Security scenarios and basic functions

Magnus Westerlund <[email protected]>
Newsgroups gmane.ietf.rmt
Message-ID <[email protected]>
Hi,

I think there the basic security issues with the RMT PIs and the BBs 
they use are common for a transport protocol.

1. Source authentication, i.e. the capability to determine and verify 
who is sending the packets

2. Integrity protection, i.e. the capability to verify that the packets 
has not been tampered with between the sender and the receiver.

3. Confidentiality, i.e. the possibility to prevent someone not 
authorized to see what is transported within the protocol, and in some 
case even seeing what is happening within the protocol itself.

The above are all cases that applies in the direction of the sender -> 
receivers. To my understanding there are also cases of the above when 
some or all of these functions needs to exist also in the direction 
receiver to sender, or maybe even receiver to receiver. I think 
congestion control mechanisms are such a case where the this may occur.

The usage of the above security mechanisms can vary and I think one of 
the more fundamental ones are in regards to the association between the 
entities in the transport session. In many cases the receivers will 
create some kind of relationship. This will be especially true for the 
confidentiality protection where the transmitter will need the identity 
of the receiver before giving them keys necessary for decrypting to 
ensure only intended receivers see the content. This is certainly a 
model that can be used in many applications however maybe not all.

In applications where the identity of the receiver is irrelevant (or 
possible intended to allow for anonymous participation), but the 
integrity and commonly the source identify is the data important another 
model is needed.

To my understanding a extended IPsec solution could cover the first use 
cases, while the second can be covered by the TESLA BB. Both under 
development in MSEC. Or is integrity protecton plus object 
confidentiality a more interesting model? My big questions here are;
- Which security models are going to be mandatory to implement for 
Internet usage?
- does the necessary key management exist for that solution?
- are there anything in the protocols and BBs that prevents this from 
working?
- are there other issues that should be considered when defining how one 
per default secures the different PIs?

This is only a start, or rather a reminder about the need for continuing 
the work on the security solutions. I would appreciate some discussion 
on how to secure the present existing PIs.


Cheers

Magnus Westerlund

Multimedia Technologies, Ericsson Research EAB/TVA/A
----------------------------------------------------------------------
Ericsson AB                | Phone +46 8 4048287
Torshamsgatan 23           | Fax   +46 8 7575550
S-164 80 Stockholm, Sweden | mailto: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.