Re: Replays - thoughts on Gutmann response

Sandino Araico Sanchez <[email protected]>
Newsgroups gmane.comp.encryption.cipe
Message-ID <[email protected]>
Allan Latham wrote:

>If that were all, my opinion would be that we don't have a replay problem with 
>CIPE. Unfortunately there are some concerns:
>
>1. ICMP and UDP traffic could possibly be replayed to cause a DOS attack.
>2. Key exchange replays may allow an attacker to force CIPE to use the static 
>key or an already cracked dynamic key.
>
>I hope to cover the whole subject of how to harden key exchange later.
>
>  
>
If we use TCP instead of UDP for key exchange the replay problem can be 
worked around and there's no performance impact since there's no TCP 
over TCP encapsulation in key exchange.

There's lower complexity using UDP exclusively for traffic and TCP 
exclusively for key exchange since we don't need  to find out if the 
received UDP package contains a package or a key. When we are sure no 
UDP package contains a key we just need to check integrity, decrypt the 
encapsulated package and pass it to the upper layer so the process is 
simplified.

-- 
Sandino Araico Sánchez
-- Lo que no mata engorda.



--
Message sent by the [email protected] mailing list.
Unsubscribe: mail [email protected], "unsubscribe cipe-l" in body
Other commands available with "help" in body to the same address.
CIPE info and list archive: <URL:http://sites.inka.de/~bigred/devel/cipe.html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.