Date: Tue, 23 Jan 96 14:15:04 From: "Housley, Russ" To: mjs@nsd.3com.com, p8021@nic.hep.net, vlan-wg@cisco.com Cc: sils@orion.ncsc.mil Subject: Use of SDE to within VLAN standard Since the VLAN interim meeting was rescheduled, it conflicts with the IEEE 802.10 interim meeting. Since no one from IEEE 802.10 can attend the VLAN meeting, we are sending this note to represent our views. Russ ___________________________________________________________________________ FROM: Russell Housley Vice Chair, IEEE 802.10 Working Group TO: Mick Seaman Chair, IEEE 802.1 Interworking Task Group DATE: January 23, 1996 SUBJECT: Use of SDE to within VLAN standard Dear Mick: I am writing to the Interworking Task Group of the IEEE 802.1 Working Group on behalf of the IEEE 802.10 Working Group. We strongly encourage you to use SDE as part of the Virtual LAN (VLAN) effort. We believe that SDE already includes all of the multiplexing functions that you require. Further, it is our belief that users will require separation between their VLANs, and SDE was specifically designed to provide cryptographic separation (confidentiality). The IEEE 802.11 Working Group has made the use of SDE mandatory. In the Wireless LAN standard, SDE provides separation between wireless LAN within the same spectrum. We think that this same technique should be used to separate virtual LANs that share a common backbone. We realize that the selection of a mandtory encryption algorithm is a complex issue. An exportable algorithm must be selected. For this porpose, IEEE 802.11 has selected RC4 with a 40 bit key. Other options exist, including Exclusive-OR (XOR) with a key mask. Sincerely, Russell Housley Date: 26 Jan 96 04:46:55 EST From: Vic Hayes <100071.3061@compuserve.com> To: "Housley, Russ" Cc: "IEEE 802.11 reflector" , "IEEE 802.0 reflector" <802exec@nic.hep.net>, "IEEE 802.1 reflector" Subject: Use of SDE in 802.11 In an e-mail to the VLAN group, Russ Housley wrote: >>The IEEE 802.11 Working Group has made the use of SDE mandatory. In the >>Wireless LAN standard, SDE provides separation between wireless LAN within >>the same spectrum. We think that this same technique should be used to >>separate virtual LANs that share a common backbone. > IEEE 802.11 has NOT done so. SDE is a possible we did not touch for MAC service level privacy. Within the WLAN we have addopted our own scheme. Details we will give on a tutorial, planned for the March meeting. Vic Hayes, Chair IEEE 802.11