[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [saag] The use of AES-192 and AES-256 in Secure RTP



Hi Rick,

On May 3, 2006, at 7:18 PM, Rick Porter wrote:


I was surprised to see Suite B appear on someone's radar...

IMO, most aspects of SRTP would not meet the standards for Suite B
certification. The key exchange seems to be the most blatantly lacking,
but there are other aspects.

you are right that there is probably no standardized way to provide keys to SRTP that would meet the Suite B guidelines. But this doesn't imply that we shouldn't specify a Suite B conformant profile for SRTP (since we don't want to create a chicken-or-egg-first? situation). Also, some of the proposed key management methods do incorporate or admit FIPS-140/Suite B approved key establishment methods (for example, DTLS-SRTP could be used with one of the ECC methods currently being drafted for TLS).

Let me point out that the Suite B link does
not even mention which mode(s) of AES are acceptable (e.g. counter, cbc,
ecb, wrap).


You're right that Suite B is underspecified, and it would be reassuring to get more details about it. (I prefer "underspecified" to "overly narrow" though :-)

I do not have a strong opinion about whether or not to specify longer
AES key lengths. However, I would not specify longer key lengths just to
comply with the Suite B standards--NSA is probably going to require
deviation from the IETF standard(s) anyway. NSA has its own set of
requirements (and reasons for them), and they also have a number of
government contractors who develop products to meet those requirements.

True, but I would rather work with Suite B and try to promote broader interoperability. I think that the big value of Suite B is that it will enable interoperability between the high-assurance implementations that you mention and commercial standards-based implementations. This is an obvious gain for the high-assurance community, and it could also benefit the commercial community. But I'm getting off topic here; Suite B is worth discussing, but the use of elliptic curve crypto is the most important topic there, not SRTP key sizes ;-)

David



Cheers,
Rick


Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.