[MEXT] draft-bajko-mext-sod-01

"Kent Leung (kleung)" <[email protected]>
Newsgroups gmane.ietf.nemo
Message-ID <2979E38DD6FC6544B789C8DAD7BAFC520E0A8085@xmb-sjc-235.amer.cisco.com>
In the last IETF meeting, I signed up to review this draft and provide
my comments to the WG.  Some may already be discussed.

 

1)      Sect. 1: s/cellular accesses/cellular access networks/

2)      Sect. 1: "that would unnecessarily consume resources on the HA
and radio resources on the access network"

3)      Sect. 1: HA control is mentioned in "Furthermore, the operator
of HA may have policies .. security is to be used".  But later "HA has
no ability to force the MN to secure user traffic".  Clarify if SoD is
designed to include HA control in addition to MN control.

4)      Sect. 2: s/wifi_SSID/WiFi SSID/

5)      Sect. 2: Why MAC_address of the wifi network?  Generally, it's
the WIFI SSID.  Probably better to cover general logic and not get into
specific features.

6)      Sect. 2: "MN has either a stored policy ... or it may be
provided with such information from policy stores such as ANDSF [23.402]
or AAA server ..." There is no interface between MN and AAA server.  So
not clear how MN is able to obtain info stored on AAA server.  Also,
PCRF may be another policy store.

7)      Sect. 2: "HA may require that the user plane traffic be
encrypted on the MN-HA link".  No description of how this can be
accomplished.

8)      Sect. 3: 'S' bit indicates encryption for user traffic.  But
it's not clear how encryption can be applied?  

9)      Sect. 3: What happens if MN does not encrypt after HA overwrites
with S bit set to one?

10)   Sect. 3: What happens if MN encrypt when HA does not want that?

11)   Sect. 3: There is no description of HA triggered SoD, though HA
control was implied in Sect. 1.

12)   Sect 4.2: What  this option is in the draft?  Location information
can be used for many types of operation, not specific to SoD

13)   Sect. 5.: Hmm, Type value reservation needs IANA.

14)   Sect. 6: It's not clear if there is no impact to the security
model until further explanation provided on how the encryption is
applied.

 

Overall, the I-D is a good start on the idea of SoD.  It needs more
clarification on how the S bit interact with the mechanism that actually
provides the encryption/decryption function.  Also, how does SoD work
when IKE/IPSec is providing the encryption/decryption.  

 

Kent

_______________________________________________
MEXT mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.