October 2017 Project: IEEE P802.15 Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [AES-256 for 802.15.4] Date Submitted: [17.

Slides:



Advertisements
Similar presentations
Project: IEEE Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposals for adding a version number and for the treatment.
Advertisements

Project: IEEE Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposals for adding a frame version number and for the.
Submission Title: [Add name of submission]
November 2017 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [AES-256 for ] Date Submitted:
<month year> doc.: IEEE < e> <Nov 2017>
June 2006 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposed Scenarios for Usage Model Document.
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Call for Proposals] Date Submitted:
Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Add name of submission] Date Submitted:
<month year> doc.: IEEE < e> <May 2018>
doc.: IEEE <doc#>
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Call for Proposals] Date Submitted:
October 2017 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [AES-256 for ] Date Submitted: [17.
May 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Considerations on general MAC frame] Date Submitted:
doc.: IEEE <doc#>
Submission Title: Algorithm agility without frame by frame information
NOV 01 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Application Specific Information Element] Date.
<month year> doc.: IEEE < e> <July 2018>
<month year> doc.: IEEE < e> <May 2018>
March 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Toumaz response to TG6 Call for Applications]
March 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Call for Proposals] Date Submitted:
doc.: IEEE <doc#1>
<month year> doc.: IEEE <xyz> January 2001
<month year> doc.: IEEE < e> <March 2018>
Jan Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Agenda January 2018 Interim] Date.
Submission Title: [Errors in a] Date Submitted: [18 March, 2010]
<month year> doc.: IEEE < e> <November 2018>
November 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Amendment text] Date Submitted:
August, 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Enhancing reliability of data transmission.
Submission Title: IEEE : Management Slots in the MAC.
Jan Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Agenda January 2018 Interim] Date.
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Call for Proposals] Date Submitted:
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Agenda January 2018 Interim] Date.
<month year> doc.: IEEE < e> <January 2019>
<month year> doc.: IEEE < e> <May 2018>
Submission Title: Algorithm agility without frame by frame information
<author>, <company>
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Agenda January 2018 Interim] Date.
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Agenda January 2018 Interim] Date.
Submission Title: [IEEE WPAN Mesh Reference Model]
July 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Extensions to IEEE in support of.
<month year> doc.: IEEE < e> <May 2018>
doc.: IEEE /XXXr0 Sep 19, 2007 June 2009
Submission Title: [Frame and packet structure in ]
November 2006 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Simplified geometry for the usage model.
<month year> doc.: IEEE < e> <November 2018>
July 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Extensions to IEEE in support of.
<month year> doc.: IEEE <030158r0> January 2004
doc.: IEEE <doc#>
<month year> doc.: IEEE < e> <July 2018>
May 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Considerations on general MAC frame] Date Submitted:
<month year> doc.: IEEE < e> <March 2019>
<month year> <January 2019>
March 2019 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [DF6 Radio-burst length over PSDU size] Date.
<month year> doc.: IEEE < e> <March 2018>
<month year> doc.: IEEE < e> <May 2018>
<month year> doc.: IEEE < e> <March 2016>
<author>, <company>
Submission Title: [LB 28 Results] Date Submitted: [14 March 2005]
November 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [WNG Profiles for IEEE ] Date Submitted:
<month year> doc.: IEEE < e> <March 2016>
<month year> doc.: IEEE < e> <March 2019>
<month year> doc.: IEEE < e> <July 2019>
Mar 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Resolution for Comment 70 ] Date Submitted:
Mar 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Resolution for Comment 70 ] Date Submitted:
August, 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Improve the latency between GTS request.
<month year> doc.: IEEE < e> <March 2019>
Submission Title: Security Suite Compromise
Submission Title: TG9ma Agenda for September Meeting
<month year> doc.: IEEE < e> <July 2019>
12/15/2019 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [AWGN Simulation Results] Date Submitted:
Presentation transcript:

October 2017 Project: IEEE P802.15 Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [AES-256 for 802.15.4] Date Submitted: [17 October 2017] Source: [Don Sturek, Matt Gillmore] Company [Silver Spring Networks, Itron] Address [San Jose, CA] Voice:[+1-669-770-4790], FAX: [], E-Mail:[dsturek@ssni.com] Re: [For consideration by 802.15] Abstract: [Description of a proposal to add AES-256 support for 802.15.4] Purpose: [For consideration of an amendment to 802.15.4] Notice: This document has been prepared to assist the IEEE P802.15. It is offered as a basis for discussion and is not binding on the contributing individual(s) or organization(s). The material in this document is subject to change in form and content after further study. The contributor(s) reserve(s) the right to add, amend or withdraw material contained herein. Release: The contributor acknowledges and accepts that this contribution becomes the property of IEEE and may be made publicly available by P802.15. Don Sturek, SSN Matt Gillmore, Itron

October 2017 Background For the IEEE 802.15.4-2015 auxiliary security header, there is only the option to use AES-128 for encryption There is no cipher suite or key size negotiation option, only the size of the Message Integrity Code (MIC) can be varied Per NISTIR 7628 Vol 1, key length lifetimes for AES-128 and AES-256 are 2030 or after That said, key critical infrastructure customers like utilities are asking about AES-256 support (now) Don Sturek, SSN

Some Considerations Cipher Suite and Key Length Negotiation October 2017 Some Considerations Cipher Suite and Key Length Negotiation ETSI TS102-887-2 is an example using IEEE 802.15.4 Uses a special Information Element instead of the Auxiliary Security Header Quantum Computing and ECC Security At some point there will be a security solution to the Quantum Computing threat but there is not anything to implement just yet Current Auxiliary Security Header seems hard to modify for AES-256 (see next slides) Recommendation Add in a new Header IE for Security to replace what the Auxiliary Security Header is doing today for AES-128 Make it possible to do Cipher Suite and Key Length negotiation but just define one Cipher Suite and Key Length for now (AES-256). Could optionally add in ECP-384 if we want to prove the negotiation works Work with implementers on hardware support for select Cipher Suites and Key Lengths Don Sturek, SSN

IEEE 802.15.4 Auxiliary Security Header October 2017 IEEE 802.15.4 Auxiliary Security Header General MAC Frame Format Don Sturek, SSN

IEEE 802.15.4 Auxiliary Security Header October 2017 IEEE 802.15.4 Auxiliary Security Header Frame Control Security Enabled either True or False Don Sturek, SSN

IEEE 802.15.4 Auxiliary Security Header October 2017 IEEE 802.15.4 Auxiliary Security Header Auxiliary Security Header Security Control Field   Each bit within any Reserved field shall be set to zero on transmission and shall be ignored on reception. No decision should be made on the contents of any Reserved field or field containing a reserved value. Don Sturek, SSN

IEEE 802.15.4 Auxiliary Security Header October 2017 IEEE 802.15.4 Auxiliary Security Header Security Level Where ENC always means AES-128 Don Sturek, SSN

October 2017 Proposal 802.15 Working Group starts a project to prepare a MAC amendment to 802.15.4 to define support for AES-256 encryption and, if the existing Auxiliary Security Header cannot be extended to support both AES-128 and AES-256, add the ability to support cipher suite and key length negotiation to minimally include AES-256 and ECP-384 Don Sturek, SSN

October 2017 Documents: https://www.smartgrid.gov/document/nistr_7628_guidelines_smart_grid_cyber_security_vol_1_smart_grid_cyber_security_strategy_ar http://www.etsi.org/deliver/etsi_ts/102800_102899/10288702/01.01.01_60/ts_10288702v010101p.pdf Don Sturek, SSN