Re: requirements and the security considerations
h chan <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <6E31144C030982429702B11D6746B98C370928A2@szxeml557-mbx.china.huawei.com> |
Seil or Sergio, Can you reply to the following: The comments from Byoung-Jo Kim to REQ7 in version 4 is as follows: I suggest to drop this requirement or make a clearer statement like "DMM should allow multicast to survive IP layer mobility without packet loss", or more modestly, "DMM should not foreclose multicast support during IP layer mobility.", etc.. His suggested text is to replace REQ7 with something like the following: REQ7: DMM SHOULD enable multicast packet delivery during mobility events as needed. H Anthony Chan -----Original Message----- From: h chan Sent: Thursday, June 20, 2013 7:15 PM To: 'Jouni Korhonen'; [email protected]; 'KIM, BYOUNG-JO J (BYOUNG-JO' Cc: 'Jong-Hyouk Lee' Subject: RE: [DMM] requirements and the security considerations The comments from Byoung-Jo Kim to REQ6 and Section 6 in version 4 were the following: There are too much text in the security REQ6 that are vague and too wide. And Section 6. Security considerations should say "none", 'cause that's usually the section that discusses security considerations related to the draft itself. Since this is a requirement draft, there is no such thing. There is a separate requirement earlier to cover security issues due to DMM. REQ6: Security considerations DMM protocol solutions MUST consider security risks introduced by DMM into the network. Examples of such risks to be considered may include authentication and authorization mechanisms that allow a mobile host/router to use the mobility support provided by the DMM solution; redirecting traffic to the wrong host when providing DMM support; signaling message protection for authentication, integrity and confidentiality. Motivation: Various attacks such as impersonation, denial of service, man-in-the-middle attacks, and so on, may become newly possible or easier to mount due to the introduction of DMM. Proof of possession of past and new IP addresses may be needed. H Anthony Chan -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Jouni Korhonen Sent: Tuesday, June 18, 2013 2:40 AM To: [email protected] Subject: [DMM] requirements and the security considerations <no co-chair cap/bowler> Folks, I have been reading Section 6 Security Considerations: It is necessary to provide sufficient defense against possible security attacks, or to adopt existing security mechanisms and protocols to provide sufficient security protections. For instance, EAP-based authentication can be used for access network security, while IPsec can be used for end-to-end security. I think this text still deserves some tweaking. First, "provide sufficient defense against possible security attacks".. against whom? Second, should the text say something that the DMM protocol itself must not be usable as a tool to launch an attack by a malicious mobile node that happens to know that it is attached to a network implementing DMM and knows (somehow) how the DMM protocol functions? - Jouni _______________________________________________ dmm mailing list [email protected] https://www.ietf.org/mailman/listinfo/dmm