Security scenarios and basic functions
Magnus Westerlund <[email protected]>
| Newsgroups | gmane.ietf.rmt |
|---|---|
| Message-ID | <[email protected]> |
Hi, I think there the basic security issues with the RMT PIs and the BBs they use are common for a transport protocol. 1. Source authentication, i.e. the capability to determine and verify who is sending the packets 2. Integrity protection, i.e. the capability to verify that the packets has not been tampered with between the sender and the receiver. 3. Confidentiality, i.e. the possibility to prevent someone not authorized to see what is transported within the protocol, and in some case even seeing what is happening within the protocol itself. The above are all cases that applies in the direction of the sender -> receivers. To my understanding there are also cases of the above when some or all of these functions needs to exist also in the direction receiver to sender, or maybe even receiver to receiver. I think congestion control mechanisms are such a case where the this may occur. The usage of the above security mechanisms can vary and I think one of the more fundamental ones are in regards to the association between the entities in the transport session. In many cases the receivers will create some kind of relationship. This will be especially true for the confidentiality protection where the transmitter will need the identity of the receiver before giving them keys necessary for decrypting to ensure only intended receivers see the content. This is certainly a model that can be used in many applications however maybe not all. In applications where the identity of the receiver is irrelevant (or possible intended to allow for anonymous participation), but the integrity and commonly the source identify is the data important another model is needed. To my understanding a extended IPsec solution could cover the first use cases, while the second can be covered by the TESLA BB. Both under development in MSEC. Or is integrity protecton plus object confidentiality a more interesting model? My big questions here are; - Which security models are going to be mandatory to implement for Internet usage? - does the necessary key management exist for that solution? - are there anything in the protocols and BBs that prevents this from working? - are there other issues that should be considered when defining how one per default secures the different PIs? This is only a start, or rather a reminder about the need for continuing the work on the security solutions. I would appreciate some discussion on how to secure the present existing PIs. Cheers Magnus Westerlund Multimedia Technologies, Ericsson Research EAB/TVA/A ---------------------------------------------------------------------- Ericsson AB | Phone +46 8 4048287 Torshamsgatan 23 | Fax +46 8 7575550 S-164 80 Stockholm, Sweden | mailto: [email protected]