Daniel Kaiser, Christian Huitema IETF 98 March 28, 2017

Slides:



Advertisements
Similar presentations
IETF 71: NETLMM Working Group – Proxy Mobile IPv6 1 Proxy Mobile IPv6 111 draft-ietf-netlmm-proxymip6-11.txt IETF 71: NETLMM Working Group – Proxy Mobile.
Advertisements

Dynamic Symmetric Key Provisioning Protocol (DSKPP)
CT-KIP Magnus Nyström, RSA Security OTPS Workshop, October 2005.
TGDC Meeting, July 2011 Review of VVSG 1.1 Nelson Hastings, Ph.D. Technical Project Leader for Voting Standards, ITL
Dean Cheng Jouni Korhonen Mehamed Boucadair
draft-ietf-netconf-call-home-01
IETF 531 DNS Discovery Update draft-ietf-ipv6-dns-discovery-04.txt Dave Thaler
Dnssd requirements draft-ietf-dnssd-requirements-01 Kerry Lynn Stuart Cheshire Marc Blanchet Daniel Migault IETF 89, London, 3 March 2014.
Jun Li DHCP Option for Access Network Information draft-lijun-dhc-clf-nass-option-01.
Draft-chown-v6ops-port-scanning-implications-02 IPv6 Implications for TCP/UDP Port Scanning Tim Chown IETF 65, March 23rd 2006 Dallas,
1 Content-Aware Device Benchmarking Methodology/Terminology (draft-ietf-bmwg-ca-bench-meth-00) BMWG Meeting IETF-82 Taipei November 2011 Mike Hamilton.
OSPF WG – IETF 69 - Chicago OSPF WG Document Abhay Roy/Cisco Systems Acee Lindem/Redback Networks.
Dnssd requirements draft-ietf-dnssd-requirements-03 Kerry Lynn Stuart Cheshire Marc Blanchet Daniel Migault IETF 90, Toronto, 24 July
Session Traversal Utilities for NAT (STUN) IETF-92 Dallas, March 26, 2015 draft-ietf-tram-stunbis Marc Petit-Huguenin, Gonzalo Salgueiro.
Softwire Security Requirement Update draft-ietf-softwire-security-requirements-02.txt IETF Meeting, Prague March 19, 2007 Shu Yamamoto Carl Williams Florent.
Design Guidelines Thursday July 26, 2007 Bernard Aboba IETF 69 Chicago, IL.
1 ipv6-node-02.PPT/ 18 November 2002 / John Loughney IETF 55 IPv6 Working Group IPv6 Node Requirements draft-ietf-ipv6-node-requirements-02.txt John Loughney.
MPLS over L2TPv3 Encapsulation IETF VersionIHLTOSTotal length IdentificationFlagsFragment offset TTL Protocol ==
Slide # 1 IETF-62 March 2005Conference Package Conference Package Status March 11 th, 2005 IETF 62, Minnesota draft-sipping-conference-package-09.
SPPP Transport Session Peering Provisioning Protocol draft-ietf-drinks-sppp-over-soap-04.
IETF 83 CloudLog Gene Golovinsky March 25-30, 2012.
Time-base One-time Password Eddy Kleinjan, Data Access Europe.
EAP WG EAP Key Management Framework Draft-ietf-eap-keying-05.txt Bernard Aboba Microsoft IETF 62, Minneapolis, MN.
Draft-ietf-netconf-server-model-04 NETCONF Server Configuration Model
SCVP 18 Tim Polk. Mea Culpa ● Draft -19 omits some promised changes from the March IETF meeting – Document management problems compounded by ID submission.
draft-ietf-tsvwg-diffserv-service-classes-00.txt Kwok Ho Chan
CAPWAP Threat Analysis
SPIRITS Chairs: Steve Bellovin
Max Riegel IP over ETH over IEEE draft-ietf-16ng-ip-over-ethnet-over Max Riegel
Supporting quality devices
Open issues with PANA Protocol
RADEXT WG RADIUS Attributes for WLAN Draft-aboba-radext-wlan-00.txt
dnssd WG Chairs: Ralph Droms,
DS-TE protocol Extensions DS-TE Russian Dolls Model (RDM) DS-TE Maximum Allocation Model (MAM) draft-ietf-tewg-diff-te-proto-04.txt draft-ietf-tewg-diff-te-russian-03.txt.
draft-ietf-simple-message-sessions-00 Ben Campbell
Stefan Santesson Microsoft
IETF 55 IPv6 Working Group IPv6 Node Requirements
LMP Behavior Negotiation
IETF-70 EAP Method Update (EMU)
draft-ietf-geopriv-lbyr-requirements-02 status update
Device Flow <draft-ietf-oauth-device-flow-03>
Configuration Framework draft-ietf-sipping-config-framework-06
IPv4 Support for Proxy Mobile IPv6 Ryuji Wakikawa & Sri Gundavelli
Scaling up DNS-based service discovery
Maureen Stillman March 17, 2003
Migration-Issues-xx Where it’s been and might be going
Pairing Protocol (for DNS SD privacy)
Deprecating ASM for Interdomain Multicast IETF 103 Bangkok 2018
draft-ipdvb-sec-01.txt ULE Security Requirements
dnssd WG Chairs: Ralph Droms,
IETF Liaison Report March 2003 Dorothy Stanley – Agere Systems
My name is Pascal Urien, ENST
Requirements for IPv6 Routers draft-ietf-v6ops-ipv6rtr-reqs
55th IETF Atlanta, GA, November 17-21, “EAP support in smartcards”
IEEE MEDIA INDEPENDENT HANDOVER DCN:
TCP Friendly Rate Control (TFRC): Protocol Specification RFC3448bis
Privacy Recommendations for 802 LMSC Section 8: Recommendations
GeneRic Autonomic Signaling Protocol draft-ietf-anima-grasp-08
IEEE MEDIA INDEPENDENT HANDOVER DCN:
Encrypted Database Final Presentation
IEEE MEDIA INDEPENDENT HANDOVER
RFC 5539 Update Status draft-badra-netconf-rfc5539bis-00
IEEE MEDIA INDEPENDENT HANDOVER DCN:
PW security measures PWE3 – 65th IETF 21 March 2005 Yaakov (J) Stein.
Sally Floyd and Eddie Kohler draft-floyd-ccid4-01.txt July 2007
IEEE MEDIA INDEPENDENT HANDOVER DCN:
(draft-josefsson-pppext-eap-tls-eap-06.txt)
DNS SD Privacy Christian Huitema, Daniel Kaiser
PANA enabling IPsec based Access control
OSPF WG Supporting Authentication Trailer for OSPFv3
Presentation transcript:

Daniel Kaiser, Christian Huitema IETF 98 March 28, 2017 Device Pairing Using Short Authentication Strings draft-ietf-dnssd-pairing-01.txt Daniel Kaiser, Christian Huitema IETF 98 March 28, 2017

draft-ietf-dnssd-pairing-01 Changes since draft-00 Review by Steve Kent Simplifications Precisions draft-ietf-dnssd-pairing-01

Rewrote the QR code section Was a bit confusing, now very direct Phase 1, Discovery Use DNS-SD to discover “_pairing._tcp”; Or, Optionally, scan QR code, get “server” location from code Phase 2, Agreement TLS session, use DH-Anon Phase 3, Authentication Compute SAS, manual verification Optionally, scan QR code, read server’s SAS draft-ietf-dnssd-pairing-01

Simplifications & Clarifications Removed speculative language For example, left “intra user pairing” variants out of “specification” part MUST implement TLS_DH_anon_WITH_AES_256_CBC_SHA256. draft-ietf-dnssd-pairing-01

Steve Kent Suggested Split in 2 Drafts Style of the first part seems inappropriate for a standards track document Reads like research paper Split in two? First part becoming an informational document, Second part focusing on standard track specification of the protocol Reference to the informational document as appropriate. draft-ietf-dnssd-pairing-01

draft-ietf-dnssd-pairing-01 Next steps Split the documents? Complete implementations and tests Availability of TLS_DH_anon_WITH_AES_256_CBC_SHA256 Availability of RFC 5705 key extractor Last call? draft-ietf-dnssd-pairing-01