Download presentation
Presentation is loading. Please wait.
1
Pre-Shared Key EAP methods & EAP-PSK
IETF 60 – San Diego, USA March 2004
2
Are there Pre-Shared Key EAP methods out there?
Standard: MD5-Challenge [RFC3748] - deprecated for security reasons Individual submissions (work in progress): EAP-FAST EAP-SIM/AKA - designed for GSM/UMTS authentication infrastructure EAP-PSK EAP-PAX EAP-TLS - when Pre-Shared Key support is added [I-D.ietf-tls-psk-00] EAP-IKEv2 Individual submissions (work abandoned): EAP-Archie EAP-SKE
3
Developing high-quality standard EAP methods
Nobody is currently chartered to develop EAP methods at IETF, not even EAP WG EAP without EAP method is like a pizza without toppings: useless! There are however (very) good reasons to develop Pre-Shared Key EAP methods They are the simplest ones: start with the easy tasks before moving on to more complicated ones! They would provide insights on EAP: rather than adding features to EAP, we perhaps want to make sure that EAP works well! They are needed in many usage scenarios What do we want to do?
4
Tentative requirements for a Pre-Shared Key EAP method
Pre-Shared Key not Password - IPR issues with ZKPPs Lightweight - use only symmetric cryptography Standalone - why develop methods that accommodate various types of credentials: isn't it redundant with EAP? Available quickly - people don't want to wait more IPR free Secure...
5
EAP-PSK status EAP-PSK is a proposed solution to the community
Current status: draft-bersani-eap-psk-03 published Open source implementation available at:
6
EAP-PSK next steps Slight rework to include explicit session identifiers draft-bersani-eap-psk-04 should be published by September 2004 And then, after security review by experts: Go informational Or will there be a standardization effort? Release Open source implementations On two different platforms Develop extensions for EAP-PSK
7
Any feedback welcome! Florent Bersani, France Telecom R&D
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.