
From nobody Wed May 28 06:41:22 2014
Return-Path: <Edward.Birrane@jhuapl.edu>
X-Original-To: dtn-security@ietfa.amsl.com
Delivered-To: dtn-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 77D951A0993; Wed, 28 May 2014 06:41:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.853
X-Spam-Level: 
X-Spam-Status: No, score=-4.853 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id of7XMRLomfOY; Wed, 28 May 2014 06:41:16 -0700 (PDT)
Received: from piper.jhuapl.edu (piper.jhuapl.edu [128.244.251.37]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ECCA81A0149; Wed, 28 May 2014 06:41:15 -0700 (PDT)
Received: from aplexcas1.dom1.jhuapl.edu (aplexcas1.dom1.jhuapl.edu [128.244.198.90]) by piper.jhuapl.edu with smtp (TLS: TLSv1/SSLv3,128bits,RC4-MD5) id 6b7a_394c_6e022f8f_d2bc_4891_8eee_4de3b2f39a1c; Wed, 28 May 2014 09:41:10 -0400
Received: from aplesfreedom.dom1.jhuapl.edu ([128.244.198.204]) by aplexcas1.dom1.jhuapl.edu ([128.244.198.90]) with mapi; Wed, 28 May 2014 09:40:07 -0400
From: "Birrane, Edward J." <Edward.Birrane@jhuapl.edu>
To: "dtn-interest@irtf.org" <dtn-interest@irtf.org>, "dtn-security@irtf.org" <dtn-security@irtf.org>
Date: Wed, 28 May 2014 09:40:06 -0400
Thread-Topic: Updated SBSP Document
Thread-Index: Ac96egHBtIlHfqjpRHK8eG5est6OOQ==
Message-ID: <329D879C76FDD04AAAE84BB1D89B3970094FBF9EAA@aplesfreedom.dom1.jhuapl.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/dtn-security/vkAO9ccu_EsjiwpnOYkcubo2spE
Subject: [dtn-security] Updated SBSP Document
X-BeenThere: dtn-security@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The Delay-Tolerant Networking Research Group \(DTNRG\) - Security." <dtn-security.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/dtn-security>, <mailto:dtn-security-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/dtn-security/>
List-Post: <mailto:dtn-security@irtf.org>
List-Help: <mailto:dtn-security-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/dtn-security>, <mailto:dtn-security-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 13:41:18 -0000

Good morning.

I've released a new version of the Streamlined Bundle Security Protocol (SB=
SP) document (see information below).

This change incorporates comments received to date, including:

- Minor spelling/grammar changes and text cleanup.
- Expanded discussion on extension block identification (Section 2.1)
- Clarified that a BIB may not be added to sign an encrypted block. (Sectio=
n 2.7)
- Clarified block processing order in Section 2.7.
- Clarified BIB processing (Section 3.3.3)
- Simplified bundle fragmentation discussion (Section 3.4)
- Clarified interaction of authentication and reactive fragmentation.
- Updated policy considerations.

I am cross-posting to dtn-interest and dtn-security as an announcement, but=
 would ask that technical discussion occur on dtn-security.

-Ed

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the Delay-Tolerant Networking Research Group =
Working Group of the IETF.

        Title           : Streamlined Bundle Security Protocol Specificatio=
n
        Author          : Edward J. Birrane
        Filename        : draft-irtf-dtnrg-sbsp-01.txt
        Pages           : 34
        Date            : 2014-05-27

Abstract:
   This document defines a streamlined bundle security protocol, which
   provides data authentication, integrity, and confidentiality services
   for the Bundle Protocol.  Capabilities are provided to protect the
   bundle payload, and additional data that may be included within the
   bundle, along a single path through a network.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-irtf-dtnrg-sbsp/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-irtf-dtnrg-sbsp-01

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-irtf-dtnrg-sbsp-01

---
Ed Birrane
Principal Professional Staff, Space Department
Johns Hopkins Applied Physics Laboratory
(W) 443-778-7423 / (F) 443-228-3839
=A0=20



From nobody Thu May 29 12:09:16 2014
Return-Path: <david.a.zoller@nasa.gov>
X-Original-To: dtn-security@ietfa.amsl.com
Delivered-To: dtn-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC0CF1A04F6 for <dtn-security@ietfa.amsl.com>; Thu, 29 May 2014 12:09:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nl4hD5OKr_Cb for <dtn-security@ietfa.amsl.com>; Thu, 29 May 2014 12:09:09 -0700 (PDT)
Received: from ndjsnpf01.ndc.nasa.gov (ndjsnpf01.ndc.nasa.gov [IPv6:2001:4d0:a302:1100::101]) by ietfa.amsl.com (Postfix) with ESMTP id 40A2E1A0B72 for <dtn-security@irtf.org>; Thu, 29 May 2014 12:09:08 -0700 (PDT)
Received: from ndmsppt103.ndc.nasa.gov (ndmsppt103.ndc.nasa.gov [198.117.0.68]) by ndjsnpf01.ndc.nasa.gov (Postfix) with ESMTP id 8021CD055D; Thu, 29 May 2014 14:03:39 -0500 (CDT)
Received: from NDMSCHT115.ndc.nasa.gov (ndmscht115-pub.ndc.nasa.gov [198.117.0.215]) by ndmsppt103.ndc.nasa.gov (8.14.5/8.14.5) with ESMTP id s4TJ93Qm009392; Thu, 29 May 2014 14:09:03 -0500
Received: from NDMSMBX404.ndc.nasa.gov ([169.254.4.107]) by NDMSCHT115.ndc.nasa.gov ([198.117.0.215]) with mapi id 14.03.0174.001; Thu, 29 May 2014 14:09:03 -0500
From: "Zoller, David A. (MSFC-EO50)[HOSC SERVICES CONTRACT]" <david.a.zoller@nasa.gov>
To: "Birrane, Edward J." <Edward.Birrane@jhuapl.edu>, "dtn-security@irtf.org" <dtn-security@irtf.org>
Thread-Topic: Updated SBSP Document
Thread-Index: Ac96egHBtIlHfqjpRHK8eG5est6OOQA736Hg
Date: Thu, 29 May 2014 19:09:02 +0000
Message-ID: <94CFB3711B4CAE4DBFC5BEB3374BF0C60D1835@NDMSMBX404.ndc.nasa.gov>
References: <329D879C76FDD04AAAE84BB1D89B3970094FBF9EAA@aplesfreedom.dom1.jhuapl.edu>
In-Reply-To: <329D879C76FDD04AAAE84BB1D89B3970094FBF9EAA@aplesfreedom.dom1.jhuapl.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [198.119.225.34]
Content-Type: multipart/alternative; boundary="_000_94CFB3711B4CAE4DBFC5BEB3374BF0C60D1835NDMSMBX404ndcnasa_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.96, 1.0.14,  0.0.0000 definitions=2014-05-29_06:2014-05-29,2014-05-29,1970-01-01 signatures=0
Archived-At: http://mailarchive.ietf.org/arch/msg/dtn-security/NvvaPFm3TSpOGXHEV-50SFXpBXM
Subject: Re: [dtn-security] Updated SBSP Document
X-BeenThere: dtn-security@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The Delay-Tolerant Networking Research Group \(DTNRG\) - Security." <dtn-security.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/dtn-security>, <mailto:dtn-security-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/dtn-security/>
List-Post: <mailto:dtn-security@irtf.org>
List-Help: <mailto:dtn-security-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/dtn-security>, <mailto:dtn-security-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 May 2014 19:09:15 -0000

--_000_94CFB3711B4CAE4DBFC5BEB3374BF0C60D1835NDMSMBX404ndcnasa_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Ed,

Good work - the SBSP spec continues to evolve nicely. I'll kick off the dis=
cussions with my comments below.

Cheers,

DZ






[Page 12] 2.4 Bundle Authentication Block
The security-target MUST be the entire bundle, which MUST be
represented by a <block type><occurrence number> of <0x00><0x00>.
*         Per 3.4 Bundle Fragmentation and Reassembly, bundle authenticatio=
n may be applied to bundle fragments as well as non-fragmented bundles.
*         If a bundle fragment is received that has a BAB, there is no way =
to determine if the BAB applies to the bundle fragment or if it applies to =
an entire bundle that was later fragmented by a non-security-aware BA.
o    I propose that a <block type><occurrence number> of <0x00><payload fra=
g length> indicate that the BAB applies to a bundle fragment
*         If such a bundle fragment is further fragmented by a non-security=
-aware BA then the <payload frag length> can be used to determine that the =
original fragmented bundle must be reassembled before authentication is che=
cked because it will not match the length field in the payload block.
o    Some discussion may be desirable in section 3.4 as well as 2.4 if acce=
pted



[Page 14] 2.6 Block Confidentiality Block
The block processing control flags value can be set to whatever
values are required by local policy, except that a Lone BCB or
First BCB MUST have the "replicate in every fragment" flag set.
This indicates to a receiving node that the payload portion in
each fragment represents cipher-text.
*         The intent here is only if the target of the Lone BCB or First BC=
B is the payload block which would need to be added if this is kept as a re=
quirement.
*         I think this requirement should be removed or at least reduced to=
 a "MAY"
1.       It assumes that the Lone or First BCB must be prior to the payload=
 block which is not a specific requirement and is not necessary in any case=
 for SBSP
2.       A BCB block could be quite large and add a lot of bandwidth overhe=
ad if included in every fragment
3.       I do not see a benefit gained by including the block in every frag=
ment
                                       i.            Even the destination n=
ode likely cannot decrypt any individual fragment except the first one and =
 it probably would only decrypt a partial bundle as a last resort or forens=
ic function if the entire bundle was not received before expiration
                                     ii.            Intermediate nodes shou=
ldn't generally be poking around in bundle payloads anyway and no need to p=
rovide additional clues as to whether a fragment payload is encrypted or a =
bunch of binary values - keep the bad guys guessing and wasting CPU cycles =
if possible
                                    iii.            BSP includes this requi=
rement - have any of the implementations found a need or benefit for this a=
nd would it still apply in context of the SBSP?



[Page 24] 3.1.2.3 Extension Block Canonicalization
Endpoint ID references in blocks are canonicalized using the de-
referenced text form in place of the reference pair.  The reference
count is not included, nor is the length of the endpoint ID text.
The EID reference is, therefore, canonicalized as <scheme>:<SSP>,
which includes the ":" character.
*         Need to include a statement to the effect:
o    Artificial EIDs as defined in this document (ssp reference is 0x00) mu=
st be skipped and are not included in the canonicalization.


[Page 24] 3.1.2.3 Extension Block Canonicalization
The block-length is canonicalized as its unpacked SDNV value.  If the
data to be canonicalized is less than the complete, original block
data, this field contains the size of the data being canonicalized
(the "effective block") rather than the actual size of the block.
*         Section 3.1.2.1 (Primary Block Canonicalization) details the leng=
th fields as 4 byte values and effectively reserves the term "unpacked SDNV=
 value" to mean the 8 byte value. I recommend using the same convention her=
e.
o    Personally, I would specify all SDNV values canonicalized as 8 byte va=
lues and be done with it
*         Add a statement to the effect:
o    The entirety or portion(s) of the block body data are canonicalized as=
 is.


[Page 23] 3.1.2.2 Payload Block Canonicalization
When canonicalizing the payload block, the block processing control
flags value used for canonicalization is the unpacked SDNV value with
reserved and mutable bits masked to zero.  The unpacked value is
ANDed with mask 0x0000 0000 0000 0077 to zero reserved bits and the
"last block" bit.  The "last block" bit is ignored because BABs and
other security blocks MAY be added for some parts of the journey but
not others, so the setting of this bit might change from hop to hop.

Payload blocks are canonicalized as-is, with the exception that, in
some instances, only a portion of the payload data is to be
protected.  In such a case, only those bytes are included in the
canonical form, and additional cipher suite parameters are required
to specify which part of the payload is protected, as discussed
further below.
*         The processing control flags are pulled out and masked so the Pay=
load block can no longer be considered canonicalized "as-is".
*         A Payload Block is the same underlying format as an Extension Blo=
ck with the restriction that the 'block contains an EID-reference field' is=
 never set and it should follow the same canonicalization methodology as th=
at of the Extension Block
o    I propose a single "Non-Primary Block Canonicalization" section based =
on the finalized version of the Extension Block Canonicalization


[Page 26] 3.3.2 Receiving BCB Blocks
If the relevant parts of an encrypted payload cannot be decrypted
(i.e., the decryption key cannot be deduced or decryption fails),
then the bundle MUST be discarded and processed no further; in this
case, a bundle deletion status report (see [RFC5050]) indicating the
decryption failure MAY be generated.
*         Does a new deletion reason code need to be defined?





-----Original Message-----
From: dtn-interest [mailto:dtn-interest-bounces@irtf.org] On Behalf Of Birr=
ane, Edward J.
Sent: Wednesday, May 28, 2014 8:40 AM
To: dtn-interest@irtf.org; dtn-security@irtf.org
Subject: [dtn-interest] Updated SBSP Document



Good morning.



I've released a new version of the Streamlined Bundle Security Protocol (SB=
SP) document (see information below).



This change incorporates comments received to date, including:



- Minor spelling/grammar changes and text cleanup.

- Expanded discussion on extension block identification (Section 2.1)

- Clarified that a BIB may not be added to sign an encrypted block. (Sectio=
n 2.7)

- Clarified block processing order in Section 2.7.

- Clarified BIB processing (Section 3.3.3)

- Simplified bundle fragmentation discussion (Section 3.4)

- Clarified interaction of authentication and reactive fragmentation.

- Updated policy considerations.



I am cross-posting to dtn-interest and dtn-security as an announcement, but=
 would ask that technical discussion occur on dtn-security.



-Ed



A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.

This draft is a work item of the Delay-Tolerant Networking Research Group W=
orking Group of the IETF.



        Title           : Streamlined Bundle Security Protocol Specificatio=
n

        Author          : Edward J. Birrane

        Filename        : draft-irtf-dtnrg-sbsp-01.txt

        Pages           : 34

        Date            : 2014-05-27



Abstract:

   This document defines a streamlined bundle security protocol, which

   provides data authentication, integrity, and confidentiality services

   for the Bundle Protocol.  Capabilities are provided to protect the

   bundle payload, and additional data that may be included within the

   bundle, along a single path through a network.





The IETF datatracker status page for this draft is:

https://datatracker.ietf.org/doc/draft-irtf-dtnrg-sbsp/



There's also a htmlized version available at:

http://tools.ietf.org/html/draft-irtf-dtnrg-sbsp-01



A diff from the previous version is available at:

http://www.ietf.org/rfcdiff?url2=3Ddraft-irtf-dtnrg-sbsp-01



---

Ed Birrane

Principal Professional Staff, Space Department Johns Hopkins Applied Physic=
s Laboratory

(W) 443-778-7423 / (F) 443-228-3839







_______________________________________________

dtn-interest mailing list

dtn-interest@irtf.org<mailto:dtn-interest@irtf.org>

https://www.irtf.org/mailman/listinfo/dtn-interest

--_000_94CFB3711B4CAE4DBFC5BEB3374BF0C60D1835NDMSMBX404ndcnasa_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:m=3D"http://sc=
hemas.microsoft.com/office/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-=
html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-link:"Plain Text";
	font-family:"Calibri","sans-serif";}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:85536701;
	mso-list-template-ids:995777094;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1
	{mso-list-id:1100417712;
	mso-list-template-ids:1639073508;}
@list l1:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l1:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2
	{mso-list-id:1228763622;
	mso-list-template-ids:-1767058658;}
@list l2:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level2
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3
	{mso-list-id:1229464556;
	mso-list-template-ids:-1881769512;}
@list l3:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l3:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4
	{mso-list-id:1440953918;
	mso-list-template-ids:893939734;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:right;
	text-indent:-.25in;}
@list l4:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5
	{mso-list-id:1444689577;
	mso-list-template-ids:1822076728;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l5:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6
	{mso-list-id:1758936197;
	mso-list-template-ids:-416770862;}
@list l6:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level2
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7
	{mso-list-id:1795322024;
	mso-list-template-ids:1812220258;}
@list l7:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l7:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level2 lfo6
	{mso-level-start-at:3;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoPlainText">Ed,<o:p></o:p></p>
<p class=3D"MsoPlainText">Good work - the SBSP spec continues to evolve nic=
ely. I&#8217;ll kick off the discussions with my comments below.<o:p></o:p>=
</p>
<p class=3D"MsoPlainText">Cheers,<o:p></o:p></p>
<p class=3D"MsoPlainText">DZ<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><b>[Page 12] 2.4 Bundle Authentication Block</b><o:p=
></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
The security-target MUST be the entire bundle, which MUST be<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
represented by a &lt;block type&gt;&lt;occurrence number&gt; of &lt;0x00&gt=
;&lt;0x00&gt;.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l6 level1 lfo1;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Per 3.4 Bundle=
 Fragmentation and Reassembly, bundle authentication may be applied to bund=
le fragments as well as non-fragmented bundles.</span><span style=3D"font-s=
ize:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:=
#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l5 level1 lfo2;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">If a bundle fr=
agment is received that has a BAB, there is no way to determine if the BAB =
applies to the bundle fragment or if it applies to an entire bundle that wa=
s later fragmented by a non-security-aware
 BA.</span><span style=3D"font-size:12.0pt;font-family:&quot;Times New Roma=
n&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l5 level2 lfo2;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">I propose that=
 a &lt;block type&gt;&lt;occurrence number&gt; of &lt;0x00&gt;&lt;payload f=
rag length&gt; indicate that the BAB applies to a bundle fragment</span><sp=
an style=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;=
serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt;text-indent:-.25in;mso-l=
ist:l5 level3 lfo2;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">If such a bund=
le fragment is further fragmented by a non-security-aware BA then the &lt;p=
ayload frag length&gt; can be used to determine that the original fragmente=
d bundle must be reassembled before authentication
 is checked because it will not match the length field in the payload block=
.</span><span style=3D"font-size:12.0pt;font-family:&quot;Times New Roman&q=
uot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l5 level2 lfo2;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Some discussio=
n may be desirable in section 3.4 as well as 2.4 if accepted</span><span st=
yle=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif=
&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal"><b>[Page 14] 2.6 Block Confidentiality Block</b><o:p=
></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
The block processing control flags value can be set to whatever<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
values are required by local policy, except that a Lone BCB or<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
First BCB MUST have the &quot;replicate in every fragment&quot; flag set.<o=
:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
This indicates to a receiving node that the payload portion in<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
each fragment represents cipher-text.
<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l4 level1 lfo3;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">The intent her=
e is only if the target of the Lone BCB or First BCB is the payload block w=
hich would need to be added if this is kept as a requirement.</span><span s=
tyle=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;seri=
f&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l4 level1 lfo3;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">I think this r=
equirement should be removed or at least reduced to a &quot;MAY&quot;</span=
><span style=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&q=
uot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l4 level2 lfo4;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore">1.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">It assumes tha=
t the Lone or First BCB must be prior to the payload block which is not a s=
pecific requirement and is not necessary in any case for SBSP<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l4 level2 lfo4;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore">2.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">A BCB block co=
uld be quite large and add a lot of bandwidth overhead if included in every=
 fragment<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l4 level2 lfo4;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore">3.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">I do not see a=
 benefit gained by including the block in every fragment
<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt;text-indent:-81.0pt;mso-=
text-indent-alt:-.25in;mso-list:l4 level3 lfo5;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore"><span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span>i.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></spa=
n><![endif]><span style=3D"color:#00B050">Even the destination node likely =
cannot decrypt any individual fragment except the first one and&nbsp; it pr=
obably would only decrypt a partial
 bundle as a last resort or forensic function if the entire bundle was not =
received before expiration<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt;text-indent:-81.0pt;mso-=
text-indent-alt:-.25in;mso-list:l4 level3 lfo5;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore"><span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span>ii.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></sp=
an><![endif]><span style=3D"color:#00B050">Intermediate nodes shouldn't gen=
erally be poking around in bundle payloads anyway and no need to provide ad=
ditional clues as to whether
 a fragment payload is encrypted or a bunch of binary values &#8211; keep t=
he bad guys guessing and wasting CPU cycles if possible<o:p></o:p></span></=
p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt;text-indent:-81.0pt;mso-=
text-indent-alt:-.25in;mso-list:l4 level3 lfo5;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore"><span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span>iii.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></s=
pan><![endif]><span style=3D"color:#00B050">BSP includes this requirement -=
 have any of the implementations found a need or benefit for this and would=
 it still apply in context
 of the SBSP?<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;vertical-align:middle"><s=
pan style=3D"color:#00B050"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in"><span style=3D"color:#00=
B050">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal"><b>[Page 24] 3.1.2.3 Extension Block Canonicalizatio=
n</b><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
Endpoint ID references in blocks are canonicalized using the de-<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
referenced text form in place of the reference pair.&nbsp; The reference<o:=
p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
count is not included, nor is the length of the endpoint ID text.<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
The EID reference is, therefore, canonicalized as &lt;scheme&gt;:&lt;SSP&gt=
;,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
which includes the &quot;:&quot; character.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l1 level1 lfo7;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Need to includ=
e a statement to the effect:</span><span style=3D"font-size:12.0pt;font-fam=
ily:&quot;Times New Roman&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p=
></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l1 level2 lfo7;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Artificial EID=
s as defined in this document (ssp reference is 0x00) must be skipped and a=
re not included in the canonicalization.</span><span style=3D"font-size:12.=
0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:#00B050=
"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt"><span style=3D"color:#0=
0B050">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal"><b>[Page 24] 3.1.2.3 Extension Block Canonicalizatio=
n</b><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
The block-length is canonicalized as its unpacked SDNV value.&nbsp; If the<=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
data to be canonicalized is less than the complete, original block<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
data, this field contains the size of the data being canonicalized<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
(the &quot;effective block&quot;) rather than the actual size of the block.=
<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l0 level1 lfo8;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Section 3.1.2.=
1 (Primary Block Canonicalization) details the length fields as 4 byte valu=
es and effectively reserves the term &quot;unpacked SDNV value&quot; to mea=
n the 8 byte value. I recommend using the same
 convention here.</span><span style=3D"font-size:12.0pt;font-family:&quot;T=
imes New Roman&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p=
>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l0 level2 lfo8;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Personally, I =
would specify all SDNV values canonicalized as 8 byte values and be done wi=
th it</span><span style=3D"font-size:12.0pt;font-family:&quot;Times New Rom=
an&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l3 level1 lfo9;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Add a statemen=
t to the effect:</span><span style=3D"font-size:12.0pt;font-family:&quot;Ti=
mes New Roman&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l3 level2 lfo9;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">The entirety o=
r portion(s) of the block body data are canonicalized as is.</span><span st=
yle=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif=
&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt"><span style=3D"color:#0=
0B050">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#00B050">&nbsp;<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><b>[Page 23] 3.1.2.2 Payload Block Canonicalization<=
/b><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
When canonicalizing the payload block, the block processing control<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
flags value used for canonicalization is the unpacked SDNV value with<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
reserved and mutable bits masked to zero.&nbsp; The unpacked value is<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
ANDed with mask 0x0000 0000 0000 0077 to zero reserved bits and the<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&quot;last block&quot; bit.&nbsp; The &quot;last block&quot; bit is ignored=
 because BABs and<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
other security blocks MAY be added for some parts of the journey but<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
not others, so the setting of this bit might change from hop to hop.<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
Payload blocks are canonicalized as-is, with the exception that, in<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
some instances, only a portion of the payload data is to be<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
protected.&nbsp; In such a case, only those bytes are included in the<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
canonical form, and additional cipher suite parameters are required<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
to specify which part of the payload is protected, as discussed<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
further below.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l7 level1 lfo10;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">The processing=
 control flags are pulled out and masked so the Payload block can no longer=
 be considered canonicalized &quot;as-is&quot;.</span><span style=3D"font-s=
ize:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:=
#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l7 level1 lfo10;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">A Payload Bloc=
k is the same underlying format as an Extension Block with the restriction =
that the 'block contains an EID-reference field' is never set and it should=
 follow the same canonicalization
 methodology as that of the Extension Block</span><span style=3D"font-size:=
12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:#00B=
050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l7 level2 lfo10;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">I propose a si=
ngle &quot;Non-Primary Block Canonicalization&quot; section based on the fi=
nalized version of the Extension Block Canonicalization</span><span style=
=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&qu=
ot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in"><span style=3D"color:#00=
B050">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in"><span style=3D"color:#00=
B050">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><b>[Page 26] 3.3.2 Receiving BCB Blocks</b><o:p></o:=
p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
If the relevant parts of an encrypted payload cannot be decrypted<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
(i.e., the decryption key cannot be deduced or decryption fails),<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
then the bundle MUST be discarded and processed no further; in this<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
case, a bundle deletion status report (see [RFC5050]) indicating the<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
decryption failure MAY be generated.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l2 level1 lfo11;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0=
pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Does a new del=
etion reason code need to be defined?</span><span style=3D"font-size:12.0pt=
;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:#00B050"><=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#00B050">&nbsp;<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"color:#00B050"><o:p>&nbsp;</o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"color:#00B050"><o:p>&nbsp;</o:p></spa=
n></p>
<p class=3D"MsoPlainText">-----Original Message-----<br>
From: dtn-interest [mailto:dtn-interest-bounces@irtf.org] On Behalf Of Birr=
ane, Edward J.<br>
Sent: Wednesday, May 28, 2014 8:40 AM<br>
To: dtn-interest@irtf.org; dtn-security@irtf.org<br>
Subject: [dtn-interest] Updated SBSP Document</p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Good morning.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">I've released a new version of the Streamlined Bu=
ndle Security Protocol (SBSP) document (see information below).<o:p></o:p><=
/p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">This change incorporates comments received to dat=
e, including:<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">- Minor spelling/grammar changes and text cleanup=
.<o:p></o:p></p>
<p class=3D"MsoPlainText">- Expanded discussion on extension block identifi=
cation (Section 2.1)<o:p></o:p></p>
<p class=3D"MsoPlainText">- Clarified that a BIB may not be added to sign a=
n encrypted block. (Section 2.7)<o:p></o:p></p>
<p class=3D"MsoPlainText">- Clarified block processing order in Section 2.7=
.<o:p></o:p></p>
<p class=3D"MsoPlainText">- Clarified BIB processing (Section 3.3.3)<o:p></=
o:p></p>
<p class=3D"MsoPlainText">- Simplified bundle fragmentation discussion (Sec=
tion 3.4)<o:p></o:p></p>
<p class=3D"MsoPlainText">- Clarified interaction of authentication and rea=
ctive fragmentation.<o:p></o:p></p>
<p class=3D"MsoPlainText">- Updated policy considerations.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">I am cross-posting to dtn-interest and dtn-securi=
ty as an announcement, but would ask that technical discussion occur on dtn=
-security.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">-Ed<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">A New Internet-Draft is available from the on-lin=
e Internet-Drafts directories.<o:p></o:p></p>
<p class=3D"MsoPlainText">This draft is a work item of the Delay-Tolerant N=
etworking Research Group Working Group of the IETF.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;Title&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : Streamlined B=
undle Security Protocol Specification<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Author=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : Edward J. Birrane<=
o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Filena=
me&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : draft-irtf-dtnrg-sbsp-01.txt=
<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pages&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 34<o:p></o:p>=
</p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Date&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 2014-05-=
27<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Abstract:<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; This document defines a streamlined =
bundle security protocol, which<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; provides data authentication, integr=
ity, and confidentiality services<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; for the Bundle Protocol.&nbsp; Capab=
ilities are provided to protect the<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; bundle payload, and additional data =
that may be included within the<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; bundle, along a single path through =
a network.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">The IETF datatracker status page for this draft i=
s:<o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"https://datatracker.ietf.org/doc/draft=
-irtf-dtnrg-sbsp/"><span style=3D"color:windowtext;text-decoration:none">ht=
tps://datatracker.ietf.org/doc/draft-irtf-dtnrg-sbsp/</span></a><o:p></o:p>=
</p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">There's also a htmlized version available at:<o:p=
></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"http://tools.ietf.org/html/draft-irtf-=
dtnrg-sbsp-01"><span style=3D"color:windowtext;text-decoration:none">http:/=
/tools.ietf.org/html/draft-irtf-dtnrg-sbsp-01</span></a><o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">A diff from the previous version is available at:=
<o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"http://www.ietf.org/rfcdiff?url2=3Ddra=
ft-irtf-dtnrg-sbsp-01"><span style=3D"color:windowtext;text-decoration:none=
">http://www.ietf.org/rfcdiff?url2=3Ddraft-irtf-dtnrg-sbsp-01</span></a><o:=
p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">---<o:p></o:p></p>
<p class=3D"MsoPlainText">Ed Birrane<o:p></o:p></p>
<p class=3D"MsoPlainText">Principal Professional Staff, Space Department Jo=
hns Hopkins Applied Physics Laboratory<o:p></o:p></p>
<p class=3D"MsoPlainText">(W) 443-778-7423 / (F) 443-228-3839<o:p></o:p></p=
>
<p class=3D"MsoPlainText">&nbsp; <o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">_______________________________________________<o=
:p></o:p></p>
<p class=3D"MsoPlainText">dtn-interest mailing list<o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"mailto:dtn-interest@irtf.org"><span st=
yle=3D"color:windowtext;text-decoration:none">dtn-interest@irtf.org</span><=
/a><o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"https://www.irtf.org/mailman/listinfo/=
dtn-interest"><span style=3D"color:windowtext;text-decoration:none">https:/=
/www.irtf.org/mailman/listinfo/dtn-interest</span></a><o:p></o:p></p>
</div>
</body>
</html>

--_000_94CFB3711B4CAE4DBFC5BEB3374BF0C60D1835NDMSMBX404ndcnasa_--


From nobody Fri May 30 12:17:19 2014
Return-Path: <scott.c.burleigh@jpl.nasa.gov>
X-Original-To: dtn-security@ietfa.amsl.com
Delivered-To: dtn-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C66591A045A for <dtn-security@ietfa.amsl.com>; Fri, 30 May 2014 12:17:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.85
X-Spam-Level: 
X-Spam-Status: No, score=-4.85 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1n9vKtRIivQo for <dtn-security@ietfa.amsl.com>; Fri, 30 May 2014 12:17:11 -0700 (PDT)
Received: from mail.jpl.nasa.gov (smtp.jpl.nasa.gov [128.149.139.109]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E14E1A046A for <dtn-security@irtf.org>; Fri, 30 May 2014 12:17:11 -0700 (PDT)
Received: from mail.jpl.nasa.gov (ap-ehub-sp01.jpl.nasa.gov [128.149.137.148]) by smtp.jpl.nasa.gov (Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.1) with ESMTP id s4UJH5HR009667 (using TLSv1/SSLv3 with cipher AES128-SHA (128 bits) verified NO); Fri, 30 May 2014 12:17:06 -0700
Received: from AP-EMBX-SP40.RES.AD.JPL ([169.254.7.156]) by ap-ehub-sp01.RES.AD.JPL ([169.254.3.182]) with mapi id 14.03.0174.001; Fri, 30 May 2014 12:17:05 -0700
From: "Burleigh, Scott C (312G)" <scott.c.burleigh@jpl.nasa.gov>
To: "Zoller, David A. (MSFC-EO50)[HOSC SERVICES CONTRACT]" <david.a.zoller@nasa.gov>, "Birrane, Edward J." <Edward.Birrane@jhuapl.edu>, "dtn-security@irtf.org" <dtn-security@irtf.org>
Thread-Topic: Updated SBSP Document
Thread-Index: Ac96egHBtIlHfqjpRHK8eG5est6OOQA736HgADK/lpA=
Date: Fri, 30 May 2014 19:17:04 +0000
Message-ID: <A5BEAD028815CB40A32A5669CF737C3B423B369E@ap-embx-sp40.RES.AD.JPL>
References: <329D879C76FDD04AAAE84BB1D89B3970094FBF9EAA@aplesfreedom.dom1.jhuapl.edu> <94CFB3711B4CAE4DBFC5BEB3374BF0C60D1835@NDMSMBX404.ndc.nasa.gov>
In-Reply-To: <94CFB3711B4CAE4DBFC5BEB3374BF0C60D1835@NDMSMBX404.ndc.nasa.gov>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [128.149.137.26]
Content-Type: multipart/alternative; boundary="_000_A5BEAD028815CB40A32A5669CF737C3B423B369Eapembxsp40RESAD_"
MIME-Version: 1.0
X-Source-Sender: scott.c.burleigh@jpl.nasa.gov
X-AUTH: Authorized
Archived-At: http://mailarchive.ietf.org/arch/msg/dtn-security/Bvi5HCVbH-7JpNjKv340T7hto80
Subject: Re: [dtn-security] Updated SBSP Document
X-BeenThere: dtn-security@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The Delay-Tolerant Networking Research Group \(DTNRG\) - Security." <dtn-security.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/dtn-security>, <mailto:dtn-security-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/dtn-security/>
List-Post: <mailto:dtn-security@irtf.org>
List-Help: <mailto:dtn-security-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/dtn-security>, <mailto:dtn-security-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 May 2014 19:17:17 -0000

--_000_A5BEAD028815CB40A32A5669CF737C3B423B369Eapembxsp40RESAD_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

A couple of remarks on David's comments, in-line below.

Scott

From: dtn-security [mailto:dtn-security-bounces@irtf.org] On Behalf Of Zoll=
er, David A. (MSFC-EO50)[HOSC SERVICES CONTRACT]
Sent: Thursday, May 29, 2014 12:09 PM
To: Birrane, Edward J.; dtn-security@irtf.org
Subject: Re: [dtn-security] Updated SBSP Document


Ed,

Good work - the SBSP spec continues to evolve nicely. I'll kick off the dis=
cussions with my comments below.

Cheers,

DZ






[Page 12] 2.4 Bundle Authentication Block
The security-target MUST be the entire bundle, which MUST be
represented by a <block type><occurrence number> of <0x00><0x00>.
=B7         Per 3.4 Bundle Fragmentation and Reassembly, bundle authenticat=
ion may be applied to bundle fragments as well as non-fragmented bundles.
=B7         If a bundle fragment is received that has a BAB, there is no wa=
y to determine if the BAB applies to the bundle fragment or if it applies t=
o an entire bundle that was later fragmented by a non-security-aware BA.
o    I propose that a <block type><occurrence number> of <0x00><payload fra=
g length> indicate that the BAB applies to a bundle fragment
=B7         If such a bundle fragment is further fragmented by a non-securi=
ty-aware BA then the <payload frag length> can be used to determine that th=
e original fragmented bundle must be reassembled before authentication is c=
hecked because it will not match the length field in the payload block.
o    Some discussion may be desirable in section 3.4 as well as 2.4 if acce=
pted

=D8  When a BAB is attached to a bundle that is a fragment, the bundle that=
 it applies to is always that fragment, never the bundle that carried the o=
riginal payload (of which the current bundle's payload is a fragment).  Sin=
ce BABs are not end-to-end, the BAB for an original un-fragmented bundle wi=
ll never be carried forward in any fragments generated from that bundle (se=
e the last paragraph of 3.3.1), so there's no ambiguity.  But this does bri=
ng up an important point: the block processing control flags of the BAB mus=
t always have the "replicate in every fragment" flag set to 0.


[Page 14] 2.6 Block Confidentiality Block
The block processing control flags value can be set to whatever
values are required by local policy, except that a Lone BCB or
First BCB MUST have the "replicate in every fragment" flag set.
This indicates to a receiving node that the payload portion in
each fragment represents cipher-text.
=B7         The intent here is only if the target of the Lone BCB or First =
BCB is the payload block which would need to be added if this is kept as a =
requirement.
=B7         I think this requirement should be removed or at least reduced =
to a "MAY"
1.       It assumes that the Lone or First BCB must be prior to the payload=
 block which is not a specific requirement and is not necessary in any case=
 for SBSP
2.       A BCB block could be quite large and add a lot of bandwidth overhe=
ad if included in every fragment
3.       I do not see a benefit gained by including the block in every frag=
ment
                                       i.            Even the destination n=
ode likely cannot decrypt any individual fragment except the first one and =
 it probably would only decrypt a partial bundle as a last resort or forens=
ic function if the entire bundle was not received before expiration
                                     ii.            Intermediate nodes shou=
ldn't generally be poking around in bundle payloads anyway and no need to p=
rovide additional clues as to whether a fragment payload is encrypted or a =
bunch of binary values - keep the bad guys guessing and wasting CPU cycles =
if possible
                                    iii.            BSP includes this requi=
rement - have any of the implementations found a need or benefit for this a=
nd would it still apply in context of the SBSP?

=D8  I think this a good point.  Since all decryption should only happen at=
 the bundle destination, which is where all the fragments are going to have=
 to end up, why not forward all BCBs (for all blocks that have them) only w=
ith the fragment whose offset is zero?


[Page 24] 3.1.2.3 Extension Block Canonicalization
Endpoint ID references in blocks are canonicalized using the de-
referenced text form in place of the reference pair.  The reference
count is not included, nor is the length of the endpoint ID text.
The EID reference is, therefore, canonicalized as <scheme>:<SSP>,
which includes the ":" character.
=B7         Need to include a statement to the effect:
o    Artificial EIDs as defined in this document (ssp reference is 0x00) mu=
st be skipped and are not included in the canonicalization.

=D8  Right, the AEID's offsets don't reference text in the dictionary.  Goo=
d catch!

[Page 24] 3.1.2.3 Extension Block Canonicalization
The block-length is canonicalized as its unpacked SDNV value.  If the
data to be canonicalized is less than the complete, original block
data, this field contains the size of the data being canonicalized
(the "effective block") rather than the actual size of the block.
=B7         Section 3.1.2.1 (Primary Block Canonicalization) details the le=
ngth fields as 4 byte values and effectively reserves the term "unpacked SD=
NV value" to mean the 8 byte value. I recommend using the same convention h=
ere.
o    Personally, I would specify all SDNV values canonicalized as 8 byte va=
lues and be done with it
=B7         Add a statement to the effect:
o    The entirety or portion(s) of the block body data are canonicalized as=
 is.

=D8  I agree about canonicalizing all SDNVs as 8-byte values.  FWIW, I thin=
k the canonicalization in bundle security protocol is a major pain in the n=
eck.  Is the mutability of blocks - the need to exclude mutable fields from=
 hash computations - the main reason for it?  Is there no way to simplify?


[Page 23] 3.1.2.2 Payload Block Canonicalization
When canonicalizing the payload block, the block processing control
flags value used for canonicalization is the unpacked SDNV value with
reserved and mutable bits masked to zero.  The unpacked value is
ANDed with mask 0x0000 0000 0000 0077 to zero reserved bits and the
"last block" bit.  The "last block" bit is ignored because BABs and
other security blocks MAY be added for some parts of the journey but
not others, so the setting of this bit might change from hop to hop.

Payload blocks are canonicalized as-is, with the exception that, in
some instances, only a portion of the payload data is to be
protected.  In such a case, only those bytes are included in the
canonical form, and additional cipher suite parameters are required
to specify which part of the payload is protected, as discussed
further below.
=B7         The processing control flags are pulled out and masked so the P=
ayload block can no longer be considered canonicalized "as-is".
=B7         A Payload Block is the same underlying format as an Extension B=
lock with the restriction that the 'block contains an EID-reference field' =
is never set and it should follow the same canonicalization methodology as =
that of the Extension Block
o    I propose a single "Non-Primary Block Canonicalization" section based =
on the finalized version of the Extension Block Canonicalization

=D8  Again I complain about canonicalization.

[Page 26] 3.3.2 Receiving BCB Blocks
If the relevant parts of an encrypted payload cannot be decrypted
(i.e., the decryption key cannot be deduced or decryption fails),
then the bundle MUST be discarded and processed no further; in this
case, a bundle deletion status report (see [RFC5050]) indicating the
decryption failure MAY be generated.
=B7         Does a new deletion reason code need to be defined?

=D8  Good idea.





-----Original Message-----
From: dtn-interest [mailto:dtn-interest-bounces@irtf.org] On Behalf Of Birr=
ane, Edward J.
Sent: Wednesday, May 28, 2014 8:40 AM
To: dtn-interest@irtf.org<mailto:dtn-interest@irtf.org>; dtn-security@irtf.=
org<mailto:dtn-security@irtf.org>
Subject: [dtn-interest] Updated SBSP Document



Good morning.



I've released a new version of the Streamlined Bundle Security Protocol (SB=
SP) document (see information below).



This change incorporates comments received to date, including:



- Minor spelling/grammar changes and text cleanup.

- Expanded discussion on extension block identification (Section 2.1)

- Clarified that a BIB may not be added to sign an encrypted block. (Sectio=
n 2.7)

- Clarified block processing order in Section 2.7.

- Clarified BIB processing (Section 3.3.3)

- Simplified bundle fragmentation discussion (Section 3.4)

- Clarified interaction of authentication and reactive fragmentation.

- Updated policy considerations.



I am cross-posting to dtn-interest and dtn-security as an announcement, but=
 would ask that technical discussion occur on dtn-security.



-Ed



A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.

This draft is a work item of the Delay-Tolerant Networking Research Group W=
orking Group of the IETF.



        Title           : Streamlined Bundle Security Protocol Specificatio=
n

        Author          : Edward J. Birrane

        Filename        : draft-irtf-dtnrg-sbsp-01.txt

        Pages           : 34

        Date            : 2014-05-27



Abstract:

   This document defines a streamlined bundle security protocol, which

   provides data authentication, integrity, and confidentiality services

   for the Bundle Protocol.  Capabilities are provided to protect the

   bundle payload, and additional data that may be included within the

   bundle, along a single path through a network.





The IETF datatracker status page for this draft is:

https://datatracker.ietf.org/doc/draft-irtf-dtnrg-sbsp/



There's also a htmlized version available at:

http://tools.ietf.org/html/draft-irtf-dtnrg-sbsp-01



A diff from the previous version is available at:

http://www.ietf.org/rfcdiff?url2=3Ddraft-irtf-dtnrg-sbsp-01



---

Ed Birrane

Principal Professional Staff, Space Department Johns Hopkins Applied Physic=
s Laboratory

(W) 443-778-7423 / (F) 443-228-3839







_______________________________________________

dtn-interest mailing list

dtn-interest@irtf.org<mailto:dtn-interest@irtf.org>

https://www.irtf.org/mailman/listinfo/dtn-interest

--_000_A5BEAD028815CB40A32A5669CF737C3B423B369Eapembxsp40RESAD_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-link:"Plain Text";
	font-family:"Calibri","sans-serif";}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle22
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:85536701;
	mso-list-template-ids:995777094;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1
	{mso-list-id:1027029381;
	mso-list-type:hybrid;
	mso-list-template-ids:991078528 1845675544 67698691 67698693 67698689 6769=
8691 67698693 67698689 67698691 67698693;}
@list l1:level1
	{mso-level-start-at:0;
	mso-level-number-format:bullet;
	mso-level-text:\F0D8;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";
	color:#1F497D;}
@list l1:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l1:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l1:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l1:level5
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l1:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l1:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l1:level8
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l1:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l2
	{mso-list-id:1100417712;
	mso-list-template-ids:1639073508;}
@list l2:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l2:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3
	{mso-list-id:1228763622;
	mso-list-template-ids:-1767058658;}
@list l3:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level2
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4
	{mso-list-id:1229464556;
	mso-list-template-ids:-1881769512;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l4:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5
	{mso-list-id:1440953918;
	mso-list-template-ids:893939734;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level2
	{mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l5:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:right;
	text-indent:-.25in;}
@list l5:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6
	{mso-list-id:1444689577;
	mso-list-template-ids:1822076728;}
@list l6:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l6:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7
	{mso-list-id:1758936197;
	mso-list-template-ids:-416770862;}
@list l7:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level2
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l8
	{mso-list-id:1795322024;
	mso-list-template-ids:1812220258;}
@list l8:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l8:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l8:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l8:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l8:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l8:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l8:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l8:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l8:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"color:#1F497D">A couple of remarks on=
 David&#8217;s comments, in-line below.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D"><o:p>&nbsp;</o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Scott<o:p></o:p></span=
></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D"><o:p>&nbsp;</o:p></spa=
n></p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> dtn-secu=
rity [mailto:dtn-security-bounces@irtf.org]
<b>On Behalf Of </b>Zoller, David A. (MSFC-EO50)[HOSC SERVICES CONTRACT]<br=
>
<b>Sent:</b> Thursday, May 29, 2014 12:09 PM<br>
<b>To:</b> Birrane, Edward J.; dtn-security@irtf.org<br>
<b>Subject:</b> Re: [dtn-security] Updated SBSP Document<o:p></o:p></span><=
/p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Ed,<o:p></o:p></p>
<p class=3D"MsoPlainText">Good work - the SBSP spec continues to evolve nic=
ely. I&#8217;ll kick off the discussions with my comments below.<o:p></o:p>=
</p>
<p class=3D"MsoPlainText">Cheers,<o:p></o:p></p>
<p class=3D"MsoPlainText">DZ<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><b>[Page 12] 2.4 Bundle Authentication Block</b><o:p=
></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
The security-target MUST be the entire bundle, which MUST be<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
represented by a &lt;block type&gt;&lt;occurrence number&gt; of &lt;0x00&gt=
;&lt;0x00&gt;.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l7 level1 lfo2;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Per 3.4 Bundle=
 Fragmentation and Reassembly, bundle authentication may be applied to bund=
le fragments as well as non-fragmented bundles.</span><span style=3D"font-s=
ize:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:=
#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l6 level1 lfo4;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">If a bundle fr=
agment is received that has a BAB, there is no way to determine if the BAB =
applies to the bundle fragment or if it applies to an entire bundle that wa=
s later fragmented by a non-security-aware
 BA.</span><span style=3D"font-size:12.0pt;font-family:&quot;Times New Roma=
n&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l6 level2 lfo4;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">I propose that=
 a &lt;block type&gt;&lt;occurrence number&gt; of &lt;0x00&gt;&lt;payload f=
rag length&gt; indicate that the BAB applies to a bundle fragment</span><sp=
an style=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;=
serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt;text-indent:-.25in;mso-l=
ist:l6 level3 lfo4;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">If such a bund=
le fragment is further fragmented by a non-security-aware BA then the &lt;p=
ayload frag length&gt; can be used to determine that the original fragmente=
d bundle must be reassembled before authentication
 is checked because it will not match the length field in the payload block=
.</span><span style=3D"font-size:12.0pt;font-family:&quot;Times New Roman&q=
uot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l6 level2 lfo4;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Some discussio=
n may be desirable in section 3.4 as well as 2.4 if accepted</span><span st=
yle=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif=
&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l1 level=
1 lfo19"><![if !supportLists]><span style=3D"font-family:Wingdings;color:#1=
F497D"><span style=3D"mso-list:Ignore">=D8<span style=3D"font:7.0pt &quot;T=
imes New Roman&quot;">&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">When a BAB is =
attached to a bundle that is a fragment, the bundle that it applies to is a=
lways that fragment, never the bundle that carried the original payload (of=
 which the current bundle&#8217;s payload
 is a fragment).&nbsp; Since BABs are not end-to-end, the BAB for an origin=
al un-fragmented bundle will never be carried forward in any fragments gene=
rated from that bundle (see the last paragraph of 3.3.1), so there&#8217;s =
no ambiguity.&nbsp; But this does bring up an important
 point: the block processing control flags of the BAB must always have the =
&#8220;replicate in every fragment&#8221; flag set to 0.</span><o:p></o:p><=
/p>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal"><b>[Page 14] 2.6 Block Confidentiality Block</b><o:p=
></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
The block processing control flags value can be set to whatever<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
values are required by local policy, except that a Lone BCB or<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
First BCB MUST have the &quot;replicate in every fragment&quot; flag set.<o=
:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
This indicates to a receiving node that the payload portion in<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
each fragment represents cipher-text.
<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l5 level1 lfo6;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">The intent her=
e is only if the target of the Lone BCB or First BCB is the payload block w=
hich would need to be added if this is kept as a requirement.</span><span s=
tyle=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;seri=
f&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l5 level1 lfo6;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">I think this r=
equirement should be removed or at least reduced to a &quot;MAY&quot;</span=
><span style=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&q=
uot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l5 level2 lfo7;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore">1.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">It assumes tha=
t the Lone or First BCB must be prior to the payload block which is not a s=
pecific requirement and is not necessary in any case for SBSP<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l5 level2 lfo7;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore">2.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">A BCB block co=
uld be quite large and add a lot of bandwidth overhead if included in every=
 fragment<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l5 level2 lfo7;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore">3.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">I do not see a=
 benefit gained by including the block in every fragment
<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt;text-indent:-81.0pt;mso-=
text-indent-alt:-.25in;mso-list:l5 level3 lfo8;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore"><span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span>i.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></spa=
n><![endif]><span style=3D"color:#00B050">Even the destination node likely =
cannot decrypt any individual fragment except the first one and&nbsp; it pr=
obably would only decrypt a partial
 bundle as a last resort or forensic function if the entire bundle was not =
received before expiration<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt;text-indent:-81.0pt;mso-=
text-indent-alt:-.25in;mso-list:l5 level3 lfo8;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore"><span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span>ii.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></sp=
an><![endif]><span style=3D"color:#00B050">Intermediate nodes shouldn't gen=
erally be poking around in bundle payloads anyway and no need to provide ad=
ditional clues as to whether
 a fragment payload is encrypted or a bunch of binary values &#8211; keep t=
he bad guys guessing and wasting CPU cycles if possible<o:p></o:p></span></=
p>
<p class=3D"MsoNormal" style=3D"margin-left:81.0pt;text-indent:-81.0pt;mso-=
text-indent-alt:-.25in;mso-list:l5 level3 lfo8;vertical-align:middle">
<![if !supportLists]><span style=3D"color:#00B050"><span style=3D"mso-list:=
Ignore"><span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span>iii.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></s=
pan><![endif]><span style=3D"color:#00B050">BSP includes this requirement -=
 have any of the implementations found a need or benefit for this and would=
 it still apply in context
 of the SBSP?<o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l1 level=
1 lfo19;vertical-align:middle">
<![if !supportLists]><span style=3D"font-family:Wingdings;color:#1F497D"><s=
pan style=3D"mso-list:Ignore">=D8<span style=3D"font:7.0pt &quot;Times New =
Roman&quot;">&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">I think this a=
 good point.&nbsp; Since all decryption should only happen at the bundle de=
stination, which is where all the fragments are going to have to end up, wh=
y not forward all BCBs (for all blocks
 that have them) only with the fragment whose offset is zero?&nbsp; &nbsp;<=
/span><span style=3D"color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in"><span style=3D"color:#00=
B050">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal"><b>[Page 24] 3.1.2.3 Extension Block Canonicalizatio=
n</b><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
Endpoint ID references in blocks are canonicalized using the de-<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
referenced text form in place of the reference pair.&nbsp; The reference<o:=
p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
count is not included, nor is the length of the endpoint ID text.<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
The EID reference is, therefore, canonicalized as &lt;scheme&gt;:&lt;SSP&gt=
;,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
which includes the &quot;:&quot; character.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l2 level1 lfo10;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Need to includ=
e a statement to the effect:</span><span style=3D"font-size:12.0pt;font-fam=
ily:&quot;Times New Roman&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p=
></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l2 level2 lfo10;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Artificial EID=
s as defined in this document (ssp reference is 0x00) must be skipped and a=
re not included in the canonicalization.</span><span style=3D"font-size:12.=
0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:#00B050=
"><o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l1 level=
1 lfo19"><![if !supportLists]><span style=3D"font-family:Wingdings;color:#1=
F497D"><span style=3D"mso-list:Ignore">=D8<span style=3D"font:7.0pt &quot;T=
imes New Roman&quot;">&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">Right, the AEI=
D&#8217;s offsets don&#8217;t reference text in the dictionary.&nbsp; Good =
catch!</span><span style=3D"color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal"><b>[Page 24] 3.1.2.3 Extension Block Canonicalizatio=
n</b><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
The block-length is canonicalized as its unpacked SDNV value.&nbsp; If the<=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
data to be canonicalized is less than the complete, original block<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
data, this field contains the size of the data being canonicalized<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
(the &quot;effective block&quot;) rather than the actual size of the block.=
<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l0 level1 lfo12;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Section 3.1.2.=
1 (Primary Block Canonicalization) details the length fields as 4 byte valu=
es and effectively reserves the term &quot;unpacked SDNV value&quot; to mea=
n the 8 byte value. I recommend using the same
 convention here.</span><span style=3D"font-size:12.0pt;font-family:&quot;T=
imes New Roman&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p=
>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l0 level2 lfo12;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Personally, I =
would specify all SDNV values canonicalized as 8 byte values and be done wi=
th it</span><span style=3D"font-size:12.0pt;font-family:&quot;Times New Rom=
an&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l4 level1 lfo14;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Add a statemen=
t to the effect:</span><span style=3D"font-size:12.0pt;font-family:&quot;Ti=
mes New Roman&quot;,&quot;serif&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l4 level2 lfo14;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">The entirety o=
r portion(s) of the block body data are canonicalized as is.</span><span st=
yle=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif=
&quot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l1 level=
1 lfo19;vertical-align:middle">
<![if !supportLists]><span style=3D"font-family:Wingdings;color:#1F497D"><s=
pan style=3D"mso-list:Ignore">=D8<span style=3D"font:7.0pt &quot;Times New =
Roman&quot;">&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">I agree about =
canonicalizing all SDNVs as 8-byte values.&nbsp; FWIW, I think the canonica=
lization in bundle security protocol is a major pain in the neck.&nbsp; Is =
the mutability of blocks &#8211; the need to exclude
 mutable fields from hash computations &#8211; the main reason for it?&nbsp=
; Is there no way to simplify?<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt"><span style=3D"color:#0=
0B050">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#00B050">&nbsp;<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><b>[Page 23] 3.1.2.2 Payload Block Canonicalization<=
/b><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
When canonicalizing the payload block, the block processing control<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
flags value used for canonicalization is the unpacked SDNV value with<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
reserved and mutable bits masked to zero.&nbsp; The unpacked value is<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
ANDed with mask 0x0000 0000 0000 0077 to zero reserved bits and the<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&quot;last block&quot; bit.&nbsp; The &quot;last block&quot; bit is ignored=
 because BABs and<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
other security blocks MAY be added for some parts of the journey but<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
not others, so the setting of this bit might change from hop to hop.<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
Payload blocks are canonicalized as-is, with the exception that, in<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
some instances, only a portion of the payload data is to be<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
protected.&nbsp; In such a case, only those bytes are included in the<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
canonical form, and additional cipher suite parameters are required<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
to specify which part of the payload is protected, as discussed<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
further below.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l8 level1 lfo16;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">The processing=
 control flags are pulled out and masked so the Payload block can no longer=
 be considered canonicalized &quot;as-is&quot;.</span><span style=3D"font-s=
ize:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:=
#00B050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l8 level1 lfo16;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">A Payload Bloc=
k is the same underlying format as an Extension Block with the restriction =
that the 'block contains an EID-reference field' is never set and it should=
 follow the same canonicalization
 methodology as that of the Extension Block</span><span style=3D"font-size:=
12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:#00B=
050"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in;text-indent:-.25in;mso-li=
st:l8 level2 lfo16;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#00B050"><span style=3D"mso-list:Ignore">o<span style=
=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">I propose a si=
ngle &quot;Non-Primary Block Canonicalization&quot; section based on the fi=
nalized version of the Extension Block Canonicalization</span><span style=
=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&qu=
ot;;color:#00B050"><o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l1 level=
1 lfo19"><![if !supportLists]><span style=3D"font-family:Wingdings;color:#1=
F497D"><span style=3D"mso-list:Ignore">=D8<span style=3D"font:7.0pt &quot;T=
imes New Roman&quot;">&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">Again I compla=
in about canonicalization.</span><span style=3D"color:#00B050"><o:p></o:p><=
/span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.75in"><span style=3D"color:#00=
B050">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><b>[Page 26] 3.3.2 Receiving BCB Blocks</b><o:p></o:=
p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
If the relevant parts of an encrypted payload cannot be decrypted<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
(i.e., the decryption key cannot be deduced or decryption fails),<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
then the bundle MUST be discarded and processed no further; in this<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
case, a bundle deletion status report (see [RFC5050]) indicating the<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
decryption failure MAY be generated.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:27.0pt;text-indent:-.25in;mso-l=
ist:l3 level1 lfo18;vertical-align:middle">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#00B050"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#00B050">Does a new del=
etion reason code need to be defined?</span><span style=3D"font-size:12.0pt=
;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:#00B050"><=
o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l1 level=
1 lfo19;vertical-align:middle">
<![if !supportLists]><span style=3D"font-family:Wingdings;color:#1F497D"><s=
pan style=3D"mso-list:Ignore">=D8<span style=3D"font:7.0pt &quot;Times New =
Roman&quot;">&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">Good idea.<o:p=
></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#00B050">&nbsp;<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"color:#00B050"><o:p>&nbsp;</o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"color:#00B050"><o:p>&nbsp;</o:p></spa=
n></p>
<p class=3D"MsoPlainText">-----Original Message-----<br>
From: dtn-interest [<a href=3D"mailto:dtn-interest-bounces@irtf.org">mailto=
:dtn-interest-bounces@irtf.org</a>] On Behalf Of Birrane, Edward J.<br>
Sent: Wednesday, May 28, 2014 8:40 AM<br>
To: <a href=3D"mailto:dtn-interest@irtf.org">dtn-interest@irtf.org</a>; <a =
href=3D"mailto:dtn-security@irtf.org">
dtn-security@irtf.org</a><br>
Subject: [dtn-interest] Updated SBSP Document<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Good morning.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">I've released a new version of the Streamlined Bu=
ndle Security Protocol (SBSP) document (see information below).<o:p></o:p><=
/p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">This change incorporates comments received to dat=
e, including:<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">- Minor spelling/grammar changes and text cleanup=
.<o:p></o:p></p>
<p class=3D"MsoPlainText">- Expanded discussion on extension block identifi=
cation (Section 2.1)<o:p></o:p></p>
<p class=3D"MsoPlainText">- Clarified that a BIB may not be added to sign a=
n encrypted block. (Section 2.7)<o:p></o:p></p>
<p class=3D"MsoPlainText">- Clarified block processing order in Section 2.7=
.<o:p></o:p></p>
<p class=3D"MsoPlainText">- Clarified BIB processing (Section 3.3.3)<o:p></=
o:p></p>
<p class=3D"MsoPlainText">- Simplified bundle fragmentation discussion (Sec=
tion 3.4)<o:p></o:p></p>
<p class=3D"MsoPlainText">- Clarified interaction of authentication and rea=
ctive fragmentation.<o:p></o:p></p>
<p class=3D"MsoPlainText">- Updated policy considerations.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">I am cross-posting to dtn-interest and dtn-securi=
ty as an announcement, but would ask that technical discussion occur on dtn=
-security.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">-Ed<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">A New Internet-Draft is available from the on-lin=
e Internet-Drafts directories.<o:p></o:p></p>
<p class=3D"MsoPlainText">This draft is a work item of the Delay-Tolerant N=
etworking Research Group Working Group of the IETF.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;Title&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : Streamlined B=
undle Security Protocol Specification<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Author=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : Edward J. Birrane<=
o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Filena=
me&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : draft-irtf-dtnrg-sbsp-01.txt=
<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pages&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 34<o:p></o:p>=
</p>
<p class=3D"MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Date&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 2014-05-=
27<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Abstract:<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; This document defines a streamlined =
bundle security protocol, which<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; provides data authentication, integr=
ity, and confidentiality services<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; for the Bundle Protocol.&nbsp; Capab=
ilities are provided to protect the<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; bundle payload, and additional data =
that may be included within the<o:p></o:p></p>
<p class=3D"MsoPlainText">&nbsp;&nbsp; bundle, along a single path through =
a network.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">The IETF datatracker status page for this draft i=
s:<o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"https://datatracker.ietf.org/doc/draft=
-irtf-dtnrg-sbsp/"><span style=3D"color:windowtext;text-decoration:none">ht=
tps://datatracker.ietf.org/doc/draft-irtf-dtnrg-sbsp/</span></a><o:p></o:p>=
</p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">There's also a htmlized version available at:<o:p=
></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"http://tools.ietf.org/html/draft-irtf-=
dtnrg-sbsp-01"><span style=3D"color:windowtext;text-decoration:none">http:/=
/tools.ietf.org/html/draft-irtf-dtnrg-sbsp-01</span></a><o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">A diff from the previous version is available at:=
<o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"http://www.ietf.org/rfcdiff?url2=3Ddra=
ft-irtf-dtnrg-sbsp-01"><span style=3D"color:windowtext;text-decoration:none=
">http://www.ietf.org/rfcdiff?url2=3Ddraft-irtf-dtnrg-sbsp-01</span></a><o:=
p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">---<o:p></o:p></p>
<p class=3D"MsoPlainText">Ed Birrane<o:p></o:p></p>
<p class=3D"MsoPlainText">Principal Professional Staff, Space Department Jo=
hns Hopkins Applied Physics Laboratory<o:p></o:p></p>
<p class=3D"MsoPlainText">(W) 443-778-7423 / (F) 443-228-3839<o:p></o:p></p=
>
<p class=3D"MsoPlainText">&nbsp; <o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">_______________________________________________<o=
:p></o:p></p>
<p class=3D"MsoPlainText">dtn-interest mailing list<o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"mailto:dtn-interest@irtf.org"><span st=
yle=3D"color:windowtext;text-decoration:none">dtn-interest@irtf.org</span><=
/a><o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"https://www.irtf.org/mailman/listinfo/=
dtn-interest"><span style=3D"color:windowtext;text-decoration:none">https:/=
/www.irtf.org/mailman/listinfo/dtn-interest</span></a><o:p></o:p></p>
</div>
</body>
</html>

--_000_A5BEAD028815CB40A32A5669CF737C3B423B369Eapembxsp40RESAD_--

