[pim] Re: [MSEC]Re: Q: "open" group multicast se nder authentication...

Robert Moskowitz <[email protected]>
Newsgroups gmane.ietf.pim
Message-ID <[email protected]>
Attend my Dispatch presentation on an update to TESLA as being used for 
GNSS authentication.

Of course this is a higher layer than multicast and the packets are GNSS 
timestamped so replay protection is there.

There will be a side meeting Wed morning that will also to into the CA 
that the SBAS providers will use to sign the key discloser.  but this is 
a simple CA, as there are very few SBAS providers and very few sats.

EXTREMELY bandwidth and packet size constrained!

ICAO is also looking at this for ADS-B auth where the PKI needs are 
larger.  The PKI in draft-drip-dki would be a good fit for ADS-B and I 
am having a meeting on this at ICAO (a couple blocks over) next week.

I will be updating my draft, draft-moskowitz-tesla-update-gnss-sbas, 
Sunday when submissions is reopened.  I am working on adding the FEC 
process for recovering a lost aMAC to add to what I have ready to submit...

On 10/29/25 7:16 PM, Brian Weis wrote:
> Hi Toerless.
>
> I think you’re remembering the TESLA algorithm, which was documented 
> in RFC 4082.  It needs a key management system to distribute shared 
> keys, but does provide replay attack prevention. There are a couple of 
> other RFCs which describe how TESLA keying material could be used with 
> SRTP, and keys distributed by the MIKEY protocol. You can find them on 
> this page: <https://datatracker.ietf.org/wg/msec/documents/>.
>
> That’s all I know about it though, and I’m not aware if anyone has 
> implemented any of this.
>
> Hope that helps,
> Brian
>
>> On Oct 29, 2025, at 2:49 AM, Toerless Eckert <[email protected]> wrote:
>>
>> Hi folks
>>
>> I am trying to remember if we ever wrote down a mechanism to 
>> cryptograpically
>> authenticate the sender of IP multicast packets - including replay attack
>> prevention! - without having to rely on shared keys like in GDOI and 
>> hence
>> the need to trust a group of receivers.
>>
>> I am pretty sure that there was at some time an interesting 
>> cryptographically
>> new proposal for this - a few years ago - but i don't remember enough 
>> keywords
>> to find it (which WG, what was the name). Even the AI tools are 
>> thoroughly
>> useless ;-))
>>
>> And of course, simple authenticating packets with time-stamps
>> signing with certificate is well-known... and well-known expensive...
>>
>> Cheers
>>    Toerless
>>
>> _______________________________________________
>> MSEC mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>
>
> _______________________________________________
> MSEC mailing list [email protected]
> To unsubscribe send an email [email protected]

_______________________________________________
pim mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.