z-logo
open-access-imgOpen Access
Distribution of EAP-Based Keys for Handover and Re-Authentication
Author(s) -
Madjid Nakhjiri
Publication year - 2010
Publication title -
rfc
Language(s) - English
Resource type - Reports
DOI - 10.17487/rfc5749
Subject(s) - computer science , authentication (law) , authentication server , authentication protocol , computer network , root (linguistics) , key (lock) , protocol (science) , key management , computer security , encryption , medicine , philosophy , linguistics , alternative medicine , pathology
This document describes an abstract mechanism for delivering root keysfrom an Extensible Authentication Protocol (EAP) server to anothernetwork server that requires the keys for offering security protectedservices, such as re-authentication, to an EAP peer. The distributedroot key can be either a usage-specific root key (USRK), a domain-specific root key (DSRK) or a domain-specific usage-specific root key(DSUSRK) that has been derived from an Extended Master Session Key(EMSK) hierarchy previously established between the EAP server and anEAP peer. The document defines a template for a key distributionexchange (KDE) protocol that can distribute these different types ofroot keys using an AAA (Authentication, Authorization and Accounting)protocol and discusses its security requirements. The describedprotocol template does not specify message formats, data encoding, orother implementation details. It thus needs to be instantiated with aspecific protocol (e.g. RADIUS or Diameter) before it can be used.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Accelerating Research

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom