Yme4vyNlV370qKAMZvBZeloD2Uj2rLCvWtfyluLNL41TRdMaFsRCQ+VGh/z1cU1btwn7/NyOUbhwOPfdwntIftxMf3JwDWt308TfuTRYLukxIKafAJKBlmBn3VdiaOOzPCC7czSoJ56LZAds4CYomfvF1U04wZbTd3LLeVh72KCmMzFAERyHNMbWLe/fzHifM1BjnWdWtsuoNwlTQGb9sZloxvxa+0I0o8Jvr3aZjD/VgSVzZuNTzP9wgZcW2kd1hE4dzAV3Aew2BRCxgnlgBQkiYvJgwQZBqjhH7WyRUKUxp9OvBuHonoDclNWpiLOC7Vr9EBeTQY0hTsQCq4AVodi41MsflCGWjiWZ/XwPWELDaIpV6+usx8lw/YXiG4GCIdzFZjHmKPLMXw0MZ8l7x/G67yRFTy7/3AbekndsZsYF53b9eElSl1TO/aJqwfcH2DjwtfHg6rukGOjr6Z6MGqi5LIpAnykfkzpWgtQvcLuwRf6EQL5uqS5pndT9rcrw8kag3pl4Dp0ajyCg+l+6IDNggC1lWKNDI4hzKQAKc35bhvUHUkrcinuurWxsmrLOPgP8A+h1zZds+kjcKu/XrD2qdQvktKHObCpzEI/6PLkANDVS3mQroFHiCXGc=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVXPR07MB9678.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(1800799015)(376005)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: EVuXZCpUc8PyxYME+EgcJB8nAsExUT+Oz9wQtpVM8Jc1Fz9/aEC9rKFQx11hEjPzdMRj9GUVuOYrhbMPchXjYAxsHO7NxoXADmhmc7o9eea8LxiYnUHNtu+ljak7uNzbPCgIZYYf6i6K3CxXpZVCzJuPJr8b1Th+YvUG3iJ9Knp+9XZJ23MU+t+7pMQRCJQfxLRg3vJk6UJXU+IOr6Ixw3800Txhu+NDKAvasHSUBsoZ3aajMC0O3OJSvMkFslZ5u90G/94kEv9a97ONUrhkGa5hvPK65FaXDCJHYvWr3YAnQ18WxH8z/M/37u6WeivUD4BLVZzTFx6d1sfvvVkiCgL63WTTdYKT/NmQW+n84GCS94AFcgQ1j7XVqiExLDdymmuaLCIP5qNg+ALEfo2dFm1t3j+dcWwrpdz4A4Bfak2SGXYYVRPME8SuxsHLJsLiZNbmNf9spQfY+r5kyUTahT2pjKP6msQjJmBsv3xr21HqcIXR62t4n6tZjLB4+xZ++qYhKTO4Xc6LGdVD3U/WHryTYyR9IoN4LpIaENeyjlEr2pH25L+6S8OGJX69//SIn2e66P5OVR8bGwPFhUztc01iuQf825YL9Fi5t4zjme+QspGjeyWgVGsKZC2/8ngDak+k59qfrIwyNRnKLilgG9kFnqf5RCC4WBiwNQGiMtfcV35cfPZZQorzG8YSXgBtnHX3nrHntN24GRZvix+UT5RfGHpMXhKdY75rgWyJ+oxER44L2ynS9qPTCX8V/jIp5uNtd79PZFJyZg14wCQJrq/lz5kv6ULzGO8QDWCs6r+1OvpGC8ONcaosAJzyGqyATZT06ohlIuzyIyjs2Lm43DP7kZ6l4lzrh2fzqpY4xuYe3pe08CZ1axaUmzKPSOja6dpbKd1IsvyFuPPoyTn3BRehLpPf7jXUVv9RsQOJKfFAuaaLIrc5lnrSFaLbIbrB7y3tKCXBoDcpLyw65NncwTrzLK1oirsxbgD67YlnyZVoMTkRQ4bN28nDq5A0rtzfiG19Vu1It7xNjusqZ1EIBsZjKQ2xZEnL8TKOr7YSxhInFFQj0VsTrDB33CY1Wc4SgCTsq1E3DBK6jjpWLK+2cK+kdnvg8FCM6MPJcdURgCjCZaiHKgVrIOaz0JHWTTcukb2Lpz2ql/3GiYYsh1NQAWj/daBxzNDtOZ4hb6/E2ifjqEULp1SbrtK/0NJxRVhT6RMYw+n8Hj/TGeZSpfb1wws/NVk5y5tkiB6lvK2pXmNoDsCAszMr4xh/6B71hlfk3thPN2VW3mUe3Fh7xwTtjrBKhxreI/4TF1nuQQFckRnxsoqD4yVym+zzksW5qpGoyQi8Uqv9Po507LOTsmB4i+Q/elA6lvVSSjnBJzmDDSJDdAc3ujmuDBRcYGkOsgiHWNvpCRjEU3KF4/RkaapOXyTh2TG4iEzvTe6kejzAeX5jMnN+u5y9CCeZwqwlkFPfCM54ZsF53cyZjdpfgDEllsq14CEyHo3T3iWZ9qsuYJu6ixQEBTut/xRQj8696Gyph80i+iEOYk/GG21tYOiFvQZCXNr/tIGvVQ8x/Z9tkPNPZ1ycOw9LRNYwTbqBYSZ7XpmXZjfdKlqRG1Lmh9SIYmgChPsiAv/wuAqV1d5iEA4=
Content-Type: multipart/alternative; boundary="_000_GVXPR07MB96786EE4554285EA327565B389252GVXPR07MB9678eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVXPR07MB9678.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9291eaf6-5cc4-4993-6288-08dc40cb6a71
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Mar 2024 06:29:18.7946 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 518XB6Qf9ibAHQygs6ufNhzbqzD9IPtmb0oUdULriPnVSr5kdI0+YlAdZAn8nUrrsooXiGNRBSN0N5dYQsJAtBzx3xCpHT0yyhYURZrA1ts=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4PR07MB8532
Archived-At: <https://mailarchive.ietf.org/arch/msg/tsvwg/hWyqOguLjZMcoUuZncvvT2uii5Q>
Subject: Re: [tsvwg] I-D Action: draft-ietf-tsvwg-rfc4895-bis-02.txt
X-BeenThere: tsvwg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Transport Area Working Group <tsvwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tsvwg/>
List-Post: <mailto:tsvwg@ietf.org>
List-Help: <mailto:tsvwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Mar 2024 06:29:26 -0000

Hi,

This seems to be work in progress. I assume the plan is to address all the vulnerabilities in some way. I have only focused on the security aspects.

- I think the document needs an overview that describes the changes from RFC 4895 and why they are done. The draft should e.g., describe that directional keys are introduced to stop reflection attacks. As RFC4895bis intent to continue to operate with RFC 4895 all the security issues with RFC 4895 needs to be clearly described.
https://datatracker.ietf.org/meeting/115/materials/slides-115-tsvwg-sctp-auth-security-issues-00

- If you decide to follow my previous suggestion to change HMAC to MAC. You could follow my other previous suggestion and register HMAC-SHA-256-128 instead. Having a 256-bit tag seems a bit overkill.

              +-----------------+----------------------------------------------+
              | MAC Identifier | Message Digest Algorithm
              | 0               | Reserved
              | 1               | HMAC-SHA-1
              | 2               | Reserved
              | 3               | HMAC-SHA-256
              | 4               | HMAC-SHA-256-128 with directional keys
              +-----------------+----------------------------------------------+

- "If the peer does not operate in legacy mode, the send context is
   defined as the concatenation of local key vector followed by the
   remote key vector.  The receive context is defined as the
   concatenation of the remote key vector followed by the local key
   vector.  For deriving the association shared send and receive keys, a
   method described in Section 3.1 of [RFC5926] is used.  The
   association shared send key is the result of using HMAC-SHA512 as the
   key derivation function with the endpoint shared key as the
   Master_Key, the send context as the Context and 512 as the
   Output_Length.  The association shared receive key is computed the
   same way, just using the receive context as the Context.  In both
   cases "SCTP-AUTH" is used as the Label."

   That this creates directional key contradicts another statement in the draft saying that "Otherwise, the key vectors are identical".

- My understanding that the new API text forbids per-packet switching of algorithms leading to the same key being used in several algorithms. This should be clearly described.

- My understanding is that the document does not protect against replay of control chunks. If that is not planned, the document should clearly state that is does not provide replay protection. The deduplication mechanism in RFC 9260 is not replay protection, and SCTP-AUTH is a security protocol.

- My understanding is that the document does not protect against replay of data chunks the same direction (yet). I.e., after 2^32 data chunks the TSN reaches the Initial TSN and an on-path attacker can replay authenticated data chunks as the Stream Identifier, and Stream Sequence Number “match”. If user messages are large (more chunks than 2^32), replay can trivially be done after 2^32 chunks when the TSN reaches the Initial TSN.

(If this is not fixed the document need to clearly describe that it does not provide integrity of user data. The document does not state that it does, but the reader cannot be expected to understand that the lack of replay protection lead to lack of integrity protection of the user data. The end user is likely interested in integrity of the user data).

Cheers,
John