channel binding
From: Charles Clancy (clancycs.umd.edu)
Date: Mon, 29 Aug 2005 13:03:12 -0400 (EDT)
Channel binding transmits channel parameters between the EAP client and EAP server in some protected way. When done by methods, it seems the general approach is to encrypt it (PSK, TTLS, etc), guaranteeing authenticity. Is there any reason why it a MAC over the blob would be insufficient? Is confidentiality required for some reason?

I'm working on defining a protected channel in EAP-PAX for communicating channel binding info, and I'd like to avoid defining a symmetric-key encryption ciphersuite, as PAX is based on MACs.

[ t. charles clancy ]--[ tcc [at] umd.edu ]--[ www.cs.umd.edu/~clancy ]
[ computer science ]-----[ university of maryland | college park ]


Results generated by Tiger Technologies using MHonArc.