Key disclosure request/response scheme used as traffic amplifier

Mikael Olsson <[email protected]> Mon, 03 Mar 2003 23:24:44 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>
I just realized something important here:

If we go ahead with some sort of key disclosure/request
protocol, there's one issue we definately need to solve:
traffic amplification.

A 60-byte query can not be allowed to lead to a 600-byte
response. Not for something installed on every router
on the net.

Easy solution 1: send large queries. 
Let routers only copy disclosures until the packet is
full.  Note issues with bulk signing here; one ready-to-go
blob is no longer enough. Maybe several is doable. Yuck.

Easy solution 2: move to TCP. Also solves possible
future size problems. 

Comments?

-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com