[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: LIN6 i-d for multihoming and mobility support
> Correctly qualifying, 128 bit psuedo random ID for secure
> identification is completely insecure and useless unless there
> is a *SECURE* mapping between the ID and a lot more handy ID to
> identify the owner.
Agree with this
>
> Without such mapping, such proposals are incomplete.
>
I don't agree with this
Such proposals allow and facilitate that in the future some form of secure
mapping exists.
> Note also that, if you assume something like PKI or secure DNS,
> you should also assume that session keys are shared and sessions
> are secured without bothering multi6 group. That is, there is no
> point to have the 128 bit long strings.
But in this case, the key is the identifier, only that you are not
explicitely using it in the transport layer.
Regards, marcelo
>
> Masataka Ohta
>
>
>