September 2009 doc.: IEEE November 2009

Slides:



Advertisements
Similar presentations
Doc.: IEEE wng0 Submission June 2010 Robert Moskowitz (ICSAlabs/VzB)Slide 1 Project: IEEE P Working Group for Wireless Personal.
Advertisements

Doc.: IEEE Submission November 2009 Robert Moskowitz (ICSAlabs/VzB)Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE HIP-over-TG9 Submission May 2012 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE kmp Submission September 2011 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: wng0> Submission Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Using Host.
November 2010 doc.: IEEE e Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: LB60 comment.
Submission Title: [Add name of submission]
May 2000 doc.: IEEE /109r0 May 2000 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: WPAN Requirements.
June 2006 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposed Scenarios for Usage Model Document.
Robert Moskowitz, Verizon
doc.: IEEE <doc#>
Project: IEEE Wireless Personal Area Networks (WPANs)
March 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Toumaz response to TG6 Call for Applications]
Robert Moskowitz, Verizon
<May,2009> doc.: IEEE <doc .....> <July 2009>
July 2013 Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
<month year> doc.: IEEE <xyz> January 2001
Nov 2013 Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
1/2/2019<month year> doc.: IEEE Jan 2013
Robert Moskowitz, Verizon
< Sept > Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [IG LPWA Draft Call for Contributions]
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
November 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [ Shared Group Timeslots ] Date Submitted:
May 2009 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [ 1-octet MAC Header frame types ] Date Submitted:
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
January 16, 2019 doc.: IEEE r0 September, 2004
Nov 2013 Robert Moskowitz, Verizon
Submission Title: [WG WNG Liaison Report January08]
November 2009 doc.: IEEE /0825r0 November 2009
<month year> <doc.: IEEE doc> Julyl 2015
Date Submitted: September 18, 2012 Source: Arthur Astrin
<month year> doc.: IEEE <xyz> November 2000
doc.: IEEE /XXXr0 Sep 19, 2007 June 2009
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Submission Title: [Frame and packet structure in ]
November 2006 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Simplified geometry for the usage model.
July 2013 Robert Moskowitz, Verizon
Nov 2013 Robert Moskowitz, Verizon
doc.: IEEE <doc#>
Jan 2011 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Closing report for TG4j (MBAN) Task Group, Jan.
Robert Moskowitz, Verizon
July 2012 Robert Moskowitz, Verizon
April 19 July 2010 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: WNG Closing Report for San Diego.
Robert Moskowitz, Verizon
May 2013 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: May 2013 closing report Date Submitted: May.
doc.: IEEE <doc#>
Robert Moskowitz, Verizon
Tero Kivinen, AuthenTec
January 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [TG3c Project Plan] Date Submitted: [17.
Tero Kivinen, AuthenTec
Robert Moskowitz, Verizon
November 2007 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [TG3c Project Plan] Date Submitted: [15.
July 2013 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Technical Decisions for KMP transport Date.
September 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Suggested TG3c PAR Changes] Date Submitted:
May 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [TG3c Project Plan] Date Submitted: [15 May.
Robert Moskowitz, Verizon
<month year> <doc.: IEEE doc> September 2015
Jan 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Call for THz Contributions Date Submitted: January.
Robert Moskowitz, Verizon
Submission Title: TG9ma Agenda for September Meeting
Jan 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: TeraHertz Closing Report Date Submitted: January.
May 2014 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: TG9 Hop Discussion Date Submitted: May 15, 2014.
Presentation transcript:

September 2009 doc.: IEEE 802.15-0697-00 November 2009 Project: IEEE P802.15 Working Group for Wireless Personal Area Networks (WPANs)‏ Submission Title: Key Negotiation for IEEE 802.15.6 devices using the Host Identity Protocol (HIP)‏ Date Submitted: 18 November, 2009 Source: Robert Moskowitz (ICSAlabs, an Independent Division of Verizon Business Systems)‏ Address: Detroit, MI USA Voice:[…], FAX: […], E-Mail: robert dot moskowitz at icsalabs dot com Re: Unifying keying across protocol layers Abstract: The document proposes unifying the expensive keying mechanism across the protocol layers using the Host Identity Protocol, RFC 4423. Purpose: Review layered security model, why both Layer 2 & 3 security needed and how HIP can key Layer 2 security and provide Layer 3 security. Notice: This document has been prepared to assist the IEEE P802.15. It is offered as a basis for discussion and is not binding on the contributing individual(s) or organization(s). The material in this document is subject to change in form and content after further study. The contributor(s) reserve(s) the right to add, amend or withdraw material contained herein. Release: The contributor acknowledges and accepts that this contribution becomes the property of IEEE and may be made publicly available by P802.15. Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

September 2009 doc.: IEEE 802.15-0697-00 November 2009 Key Negotiation for IEEE 802.15.6 devices using the Host Identity Protocol (HIP)‏ Robert Moskowitz (ICSAlabs, an Independent Division of Verizon Business Systems)‏ Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

September 2009 doc.: IEEE 802.15-0697-00 November 2009 What to Secure? As stated by Norm Finn at the start of the 802.1 LinkSec effort: Layer 2 security addresses the Risks and Liabilities of the Network Owner Layer 3 security addresses the Risks and Liabilities of the System Owner Layer 4 security addresses the Risks and Liabilities of the Application Owner Layer 7 security addresses the Risks and Liabilities of the Data Owner There is some natural overlap Note that each layer tends to have its own datagram framing requirements, but keying issues MAY be commonized. Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

A Security Curmudgeon Speaks out September 2009 doc.: IEEE 802.15-0697-00 November 2009 A Security Curmudgeon Speaks out MAC security is at best half the problem It boarders on impossible to design a secure system that does not implement system security protocols Even the smallest sensors are faced with this problem and thus a cost-vs-secure trade off. It is HARD to design a Key Management System And, in part, why we have so few KMSs. Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

Key Management Requirements September 2009 doc.: IEEE 802.15-0697-00 November 2009 Key Management Requirements Really Secure E.G. SigMa compliant webee.technion.ac.il/~hugo/sigma.html Minimal cost Short exchange, e.g. 4 datagrams Use ECC Long-lived state, e.g. survive power cycles Challenge of maintaining CCM counter as well Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

Key Management Requirements September 2009 doc.: IEEE 802.15-0697-00 November 2009 Key Management Requirements Avoid 3rd parties E.G. PKI and AAA (used in 802.1X)‏ Support Access Control Lists (ACLs)‏ With simple registration, e.g. password based Support Emergency Access E.G. One time Password based Restricted data flow E.G. “We detect a heartbeat in the rubble” Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

A Short Introduction to HIP And what it offers mBAN September 2009 doc.: IEEE 802.15-0697-00 November 2009 A Short Introduction to HIP And what it offers mBAN The Host Identity Protocol (HIP)‏ Started January 1998 RFCs: 4423, 5201-5206 Leverages a Public Key “Host Identity” to Set up a secure communication between 2 hosts True Peer-to-peer model Decouple the Transport layer from the Internetworking layer Currently RSA & DSA, ECC being added www.ietf.org/proceedings/09nov/slides/HIPRG-6.ppt Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

A Short Introduction to HIP And what it offers mBAN September 2009 doc.: IEEE 802.15-0697-00 November 2009 A Short Introduction to HIP And what it offers mBAN Introduces the “Host Identity Tag” (HIT)‏ A hash of the HI into the IPv6 address space Currently in ORCHID (RFC 4843) format Currently uses SHA-1 Plans to add other hashes, e.g. GMAC Applications bind to the HIT and never see routable IPv6 addresses HIP middle layer does the mappings Redirects ARE a problem Supports true multihoming Supports true mobility Local Scope Identities (LSI) for IPv4 support Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

A Short Introduction to HIP And what it offers mBAN September 2009 doc.: IEEE 802.15-0697-00 November 2009 A Short Introduction to HIP And what it offers mBAN Uses The Encapsulating Security Payload (ESP) in Transport mode for datagram protection Any ESP ciphersuite can be used ESP + CCM costs ~26 bytes The SPI (Security Parameter Index) is the per-packet index to the HIT and IP addresses All host-paired applications use the same Security Association Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

A Short Introduction to HIP And what it offers mBAN September 2009 doc.: IEEE 802.15-0697-00 November 2009 A Short Introduction to HIP And what it offers mBAN HIP is **NOT** a replacement for IKE in IPsec It is similar, but solves different problems IKEv2 came after HIP and has 'lessons learned' in its design. Currently only supports ESP in Transport mode Discussions to add AH support for IPv6 If you want a tunnel, run a tunnel within Transport (IPnIP)‏ Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

A Short Introduction to HIP And what it offers mBAN September 2009 doc.: IEEE 802.15-0697-00 November 2009 A Short Introduction to HIP And what it offers mBAN The HIP Base Exchange is 4 packets Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

A Short Introduction to HIP And what it offers mBAN September 2009 doc.: IEEE 802.15-0697-00 November 2009 A Short Introduction to HIP And what it offers mBAN Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

A Short Introduction to HIP And what it offers mBAN September 2009 doc.: IEEE 802.15-0697-00 November 2009 A Short Introduction to HIP And what it offers mBAN Limited policy negotiation e.g. Key lifetime is a local host issue HIP mobility via Rendezvous Server NOT a HOME agent Systems register to an RVS RVS only 'slingshots' I1 HIP API Applications can query their security posture Alternative to Layer 4 security Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

September 2009 doc.: IEEE 802.15-0697-00 November 2009 HIP brings to mBAN Key MAC security as well as Internetworking security Implement a single KMS Applications are IP address ignorant Mobility IPv6 datagram compression Local loop does may not need SRC and DST addresses This will take work to work right Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

September 2009 doc.: IEEE 802.15-0697-00 November 2009 HIP work HIP code Boeing has SCADA experience with their implementation www.openhip.org Ericsson's NomadicLabs has BSD licensed code hip4inter.net Helsinki Institute of Information Technologies hipl.infrahip.net Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

HIP work “Internet of Things” HIP EAP September 2009 doc.: IEEE 802.15-0697-00 November 2009 HIP work “Internet of Things” perso.telecom- paristech.fr/~urien/hiptag/index.html HIP EAP Password challenge/response within HIP draft-varjonen-hip-eap-00.txt Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.

Questions? September 2009 doc.: IEEE 802.15-0697-00 November 2009 Robert Moskowitz (ICSAlabs/VzB) Michael Bahr (Siemens AG) et al.