Re: Issue 170: Terminology
From: Jari Arkko (jari.arkkopiuha.net)
Date: Thu, 11 Sep 2003 21:42:15 -0500 (CDT)
Agreed. I also agree about issues 171, 172,and 173.

Bernard Aboba wrote:

For the purposes of RFC 2284bis, it is not necessary to delve into the
uses of the MSK/EMSK -- it's just enough to say that they must be produced
and exported. Let's leave discussion of uses to the Key Framework
document.

In Section 1.2, change:

" Master Session Key (MSK)
Keying material that is derived between the EAP peer and
server and exported by the EAP method. The MSK is used in
the derivation of Transient Session Keys (TSKs) for the
ciphersuite negotiated between the EAP peer and
authenticator. Where a backend authentication server is
present, acting as an EAP server, it will typically
transport the MSK to the authenticator, so that in this
case, the MSK is available to the peer, authenticator and
authentication server.

Extended Master Session Key (EMSK)
Additional keying material derived between the EAP client
and server that is exported by the EAP method. Unlike the
MSK, the EMSK is known only to the EAP peer and EAP server
and is not provided to a third party. The EMSK is reserved
for future uses that are not defined yet. For example, it
could be used to derive additional keying material for
purposes such as fast handoff, cryptographic binding, etc."

To:

" Master Session Key (MSK)
Keying material that is derived between the EAP peer and
server and exported by the EAP method. The MSK is at
least 64 octets in length. In existing implementations
a AAA server acting as an EAP server transports the MSK
to the authenticator.

Extended Master Session Key (EMSK)
Additional keying material derived between the EAP client
and server that is exported by the EAP method. The EMSK
is at least 64 octets in length. The EMSK is reserved
for future uses that are not defined yet and is not
provided to a third party."

_______________________________________________
eap mailing list
eap [at] frascone.com
http://mail.frascone.com/mailman/listinfo/eap





  • Issue 170: Terminology Bernard Aboba, September 11 2003
    • Re: Issue 170: Terminology Jari Arkko, September 11 2003

Results generated by Tiger Technologies using MHonArc.