Hannes Tschofenig <[email protected]> wrote:
    > Regarding the randomness requirement and the energy consumption. We
    > have been a bit advocate for adding hardware-based random numbers to
    > devices since randomness is a basic requirement for most security
    > protocols.

I think that this is the future, and I very much agree with you.

There seems to be a stock of older designs which have gone through other
kinds of validation (for instance, think about the engineering review of
physical cases and PCB design for electric metering).

My impression is that there is a desire to significantly update the security
profile of these devices (some of which are in the field already).  What was
deployed had poor security, or had proprietary protocols and there is a
desire to move it up to "par".

The other thing I hear is that the crypto libraries involved take some time
to get FIPS-140 certified and so the one that the devices were deployed with
do RSA only, and there is a desire to update them to ECDSA (or EdDSA), and
means new keys.

I think that any device with any kind of TPM would rather generate it's own
keys.  Whether it's a physical TPM, or some kind of TrustZone,etc. version.

    > In a nutshell, I think you are better of recommending OEMs to select
    > the right hardware for the given task.

I'd like to find some text that acknowledges the past, while setting things
up better for the future.

    > PS: For the proxy work (in context of DTLS/TLS) you might want to reach
    > out to your co-worker Owen Friel.

he's in other loops already, but he seems shy to post to lists.

    > IMPORTANT NOTICE: The contents of this email and any attachments are

I wish your email system would omit this, as it's both meaningless and
sometimes harmful.

-- 
Michael Richardson <[email protected]>, Sandelman Software Works
 -= IPv6 IoT consulting =-



Attachment: signature.asc
Description: PGP signature

_______________________________________________
Ace mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ace

Reply via email to