[pim] Re: [MSEC]Re: Q: "open" group multicast se nder authentication...
Robert Moskowitz <[email protected]>
| Newsgroups | gmane.ietf.pim |
|---|---|
| Message-ID | <[email protected]> |
Attend my Dispatch presentation on an update to TESLA as being used for GNSS authentication. Of course this is a higher layer than multicast and the packets are GNSS timestamped so replay protection is there. There will be a side meeting Wed morning that will also to into the CA that the SBAS providers will use to sign the key discloser. but this is a simple CA, as there are very few SBAS providers and very few sats. EXTREMELY bandwidth and packet size constrained! ICAO is also looking at this for ADS-B auth where the PKI needs are larger. The PKI in draft-drip-dki would be a good fit for ADS-B and I am having a meeting on this at ICAO (a couple blocks over) next week. I will be updating my draft, draft-moskowitz-tesla-update-gnss-sbas, Sunday when submissions is reopened. I am working on adding the FEC process for recovering a lost aMAC to add to what I have ready to submit... On 10/29/25 7:16 PM, Brian Weis wrote: > Hi Toerless. > > I think you’re remembering the TESLA algorithm, which was documented > in RFC 4082. It needs a key management system to distribute shared > keys, but does provide replay attack prevention. There are a couple of > other RFCs which describe how TESLA keying material could be used with > SRTP, and keys distributed by the MIKEY protocol. You can find them on > this page: <https://datatracker.ietf.org/wg/msec/documents/>. > > That’s all I know about it though, and I’m not aware if anyone has > implemented any of this. > > Hope that helps, > Brian > >> On Oct 29, 2025, at 2:49 AM, Toerless Eckert <[email protected]> wrote: >> >> Hi folks >> >> I am trying to remember if we ever wrote down a mechanism to >> cryptograpically >> authenticate the sender of IP multicast packets - including replay attack >> prevention! - without having to rely on shared keys like in GDOI and >> hence >> the need to trust a group of receivers. >> >> I am pretty sure that there was at some time an interesting >> cryptographically >> new proposal for this - a few years ago - but i don't remember enough >> keywords >> to find it (which WG, what was the name). Even the AI tools are >> thoroughly >> useless ;-)) >> >> And of course, simple authenticating packets with time-stamps >> signing with certificate is well-known... and well-known expensive... >> >> Cheers >> Toerless >> >> _______________________________________________ >> MSEC mailing list -- [email protected] >> To unsubscribe send an email to [email protected] > > > _______________________________________________ > MSEC mailing list [email protected] > To unsubscribe send an email [email protected] _______________________________________________ pim mailing list -- [email protected] To unsubscribe send an email to [email protected]