Mutual Network Endpoint Assessment Jiwei Wei [email protected] Han Yin [email protected] Ke Jia...

12
Mutual Network Endpoint Assessment Jiwei Wei [email protected] Han Yin [email protected] Ke Jia [email protected] IETF 70

Transcript of Mutual Network Endpoint Assessment Jiwei Wei [email protected] Han Yin [email protected] Ke Jia...

Page 1: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Mutual Network Endpoint Assessment

Jiwei Wei [email protected] Yin [email protected] Jia [email protected]

IETF 70

Page 2: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Goals and Non-Goals

• Goal for Today:– Discuss MNEA Concept– Gather Feedback

• Not a Goal:– Change NEA Charter– Change NEA Model or Requirements

Page 3: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Current NEA

1, Focused on the scenarios where the owner of the endpoint is the same as the owner of the network.

2, A very common model for enterprises which provide equipment to employees to perform their duties.3, For some applications like online business and file

sharing, the current assessment is not enough to ensure the two communication parties are both secure.

4, Especially in P2P application, the endpoints perform equal responsibility and hence the mutual network endpoint assessment seems more necessary.

Page 4: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Current NEA Flows

NEA Client NEA Server | | | client requests network access | | --------------> | | | | Request | | <-------------- | | | | Posture | | --------------> | | | | Result | | <-------------- | | |

Page 5: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Mutual NEA

• Every network endpoint can perform the assessment of the peer as well as can assist the peer in assessing itself.

• Every endpoint can decide whether or not to continue the subsequent interaction according to the peer's compliance with its security policy.

Page 6: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Mutual NEA Reference Model

• PA, PB and PT layer is the same as the current NEA model

• Posture Peer (PP) has the function of both PC and PV

• Posture Broker Peer (PBP) has the function of both PBC and PBS

• Posture Transport Peer (PTP) has the function of both PTS and PTC

Page 7: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Mutual NEA Reference Model

Posture Peer

Posture Peer

PostureTransportPeer

Posture Attribute (PA) protocol

Posture Broker (PB) protocol

NEA Peer NEA Peer

Posture Transport (PT) protocolsPostureTransportPeer

PostureBrokerPeer

PostureBrokerPeer

Page 8: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

MNEA Flows

Endpoint A EndpointB | | | 1,ReqB | | <------------ | | | | 2,PosA ReqA | | ------------> | | | | 3,ResB PosB | | <------------ | | | | 4,ResA | | ------------> | | |

Page 9: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

MNEA Flows

• Step2: As requested by Endpoint BEndpoint A returns its posture information (PosA) with the permission of the Endpoint A’s privacy policy. At the same time, Endpoint A responds a Posture Request (ReqA) to indicate what posture information the Endpoint B should provide.

Page 10: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

MNEA Flows

• Step 3:Endpoint B assesses its received PosA according to the security policy and returns its assessment result (ResB). At the same time, Endpoint B returns the related posture information (PosB) requested by Endpoint A with the permission of the Endpoint B’s privacy policy.

Page 11: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Questions

• Do you find this useful?

• Should NEA support this use case?

• Any other feedback?

Page 12: Mutual Network Endpoint Assessment Jiwei Wei jiwei.wei@huawei.com Han Yin ayinhan@huawei.com Ke Jia jiake.cn@huawei.com IETF 70jiwei.wei@huawei.com.

Thanks