| Re: Eap keying review: use of MSK/ EMSK for AMSK creation | <– Date –> <– Thread –> |
|
From: Jari Arkko (jari.arkko |
|
| Date: Sun, 6 Nov 2005 19:55:12 -0500 (EST) | |
Nakhjiri Madjid-MNAKHJI1 wrote:
--Jari
It would indeed be unfortunate to create an "application dependence" in the EAP layer. However, I'm not sure that AMSK proposal does that, necessarily. If all the EAP layer does it take parameters from the lower layer to create AMSKs, and then unconditionally carry out the lower layer's instructions, then I think the mechanism could be quite general.
Madjid>> Yes, I agree, but prohibiting EMSK export will make application
dependence very hard.
(Not sure if I'm responding to the e-mails in the correct order. This may have already been agreed upon...)
The fundamental requirement appears to be to not transport EMSK and to avoid compromised applications from affecting each other. Presumably there are multiple ways to achieve this, but IMHO one good way would be to keep EMSK in the EAP layer and have the EAP layer produce AMSKs, based on the same formula for all keys, upon the request of the lower layer. Then the lower layer can get all the AMSKs that it needs, and as long as it requests different AMSKs for different applications, there's no chance of one application compromising another one.
--Jari
- Re: Eap keying review: use of MSK/ EMSK for AMSK creation, (continued)
- Re: Eap keying review: use of MSK/ EMSK for AMSK creation Jari Arkko, November 7 2005
-
RE: Eap keying review: use of MSK/ EMSK for AMSK creation Salowey, Joe, November 1 2005
- Re: Eap keying review: use of MSK/ EMSK for AMSK creation Jari Arkko, November 6 2005
-
RE: Eap keying review: use of MSK/ EMSK for AMSK creation Nakhjiri Madjid-MNAKHJI1, November 1 2005
- Re: Eap keying review: use of MSK/ EMSK for AMSK creation Jari Arkko, November 6 2005
- RE: Eap keying review: use of MSK/ EMSK for AMSK creation Nakhjiri Madjid-MNAKHJI1, November 1 2005
- RE: Eap keying review: use of MSK/ EMSK for AMSK creation Salowey, Joe, November 1 2005
-
RE: Re: Eap keying review: use of MSK/ EMSK for AMSK creation Nakhjiri Madjid-MNAKHJI1, November 8 2005
- Re: Re: Eap keying review: use of MSK/ EMSK for AMSK creation Yoshihiro Ohba, November 8 2005
Results generated by Tiger Technologies using MHonArc.