Key disclosure request/response scheme used as traffic amplifier
Mikael Olsson <[email protected]> Mon, 03 Mar 2003 23:24:44 +0100
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
I just realized something important here: If we go ahead with some sort of key disclosure/request protocol, there's one issue we definately need to solve: traffic amplification. A 60-byte query can not be allowed to lead to a 600-byte response. Not for something installed on every router on the net. Easy solution 1: send large queries. Let routers only copy disclosures until the packet is full. Note issues with bulk signing here; one ready-to-go blob is no longer enough. Maybe several is doable. Yuck. Easy solution 2: move to TCP. Also solves possible future size problems. Comments? -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com