Terminology related to TLS and DTLS; RE: TLS 1.3: Enhanced definitions of terms "TLS session" and "TLS connection"

"Schwarz, Albrecht (Albrecht)" <[email protected]> Fri, 10 Oct 2014 19:32:40 +0000
Newsgroups gmane.ietf.megaco,gmane.ietf.tls
Message-ID <786615F3A85DF44AA2A76164A71FE1AC33F0C0@FR711WXCHMBA03.zeu.alcatel-lucent.com>
fyi,
we've developed an hierarchical terminology framework for TLS and DTLS (in =
context of H.248 gateways, serving the termination or interworking of (D)TL=
S protocol).
However, the terminology isn't gateway specific, defined in a general manne=
r, thus applicable (and fully consistent) to IETF TLS RFCs in our understan=
ding.

Download:
AVD-4600 H.Sup.13 (Rel. 2): Terminology related to TLS and DTLS
http://wftp3.itu.int/av-arch/avc-site/2013-2016/1411_Seo/AVD-4600.zip  =


Regards,

Albrecht, Jens & Juergen

PS
The formal proceeding behind AVD-4600 may be found in:
AVD-4614 Backup-material to AVD-4600: Formal description of "TLS terminolog=
y framework"
http://wftp3.itu.int/av-arch/avc-site/2013-2016/1411_Seo/AVD-4614.zip =


-----Original Message-----
From: TLS [mailto:[email protected]] On Behalf Of Schwarz, Albrecht (Alb=
recht)
Sent: Mittwoch, 19. M=E4rz 2014 17:10
To: [email protected]
Subject: [TLS] TLS 1.3: Enhanced definitions of terms "TLS session" and "TL=
S connection"

Dear All,
like to raise a question related to the RFC 5246, Appendix B "Glossary":

Status: =

- connection:	=

       A connection is a transport (in the OSI layering model definition) t=
hat provides a suitable type of service.  For TLS, such connections are pee=
r-to-peer relationships.  The connections are transient.  Every connection =
is associated with one session.

- session:	=

       A TLS session is an association between a client and a server. Sessi=
ons are created by the handshake protocol.  Sessions define a set of crypto=
graphic security parameters that can be shared among multiple connections. =
 Sessions are used to avoid the expensive negotiation of new security param=
eters for each connection.

Both terms are rather high-level and silent concerning a number of key char=
acteristics.
E.g.,
What constitutes exactly a "TLS session"? Just the 1-tuple of a "session id=
" or the 6-tuple of {session identifier, peer certificate, compression meth=
od, cipher spec, master secret, is resumable}" (based on clause 7/RFC 5246)?

Similar, what constitues exactly a "TLS connection"? An n-tuple based on th=
e ConnectionState on clause 6.1/RFC 5246, just a sub-set ..., the 5-tuple o=
f IP transport connection endpoint addresses?

What exactly is the relation between a "TLS session" and its associated "TL=
S connection(s)"?

Resumption of a "TLS session"? What kind of "data object (configuration)" i=
s exactly used as starting point for the "resumption procedure"?

Such kind of questions are all leading to the baseline of good terminology.=
 The existing Glossary could and should be improved in my understanding.

Any opinions, comments from TLS expert side?
Anyone aware of similar terminology enhancements requests in the past?

Thanks,
Albrecht


_______________________________________________
TLS mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/tls