-
"Dynamic Symmetric Key Provisioning Protocol (DSKPP)", Andrea Doherty, Mingliang Pei, Salah Machani, Magnus Nystrom, 25-Feb-08. ( bytes)
- DSKPP is a client-server protocol for initialization (and
configuration) of symmetric keys to locally and remotely accessible
cryptographic modules. The protocol can be run with or without
private-key capabilities in the cryptographic modules, and with or
without an established public-key infrastructure.
Two variations of the protocol support multiple usage scenarios.
With the four-pass variant, keys are mutually generated by the
provisioning server and cryptographic module; provisioned keys are
not transferred over-the-wire or over-the-air. The two-pass variant
enables secure and efficient download and installation of pre-
generated symmetric keys to a cryptographic module.
This document builds on information contained in [RFC4758], adding
specific enhancements in response to implementation experience and
liaison requests. It is intended that this document or a successor
version thereto will become the basis for subsequent progression of a
symmetric key provisioning protocol specification on the standards
track.
-
"Portable Symmetric Key Container", Philip Hoyer, 22-Apr-08. ( bytes)
- This document specifies a symmetric key format for transport and
provisioning of symmetric keys (for example One Time Password (OTP)
shared secrets or symmetric cryptographic keys) to different types of
crypto modules such as a strong authentication device. The standard
key transport format enables enterprises to deploy best-of-breed
solutions combining components from different vendors into the same
infrastructure.
This work is a joint effort by the members of OATH (Initiative for
Open AuTHentication) to specify a format that can be freely
distributed to the technical community. The authors believe that a
common and shared specification will facilitate adoption of two-
factor authentication on the Internet by enabling interoperability
between commercial and open-source implementations.
-
"Symmetric Key Package Content Type", Sean Turner, Russ Housley, 25-Feb-08. ( bytes)
- This document defines the symmetric key format content type. It is
transport independent. The Cryptographic Message Syntax can be used
to digitally sign, digest, authenticate, or encrypt this content
type.
IETF Secretariat - Please send questions, comments, and/or
suggestions to ietf-web@ietf.org.
Return to Internet-Draft directory.
Return to IETF home page.