Re: #12 [**] Subsession keys (section 5 and 8)
"KAMADA Ken'ichi" <[email protected]> Wed, 09 Mar 2005 09:57:48 -0600
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <20050309095748DV%[email protected]> |
At Wed, 09 Mar 2005 23:20:40 +0900, Shoichi Sakane <[email protected]> wrote: > > I also don't think it is necessary to forbid using sub session keys. > but Michael pointed that there were some discussion about this topic > in the mailing list long time before. It might be necessary to consider > something. I've reread old mails on this topic and I need suspend my previous comment that we should use subsession keys. > If we allow using sub session key, then we have to add a text to > the document. we have to describe precisely where a session key or > a sub session key is used. I'd like to complement this. We should consider What key is used Where. "What key" in my mind is base key, initiator's subkey, or responder's subkey. "Where" is KINK_ENCRYPT of command, checksum of command, KINK_ENCRYPT of reply, checksum of reply, and checksum of ACK). > and if my understanding is correct, the responder can change the > subsession key by the responder's policy. So if the responder > changes the sub session key, the exchange needs the 3 way handshake. > because the initiator will have to recalculate the KEYMAT from > the subsession key from the responder. -- KAMADA Ken'ichi <[email protected]>