[MEXT] draft-bajko-mext-sod-01
"Kent Leung (kleung)" <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <2979E38DD6FC6544B789C8DAD7BAFC520E0A8085@xmb-sjc-235.amer.cisco.com> |
In the last IETF meeting, I signed up to review this draft and provide my comments to the WG. Some may already be discussed. 1) Sect. 1: s/cellular accesses/cellular access networks/ 2) Sect. 1: "that would unnecessarily consume resources on the HA and radio resources on the access network" 3) Sect. 1: HA control is mentioned in "Furthermore, the operator of HA may have policies .. security is to be used". But later "HA has no ability to force the MN to secure user traffic". Clarify if SoD is designed to include HA control in addition to MN control. 4) Sect. 2: s/wifi_SSID/WiFi SSID/ 5) Sect. 2: Why MAC_address of the wifi network? Generally, it's the WIFI SSID. Probably better to cover general logic and not get into specific features. 6) Sect. 2: "MN has either a stored policy ... or it may be provided with such information from policy stores such as ANDSF [23.402] or AAA server ..." There is no interface between MN and AAA server. So not clear how MN is able to obtain info stored on AAA server. Also, PCRF may be another policy store. 7) Sect. 2: "HA may require that the user plane traffic be encrypted on the MN-HA link". No description of how this can be accomplished. 8) Sect. 3: 'S' bit indicates encryption for user traffic. But it's not clear how encryption can be applied? 9) Sect. 3: What happens if MN does not encrypt after HA overwrites with S bit set to one? 10) Sect. 3: What happens if MN encrypt when HA does not want that? 11) Sect. 3: There is no description of HA triggered SoD, though HA control was implied in Sect. 1. 12) Sect 4.2: What this option is in the draft? Location information can be used for many types of operation, not specific to SoD 13) Sect. 5.: Hmm, Type value reservation needs IANA. 14) Sect. 6: It's not clear if there is no impact to the security model until further explanation provided on how the encryption is applied. Overall, the I-D is a good start on the idea of SoD. It needs more clarification on how the S bit interact with the mechanism that actually provides the encryption/decryption function. Also, how does SoD work when IKE/IPSec is providing the encryption/decryption. Kent _______________________________________________ MEXT mailing list [email protected] https://www.ietf.org/mailman/listinfo/mext