Re: Key Disclosures

Mikael Olsson <[email protected]> Wed, 19 Feb 2003 16:07:10 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>
Tom Taylor wrote:
> 
> Does the hash key disclosure actually have to be part of the packet?  
> Could the packet instead point to a location where the hash keys can 
> be found, along with suitable certification et cetera?  [...] An 
> attacker can't really provoke a DOS on the key repository if we go 
> this way, since queries would come in on a per-analysis batch basis 
> rather than per-packet.

Would this be a separate server?  I think that's a bad idea, given
that people have no real incentive to set up such a server; I don't
gain anything from building my own itrace infrastructure.

If the "server" is on the router itself, this is much the same
as the (twice) proposed key query protocol.

(A related problem is with routers that we cannot route to, but
 if we also disclose the previous key in normal itrace packets,
 that problem is at least partially solved.)

A key query protocol also has the same "per-analysis" characteristics. 
(Unless the analysis server is plain stupid, but a separate key 
disclosure server would suffer the same problem.)


-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com

"Senex semper diu dormit"