[ippm] Re: WG Last Call: draft-ietf-ippm-alt-mark-deployme nt-05 (Ends 2026-05-28)
Giuseppe Fioccola <giuseppe.fioccola=40huawei.com-Tr9gZwTxerDR74oF6e/[email protected]> Fri, 29 May 2026 08:56:26 +0000
| Newsgroups | gmane.ietf.ippm,gmane.ietf.bmwg |
|---|---|
| Message-ID | <[email protected]> |
--===============6593496258274406538== Content-Language: en-US Content-Type: multipart/related; boundary="_004_6848d4f6da6c4a55ade0a44fc6a76043huaweicom_"; type="multipart/alternative" --_004_6848d4f6da6c4a55ade0a44fc6a76043huaweicom_ Content-Type: multipart/alternative; boundary="_000_6848d4f6da6c4a55ade0a44fc6a76043huaweicom_" --_000_6848d4f6da6c4a55ade0a44fc6a76043huaweicom_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Thank you Tim for your feedback. As mentioned, when we talk about controlled domain, I can highlight that a = trust relationship between the different entities can also create a control= led domain. Note that the notion of controlled domain was better described in section 2= .1. of RFC 9343 to address the security concerns raised at that time. Regards, Giuseppe From: Tim Chown <[email protected]> Sent: Friday, May 29, 2026 10:43 AM To: Pinkert, Tjeerd <tjeerd.pinkert=3D40siemens.com-Tr9gZwTxerDR74oF6e/[email protected]>; Giusep= pe Fioccola <[email protected]>; draft-ietf-ippm-alt-mark-deploy= [email protected]; [email protected]; [email protected] Subject: Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Hi, Some of Tjeerd's comments align with what I just posted. In R&E networks traffic from a university would typically traverse that uni= versity's national research and education network (NREN), out to some R&E b= ackbone, perhaps across a transatlantic link, into another NREN, and then o= n to the destination university. We'd expect DSCP to be conveyed end to en= d, and EHs to be carried end to end. And VPN/IPsec to not be used for that= . There is a L3VPN overlay for the International CERN experiment traffic (spa= nning over 100 of around 170 participating sites in 40 countries) but that'= s not the norm - the overlay is principally to allow differential traffic h= andling by NRENs and by security policy on entry/exit from sites. Tim On 28/05/2026, 17:15, "Pinkert, Tjeerd" <tjeerd.pinkert=3D40siemens.com@dma= rc.ietf.org> wrote: Dear Guiseppe, A clarification in the draft would be appreciated. VPNs or IPsec tunnels are rigid methods of creating user-domains, so that i= s always possible. When asking the question, I was thinking about something else, namely, the = cases where such virtual networks are not used or not necessarily needed. E.g. in situations where the network is controlled by entity A and entity B= uses that network. When entity B, partially trusts entity A (e.g. that the network provided is= private), but still has need to check the quality. When entity A and B use the same alternate marker technology (and B signs),= what measures must the network owner (A) take to honour the network user (= B) his alternate markers? Is that possible with the currently designed methods? (Should it be?) Slightly OT some thoughts on use of the DSCP field: When using DSCP, or the reserved Flag on IPv4 (these were exactly the field= s I had in mind as usable). A signature over the IP header, added as IP option could be a possibility f= or the user to ensure that the packet was not manipulated. Internal to the controlled domain, the DSCP field should than not be change= d uncontrolled (e.g. it should be reset to the original value on exit of th= e controlled domain). DSCP has the disadvantage of being designed to be changed by nodes an-route= , especially when certain traffic classes are used. The DSCP field is thus basically only possible for a controlled domain, not= for an end-user, unless this would be explicitly specified by the network = owner how to do this. In my I-D for the IP measurement option, I added a flag field as alternate = marker, that could be used when the DSCP field is not feasible. All other fields can be zeroed out in that case. Next to that, it contains = the possibility of adding a cryptographic signature. In that sense it would be usable for both controlled and end-user domains. Best regards, Tjeerd From: Giuseppe Fioccola <[email protected]> Sent: Donnerstag, 28. Mai 2026 16:20 To: Pinkert, Tjeerd (SMO RI ML COC SM 2) <[email protected]>; draf= [email protected]; IPPM Chairs <[email protected]= >; [email protected]; [email protected]; [email protected] Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Hi Tjeerd, I agree with you regarding the use of cryptography for the controlled domai= n. Indeed, if you look at section 2.1 of RFC9343, it is also mentioned that= multiple domains can create a whole controlled domain while traversing the= external domain by employing IPsec authentication and encryption or other = VPN technology. I can clarify this point in draft-ietf-ippm-alt-mark-deploy= ment too. Regarding the AltMark encapsulations, note that RFC9343 defines the extensi= on for IPv6, while in RFC9714 it is defined the extension for MPLS. There i= s no standard extension for IPv4, but, just to satisfy your curiosity, we i= nitially experimented the method by marking the DSCP field (see RFC8321) or= the last reserved bit of the Flag field (see draft-chen-ippm-coloring-base= d-ipfpm-framework). Other extensions are in progress, as you can notice in section 8 of draft-i= etf-ippm-alt-mark-deployment. Regards, Giuseppe From: Pinkert, Tjeerd <[email protected]<mailto:tjeerd.pinkert@sie= mens.com>> Sent: Wednesday, May 27, 2026 3:10 PM To: Giuseppe Fioccola <[email protected]<mailto:giuseppe.fioccol= [email protected]>>; [email protected]<mailto:draft-i= [email protected]>; IPPM Chairs <[email protected]<m= ailto:[email protected]>>; [email protected]<mailto:[email protected]>; bmwg@iet= f.org<mailto:[email protected]>; [email protected]<mailto:[email protected]= rg> Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Dear Guiseppe, OK, so that scenario is possible. You may notice that I am interested in the network performance from the net= work user perspective. It is the question if the user domain could form such a controlled domain, = and the packets are allowed to travel though a foreign domain. >From a security perspective, one needs to know one thing: was my packet (th= e alternate marker) manipulated by the foreign domain? This can be achieved with cryptographic signatures, so that would need to b= e designed into the measurement protocols (alternate marker data). (Removal of alternate marker data is also a manipulation of the packet and = can be detected by the user.) I think a controlled user domain would be characterised by a shared secret = for signing / encryption. A user on the network edge, owning ten- to hundred-thousand machines formin= g a distributed system, is a common use-case. In particular, when the distributed system must be capable of adjusting to = the network conditions, alternate marking methods could also be used. Then the use of alternate markers by the user and the network owner should = not collide. One (off topic) thing I would be interested in, is what fields are typicall= y used for alternate marking methods, and if signatures come into question = for that? Best regards, Tjeerd From: Giuseppe Fioccola <[email protected]<mailto:giuseppe.fiocc= [email protected]>> Sent: Donnerstag, 21. Mai 2026 10:32 To: Pinkert, Tjeerd (SMO RI ML COC SM 2) <[email protected]<mailto= :[email protected]>>; [email protected]= <mailto:[email protected]>; IPPM Chairs <ippm-ch= [email protected]<mailto:[email protected]>>; [email protected]<mailto:ippm@ietf= .org>; [email protected]<mailto:[email protected]>; [email protected]<mailto:bmw= [email protected]> Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Hi Tjeerd, Thank you for the question. Yes, it would be possible. But, for security reasons, In-Data-Packet OAM me= thods, such as Alternate-Marking and IOAM, should be applied to limited/con= trolled domains. You can find more details about this requirement in RFC 93= 41 and RFC 9197. It was initially discussed in RFC 8799. Regards, Giuseppe From: Pinkert, Tjeerd <[email protected]<mailto:tjeerd.pinkert@sie= mens.com>> Sent: Wednesday, May 20, 2026 4:19 PM To: [email protected]<mailto:draft-ietf-ippm-alt= [email protected]>; IPPM Chairs <[email protected]<mailto:ippm-c= [email protected]>>; [email protected]<mailto:[email protected]>; [email protected]<mailto= :[email protected]>; [email protected]<mailto:[email protected]> Subject: Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Dear all, I'm just wondering, can internet users form a controlled (boundary) domain = and apply the alternate marking method independently of the controlled netw= ork domain? This should be possible, but is not very deeply explored? (Or maybe I'm just missing the point, and the remarks on encapsulating traf= fic cover this sufficiently?) With best regards, Dr. Tjeerd Pinkert Siemens Mobility GmbH Mobility Rail Infrastructure System Management 2 SMO RI ML COC SM 2 Ackerstr. 22 38126 Braunschweig, Germany Phone: +49 (1520) 2884088 Mobile: +49 (1520) 2884088 mailto:[email protected] www.siemens.com<https://www.siemens.com> [Logo] Siemens Mobility GmbH; Chairman of the Supervisory Board: Roland Busch; Man= agement Board: Beatrice Bock, Michael Peter; Registered office: Munich, Ger= many; Commercial registry Munich, HRB 237219; WEEE-Reg.-No. DE 92917817 --_000_6848d4f6da6c4a55ade0a44fc6a76043huaweicom_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr= osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:= //www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <!--[if !mso]><style>v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style><![endif]--><style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Aptos;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; font-size:11.0pt; font-family:"Calibri",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} span.EmailStyle18 {mso-style-type:personal-reply; font-family:"Calibri",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--> </head> <body lang=3D"EN-US" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea= k-word"> <div class=3D"WordSection1"> <p class=3D"MsoNormal">Thank you Tim for your feedback.<o:p></o:p></p> <p class=3D"MsoNormal">As mentioned, when we talk about controlled domain, = I can highlight that a trust relationship between the different entities ca= n also create a controlled domain.<o:p></o:p></p> <p class=3D"MsoNormal"><o:p> </o:p></p> <p class=3D"MsoNormal">Note that the notion of controlled domain was better= described in section 2.1. of RFC 9343 to address the security concerns rai= sed at that time.<o:p></o:p></p> <p class=3D"MsoNormal"><o:p> </o:p></p> <p class=3D"MsoNormal">Regards,<o:p></o:p></p> <p class=3D"MsoNormal"><o:p> </o:p></p> <p class=3D"MsoNormal">Giuseppe<o:p></o:p></p> <p class=3D"MsoNormal"><o:p> </o:p></p> <div> <div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in = 0in 0in"> <p class=3D"MsoNormal"><b>From:</b> Tim Chown <[email protected]> = <br> <b>Sent:</b> Friday, May 29, 2026 10:43 AM<br> <b>To:</b> Pinkert, Tjeerd <tjeerd.pinkert=3D40siemens.com-Tr9gZwTxerCJKFBe7AYdWQ@public.gmane.org= g>; Giuseppe Fioccola <[email protected]>; draft-ietf-i= [email protected]; [email protected]; [email protected]<br> <b>Subject:</b> Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E= nds 2026-05-28)<o:p></o:p></p> </div> </div> <p class=3D"MsoNormal"><o:p> </o:p></p> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black">Hi,<o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black"><o:p> </o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black">Some of Tjeerd’s comments align with what I just posted.&n= bsp;<o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black"><o:p> </o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black">In R&E networks traffic from a university would typically tr= averse that university’s national research and education network (NRE= N), out to some R&E backbone, perhaps across a transatlantic link, into another NREN, and then on to the destination univ= ersity. We’d expect DSCP to be conveyed end to end, and EHs to = be carried end to end. And VPN/IPsec to not be used for that.<o:p></o= :p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black"><o:p> </o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black">There is a L3VPN overlay for the International CERN experiment t= raffic (spanning over 100 of around 170 participating sites in 40 countries= ) but that’s not the norm - the overlay is principally to allow differential traffic handling by NRENs and by secu= rity policy on entry/exit from sites.<o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black"><o:p> </o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black">Tim<o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:Aptos;co= lor:black"><o:p> </o:p></span></p> </div> <div id=3D"mail-editor-reference-message-container"> <div> <p class=3D"MsoNormal">On 28/05/2026, 17:15, "Pinkert, Tjeerd" &l= t;tjeerd.pinkert=3D40siemens.com-Tr9gZwTxerDR74oF6e/[email protected]> wrote:<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear Guiseppe,</spa= n><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A clarification in = the draft would be appreciated.</span><span style=3D"font-size:10.0pt"><o:p= ></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">VPNs or IPsec tunne= ls are rigid methods of creating user-domains, so that is always possible.<= /span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When asking the que= stion, I was thinking about something else, namely, the cases where such vi= rtual networks are not used or not necessarily needed.</span><span style=3D= "font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">E.g. in situations = where the network is controlled by entity A and entity B uses that network.= </span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When entity B, part= ially trusts entity A (e.g. that the network provided is private), but stil= l has need to check the quality.</span><span style=3D"font-size:10.0pt"><o:= p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When entity A and B= use the same alternate marker technology (and B signs), what measures must= the network owner (A) take to honour the network user (B) his alternate ma= rkers?</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Is that possible wi= th the currently designed methods? (Should it be?)</span><span style=3D"fon= t-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Slightly OT some th= oughts on use of the DSCP field:</span><span style=3D"font-size:10.0pt"><o:= p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When using DSCP, or= the reserved Flag on IPv4 (these were exactly the fields I had in mind as = usable).</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A signature over th= e IP header, added as IP option could be a possibility for the user to ensu= re that the packet was not manipulated.</span><span style=3D"font-size:10.0= pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Internal to the con= trolled domain, the DSCP field should than not be changed uncontrolled (e.g= . it should be reset to the original value on exit of the controlled domain= ).</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">DSCP has the disadv= antage of being designed to be changed by nodes an-route, especially when c= ertain traffic classes are used.</span><span style=3D"font-size:10.0pt"><o:= p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">The DSCP field is t= hus basically only possible for a controlled domain, not for an end-user, u= nless this would be explicitly specified by the network owner how to do thi= s.</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In my I-D for the I= P measurement option, I added a flag field as alternate marker, that could = be used when the DSCP field is not feasible.</span><span style=3D"font-size= :10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">All other fields ca= n be zeroed out in that case. Next to that, it contains the possibility of = adding a cryptographic signature.</span><span style=3D"font-size:10.0pt"><o= :p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In that sense it wo= uld be usable for both controlled and end-user domains.</span><span style= =3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Best regards,</span= ><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><br> Tjeerd</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt"> <o:p></o:p></= span></p> <div style=3D"border:none;border-top:solid windowtext 1.0pt;padding:3.0pt 0= in 0in 0in;border-color:currentcolor currentcolor"> <p class=3D"MsoNormal"><b>From:</b> Giuseppe Fioccola <giuseppe.fio= [email protected]><br> <b>Sent:</b> Donnerstag, 28. Mai 2026 16:20<br> <b>To:</b> Pinkert, Tjeerd (SMO RI ML COC SM 2) <tjeerd.pinkert@sie= mens.com>; [email protected]; IPPM Chairs <= ;[email protected]>; [email protected]; [email protected]; [email protected]= rg<br> <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-= 05 (Ends 2026-05-28)<span style=3D"font-size:10.0pt"><o:p></o:p></span></p> </div> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt"> <o:p></o:p></= span></p> <p class=3D"MsoNormal">Hi Tjeerd,<span style=3D"font-size:10.0pt"><o:p></o:= p></span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <p class=3D"MsoNormal">I agree with you regarding the use of cryptography f= or the controlled domain. Indeed, if you look at section 2.1 of RFC9343, it= is also mentioned that multiple domains can create a whole controlled doma= in while traversing the external domain by employing IPsec authentication and encryption or other VPN technology. = I can clarify this point in draft-ietf-ippm-alt-mark-deployment too.<span s= tyle=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <p class=3D"MsoNormal">Regarding the AltMark encapsulations, note that RFC9= 343 defines the extension for IPv6, while in RFC9714 it is defined the exte= nsion for MPLS. There is no standard extension for IPv4, but, just to satis= fy your curiosity, we initially experimented the method by marking the DSCP field (see RFC8321) or the last reserved bi= t of the Flag field (see draft-chen-ippm-coloring-based-ipfpm-framework).<s= pan style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal">Other extensions are in progress, as you can notice = in section 8 of draft-ietf-ippm-alt-mark-deployment.<span style=3D"font-siz= e:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <p class=3D"MsoNormal">Regards,<span style=3D"font-size:10.0pt"><o:p></o:p>= </span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <p class=3D"MsoNormal">Giuseppe<span style=3D"font-size:10.0pt"><o:p></o:p>= </span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <div style=3D"border:none;border-top:solid windowtext 1.0pt;padding:3.0pt 0= in 0in 0in;border-color:currentcolor currentcolor"> <p class=3D"MsoNormal"><b>From:</b> Pinkert, Tjeerd <<span style=3D= "color:#0563C1"><a href=3D"mailto:[email protected]"><span style= =3D"color:#0563C1">[email protected]</span></a></span>><br> <b>Sent:</b> Wednesday, May 27, 2026 3:10 PM<br> <b>To:</b> Giuseppe Fioccola <<span style=3D"color:#0563C1"><a href= =3D"mailto:[email protected]"><span style=3D"color:#0563C1">gius= [email protected]</span></a></span>>; <span style=3D"color:#0563C1"><a href=3D"mailto:draft-ietf-ippm-alt-mark-de= [email protected]"><span style=3D"color:#0563C1">draft-ietf-ippm-alt-mark-d= [email protected]</span></a></span>; IPPM Chairs <<span style=3D"color:= #0563C1"><a href=3D"mailto:[email protected]"><span style=3D"color:#0563= C1">[email protected]</span></a></span>>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span style= =3D"color:#0563C1">[email protected]</span></a></span>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span style= =3D"color:#0563C1">[email protected]</span></a></span>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span= style=3D"color:#0563C1">[email protected]</span></a></span><br> <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-= 05 (Ends 2026-05-28)<span style=3D"font-size:10.0pt"><o:p></o:p></span></p> </div> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt"> <o:p></o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear Guiseppe,</spa= n><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">OK, so that scenari= o is possible.</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p= > <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">You may notice that= I am interested in the network performance from the network user perspecti= ve.</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">It is the question = if the user domain could form such a controlled domain, and the packets are= allowed to travel though a foreign domain.</span><span style=3D"font-size:= 10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">From a security per= spective, one needs to know one thing: was my packet (the alternate marker)= manipulated by the foreign domain?</span><span style=3D"font-size:10.0pt">= <o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">This can be achieve= d with cryptographic signatures, so that would need to be designed into the= measurement protocols (alternate marker data).</span><span style=3D"font-s= ize:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">(Removal of alterna= te marker data is also a manipulation of the packet and can be detected by = the user.)</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">I think a controlle= d user domain would be characterised by a shared secret for signing / encry= ption.</span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A user on the netwo= rk edge, owning ten- to hundred-thousand machines forming a distributed sys= tem, is a common use-case.</span><span style=3D"font-size:10.0pt"><o:p></o:= p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In particular, when= the distributed system must be capable of adjusting to the network conditi= ons, alternate marking methods could also be used.</span><span style=3D"fon= t-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Then the use of alt= ernate markers by the user and the network owner should not collide.</span>= <span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">One (off topic) thi= ng I would be interested in, is what fields are typically used for alternat= e marking methods, and if signatures come into question for that?</span><sp= an style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Best regards,</span= ><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Tjeerd</span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt"> <o:p></o:p></= span></p> <div style=3D"border:none;border-top:solid windowtext 1.0pt;padding:3.0pt 0= in 0in 0in;border-color:currentcolor currentcolor"> <p class=3D"MsoNormal"><b>From:</b> Giuseppe Fioccola <<span style= =3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span st= yle=3D"color:#0563C1">[email protected]</span></a></span>><br= > <b>Sent:</b> Donnerstag, 21. Mai 2026 10:32<br> <b>To:</b> Pinkert, Tjeerd (SMO RI ML COC SM 2) <<span style=3D"col= or:#0563C1"><a href=3D"mailto:[email protected]"><span style=3D"co= lor:#0563C1">[email protected]</span></a></span>>; <span style=3D"color:#0563C1"><a href=3D"mailto:draft-ietf-ippm-alt-mark-de= [email protected]"><span style=3D"color:#0563C1">draft-ietf-ippm-alt-mark-d= [email protected]</span></a></span>; IPPM Chairs <<span style=3D"color:= #0563C1"><a href=3D"mailto:[email protected]"><span style=3D"color:#0563= C1">[email protected]</span></a></span>>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span style= =3D"color:#0563C1">[email protected]</span></a></span>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span style= =3D"color:#0563C1">[email protected]</span></a></span>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span= style=3D"color:#0563C1">[email protected]</span></a></span><br> <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-= 05 (Ends 2026-05-28)<span style=3D"font-size:10.0pt"><o:p></o:p></span></p> </div> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt"> <o:p></o:p></= span></p> <p class=3D"MsoNormal">Hi Tjeerd,<span style=3D"font-size:10.0pt"><o:p></o:= p></span></p> <p class=3D"MsoNormal">Thank you for the question.<span style=3D"font-size:= 10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal">Yes, it would be possible. But, for security reasons= ,<span style=3D"font-size:10.0pt"> </span>In-Data-Packet OAM methods, such as Alternate-Marking and IOAM, shou= ld be applied to limited/controlled domains. You can find more details abou= t this requirement in RFC 9341 and RFC 9197. It was initially discussed in = RFC 8799.<span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <p class=3D"MsoNormal">Regards,<span style=3D"font-size:10.0pt"><o:p></o:p>= </span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <p class=3D"MsoNormal">Giuseppe<span style=3D"font-size:10.0pt"><o:p></o:p>= </span></p> <p class=3D"MsoNormal"> <span style=3D"font-size:10.0pt"><o:p></o:p></= span></p> <div style=3D"border:none;border-top:solid windowtext 1.0pt;padding:3.0pt 0= in 0in 0in;border-color:currentcolor currentcolor"> <p class=3D"MsoNormal"><b>From:</b> Pinkert, Tjeerd <<span style=3D= "color:#0563C1"><a href=3D"mailto:[email protected]"><span style= =3D"color:#0563C1">[email protected]</span></a></span>><br> <b>Sent:</b> Wednesday, May 20, 2026 4:19 PM<br> <b>To:</b> <span style=3D"color:#0563C1"><a href=3D"mailto:draft-ietf-ippm-= [email protected]"><span style=3D"color:#0563C1">draft-ietf-ippm= [email protected]</span></a></span>; IPPM Chairs <<span styl= e=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span style=3D"= color:#0563C1">[email protected]</span></a></span>>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span style= =3D"color:#0563C1">[email protected]</span></a></span>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span style= =3D"color:#0563C1">[email protected]</span></a></span>; <span style=3D"color:#0563C1"><a href=3D"mailto:[email protected]"><span= style=3D"color:#0563C1">[email protected]</span></a></span><br> <b>Subject:</b> Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-= 05 (Ends 2026-05-28)<span style=3D"font-size:10.0pt"><o:p></o:p></span></p> </div> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt"> <o:p></o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear all,</span><sp= an style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">I’m just wond= ering, can internet users form a controlled (boundary) domain and apply the= alternate marking method independently of the controlled network domain?</= span><span style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">This should be poss= ible, but is not very deeply explored?</span><span style=3D"font-size:10.0p= t"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">(Or maybe I’m= just missing the point, and the remarks on encapsulating traffic cover thi= s sufficiently?)</span><span style=3D"font-size:10.0pt"><o:p></o:p></span><= /p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"> </span><span = style=3D"font-size:10.0pt"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Ar= ial",sans-serif;color:black">With best regards,<br> Dr. Tjeerd Pinkert<br> <br> Siemens Mobility GmbH<br> Mobility<br> Rail Infrastructure<br> System Management 2<br> SMO RI ML COC SM 2<br> Ackerstr. 22<br> 38126 Braunschweig, Germany<br> Phone: +49 (1520) 2884088<br> Mobile: +49 (1520) 2884088<br> </span><span style=3D"font-size:10.0pt;font-family:"Arial",sans-s= erif;color:blue"><a href=3D"mailto:[email protected]">mailto:tjeer= [email protected]</a></span><span style=3D"font-size:10.0pt;font-family= :"Arial",sans-serif;color:black"><br> </span><span style=3D"font-size:10.0pt;font-family:"Arial",sans-s= erif;color:blue"><a href=3D"https://www.siemens.com" target=3D"_blank">www.= siemens.com</a></span><span style=3D"font-size:10.0pt;font-family:"Ari= al",sans-serif;color:black"><br> <img border=3D"0" width=3D"201" height=3D"79" style=3D"width:2.0916in;heigh= t:.825in" id=3D"Picture_x0020_1" src=3D"cid:[email protected]"= alt=3D"Logo"><br> </span><span style=3D"font-size:8.0pt;font-family:"Arial",sans-se= rif;color:black">Siemens Mobility GmbH; Chairman of the Supervisory Board: = Roland Busch; Management Board: Beatrice Bock, Michael Peter; Registered of= fice: Munich, Germany; Commercial registry Munich, HRB 237219; WEEE-Reg.-No. DE 92917817</span><span style=3D"font-size:10.0p= t"><o:p></o:p></span></p> </div> </div> </body> </html> --_000_6848d4f6da6c4a55ade0a44fc6a76043huaweicom_-- --_004_6848d4f6da6c4a55ade0a44fc6a76043huaweicom_ Content-Type: image/gif; name="image001.gif" Content-Description: image001.gif Content-Disposition: inline; filename="image001.gif"; size=2730; creation-date="Fri, 29 May 2026 08:56:25 GMT"; modification-date="Fri, 29 May 2026 08:56:25 GMT" Content-ID: <[email protected]> Content-Transfer-Encoding: base64 R0lGODlhygBQAPcAAAAAAP///wCZmQCamgCYmACXlwCUlACTkwCRkQCOjgCNjQCLiwKamgKZmQKT kwOXlwSZmQSVlQWamgWXlwabmwaXlweZmQiYmAmbmwmXlwqdnQqamgqWlguZmQ2eng2amg6cnA2X lw6amhCfnxGcnBGbmxKcnBOenhKWlhSfnxWdnRafnxeiohehoRednRihoRmfnxqiohugoBygoBub mx2jox6kpB6ioiCkpB+hoSCjoyChoSKlpSKioiWnpySkpCenpyelpSqrqymoqCmnpyikpCqoqCun pyqlpSqjoyyqqiypqS6pqS+qqi6npzCrqzKrqzGoqDOsrDStrTWurjatrTWrqzeurjeqqjmtrTuw sDqsrD2xsT+ysj2trT+xsT6urj+vr0Kzs0GxsUCurkCtrUO0tEKxsUOyska0tEe1tUezs0m2tkex sUm1tUiysku2tky3t0y1tU+4uE63t020tE2zs1C4uE+1tVG3t1K4uFW7u1W5uVe6ule5uVq8vFu7 u129vV27u1+9vWC+vmG/v2C9vWK/v2TBwWPAwGfDw2bAwGnCwmvDw2nAwGrAwG3ExGzCwm/FxXPH x3HDw3XGxn3Ly3rGxn3JyYDMzH/Ly4HLy4XOzofPz4XMzIfNzYnPz4jNzYrPz43S0ovQ0IzQ0I7R 0ZHS0pHR0ZTU1JPT05LR0ZfW1pXT05fV1ZjV1ZnW1prW1prU1J3Y2J3X15/Y2J7X153V1aLa2qHY 2KXb26PZ2afb26nc3Kve3qnb263f36vd3azd3a/f37Lh4bHg4LDf37Xh4bfi4rbg4Lvk5L3m5rvj 473l5b/m5r7l5cHn58Ln58bp6cTn58nq6sbn58rq6sjo6Mzr687s7NHt7dPt7dXu7tnw8Nrw8Nnv 793y8tzx8d/z8+H09OL09OHz8+T19eLz8+f29un39+f19ev4+Or39+75+fH6+u/4+PH5+fX8/PP6 +vX7+/f8/Pb7+/n9/fv+/vr9/fz+/v7//////wAAAAAAAAAAAAAAACH/C05FVFNDQVBFMi4wAwEA AAAh+QQFAAD7ACwAAAAAygBQAAAI/wADCBxIsKDBgwgTKlzIsKHDhxAjSpxIsaLFixgzatzIsaPH jyBDihxJsqTJkyhTqlzJsqXLlzBjypxJs6bNmzhz6tzJs6fPn0CDCh1KtKjRo0iTKl3KtKnTp1Cj Sp1KtarVq1izat3KtavXr2DDih1LtqzZs2gh5ku37Zo2cvX0GcxHt27Bunjz0pUrMN+9vAv16b37 V29evgEEA55rF6G7btaseWuXbym2UGhaUIBAYcQQOpe0EZwEBg0aL47aDUwnqLTp17DRlME1sNQW 2GEI2UPYrc6X12H8mBt4D5OX2MjBWBqIjMyZ115q3V0U5ksd0QTR2QLEQwMECRpsfP95FAypKBMI DhQgwL5AgQMKQBHkksCAgQRO0A0Ul6O+/f8A3qfJQIQoAOABByCDkCUG/oeACt0MZI8dDQYIYAJs DMRKAgf8l8AQ9BB0DxEIIMDBMwQpEwWC67FHQAEGKEDFUad0OIAABnQIo30ImEKQGgYIIMABVqQz EDlBBCnAADsGmEAmAyFygJBUGqDHQflMYcCNQhpwQzgS5jHlkgRYeB8cA81iAAFU4piKiFAYUEAJ 0QyEzQkILPnefx0i0IVR2qgQ5ItMaNJLMKxAUgUKpfyoJJFGCoSkkgS0sIQRmGaaxCtRjkllASZQ Y9AzD7SJ45dhjkmAB5dmimkSkKT/uWabBuCgDnFxzllnAPjAkacABazAyC7C5GKJGzT8WVQnB7Bp ABD6EUTPNN84KiSkRyZ5rSbyvOPtt++EKJCUpg65XEF6eNolqgLZI2aXcXQLrrfzyMomlQQcgAmu ctIpEDYqFADsB8MYxM00RiHyqwFUVLYQkNcWme2jnTBELrBUHnBGvXaSIPC9p4LZ7rtDXrmQmmyC fMARkd6Tq78B+DKBwAWoYI1TiqhKAB7VPPyoxJJqOyQnFjfLgBD3FvAAigNZggB7PkiwrsgBuDvm AXcwhLIAFAh8bcUBuNzvrsNU4HUBRNjiDlM1qrzBIcSIaxDEQwIdwKTXNrqQlC9y/+KD1wcEMpA8 Y6jXAiMXTJ3qtXtovaYBd1yhZAEtgBP2y7tyA4OSOGoMSzlKmaODp0wicEEWvSA2EN3YBj35FIkU Irvsf0hDELkHAPPJmAVgUG0AyERAAAKE6FJqyIsDa0PssxcCiC4EoXxAJcQ0KyQCklw+tkD6JPKr kPka0IMm7yQVTAfqAtshHzdbW3ekdwutPoL0K0DL7VMe4Is2D9x7wLnpIkAEiCEMJXmJalb7FP3q 54jorekAjEjHEcZkAB7cCnMDOQcTEFAALgmgTAhgwi7wgRRkYKFDpspXCWizup/BD29Ces8C4TML /A0JF/OowtW4oA9tWKBMVaAHLf8oyK6qkWx+C1TAIxyYr0MEgBUOSJm+AiCF7Q0EHIEwwNNMlaNF qOYo7IhFFuzjtSUd4ALKaGHEXii0AiyhD3qIYxzrwLRx5a+GprBeATogjVLkr1GxICICSVaAGPBB jnG0wy2YeABCBGAeX5hcCrLBBSsOJB/HAMQF1AOyAiTgXEipRy64kIFZXW8RfGGd3WB4gIrp45Ww LAjuaiiOGxjwD1xYjwW4EYBAKm5kV7sSLGPJSEcGoBeeQkAlxGDJgkwjEC5QT8Z+QI6l2OMYfVjP taqwDoGoko2PItre7igQSHCuAWbsg1x8iTxgXitrJ3ugMd1hhS0B6wUseBHMEIL/jUyA4GwFaEZT 6OEGAwZhHN504cSuJU6FzFIgyiijiwrADIGw84DJw5rj8mXMABjDlNrUFUNOQSkDAIMo+FDdaK62 hfIF4JsLHZKPxjmkGgaAHk3g3JDWwLGLFjGBQ2pcPDlKHD58L4Ywy8duDoKN/n2wANAgCjUM4Qpl ZIMc7niHN3pRA68hoBFqfF9MDTCHWMDirGhNhYLsWNOB1AhfBxjFQHw6SAo+waxoPWsqeBEPgUiv o8DLQBmBBTN6SMISxaBGON4BD3I4g3VHiJZQlHEABHwABj9QghFuMLNrhUCgCV1jTIFlpgSYoVNt FUg5eGDAE2Cnl4JMHmkthIAd/0Trr9JKg7pEetMhJOACKtCBEZbwgxJM7pNFWYYI5OQeMhKgdCS4 X1hbFz/Ouei6+coQWw9gU4FMYkoDCBxB6CrbD2K3TD+IFG4JEo0ffgpm9piCeppLxmsdwIvJrQCH EGQfBHGwDVEliBYUgCAFIEGy4pABgWc4QwWIYSCBWAB8WEGQYZQIAQaw3UBaseAEnMAbEnqDhBm8 wATMIFobQsAC+mCQQiz4AAmIAGjxIYX98jdHCCqCKo4Cj2KcAhOGkMMYxiCHSJQCGfIwiDFQoQpV rOIXfRWIPHaxiiZb+cpNXkUxBtIMJqOClwNpxycoQQlSqI4bVXZyLeBxyWQwGXTLWF7FLjiGZidX tCDgeLMqTiGL4QjkGq/wRCTugIYvpGEQm9DFOZqiGJWmZSCKcdijJ03pSlv60pjOtKY3zelOe/rT oA61qEdN6lKb+tSoTrWqV83qVrv61bCOtaxnTeta2/rWuM61rnfN6177+tfAtklAAAA7 --_004_6848d4f6da6c4a55ade0a44fc6a76043huaweicom_-- --===============6593496258274406538== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KaXBwbSBtYWls aW5nIGxpc3QgLS0gaXBwbUBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IGlwcG0tbGVhdmVAaWV0Zi5vcmcK --===============6593496258274406538==--