datatracker.ietf.org
Sign in
Version 5.13.0, 2015-03-25
Report a bug

On the Applicability of Various Multimedia Internet KEYing (MIKEY) Modes and Extensions
RFC 5197

Network Working Group                                           S. Fries
Request for Comments: 5197                                       Siemens
Category: Informational                                      D. Ignjatic
                                                                 Polycom
                                                               June 2008

   On the Applicability of Various Multimedia Internet KEYing (MIKEY)
                          Modes and Extensions

Status of This Memo

   This memo provides information for the Internet community.  It does
   not specify an Internet standard of any kind.  Distribution of this
   memo is unlimited.

Abstract

   Multimedia Internet Keying (MIKEY) is a key management protocol that
   can be used for real-time applications.  In particular, it has been
   defined focusing on the support of the Secure Real-time Transport
   Protocol (SRTP).  MIKEY itself is standardized within RFC 3830 and
   defines four key distribution methods.  Moreover, it is defined to
   allow extensions of the protocol.  As MIKEY becomes more and more
   accepted, extensions to the base protocol arise, especially in terms
   of additional key distribution methods but also in terms of payload
   enhancements.

   This document provides an overview about the MIKEY base document in
   general as well as the existing extensions for MIKEY, which have been
   defined or are in the process of definition.  It is intended as an
   additional source of information for developers or architects to
   provide more insight in use case scenarios and motivations as well as
   advantages and disadvantages for the different key distribution
   schemes.  The use cases discussed in this document are strongly
   related to dedicated SIP call scenarios providing challenges for key
   management in general, among them media before Session Description
   Protocol (SDP) answer, forking, and shared key conferencing.

Fries & Ignjatic             Informational                      [Page 1]
RFC 5197               MIKEY Modes Applicability               June 2008

Table of Contents

   1.  Introduction . . . . . . . . . . . . . . . . . . . . . . . . .  3
   2.  Terminology and Definitions  . . . . . . . . . . . . . . . . .  4
   3.  MIKEY Overview . . . . . . . . . . . . . . . . . . . . . . . .  7
     3.1.  Pre-Shared Key (PSK) Protected Distribution  . . . . . . .  9
     3.2.  Public Key Encrypted Key Distribution  . . . . . . . . . .  9
     3.3.  Diffie-Hellman Key Agreement Protected with Digital
           Signatures . . . . . . . . . . . . . . . . . . . . . . . . 10
     3.4.  Unprotected Key Distribution . . . . . . . . . . . . . . . 11
     3.5.  Diffie-Hellman Key Agreement Protected with Pre-Shared
           Secrets  . . . . . . . . . . . . . . . . . . . . . . . . . 12
     3.6.  SAML-Assisted DH key Agreement . . . . . . . . . . . . . . 12
     3.7.  Asymmetric Key Distribution with In-Band Certificate
           Exchange . . . . . . . . . . . . . . . . . . . . . . . . . 15
   4.  Further MIKEY Extensions . . . . . . . . . . . . . . . . . . . 16
     4.1.  ECC Algorithms Support . . . . . . . . . . . . . . . . . . 16
       4.1.1.  Elliptic Curve Integrated Encryption Scheme
               application in MIKEY . . . . . . . . . . . . . . . . . 17
       4.1.2.  Elliptic Curve Menezes-Qu-Vanstone Scheme
               Application in MIKEY . . . . . . . . . . . . . . . . . 17
     4.2.  New MIKEY Payload for Bootstrapping TESLA  . . . . . . . . 17
     4.3.  MBMS Extensions to the Key ID Information Type . . . . . . 18
     4.4.  OMA BCAST MIKEY General Extension Payload Specification  . 18
     4.5.  Supporting Integrity Transform Carrying the Rollover
           Counter  . . . . . . . . . . . . . . . . . . . . . . . . . 19
   5.  Selection and Interworking of MIKEY Modes  . . . . . . . . . . 19
     5.1.  MIKEY and Early Media  . . . . . . . . . . . . . . . . . . 21
     5.2.  MIKEY and Forking  . . . . . . . . . . . . . . . . . . . . 22
     5.3.  MIKEY and Call Transfer/Redirect/Retarget  . . . . . . . . 23
     5.4.  MIKEY and Shared Key Conferencing  . . . . . . . . . . . . 23
     5.5.  MIKEY Mode Summary . . . . . . . . . . . . . . . . . . . . 24
   6.  Transport of MIKEY Messages  . . . . . . . . . . . . . . . . . 24
   7.  MIKEY Alternatives for SRTP Security Parameter Negotiation . . 25
   8.  Summary of MIKEY-Related IANA Registrations  . . . . . . . . . 26
   9.  Security Considerations  . . . . . . . . . . . . . . . . . . . 26
   10. Acknowledgments  . . . . . . . . . . . . . . . . . . . . . . . 27
   11. References . . . . . . . . . . . . . . . . . . . . . . . . . . 27
     11.1. Normative References . . . . . . . . . . . . . . . . . . . 27
     11.2. Informative References . . . . . . . . . . . . . . . . . . 27

Fries & Ignjatic             Informational                      [Page 2]

[include full document text]