Kristof Teichel, Dieter Sibold, Daniel Franke

Slides:



Advertisements
Similar presentations
Adapted Multimedia Internet KEYing (AMIKEY): An extension of Multimedia Internet KEYing (MIKEY) Methods for Generic LLN Environments draft-alexander-roll-mikey-lln-key-mgmt-01.txt.
Advertisements

Tal Mizrahi Marvell IETF Meeting 81, July 2011
IP over ETH over IEEE draft-riegel-16ng-ip-over-eth-over Max Riegel
1996/2/13Amy, Mei-Hsuan Lu CML/CSIE/NTU1 Implementation Issues (1/6) Usage of TSAP IDs Reliable or Unreliable Well known or dynamic Audio/RTPUnreliableDynamic.
Draft-ietf-dhc-stateless-dhcpv6- renumbering-01 Tim Chown dhc WG, IETF 60, San Diego, August 2, 2004.
NORM PI Update draft-ietf-rmt-pi-norm-revised-04 68th IETF - Prague Brian Adamson NRL.
6LoWPAN Ad Hoc On-Demand Distance Vector Routing (LOAD) Ki-Hyung Kim, S. Daniel Park, G. Montenegro, S. Yoo, and N. Kushalnagar IETF 6LoWPAN WG 66th, Montreal,
Common Log Format (CLF) DISPATCH ad hoc – IETF 75 Spencer Dawkins Theo Zourzouvillys
Light Weight Access Point Protocol (LWAPP) IETF 57 Pat Calhoun, Airespace.
WG RAQMON Internet-Drafts RMON MIB WG Meeting Washington, Nov. 11, 2004.
Softwire Security Requirement draft-ietf-softwire-security-requirements-03.txt Softwires WG IETF#69, Chicago 25 th July 2007 Shu Yamamoto Carl Williams.
EAP Bluetooth Extension Draft-kim-eap-bluetooth-00 Hahnsang Kim (INRIA), Hossam Afifi (INT), Masato Hayashi (Hitachi)
DCN: March 7, 2005 IETF 62 - Minneapolis, MN Media Independent Handover Services and Interoperability Ajay Rajkumar Chair, IEEE
IETF 60 – San Diegodraft-ietf-mmusic-rfc2326bis-07 Magnus Westerlund Real-Time Streaming Protocol draft-ietf-mmusic-rfc2326bis-07 Magnus Westerlund Aravind.
Real-time Flow Management 2 BOF: Remote Packet Capture Extensions Jürgen Quittek NEC Europe Ltd, Heidelberg, Germany Georg Carle GMD.
DNS Discovery Discussion Report Draft-ietf-ipngwg-dns-discovery-01.txt.
GTP (Generic Tunneling Protocol) Alessio Casati/Lucent Technologies Charles E. Perkins/Nokia Research IETF 47 draft-casati-gtp-00.txt.
6lowpan ND Optimization draft Update Samita Chakrabarti Erik Nordmark IETF 69, 2007 draft-chakrabarti-6lowpan-ipv6-nd-03.txt.
March 2006 CAPWAP Protocol Specification Update March 2006
Doc.: IEEE 11-04/0319r0 Submission March 2004 W. Steven Conner, Intel Corporation Slide 1 Architectural Considerations and Requirements for ESS.
Draft-ietf-fecframe-config-signaling-02 1 FEC framework Configuration Signaling draft-ietf-fecframe-config-signaling-02.txt IETF 76 Rajiv Asati.
Requirements For Handover Information Services MIPSHOP – IETF #65 Srinivas Sreemanthula (Ed.)
Magnus Westerlund 1 The RTSP Core specification draft-ietf-mmusic-rfc2326bis-06.txt Magnus Westerlund Aravind Narasimhan Rob Lanphier Anup Rao Henning.
By Mau, Morgan Arora, Pankaj Desai, Kiran.  Large address space  Briefing on IPsec  IPsec implementation  IPsec operational modes  Authentication.
Requirements and Selection Process for RADIUS Crypto-Agility December 5, 2007 David B. Nelson IETF 70 Vancouver, BC.
Draft-ietf-pim-port-03 wglc. WGLC responses Thomas suggested a long list of changes, mostly editorial –I believe I addressed all Dimitri also had comments.
Conclusions to date Based on discussion on Dec. 8, 2005 Options 1a and 3a are more likely to succeed with IETF, since they enable cooperation.
Doc.: IEEE /1147r1 Submission November 2009 David Halasz, AclaraSlide 1 Path Protection Date: Authors:
DOTS Requirements Andrew Mortensen November 2015 IETF 94 1.
History and Implementation of the IEEE 802 Security Architecture
Emerging Solutions in Network Time Synchronization Security
IEEE-1588 IEEE-1588 – Standard for a Precision Clock Synchronization Protocol for Networked Measurement and Control Systems Defines a Precision Time Protocol.
IPSec Detailed Description and VPN
Transmission of IP Packets over IEEE 802
History and Implementation of the IEEE 802 Security Architecture
November 14, 2016 Secure MAC algorithms for use with NTP draft-aanchal4-ntp-mac-03 CFRG: IETF97 Aanchal Malhotra Sharon Goldberg.
47th IETF - Adelaide Chris Lonvick
Chapter 18 IP Security  IP Security (IPSec)
IETF 82 BFCPBIS WG Meeting
IETF#67 – 5-10 November 2006 FECFRAME requirements (draft-ietf-fecframe-req-01) Mark Watson.
UNIT.4 IP Security.
IP Router-Alert Considerations and usage
Transport Layer.
ERP extension for EAP Early-authentication Protocol (EEP)
15th November 2016 Gorry Fairhurst (via webrtc) David Black WG chairs
Results of San-Jose meeting March 16-20
Softwire Security Update
ATIS Cybersecurity DOCUMENT #: GSC13-GTSC6-12 FOR: Presentation
Extending Option Space Discussion Overview and its requirements
Joint TICTOC and NTP Meeting
GS2: Bridge between SASL and GSS-API
CSE 4095 Transport Layer Security TLS
draft-ipdvb-sec-01.txt ULE Security Requirements
STIR WG IETF-100 PASSPorT Extension for Resource-Priority Authorization (draft-ietf-stir-rph-01) November, 2017 Ray P. Singh, Martin Dolly, Subir Das,
David Noveck IETF99 at Prague July 20, 2017
Juan Carlos Zuniga, InterDigital Labs (EC SG Chair)
doc.: IEEE /454r0 Bob Beach Symbol Technologies
Binary Floor Control Protocol BIS (BFCPBIS)
RFC 5539 Update Status draft-badra-netconf-rfc5539bis-00
IEEE MEDIA INDEPENDENT HANDOVER
Conclusions to date Based on discussion on Dec. 8, 2005
PW security measures PWE3 – 65th IETF 21 March 2005 Yaakov (J) Stein.
Joint NTP and TICTOC Meeting
draft-ietf-bier-ipv6-requirements-01
IEEE MEDIA INDEPENDENT HANDOVER DCN: xx-00-sec
Editors: Bala’zs Varga, Jouni Korhonen
James Polk Gorry Fairhurst
Update for “Multicast Considerations over IEEE 802 Wireless Media”
DetNet Architecture Updates
Presentation transcript:

Kristof Teichel, Dieter Sibold, Daniel Franke Network Time Security draft-ietf-ntp-network-time-security-15 draft-ietf-ntp-using-nts-for-ntp-07 Kristof Teichel, Dieter Sibold, Daniel Franke

NTS: WGLC Design Team Progress WGLC generated large amounts of feedback Led to creation of the NTS Design Team Latest proposals developed at NTP WG Interim (Oct 2016) regarding draft-ietf-ntp-using-nts-for-ntp-07 Key exchange Privacy (NTS shall not leak information suitable to track a NTP client) Peer mode (DTLS payload) Nov 13-18, 2016 IETF 97, Seoul, South Korea

Key Exchange Mode Key Exchange KE Port / Transport NTP Packet Transport Port / Transport Mode 1 & 2 DTLS UDP / ??? as DTLS payload Mode 3 & 4 TLS TCP / ??? NTP Packet with NTS extensions UDP / 123 Mode 6 DTLS/TLS UDP/TCP/ ??? as (D)TLS payload UDP/TCP/??? Piggy backing DTLS KE over NTP (within extension fields) is postponed Optional key exchange mechanism are not allowed for NTS for NTP Nov 13-18, 2016 IETF 97, Seoul, South Korea

Open Issues/Questions ASN.1 versus ad hoc binary encoding versus something else? What to do with non-NTP-specific NTS document (draft-ietf-ntp-network-time-security)? Was intended to provide protection schemes for unicast and broadcast/multicast time sync messages (NTP and PTP) Until now very limited feedback on the NTS messages for broadcast/multicast time sync messages IEEE P1588 WG security subcommittee is specifying a security scheme for PTP Nov 13-18, 2016 IETF 97, Seoul, South Korea

Next Steps draft-ietf-ntp-using-nts-for-ntp: draft-aanchal4-ntp-mac-00 Next Steps draft-ietf-ntp-using-nts-for-ntp: Client/Server associations: TLS instead of DTLS Privacy considerations:  Attack vector for active monitoring Security Considerations Revision of the section “Usage of NTP Pools” draft-ietf-ntp-network-time-security: Adapt this draft (if desired) Nov 13-18, 2016 IETF 97, Seoul, South Korea