Distribution of EAP-Based Keys for Handover and Re-Authentication
Author(s) -
Madjid Nakhjiri
Publication year - 2010
Publication title -
rfc
Language(s) - English
Resource type - Reports
DOI - 10.17487/rfc5749
Subject(s) - computer science , authentication (law) , authentication server , authentication protocol , computer network , root (linguistics) , key (lock) , protocol (science) , key management , computer security , encryption , medicine , philosophy , linguistics , alternative medicine , pathology
This document describes an abstract mechanism for delivering root keysfrom an Extensible Authentication Protocol (EAP) server to anothernetwork server that requires the keys for offering security protectedservices, such as re-authentication, to an EAP peer. The distributedroot key can be either a usage-specific root key (USRK), a domain-specific root key (DSRK) or a domain-specific usage-specific root key(DSUSRK) that has been derived from an Extended Master Session Key(EMSK) hierarchy previously established between the EAP server and anEAP peer. The document defines a template for a key distributionexchange (KDE) protocol that can distribute these different types ofroot keys using an AAA (Authentication, Authorization and Accounting)protocol and discusses its security requirements. The describedprotocol template does not specify message formats, data encoding, orother implementation details. It thus needs to be instantiated with aspecific protocol (e.g. RADIUS or Diameter) before it can be used.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom