ROLL
Internet Engineering Task Force (IETF) P. Thubert, Ed.
Internet-Draft
Request for Comments: 9035 L. Zhao
Updates: 8138 (if approved) Cisco Systems
Intended status:
Category: Standards Track 18 December 2020
Expires: 21 June April 2021
ISSN: 2070-1721
A RPL DODAG Routing Protocol for Low-Power and Lossy Networks (RPL)
Destination-Oriented Directed Acyclic Graph (DODAG) Configuration Option
for the 6LoWPAN Routing Header
draft-ietf-roll-turnon-rfc8138-18
Abstract
This document updates RFC 8138 by defining a bit in the RPL DODAG Routing
Protocol for Low-Power and Lossy Networks (RPL) Destination-Oriented
Directed Acyclic Graph (DODAG) Configuration Option option to indicate
whether compression is used within the RPL Instance, Instance and to specify
the behavior of RFC 8138-capable nodes compliant with RFC 8138 when the bit is set and
unset.
Status of This Memo
This Internet-Draft is submitted in full conformance with the
provisions of BCP 78 and BCP 79.
Internet-Drafts are working documents an Internet Standards Track document.
This document is a product of the Internet Engineering Task Force
(IETF). Note that other groups may also distribute
working documents as Internet-Drafts. The list It represents the consensus of current Internet-
Drafts is at https://datatracker.ietf.org/drafts/current/.
Internet-Drafts are draft documents valid the IETF community. It has
received public review and has been approved for a maximum publication by the
Internet Engineering Steering Group (IESG). Further information on
Internet Standards is available in Section 2 of six months RFC 7841.
Information about the current status of this document, any errata,
and how to provide feedback on it may be updated, replaced, or obsoleted by other documents obtained at any
time. It is inappropriate to use Internet-Drafts as reference
material or to cite them other than as "work in progress."
This Internet-Draft will expire on 21 June 2021.
https://www.rfc-editor.org/info/rfc9035.
Copyright Notice
Copyright (c) 2020 2021 IETF Trust and the persons identified as the
document authors. All rights reserved.
This document is subject to BCP 78 and the IETF Trust's Legal
Provisions Relating to IETF Documents (https://trustee.ietf.org/
license-info)
(https://trustee.ietf.org/license-info) in effect on the date of
publication of this document. Please review these documents
carefully, as they describe your rights and restrictions with respect
to this document. Code Components extracted from this document must
include Simplified BSD License text as described in Section 4.e of
the Trust Legal Provisions and are provided without warranty as
described in the Simplified BSD License.
Table of Contents
1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2
2. Terminology . . . . . . . . . . . . . . . . . . . . . . . . . 3
2.1. References . . . . . . . . . . . . . . . . . . . . . . . 3 Related Documents
2.2. Glossary . . . . . . . . . . . . . . . . . . . . . . . . 3
2.3. Requirements Language . . . . . . . . . . . . . . . . . . 4
3. Extending RFC 6550 . . . . . . . . . . . . . . . . . . . . . 4
4. Updating RFC 8138 . . . . . . . . . . . . . . . . . . . . . . 5
5. Transition Scenarios . . . . . . . . . . . . . . . . . . . . 5
5.1. Coexistence . . . . . . . . . . . . . . . . . . . . . . . 6
5.2. Inconsistent State While Migrating . . . . . . . . . . . 6
5.3. Rolling Back . . . . . . . . . . . . . . . . . . . . . . 6
6. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 7
7. Security Considerations . . . . . . . . . . . . . . . . . . . 7
8. Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . 8
9. References
8.1. Normative References . . . . . . . . . . . . . . . . . . . . 8
10.
8.2. Informative References . . . . . . . . . . . . . . . . . . . 9
Acknowledgments
Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 9
1. Introduction
The design of Low Power Low-Power and Lossy Networks (LLNs) is generally
focused on saving energy, which is the most constrained resource of
all. The routing optimizations in the "Routing "RPL: IPv6 Routing Protocol for Low
Power
Low-Power and Lossy Networks" [RFC6550] (RPL) [RFC6550], such as routing along a
Destination-Oriented Directed Acyclic Graph (DODAG) to a Root Node
and the associated routing header compression and forwarding
technique specified in [RFC8138] [RFC8138], derive from that primary concern.
Enabling [RFC8138] on a running network requires a Flag Day "flag day", where
the network is upgraded and rebooted. Otherwise, if acting as a Leaf,
leaf, a node that does not support the compression per [RFC8138] would
fail to communicate; if acting as a router router, it would drop the
compressed packets and black-
hole black-hole a portion of the network. This
specification enables a hot upgrade where a live network is migrated.
During the migration, the compression remains inactive, inactive until all nodes
are upgraded.
This document complements [RFC8138] and signals whether it should be
used within a RPL DODAG with a new flag in the RPL DODAG
Configuration Option. option. The setting of this new flag is controlled by
the Root and propagates as is in the whole network as part of the
normal RPL signaling.
The flag is cleared to maintain the ensure that compression remains inactive
during the migration phase. When the migration is complete (e.g., as
known by network management and/or inventory), the flag is set and the
compression is globally activated in the whole DODAG.
2. Terminology
2.1. References Related Documents
The terminology used in this document is consistent with with, and
incorporates that described in the terms provided in, "Terms Used in Routing for
Low-Power and Lossy Networks (LLNs)" Networks" [RFC7102]. Other terms in use in as
related to LLNs are found in "Terminology for Constrained-Node
Networks" [RFC7228].
"RPL", the "RPL Packet Information" (RPI), and "RPL Instance" (indexed by
a RPLInstanceID) are defined in "RPL: IPv6 Routing Protocol for
Low-Power and Lossy Networks" [RFC6550]. The RPI is the abstract
information that RPL defines to be placed in data packets, e.g., as
the RPL Option [RFC6553] within the IPv6 Hop-By-Hop Header. By extension
extension, the term "RPI" is often used to refer to the RPL Option
itself. The DODAG Information Solicitation (DIS), Destination
Advertisement Object (DAO) (DAO), and DODAG Information Object (DIO)
messages are also specified in [RFC6550].
This document uses the terms RPL-Unaware Leaf "RPL-Unaware Leaf" (RUL) and RPL-Aware
Leaf "RPL-Aware
Leaf" (RAL) consistently with "Using RPI Option Type, Routing Header
for Source Routes Routes, and IPv6-in-IPv6 encapsulation Encapsulation in the RPL Data
Plane" [USEofRPLinfo]. [RFC9008]. The term RPL-Aware Node "RPL-Aware Node" (RAN) refers to a node
that is either a RAL or a RPL Router. router. A RAN manages the reachability
of its addresses and prefixes by injecting them in RPL by itself. In
contrast, a RUL leverages "Registration Extensions for IPv6 over
Low-Power Wireless Personal Area Network (6LoWPAN) Neighbor
Discovery" [RFC8505] to obtain reachability services from its parent
router(s) as specified in "Routing for RPL (Routing Protocol for
Low-Power and Lossy Networks) Leaves" [UNAWARE-LEAVES]. [RFC9010].
2.2. Glossary
This document often uses the following acronyms: abbreviations:
6LoRH: 6LoWPAN Routing Header
6LoWPAN: IPv6 over Low-Power Wireless Personal Area Network
6LoRH: 6LoWPAN Routing Header
DIO: DODAG Information Object (a RPL message)
DODAG: Destination-Oriented Directed Acyclic Graph
LLN: Low-Power and Lossy Network
MOP: RPL Mode of Operation
RAL: RPL-Aware Leaf
RAN: RPL-Aware Node
RPI: RPL Packet Information
RPL: IPv6 Routing Protocol for Low-Power and Lossy Networks
SubDAG: A DODAG rooted at
RUL: RPL-Unaware Leaf
SRH: Source Routing Header
Sub-DODAG: The sub-DODAG of a node which is a child of DODAG rooted at that node and
that is a subset of a larger DAG
MOP: RPL Mode of Operation
RPI: RPL Packet Information
RAL: RPL-Aware Leaf
RAN: RPL-Aware Node
RUL: RPL-Unaware Leaf
SRH: Source Routing Header main DODAG the node belongs to. It is
formed by the other nodes in the main DODAG whose paths to the
main DODAG root pass through that node.
2.3. Requirements Language
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
"SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and
"OPTIONAL" in this document are to be interpreted as described in
BCP 14 [RFC2119][RFC8174] [RFC2119] [RFC8174] when, and only when, they appear in all
capitals, as shown here.
3. Extending RFC 6550
The DODAG Configuration Option option is defined in Section 6.7.6 of
[RFC6550]. Its purpose is extended to distribute configuration
information affecting the construction and maintenance of the DODAG,
as well as operational parameters for RPL on the DODAG, through the
DODAG. As shown in Figure 1, the Option The DODAG Configuration option was originally designed with
4
four bit positions reserved for future use as Flags. flags.
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Type = 0x04 |Opt Length = 14| | |T| |A| ... |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +
<- Flags flags ->
Figure 1: DODAG Configuration Option (Partial View)
This specification defines a new flag flag, "Enable RFC8138 Compression"
(T). Compression per RFC
8138 (T)". The "T" 'T' flag is set to turn-on turn on the use of [RFC8138]
within the DODAG. The "T" 'T' flag is encoded in position 2 of the
reserved Flags flags in the DODAG Configuration Option option (counting from bit 0
as the most significant bit) and set to 0 in legacy implementations
as specified
respectively in Sections 20.14 and 6.7.6 of [RFC6550]. [RFC6550], respectively.
Section 4.3 4.1.2 of [USEofRPLinfo] [RFC9008] updates [RFC6550] to indicate that the
definition of the Flags flags applies to Mode of Operation (MOP) values
zero (0) to six (6) only. For a MOP value of 7, [RFC8138] MUST be
used on Links links where 6LoWPAN Header Compression [RFC6282] applies and
MUST NOT be used otherwise.
The RPL DODAG Configuration Option option is typically placed in a DODAG
Information Object (DIO) DIO
message. The DIO message propagates down the DODAG to form and then
maintain its structure. The DODAG Configuration Option option is copied
unmodified from parents to children. [RFC6550] states that "Nodes
other than the DODAG Root root MUST NOT modify this information when
propagating the DODAG Configuration
option". option." Therefore, a legacy
parent propagates the "T" 'T' flag as set by the Root, and when the "T" 'T'
flag is set, it is transparently flooded to all the nodes in the
DODAG.
4. Updating RFC 8138
A node SHOULD generate packets in the compressed form using [RFC8138] if
and only if the "T" 'T' flag is set. This behavior can be overridden by
configuration or network management. Overriding may be needed needed, e.g.,
to turn on the compression in a network where all nodes support [RFC8138]
but the Root does not support this specification and cannot set the "T"
'T' flag, or to disable it locally in case of a problem.
The decision to use [RFC8138] is made by the originator of the packet
packet, depending on its capabilities and its knowledge of the state
of the
"T" 'T' flag. A router encapsulating a packet is the originator
of the resulting packet and is responsible for compressing the outer
headers
with per [RFC8138], but it MUST leave NOT perform compression on the
encapsulated packet as is. packet.
An external target [USEofRPLinfo] [RFC9008] is not expected to support [RFC8138].
In most cases, packets to and from an external target are tunneled
back and forth between the border router (referred to as
6LR) a 6LoWPAN
Router (6LR)) that serves the external target and the Root,
regardless of the MOP used in the RPL DODAG. The inner packet is
typically not compressed with per [RFC8138], so for outgoing packets, the
border router just needs to decapsulate the (compressed) outer header
and forward the (uncompressed) inner packet towards the external
target.
A border router MUST uncompress that forwards a packet that is to be forwarded to an external target. Otherwise, target MUST
uncompress the packet first. In all other cases, a router MUST
forward the a packet in the form that the source used, either compressed
or uncompressed.
A RUL [UNAWARE-LEAVES] [RFC9010] is both a leaf and an external target. A RUL does
not participate in RPL and depends on the parent router to obtain
connectivity. In the case of a RUL, forwarding towards an external
target actually means delivering the packet.
5. Transition Scenarios
A node that supports [RFC8138] but not this specification can only be
used in a homogeneous network. Enabling the [RFC8138] compression per [RFC8138]
without a turn-on signaling method requires a "flag day"; flag day, by which time
all nodes must be upgraded, upgraded and at which point the network can be
rebooted with the [RFC8138] 6LoRH compression [RFC8138] turned on.
The intent for of this specification is to perform a migration once and
for all all, without the need for a flag day. In particular it particular, the intent
is not the
intention to undo the setting of the "T" 'T' flag. Though it is possible to
roll back (see Section 5.3), the roll back rollback operation SHOULD be
complete before the network operator adds nodes that do not support
[RFC8138].
5.1. Coexistence
A node that supports this specification can operate in a network with
the [RFC8138]
6LoRH compression [RFC8138] turned on or off with the "T" 'T' flag set
accordingly and in a network in transition from off to on or on to
off (see Section 5.2).
A node that does not support [RFC8138] can interoperate with nodes
that do in a network with [RFC8138] 6LoRH compression [RFC8138] turned off. If the
compression is turned on, all the RPL-Aware Nodes RANs are expected to be able to
handle compressed packets in the compressed form. A node that cannot do so may
remain connected to the network as a RUL as described in [UNAWARE-LEAVES]. [RFC9010].
5.2. Inconsistent State While Migrating
When the "T" 'T' flag is turned on by the Root, the information slowly
percolates through the DODAG as the DIO gets propagated. Some nodes
will see the flag and start sourcing packets in the compressed form form,
while other nodes in the same RPL DODAG are will still not be aware of
it. In non-storing Non-Storing mode, the Root will start using [RFC8138] with a
Source Routing Header 6LoRH (SRH-6LoRH) that routes all the way to
the parent router or to the leaf.
To ensure that a packet is forwarded across the RPL DODAG in the form
in which it was generated, it is required that all the RPL nodes
support [RFC8138] at the time of the switch.
Setting the "T" 'T' flag is ultimately the responsibility of the Network
Administrator. network
administrator. The expectation is that the network management or
upgrading tools in place enable the Network Administrator network administrator to know
when all the nodes that may join a DODAG were migrated. In the case
of a RPL instance Instance with multiple Roots, all nodes that participate to in
the RPL Instance may potentially join any DODAG. The network MUST be
operated with the "T" 'T' flag unset until all nodes in the RPL Instance
are upgraded to support this specification.
5.3. Rolling Back
When turning [RFC8138] 6LoRH compression [RFC8138] off in the network, the Network
Administrator
network administrator MUST wait until all nodes have converged to the "T" each node has its 'T' flag
unset before allowing nodes that do not support the compression in the
network. To that effect, Information regarding whether the compression is active in a
node SHOULD be exposed in the node's management interface.
Nodes that do not support [RFC8138] SHOULD NOT be deployed in a
network where the compression is turned on. If that is done, the node
can only operate as a RUL.
6. IANA Considerations
This specification updates the Registry that was created for
[RFC6550] as the registry for "DODAG Configuration Option Flags" and
updated as the registry Flags for
MOP 0..6" registry [RFC9008] (formerly the "DODAG Configuration
Option Flags Flags" registry, which was created for MOP
0..6" by [USEofRPLinfo], [RFC6550]), by
allocating one new Flag flag as follows:
+---------------+---------------------------------+-----------+
+------------+-------------------------------------+-----------+
| Bit Number | Capability Description | Reference |
+---------------+---------------------------------+-----------+
+------------+-------------------------------------+-----------+
| 2 (suggested) | Turn on RFC8138 Enable Compression per RFC 8138 (T) | THIS RFC 9035 |
+---------------+---------------------------------+-----------+
+------------+-------------------------------------+-----------+
Table 1: New DODAG Configuration Option Flag
IANA is requested to add [this document] has added this document as a reference for MOP 7 in the RPL Mode
"Mode of Operation Operation" registry.
7. Security Considerations
It is worth noting that in RPL [RFC6550], every node in the LLN that
is RPL-aware RPL aware and has access to the RPL domain can inject any RPL-
based attack in the network, more in [RFC7416]. network; see [RFC7416] for details. This
document
applies typically applies to an existing deployment and does not
change its security requirements and operations. It is assumed that
the security mechanisms as defined for RPL are followed.
Setting the "T" 'T' flag before all routers are upgraded may cause a loss
of packets. The new bit is protected benefits from the same protection as the
rest of the
configuration so this information in the DODAG Configuration option that
transports it. Touching the new bit is just one of the many attacks
that can happen if an attacker manages to inject a corrupted configuration.
configuration option in the network.
Setting and unsetting the "T" 'T' flag may create inconsistencies in the
network
network, but as long as all nodes are upgraded to [RFC8138] provide support for
[RFC8138], they will be able to forward both forms. The source is
responsible for selecting whether the packet is compressed or not,
and all routers must use the format that the source selected. So So,
the result of an inconsistency is merely that both forms will be
present in the network, at an additional cost of bandwidth for
packets in the uncompressed form.
An attacker may unset the "T" 'T' flag to force additional energy
consumption of child or descendant nodes in its subDAG. Conversely sub-DODAG.
Conversely, it may set the "T" flag, 'T' flag so that nodes located downstream
would compress packets even when that it compression is not desired,
potentially resulting in the
loss of packets. causing packet loss. In a tree structure, the attacker
would be in a position to drop the packets from and to the attacked
nodes. So So, the attacks mentioned above would be more complex and
more visible than simply dropping selected packets. The downstream
node may have other parents and see the bit with both settings, which could raise attention.
8. Acknowledgments
The authors wish to thank Murray Kucherawy, Meral Shirazipour, Barry
Leiba, Tirumaleswar Reddy, Nagendra Kumar Nainar, Stewart Bryant,
Carles Gomez, Eric Vyncke, Roman Danyliw, and especially Benjamin
Kaduk, Alvaro Retana, Dominique Barthel and Rahul Jadhav for their
in-depth reviews and constructive suggestions.
Also many thanks to Michael Richardson for being always helpful settings; such
a situation may be detected, and
responsive when need comes.
9. an alert may be triggered.
8. References
8.1. Normative References
[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
Requirement Levels", BCP 14, RFC 2119,
DOI 10.17487/RFC2119, March 1997,
<https://www.rfc-editor.org/info/rfc2119>.
[RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC
2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174,
May 2017, <https://www.rfc-editor.org/info/rfc8174>.
[RFC6550] Winter, T., Ed., Thubert, P., Ed., Brandt, A., Hui, J.,
Kelsey, R., Levis, P., Pister, K., Struik, R., Vasseur,
JP., and R. Alexander, "RPL: IPv6 Routing Protocol for
Low-Power and Lossy Networks", RFC 6550,
DOI 10.17487/RFC6550, March 2012,
<https://www.rfc-editor.org/info/rfc6550>.
[RFC7102] Vasseur, JP., "Terms Used in Routing for Low-Power and
Lossy Networks", RFC 7102, DOI 10.17487/RFC7102, January
2014, <https://www.rfc-editor.org/info/rfc7102>.
[RFC8138] Thubert, P., Ed., Bormann, C., Toutain, L., and R. Cragie,
"IPv6 over Low-Power Wireless Personal Area Network
(6LoWPAN) Routing Header", RFC 8138, DOI 10.17487/RFC8138,
April 2017, <https://www.rfc-editor.org/info/rfc8138>.
[RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC
2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174,
May 2017, <https://www.rfc-editor.org/info/rfc8174>.
[RFC8505] Thubert, P., Ed., Nordmark, E., Chakrabarti, S., and C.
Perkins, "Registration Extensions for IPv6 over Low-Power
Wireless Personal Area Network (6LoWPAN) Neighbor
Discovery", RFC 8505, DOI 10.17487/RFC8505, November 2018,
<https://www.rfc-editor.org/info/rfc8505>.
[UNAWARE-LEAVES]
[RFC9010] Thubert, P. P., Ed. and M. Richardson, "Routing for RPL
(Routing Protocol for Low-Power and Lossy Networks)
Leaves",
Work in Progress, Internet-Draft, draft-ietf-roll-unaware-
leaves-27, 17 December 2020, <https://tools.ietf.org/html/
draft-ietf-roll-unaware-leaves-27>.
10. RFC 9010, DOI 10.17487/RFC9010, April 2021,
<https://www.rfc-editor.org/info/rfc9010>.
8.2. Informative References
[RFC6282] Hui, J., Ed. and P. Thubert, "Compression Format for IPv6
Datagrams over IEEE 802.15.4-Based Networks", RFC 6282,
DOI 10.17487/RFC6282, September 2011,
<https://www.rfc-editor.org/info/rfc6282>.
[RFC6553] Hui, J. and JP. Vasseur, "The Routing Protocol for Low-
Power and Lossy Networks (RPL) Option for Carrying RPL
Information in Data-Plane Datagrams", RFC 6553,
DOI 10.17487/RFC6553, March 2012,
<https://www.rfc-editor.org/info/rfc6553>.
[RFC7228] Bormann, C., Ersue, M., and A. Keranen, "Terminology for
Constrained-Node Networks", RFC 7228,
DOI 10.17487/RFC7228, May 2014,
<https://www.rfc-editor.org/info/rfc7228>.
[RFC7416] Tsao, T., Alexander, R., Dohler, M., Daza, V., Lozano, A.,
and M. Richardson, Ed., "A Security Threat Analysis for
the Routing Protocol for Low-Power and Lossy Networks
(RPLs)", RFC 7416, DOI 10.17487/RFC7416, January 2015,
<https://www.rfc-editor.org/info/rfc7416>.
[USEofRPLinfo]
[RFC9008] Robles, I., M.I., Richardson, M., and P. Thubert, "Using RPI
Option Type, Routing Header for Source Routes Routes, and IPv6-in-
IPv6 encapsulation IPv6-
in-IPv6 Encapsulation in the RPL Data Plane", Work in
Progress, Internet-Draft, draft-ietf-roll-useofrplinfo-42,
12 November 2020, <https://tools.ietf.org/html/draft-ietf-
roll-useofrplinfo-42>. RFC 9008,
DOI 10.17487/RFC9008, April 2021,
<https://www.rfc-editor.org/info/rfc9008>.
Acknowledgments
The authors wish to thank Murray Kucherawy, Meral Shirazipour, Barry
Leiba, Tirumaleswar Reddy, Nagendra Kumar Nainar, Stewart Bryant,
Carles Gomez, Éric Vyncke, Roman Danyliw, and especially Benjamin
Kaduk, Alvaro Retana, Dominique Barthel, and Rahul Jadhav for their
in-depth reviews and constructive suggestions.
Also, many thanks to Michael Richardson for always being helpful and
responsive when the need arises.
Authors' Addresses
Pascal Thubert (editor)
Cisco Systems, Inc Inc.
Building D
45 Allee des Ormes - BP1200
06254 MOUGINS - Sophia Antipolis
France
Phone: +33 497 23 26 34
Email: pthubert@cisco.com
Li Zhao
Cisco Systems, Inc Inc.
Xinsi Building
No. 926 Yi Shan Rd
SHANGHAI
Shanghai
200233
China
Email: liz3@cisco.com