Draft-ietf-dime-ikev2-psk-diameter-0draft-ietf-dime-ikev2-psk-diameter-08 draft-ietf-dime-ikev2-psk-diameter-09 in progress Diameter IKEv2 PSK: Pre-Shared.

Slides:



Advertisements
Similar presentations
Dynamic Symmetric Key Provisioning Protocol (DSKPP)
Advertisements

EAP-Only Authentication in IKEv2 draft-eronen-ipsec-ikev2-eap-auth
CT-KIP Magnus Nyström, RSA Security OTPS Workshop, October 2005.
External User Security Model (EUSM) for SNMPv3 draft-kaushik-snmp-external-usm-00.txt November, 2004.
1Nokia Siemens Networks Presentation / Author / Date University of Twente On the Security of the Mobile IP Protocol Family Ulrike Meyer and Hannes Tschofenig.
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Lionel Morand DIME WG IETF 79 Diameter Design Guidelines Thursday, November 11, 2010 Lionel Morand.
1 Improved DNS Server Selection for Multi-Homed Nodes draft-savolainen-mif-dns-server-selection-04 Teemu Savolainen (Nokia) Jun-ya Kato (NTT) MIF WG meeting.
Carrying Location Objects in RADIUS Hannes Tschofenig, Farid Adrangi, Avi Lior, Mark Jones.
AAA-Mobile IPv6 Frameworks Alper Yegin IETF Objective Identify various frameworks where AAA is used for the Mobile IPv6 service Agree on one (or.
ERP for IKEv2 draft-nir-ipsecme-erx-01. Why ERP for IKEv2? RFC 5296 and the bis document define a quick re- authentication protocol for EAP. ERP requires.
July 16, 2003AAA WG, IETF 571 AAA WG Meeting IETF 57 Vienna, Austria Wednesday, July 16,
Russ Housley IETF Chair Founder, Vigil Security, LLC 8 June 2009 NIST Key Management Workshop Key Management in Internet Security Protocols.
Draft-ietf-abfab-aaa-saml Josh Howlett, JANET IETF 82.
WG RAQMON Internet-Drafts RMON MIB WG Meeting Washington, Nov. 11, 2004.
November st IETF MIP6 WG Mobile IPv6 Bootstrapping Architecture using DHCP draft-ohba-mip6-boot-arch-dhcp-00 Yoshihiro Ohba, Rafael Marin Lopez,
Softwire Security Requirement draft-ietf-softwire-security-requirements-03.txt Softwires WG IETF#69, Chicago 25 th July 2007 Shu Yamamoto Carl Williams.
Hokey IETF 81 Quebec1 EAP Extensions for EAP Re- authentication Protocol draft-ietf-hokey-rfc5296bis-04 Qin Wu Zhen Cao Yang Shi Baohong He.
Identities and Network Access Identifier in M2M Page 1 © GPP2 3GPP2 and its Organizational Partners claim copyright in this document and individual.
July 16, Diameter EAP Application (draft-ietf-aaa-eap-02.txt) on behalf of...
Session Peering Protocol over SOAP I-D ( draft-ietf-drinks-spp-over-soap-01) draft-ietf-drinks-spp-over-soap-01 0 Presenter: Vikas Bhatia (On behalf of.
Dime WG Status Update IETF#80, 1-April Agenda overview Agenda bashing WG status update Active drafts Recently expired IESG processing Current milestones.
1 RADIUS Mobile IPv6 Support draft-ietf-mip6-radius-01.txt Kuntal Chowdhury Avi Lior Hannes Tschofenig.
AAA and Mobile IPv6 Franck Le AAA WG - IETF55. Why Diameter support for Mobile IPv6? Mobile IPv6 is a routing protocol and does not deal with issues related.
Carrying Location Objects in RADIUS Hannes Tschofenig, Farid Adrangi, Avi Lior, Mark Jones.
© 2003 The MITRE Corporation. All rights reserved For Internal MITRE Use Addressing ISO-RTO e-MARC Concerns: Clarifications and Ramifications Response.
Comments on draft-ietf-pkix-scvp-19.txt IETF Meeting Paris - August 2005 Denis Pinkas
IEEE MEDIA INDEPENDENT HANDOVER DCN: Sec Title: Considerations on use of TLS for MIH protection Date Submitted: January 14, 2010.
EAP Keying Framework Draft-aboba-pppext-key-problem-06.txt EAP WG IETF 56 San Francisco, CA Bernard Aboba.
EAP Extensions for EAP Re- authentication Protocol (ERP) draft-wu-hokey-rfc5296bis-01 Glen Zorn Qin Wu Zhen Cao.
1 HRPD Roamer Authentication Zhibi Wang, Sarvar Patel, Simon Mizikovsky, Nancy Lee.
Mobile IPv6 with IKEv2 and revised IPsec architecture IETF 61
Emu wg, IETF 70 Steve Hanna, EAP-TTLS draft-funk-eap-ttls-v0-02.txt draft-hanna-eap-ttls-agility-00.txt emu wg, IETF 70 Steve Hanna,
Mobile IPv4 – Diameter Draft Status Tom Hiller Lucent Technologies.
Draft-ietf-aaa-diameter-mip-15.txt Tom Hiller et al Presented by Pete McCann.
IETF68 DIME WG Open Issues for RFC3588bis Victor Fajardo (draft-ietf-dime-rfc3588bis-02.txt)
1 3GPP2 GBA Overview Adrian Escott Chair, TSG-S WG4 24 May 2006.
Washinton D.C., November 2004 IETF 61 st – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-02) Gerardo.
3GPP GBA Overview Adrian Escott.
Softwire Security Requirement Update draft-ietf-softwire-security-requirements-02.txt IETF Meeting, Prague March 19, 2007 Shu Yamamoto Carl Williams Florent.
1 Remote IP Access - Stage 2 Architecture proposal for adoption Peerapol Tinnakornsrisuphap Anand.
N. Asokan, Kaisa Nyberg, Valtteri Niemi Nokia Research Center
Channel Binding Support for EAP Methods Charles Clancy, Katrin Hoeper.
RFC 2716bis Wednesday, July 12, 2006 Draft-simon-emu-rfc2716bis-02.txt Dan Simon Bernard Aboba IETF 66, Montreal, Canada.
1 Mobility for IPv6 [MIP6] November 12 th, 2004 IETF61.
San Diego, August 2004 IETF 60 th – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-01) Gerardo Giaretta.
Draft-ietf-dime-ikev2-psk-diameter-10 Diameter IKEv2 PSK: Pre-Shared Secret-based Support for IKEv2 Server to Diameter Server Interaction draft-ietf-dime-ikev2-psk-diameter-10.
Diameter SIP Application
Minneapolis, March 2005 IETF 62 nd – mip6 WG Goals for AAA-HA interface (draft-giaretta-mip6-aaa-ha-goals-00) Gerardo Giaretta Ivano Guardini Elena Demaria.
Diameter Group Signaling Thursday, March 6 th, 2014 draft-ietf-diameter-group-signaling-03 Mark Jones, Marco Liebsch, Lionel Morand IETF 89 London, U.K.
DIME WG IETF 84 Diameter Design Guidelines draft-ietf-dime-app-design-guide-15 Tuesday, July 31, 2012 Lionel Morand.
1 Extensible Authentication Protocol (EAP) Working Group IETF-57.
Paris, August 2005 IETF 63 rd – mip6 WG Mobile IPv6 bootstrapping in split scenario (draft-ietf-mip6-bootstrapping-split-00) mip6-boot-sol DT Gerardo Giaretta,
MIP6 RADIUS IETF-72 Update draft-ietf-mip6-radius-05.txt A. LiorBridgewater Systems K. ChowdhuryStarent Networks H. Tschofenig Nokia Siemens Networks.
SPPP Transport Session Peering Provisioning Protocol draft-ietf-drinks-sppp-over-soap-04.
IETF68 DIME WG Diameter Applications Design Guidelines Document (draft-fajardo-dime-app-design-guide-00.txt)
SCVP-28 Tim Polk November 8, Current Status Draft -27 was submitted in June ‘06 –AD requested a revised ID 8/11 –No related discussion on list –Editors.
IP Security (IPSec) Matt Hermanson. What is IPSec? It is an extension to the Internet Protocol (IP) suite that creates an encrypted and secure conversation.
San Diego, November 2006 IETF 67 th – mip6 WG Goals for AAA-HA interface (draft-ietf-mip6-aaa-ha-goals-03) Gerardo Giaretta Ivano Guardini Elena Demaria.
WLAN IW Enhancement for Multiple Authentications Support QUALCOMM Inc.: Raymond Hsu, QUALCOMM Inc.: Masa Shirota,
Doc.: IEEE /2179r0 Submission July 2007 Steve Emeott, MotorolaSlide 1 Summary of Updates to MSA Overview and MKD Functionality Text Date:
Thoughts on Bootstrapping Mobility Securely Chairs, with help from James Kempf, Jari Arkko MIP6 WG/BOF 57 th IETF Vienna Wed. July 16, 2003.
Open issues with PANA Protocol
RADEXT WG RADIUS Attributes for WLAN Draft-aboba-radext-wlan-00.txt
PANA Discussion and Open Issues (draft-ietf-pana-pana-01.txt)
Hokey Architecture Deployment and Implementation
Carrying Location Objects in RADIUS
for IP Mobility Protocols
Carlos Pignataro Bruno Stevant Jean-Francois Tremblay Bill Storer
IEEE MEDIA INDEPENDENT HANDOVER
Presentation transcript:

draft-ietf-dime-ikev2-psk-diameter-0draft-ietf-dime-ikev2-psk-diameter-08 draft-ietf-dime-ikev2-psk-diameter-09 in progress Diameter IKEv2 PSK: Pre-Shared Secret-based Support for IKEv2 Server to Diameter Server Interaction draft-ietf-dime-ikev2-psk-diameter-08 draft-ietf-dime-ikev2-psk-diameter-09 in progress draft-ietf-dime-ikev2-psk-diameter-0 Violeta Cakulev Avi Lior Simon Mizikovsky ITEF 81 – Quebec City,

2 Diameter IKEv2 PSK Specification of the interaction between the IKEv2 Server (e.g. Home Agent, Access Gateway) and Diameter server for the IKEv2 based on pre-shared secrets Diameter Server Diameter Client/IKEv2 Server IKEv2 Peer IKEv2 Server HAAA Server Interaction (this document) Back-end support Protocol Front-end protocol IKEv2 Draft is currently under IESG evaluation Has 4 Open COMMENTS Has enough positions to pass once DISCUSS is resolved

3 Resolved Comments in Re.08 1.Clarified that mutually authenticated TLS between Diameter nodes is already expected 2."Encr" column in earlier version of the Draft is removed. 3.Initial recommendation to use Diameter agents that can be trusted was removed as unenforceable. 4.Auth-Request-Type AVP in the Request MUST be set to ‘Authorize- Only’ 5.Key-SPI AVP is included in the request instead of Key AVP 6.Trust model is described in Security Consideration Section 7.Abbreviations section added 8.Editorials

4 Resolved Comments in Rel.09 (in progress) 1.Added the figure showing general Architecture (Rel.09). 2.Ni and Nr format was changed to OcterString from Unsigned32 because in RFC 5996 they are of variable length. 3.Recommendation to roll this draft into the 3588bis was withdrawn, because it was not clear when will 3588bis be ready. 4.It was clarified that SPI used in this draft (identifying the PSK for IKEv2) is different than SPI defined by IKEv2 for IPSec.

5 Open Discuss (Comment 1) 1. Procedure for Pre-Shared Key generation “For interoperability, procedure for PSK generation needs to be specified”  Response: The PSK could be generated following outside rules established between AAA and IKEv2 Client, or could be provisioned and stale.  For systems and protocols that leverage this Diameter application but do not specify the key derivation procedure, Rel.09 specifies the default key generation procedure that uses N i and N R for freshness, similar to that in RFC 5295 sec.3.1 for USRK generation. PSK = KDF (Root Key i |N R |ID i |length)

6 Open Discuss (Comments 2 & 3) 2. Need for applicability text “Limit the applicability to MIPv6”  Response: MIPv6 is described as an example of use in the Draft. Multiple uses are possible. Limiting the applicability in the text can disable any future use. 3. Routing based on NAI “Routing based on NAI (realm) seems to make it very hard to do with security, unless there is some way to validate the domain component of the NAI. Generic text that could be referenced is requested.”  Response: Routing based on NAI is a generic issue true for all Diameter deployments, not specific for this draft. Business agreement between IKEv2 Server and AAA Server (associated with the realm in NAI) is expected.

7 Open Discuss (Comment 4) 4. IDr in IKEv2-PSK-Request “If IDr is included in IKE_AUTH from Initiator to Responder should it be included in IKEv2-PSK-Request for IKEv2 Server binding into the PSK generation.”  Response:  IKEv2 allows the Peer to specify an IDr as optional parameter. But according to RFC 5996, the IKEv2 server can assert a different IDr.  The Peer needs the PSK at the time of computing the IKEv2 AUTH for the CREATE_CHILD_SA Request. But the correct IDr only comes from the IKEv2 Server in the CREATE_CHILD_SA Response, or too late.  Therefore, IDr is not included in IKEv2 PSK computation.