Re: Security scenarios and basic functions
Magnus Westerlund <[email protected]>
| Newsgroups | gmane.ietf.rmt |
|---|---|
| Message-ID | <[email protected]> |
Hi, Great that a discussion has started. >> Or is integrity protecton plus object >> > confidentiality a more interesting model? > > I'm not sure I understand what you're alluding to here, could you please > elaborate? do you mean an application layer security mechanism? > At least for FLUTE it is quite clear that you can provide security for the file objects being delivered using for example SMIME. The question with such a solution for FLUTE is the leakage of information about what you are transporting due to the FDT and the protocol headers. When it comes to a RMTTLS I think it misses the goal. I think it is quite clear that RMT will need packet integrity and authentication to protect against some serious attacks. Especially important when RMT PIs are used in ASM networks when spoofing and insert attacks become way to easy. Having something on payload level may not be sufficient in these cases. You need to bind the protocol information to a particular payload. Cheers Magnus Westerlund Multimedia Technologies, Ericsson Research EAB/TVA/A ---------------------------------------------------------------------- Ericsson AB | Phone +46 8 4048287 Torshamsgatan 23 | Fax +46 8 7575550 S-164 80 Stockholm, Sweden | mailto: [email protected]