| RE: EAP-SIM fast re-auth identity | <– Date –> <– Thread –> |
|
From: henry.haverinen (henry.haverinen |
|
| Date: Mon, 11 Apr 2005 04:57:10 -0400 (EDT) | |
|
Hi
Madjid,
Please
see in line.
Yes, if we had designed the protocol differently :-)
This all relates to the management of temporary identities. If you want to use a separate identity upon each EAP exchange, and if you perform a full authentication after a fast re-authentication, then the last temporary identity that you distributed during fast re-authentication would have to be available to the module that performs full authentication.
You don't need triplets for fast re-authentication. The fast-reauthentication id, the counter, and the MK are enough.
Yes. In this procol, we did it with a separate identity.
As said, this relates to the use of temporary identities, which are used instead of the permanent identity for privacy reasons. If there were scenarios where fast re-authentication would be distributed closer to the access network (which I am not aware of, BTW ), and if you want to use temporary identities, then it is better to have a separate identity "space" for the local server to administer -- just as we have currently in EAP-SIM.
EAP-SIM does not allow the use of the permanent identity upon fast re-authentication. This is not a problem, since the server needs to keep state anyway, so the identity can be managed as part of the other state.
Regards, Henry
|
- RE: EAP-SIM fast re-auth identity, (continued)
- RE: EAP-SIM fast re-auth identity henry.haverinen, April 6 2005
- RE: EAP-SIM fast re-auth identity Nakhjiri Madjid-MNAKHJI1, April 6 2005
- RE: EAP-SIM fast re-auth identity Nakhjiri Madjid-MNAKHJI1, April 6 2005
- RE: EAP-SIM fast re-auth identity henry.haverinen, April 11 2005
- RE: EAP-SIM fast re-auth identity henry.haverinen, April 11 2005
- RE: EAP-SIM fast re-auth identity Nakhjiri Madjid-MNAKHJI1, April 12 2005
- RE: EAP-SIM fast re-auth identity henry.haverinen, April 14 2005
Results generated by Tiger Technologies using MHonArc.