Robert Moskowitz, Verizon

Slides:



Advertisements
Similar presentations
Doc.: IEEE tg9-proposed-document-changes Submission Nov 2013 Robert Moskowitz, VerizonSlide 1 Project: IEEE P Working Group for.
Advertisements

Doc.: IEEE xxxxx Submission doc. : IEEE Slide 1 Junbeom Hur and Sungrae Cho, Chung-Ang University Project: IEEE P
Doc.: IEEE Hop-Discuss Submission July 2014 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE Moving-KMP-Forward Submission September 2012 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless.
Doc.: IEEE KMP-Transport-Joint Submission July 2012 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless.
Doc.: IEEE HIP-over-TG9 Submission May 2012 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE Moving-KMP-Forward Submission January 2013 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless.
Doc.: IEEE kmp Submission September 2011 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE tg9-technical-decisions Submission July 2013 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless.
Robert Moskowitz, Verizon
Project: IEEE Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposals for adding a version number and for the treatment.
Project: IEEE Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposals for adding a frame version number and for the.
Project: IEEE 802 EC Privacy Recommendation Study Group
November 2012 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Moving KMP Forward Date Submitted: November.
Robert Moskowitz, Verizon
Jan 2014 Robert Moskowitz, Verizon
May 2013 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Technical Review of KMP transport Date Submitted:
Robert Moskowitz, Verizon
July 2013 Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Project: IEEE 802 EC Privacy Recommendation Study Group
Nov 2013 Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
1/2/2019<month year> doc.: IEEE Jan 2013
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Nov 2013 Robert Moskowitz, Verizon
March 2013 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Moving KMP Forward Date Submitted: March.
Nov 2014 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: KMP TG9 Opening Report San Antonio 2014 Date.
Jan 2015 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Jan 2015 closing report Date Submitted: Jan.
Jan 2014 Robert Moskowitz, Verizon
Jan Robert Moskowitz, Verizon
July 2014 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: July 2014 closing report Date Submitted: July.
July 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Extensions to IEEE in support of.
July 2014 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: KMP TG9 Opening Report San Diego 2014 Date.
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Submission Title: [Frame and packet structure in ]
July 2013 Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Nov 2013 Robert Moskowitz, Verizon
Sept 2014 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: KMP TG9 Opening Report Athens 2014 Date Submitted:
Robert Moskowitz, Verizon
July 2012 Robert Moskowitz, Verizon
doc.: IEEE <doc#>
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Tero Kivinen, AuthenTec
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Tero Kivinen, AuthenTec
Robert Moskowitz, Verizon
July 2013 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Technical Decisions for KMP transport Date.
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Sept 2014 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: KMP TG9 Opening Report Athens 2014 Date Submitted:
Robert Moskowitz, Verizon
Submission Title: TG9ma Agenda for September Meeting
May 2014 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: TG9 Hop Discussion Date Submitted: May 15, 2014.
Submission Title: TG9ma Closing Report for July Meeting
Presentation transcript:

Robert Moskowitz, Verizon September 2011 Project: IEEE P802.15 Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Key Management over 4e Multipurpose Frames Date Submitted: September 19, 2011 Source: Robert Moskowitz, Verizon Address 1000 Bent Creek Blvd, MechanicsBurg, PA, USA Voice:+1 (248) 968-9809, e-mail: rgm@labs.htt-consult.com Re: Key Managementn over 4e Multipurpose Frames Abstract: Using 4e Multipurpose Frames to provide for Key Mangement Purpose: To add Key Management capabilities to 15.4 Notice: This document has been prepared to assist the IEEE P802.15. It is offered as a basis for discussion and is not binding on the contributing individual(s) or organization(s). The material in this document is subject to change in form and content after further study. The contributor(s) reserve(s) the right to add, amend or withdraw material contained herein. Release: The contributor acknowledges and accepts that this contribution becomes the property of IEEE and may be made publicly available by P802.15. Robert Moskowitz, Verizon

Key Management over 15.4e Multipurpose Frames September 2011 Key Management over 15.4e Multipurpose Frames Robert Moskowitz Okinawa September 21, 2011 Robert Moskowitz, Verizon

Abstract To provide for a Key Management Protocol for 802.15.4 September 2011 Abstract To provide for a Key Management Protocol for 802.15.4 KMP agnostic Support: HIP, IKEv2, 802.1X, ... Provide recommended functionality for KMPs Use Information Elements in the new Multipurpose and existing Comand Frames added via 15.4e for the transport of the KMP frames Robert Moskowitz, Verizon

Discussion Functionality needed September 2011 Discussion Functionality needed Manage keying variables in 802.15.4 security Security mode, key value,key rollover, ... Manage long-lived PMK and key- lifetime PTK (including key refresh) Distribute GTK for broadcast/multicast Robert Moskowitz, Verizon

Discussion Functionality needed Provide authentication Manage September 2011 Discussion Functionality needed Provide authentication Manage Short addresses Collisions Duplicate transmissions Robert Moskowitz, Verizon

Discussion 4e Multipurpose Frame Pre 4e usage Adds flexibilty to 15.4 September 2011 Discussion 4e Multipurpose Frame Adds flexibilty to 15.4 New functions without major standards revisions Pre 4e usage Recommendation on equivalent method Should be 'easy' for 6lowpan Robert Moskowitz, Verizon

Discussion 4e Information Elements September 2011 Discussion 4e Information Elements Available in Multipurpose and Command frames Basic TLV – Type/Length/Value Robert Moskowitz, Verizon

Discussion KMP Information Element September 2011 Discussion KMP Information Element Type value assigned from 802.15.4 reserved range 2 Byte KMP info field KMP type 5bits (HIP, IKEv2, 802.1X, SAE, 4-Way-Handshake, vendor ) Chaining flag 1 bit (yes, last) Chaining REQUIRES frame ack Chain count 8bits (multiple frames per KMP packet) Robert Moskowitz, Verizon

Discussion Duplicate transmission management KMP Information Element September 2011 Discussion Duplicate transmission management Keep last frame received to determine if duplicate Duplicates result of lost ACKs. Other reasons? KMP Information Element KMP payload Guidelines provided for 15.4 specific use Robert Moskowitz, Verizon

Discussion Short address for KMP frames September 2011 Discussion Short address for KMP frames Need general collision handling Or NO short address support? What if multiple KMPs in a PAN? When HIP is KMP I1 always uses long addresses HITs used derive short addresses Low order 16 bits? Include short addresses in R1 over long addresses, THEN I2 over short addresses to handle collisions? Robert Moskowitz, Verizon

Discussion If no short address for initial KMP frames September 2011 Discussion If no short address for initial KMP frames KMP update frames MAY use short addresses established by other higher layers E.G. 6lowpan Robert Moskowitz, Verizon

September 2011 Discussion BEACONLESS PANs are commonly deployed and thus first step in participation would be to KMP over Multipurpose frames. BEACON PANs use ASSOCIATE Command Frames to start participation. These frames can contain IEs so they would be used for KMP transport. Robert Moskowitz, Verizon

Discussion What options for TX only devices? BLINK frames September 2011 Discussion What options for TX only devices? BLINK frames Open for presentations Robert Moskowitz, Verizon

September 2011 HIP KMP Discussion HIT discovery and defense from Diffie- Hellman MITM attacks Assume Initiator has no knowledge of Responders HIT for I1, so use I1 opportunistic mode (no Responder HIT) Responder authenticates Initiator HIT Pre-configured ACL Restricted time window Robert Moskowitz, Verizon

September 2011 Moving Forward Create 802.15.4 Recommended Practice document for KMP support as outlined Include HIP DEX, IKEv2, 802.1X, SAE, and 4-Way-Handshake guidelines Allow for other KMPs defined elsewhere Robert Moskowitz, Verizon

Moving Forward Address issues raised for 15.4f support September 2011 Moving Forward Address issues raised for 15.4f support KMP REQUIRES bi-directional data flows Research Blink frames Robert Moskowitz, Verizon

Moving Forward Use by other 802.15 MACs (e.g. .3, .6, .7) September 2011 Moving Forward Use by other 802.15 MACs (e.g. .3, .6, .7) They will need Information Element support and Multipurpose frame Common Type value for IE? Short address collision detection Need general solution or KMP will be forced to long addresses only Robert Moskowitz, Verizon

September 2011 Moving Forward Work with IETF with 'mess under' to support KMP within a 15.4 mess? E.G. to protect IPv6 Neighbor Discovery Robert Moskowitz, Verizon