| Re: Re: EAP key binding discussion | <– Date –> <– Thread –> |
|
From: Jari Arkko (jari.arkko |
|
| Date: Tue, 3 May 2005 09:40:51 -0400 (EDT) | |
Rafa Marin Lopez wrote:
Regarding the derivation of "PMKs" per EP, isn't that already specified
in Section 5 of draft-ietf-pana-ipsec-05.txt -- the keys are different per EP
address and session ID.
--Jari
After I read this, I think it seems to be similar to PANA when PAA is not colocated in the EP for example in the wireless LAN model(http://www.ietf.org/internet-drafts/draft-ietf-pana-framework-03.txt).
In fact PaC/EAP peer can derive one PMK per each EP/AP controlled by PAA. PAA can derive the same keys that would send to different EPs controlled by this PAA (how to derive PMKs per each EP/AP derived from AAA-key that PAA receives from AAA is ongoing work). So PAA would be like your LKDC. However PAA is also acting as NAS that is a difference what you propose.
On the other hand , when a EAP peer moves to another EP/AP controlled by another LKDC then we are moving the problem to allow a fast handoff between LKDCs. In the case of PANA , it is being treated in http://www.ietf.org/internet-drafts/draft-bournelle-pana-ctp-02.txt and http://www.ietf.org/internet-drafts/draft-ietf-pana-mobopts-00.txt
Moving the key controller node higher in the hierarchy does help a lot. Both in your example above as well as in various L2 concentrator designs.
Regarding the derivation of "PMKs" per EP, isn't that already specified
in Section 5 of draft-ietf-pana-ipsec-05.txt -- the keys are different per EP
address and session ID.
--Jari
- Re: EAP key binding discussion, (continued)
- Re: EAP key binding discussion Bernard Aboba, April 18 2005
-
RE: Re: EAP key binding discussion Nakhjiri Madjid-MNAKHJI1, April 27 2005
- Re: Re: EAP key binding discussion Jari Arkko, April 28 2005
-
Re: Re: EAP key binding discussion Rafa Marin Lopez, April 28 2005
- Re: Re: EAP key binding discussion Jari Arkko, May 3 2005
- Re: Re: EAP key binding discussion Rafa Marin Lopez, May 4 2005
-
RE: Re: EAP key binding discussion Nakhjiri Madjid-MNAKHJI1, April 28 2005
- Re: Re: EAP key binding discussion Jari Arkko, May 3 2005
Results generated by Tiger Technologies using MHonArc.