[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[AVT] draft-perkins-avt-srtp-vbr-audio-00
Hi Colin,
thanks for writing this draft, it provides guidance on an important
issue.
I think we should consider using the RTP padding facility with SRTP
and VBR codecs. It is "legal" according to RFC 3711, and it could
provide significant security advantages. The security concerns with
the interaction between padding and encryption that are mentioned in
RFC 3711 would not apply if message authentication were in use, and we
could include this in the recommendation. (Here I'm revisiting
Section 7 of [V02] from RFC 3711, which is online at http://lasecwww.epfl.ch/pub/lasec/doc/Vau02a.ps)
I offer to help look into the security more if it seems desirable
to use SRTP with VBRs. (It might be desirable for interoperability
reasons, even if padding was used to hide VBR lengths; at least that's
my thinking.)
One consideration is that the maximum padding that can be added with
the RTP padding facility is 255 bytes, and depending on the VBR codec,
that might not be enough for security.
I think that we're up against some theoretical limits here, in that we
have to choose between compression efficiency, latency, and
confidentiality.
best regards,
David