| < draft-haddad-alien-threat-model-02.txt | draft-haddad-alien-threat-model-03.txt > | |||
|---|---|---|---|---|
| Network Working Group W. Haddad | Network Working Group W. Haddad | |||
| Internet-Draft Qualcomm | Internet-Draft | |||
| Intended status: Informational E. Nordmark | Intended status: Informational E. Nordmark | |||
| Expires: December 27, 2008 Sun Microsystems, Inc. | Expires: September 10, 2009 Sun Microsystems, Inc. | |||
| F. Dupont | F. Dupont | |||
| ISC | ISC | |||
| M. Bagnulo | M. Bagnulo | |||
| Universidad Carlos III de Madrid | Universidad Carlos III de Madrid | |||
| B. Patil | B. Patil | |||
| Nokia | ||||
| H. Tschofenig | H. Tschofenig | |||
| Nokia Siemens | Nokia Siemens | |||
| June 25, 2008 | March 9, 2009 | |||
| Anonymous Layers Identifiers (ALIen): Threat Model for Mobile and | Anonymous Layers Identifiers (ALIen): Threat Model for Mobile and | |||
| Multihomed Nodes | Multihomed Nodes | |||
| draft-haddad-alien-threat-model-02 | draft-haddad-alien-threat-model-03 | |||
| Status of this Memo | Status of this Memo | |||
| By submitting this Internet-Draft, each author represents that any | This Internet-Draft is submitted to IETF in full conformance with the | |||
| applicable patent or other IPR claims of which he or she is aware | provisions of BCP 78 and BCP 79. | |||
| have been or will be disclosed, and any of which he or she becomes | ||||
| aware will be disclosed, in accordance with Section 6 of BCP 79. | ||||
| Internet-Drafts are working documents of the Internet Engineering | Internet-Drafts are working documents of the Internet Engineering | |||
| Task Force (IETF), its areas, and its working groups. Note that | Task Force (IETF), its areas, and its working groups. Note that | |||
| other groups may also distribute working documents as Internet- | other groups may also distribute working documents as Internet- | |||
| Drafts. | Drafts. | |||
| Internet-Drafts are draft documents valid for a maximum of six months | Internet-Drafts are draft documents valid for a maximum of six months | |||
| and may be updated, replaced, or obsoleted by other documents at any | and may be updated, replaced, or obsoleted by other documents at any | |||
| time. It is inappropriate to use Internet-Drafts as reference | time. It is inappropriate to use Internet-Drafts as reference | |||
| material or to cite them other than as "work in progress." | material or to cite them other than as "work in progress." | |||
| The list of current Internet-Drafts can be accessed at | The list of current Internet-Drafts can be accessed at | |||
| http://www.ietf.org/ietf/1id-abstracts.txt. | http://www.ietf.org/ietf/1id-abstracts.txt. | |||
| The list of Internet-Draft Shadow Directories can be accessed at | The list of Internet-Draft Shadow Directories can be accessed at | |||
| http://www.ietf.org/shadow.html. | http://www.ietf.org/shadow.html. | |||
| This Internet-Draft will expire on December 27, 2008. | This Internet-Draft will expire on September 10, 2009. | |||
| Copyright Notice | ||||
| Copyright (c) 2009 IETF Trust and the persons identified as the | ||||
| document authors. All rights reserved. | ||||
| This document is subject to BCP 78 and the IETF Trust's Legal | ||||
| Provisions Relating to IETF Documents in effect on the date of | ||||
| publication of this document (http://trustee.ietf.org/license-info). | ||||
| Please review these documents carefully, as they describe your rights | ||||
| and restrictions with respect to this document. | ||||
| Abstract | Abstract | |||
| This memo describes privacy threats related to the MAC and IP layers | This memo describes privacy threats related to the MAC and IP layers | |||
| identifiers in a mobile and multi-homed environment. | identifiers in a mobile and multi-homed environment. | |||
| Table of Contents | Table of Contents | |||
| 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . . 3 | 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . . 4 | |||
| 2. Terminology . . . . . . . . . . . . . . . . . . . . . . . . . 4 | 2. Terminology . . . . . . . . . . . . . . . . . . . . . . . . . 5 | |||
| 3. Threat Model Applied to Privacy . . . . . . . . . . . . . . . 5 | 3. Threat Model Applied to Privacy . . . . . . . . . . . . . . . 6 | |||
| 4. Threat Model Applied to Privacy on the MAC Layer . . . . . . . 7 | 4. Threat Model Applied to Privacy on the MAC Layer . . . . . . . 8 | |||
| 4.1. Threats from Collecting Data . . . . . . . . . . . . . . . 7 | 4.1. Threats from Collecting Data . . . . . . . . . . . . . . . 8 | |||
| 4.1.1. Discovering the Identity Presence . . . . . . . . . . 7 | 4.1.1. Discovering the Identity Presence . . . . . . . . . . 8 | |||
| 4.1.2. Determining the Location . . . . . . . . . . . . . . . 8 | 4.1.2. Determining the Location . . . . . . . . . . . . . . . 9 | |||
| 5. Threat Model Applied to Privacy on the IP Layer . . . . . . . 10 | 5. Threat Model Applied to Privacy on the IP Layer . . . . . . . 11 | |||
| 5.1. Threats Against Privacy in Mobile IPv6 Protocol . . . . . 10 | 5.1. Threats Against Privacy in Mobile IPv6 Protocol . . . . . 11 | |||
| 5.1.1. Quick Overview of MIPv6 Protocol . . . . . . . . . . . 10 | 5.1.1. Quick Overview of MIPv6 Protocol . . . . . . . . . . . 11 | |||
| 5.1.2. Threats Related to MIPv6 BT Mode . . . . . . . . . . . 10 | 5.1.2. Threats Related to MIPv6 BT Mode . . . . . . . . . . . 11 | |||
| 5.1.3. Threats Related to MIPv6 RO Mode . . . . . . . . . . . 11 | 5.1.3. Threats Related to MIPv6 RO Mode . . . . . . . . . . . 12 | |||
| 6. Threat Model Applied to a Static Multi-homed Node . . . . . . 13 | 6. Threat Model Applied to a Static Multi-homed Node . . . . . . 14 | |||
| 6.1. Threats againt Privacy on the MAC Layer . . . . . . . . . 13 | 6.1. Threats againt Privacy on the MAC Layer . . . . . . . . . 14 | |||
| 6.2. Threats against Privacy on the IP Layer . . . . . . . . . 14 | 6.2. Threats against Privacy on the IP Layer . . . . . . . . . 15 | |||
| 7. Security Considerations . . . . . . . . . . . . . . . . . . . 15 | 7. Security Considerations . . . . . . . . . . . . . . . . . . . 16 | |||
| 8. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 16 | 8. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 17 | |||
| 9. References . . . . . . . . . . . . . . . . . . . . . . . . . . 17 | 9. References . . . . . . . . . . . . . . . . . . . . . . . . . . 18 | |||
| 9.1. Normative References . . . . . . . . . . . . . . . . . . . 17 | 9.1. Normative References . . . . . . . . . . . . . . . . . . . 18 | |||
| 9.2. Informative References . . . . . . . . . . . . . . . . . . 17 | 9.2. Informative References . . . . . . . . . . . . . . . . . . 18 | |||
| Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . . 19 | Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . . 20 | |||
| Intellectual Property and Copyright Statements . . . . . . . . . . 21 | ||||
| 1. Introduction | 1. Introduction | |||
| The ALIen problem statement document [ALIen] introduced new | The ALIen problem statement document [ALIen] introduced new | |||
| attributes related to the privacy and described critical privacy | attributes related to the privacy and described critical privacy | |||
| issues related to providing these attributes on both the IP and MAC | issues related to providing these attributes on both the IP and MAC | |||
| layers. In addition, ALIen highlighted the interdependency between | layers. In addition, ALIen highlighted the interdependency between | |||
| privacy issues on the MAC and IP layers and the need to solve them | privacy issues on the MAC and IP layers and the need to solve them | |||
| all together. | all together. | |||
| skipping to change at page 19, line 8 ¶ | skipping to change at page 20, line 8 ¶ | |||
| [SHIM6] Nordmark, E. and M. Bagnulo, "Shim6: Level 3 Multihoming | [SHIM6] Nordmark, E. and M. Bagnulo, "Shim6: Level 3 Multihoming | |||
| Shim Protocol for IPv6", Internet | Shim Protocol for IPv6", Internet | |||
| Draft, draft-ietf-shim6-proto-10.txt, February 2008. | Draft, draft-ietf-shim6-proto-10.txt, February 2008. | |||
| [WIGLE] "Wireless Geographic Logging Engine, | [WIGLE] "Wireless Geographic Logging Engine, | |||
| http://wigle.net/gps/gps/Map/", 2006. | http://wigle.net/gps/gps/Map/", 2006. | |||
| Authors' Addresses | Authors' Addresses | |||
| Wassim Haddad | Wassim Haddad | |||
| Qualcomm | ||||
| 500 Somerset Corporate Blvd | ||||
| Bridgewater, NJ 08807 | ||||
| USA | USA | |||
| Phone: +1 908 9385027 | Phone: +1 6462568041 | |||
| Email: whaddad@qualcomm.com | Email: wmhaddad@gmail.com | |||
| Erik Nordmark | Erik Nordmark | |||
| Sun Microsystems, Inc. | Sun Microsystems, Inc. | |||
| 17 Network Circle | 17 Network Circle | |||
| Mountain View, CA | Mountain View, CA | |||
| USA | USA | |||
| Email: Erik.Nordmark@sun.com | Email: Erik.Nordmark@sun.com | |||
| Francis Dupont | Francis Dupont | |||
| skipping to change at page 19, line 40 ¶ | skipping to change at page 20, line 37 ¶ | |||
| Marcelo Bagnulo | Marcelo Bagnulo | |||
| Universidad Carlos III de Madrid | Universidad Carlos III de Madrid | |||
| Av. Universidad 30, leganes | Av. Universidad 30, leganes | |||
| Madrid 28911 | Madrid 28911 | |||
| Spain | Spain | |||
| Email: Marcelo@it.uc3m.es | Email: Marcelo@it.uc3m.es | |||
| Basavaraj Patil | Basavaraj Patil | |||
| Nokia Siemens Network | Nokia | |||
| 6000 Connection Drive | 6000 Connection Drive | |||
| Irving, Tx 75039 | Irving, Tx 75039 | |||
| USA | USA | |||
| Email: Basavaraj.Patil@nsn.com | Email: Basavaraj.Patil@nsn.com | |||
| Hannes Tschofenig | Hannes Tschofenig | |||
| Nokia Siemens Networks | Nokia Siemens Networks | |||
| Otto-Hahn-Ring 6 | Linnoitustie 6 | |||
| Munich, Bayern 81739 | Espoo 02600 | |||
| Germany | Finland | |||
| Email: Hannes.Tschofenig@nsn.com | Email: Hannes.Tschofenig@nsn.com | |||
| Full Copyright Statement | ||||
| Copyright (C) The IETF Trust (2008). | ||||
| This document is subject to the rights, licenses and restrictions | ||||
| contained in BCP 78, and except as set forth therein, the authors | ||||
| retain all their rights. | ||||
| This document and the information contained herein are provided on an | ||||
| "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS | ||||
| OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY, THE IETF TRUST AND | ||||
| THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS | ||||
| OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF | ||||
| THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED | ||||
| WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. | ||||
| Intellectual Property | ||||
| The IETF takes no position regarding the validity or scope of any | ||||
| Intellectual Property Rights or other rights that might be claimed to | ||||
| pertain to the implementation or use of the technology described in | ||||
| this document or the extent to which any license under such rights | ||||
| might or might not be available; nor does it represent that it has | ||||
| made any independent effort to identify any such rights. Information | ||||
| on the procedures with respect to rights in RFC documents can be | ||||
| found in BCP 78 and BCP 79. | ||||
| Copies of IPR disclosures made to the IETF Secretariat and any | ||||
| assurances of licenses to be made available, or the result of an | ||||
| attempt made to obtain a general license or permission for the use of | ||||
| such proprietary rights by implementers or users of this | ||||
| specification can be obtained from the IETF on-line IPR repository at | ||||
| http://www.ietf.org/ipr. | ||||
| The IETF invites any interested party to bring to its attention any | ||||
| copyrights, patents or patent applications, or other proprietary | ||||
| rights that may cover technology that may be required to implement | ||||
| this standard. Please address the information to the IETF at | ||||
| ietf-ipr@ietf.org. | ||||
| End of changes. 13 change blocks. | ||||
| 40 lines changed or deleted | 46 lines changed or added | |||
This html diff was produced by rfcdiff 1.48. The latest version is available from http://tools.ietf.org/tools/rfcdiff/ | ||||