Re: RFC 3077 Security Issues

Patrick Cipiere <[email protected]> Thu, 20 May 2004 09:32:09 +0200 (CEST)
Newsgroups gmane.ietf.udlr
Message-ID <[email protected]>
[email protected] said

>  There are Security issues with ULDR during L2 tunneling through GRE from
> receiver to feed, which passes through the public network without any
> encryption. By which any packet sniffer in the path can expose the satellite
> private network information which is dangerous.
>
> Hence we should work out different method, not just L2 tunneling rather L2
> entrypted tunneling using GRE to any other protocol.

I think that the security issue is even worse on the on air interface, which
in most cases is DVB-{ST}/mpeg2. Anyone on a very large foot print with a dish
or antenna may snoop  the traffic.
The UDLR GRE tunneling interface gives the same level of exposure security as
the one that is available on the broadcast link, but limited to the link path.

So I do not see a need for specific encryption on the UDLR GRE interface.
However, if security is a concern (which should often be the case) I would
recommend the use of standard technology above the broadcast link (and its
companion UDLR GRE link)
Using IPsec on the broadcast interface will make natural IPsec encryption on
the IP packets encapsulated in the L2 UDLR GRE interface.

Patrick.
-- 
UDcast: Full IP over Broadcast Media

Phone:  (+33) (0)4 93 00 16 99
Mobile: (+33) (0)6 14 21 55 98
Fax:    (+33) (0)4 93 00 16 61                 http://www.UDcast.com