Asymmetric Security

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <DC504E9C3384054C8506D3E6BB012460CD8C73@bsebe001.americas.nokia.com>
Hi All,

I wanted to start a discussion on Asymmetric Security.

Asymmetry can show up in different ways in a secure transmission. For example:
	* we can have asymmetry in the gateways involved in secure transmission. 
	* we can have asymmetry in the tunnels between two possible multihomed 
	  gateways
	* we can have asymmetry in the tunnel endpoints of the a tunnel


(1) Asymmetry in Gateways: 
Let us say there are three gateways A, B, C. In the forward direction secure traffic 
flows from Gateway A to Gateway B. In the reverse direction traffic flows from 
Gateway C to Gateway A.  A Mobile IP End-to-End Security between a 
correspondent node and a mobile node will be an example scenario here.
IKE negotiations between A and B can setup a tunnel and IKE negotiations
between C and A can set up the tunnels. Both the tunnels shall still protect the
same hosts/addresses. [Since IKE negotiations do not allow asymmetry we will
have to have two separate IKE negotiations]

(2) Asymmetry in Tunnels:
Let us say there are two multihomed Gateways. These gateways negotiate TWO 
tunnels, each with different tunnel endpoints (corresponding to multihomed addresses).
But both the tunnels still protecting the same hosts/addresses. This can be a real
life scenario to acheive redundancy/high availability

(3) Asymmetry in Tunnel Endpoints
Let us say there are two multihome Gateways. These gateways negotiate ONE tunnel,
but with different tunnel endpoints in forward and reverse direction. Something recently
discussed in MOBIKE mailing list.


I wanted to ask folks if current efforts (standards, or to-be-standards) solve all the 
Asymmetry needs of Security? Does it make sense to start new efforts to deal 
Asymmetry in Security (ASEC )? 

Should we have a BoF, when we can, to discuss the Asymmetric needs of Security?


Atul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.