Re: Strawman -10
From: Rafa Marin Lopez (rafadif.um.es)
Date: Tue, 31 Jan 2006 13:46:17 -0800 (PST)

I see. But I was wondering for example in the case of standalone authenticator : will only MSK be available to lower layer as usual or both (MSK,EMSK) now?




[Joe] In order to preserve mode independence the EMSK must not be
directly consumed by the lower layer. The lower layer must not require
direct access to the EMSK to function. However, the lower layer may
rely upon keys derived from the EMSK.


Then my question is what layer is going to derive keys (i.e. AMSK) from EMSK? EAP layer?.




Thanks.





--------------------------------------------------------------
--------------------------------------------------------------
------------


Change

"The EMSK MUST NOT be provided to the lower layer, nor is

it permitted


to pass any quantity to the lower layer from which the EMSK could be
computed without breaking some cryptographic assumption, such as
inverting a one-way function."

To

"The EMSK MUST NOT be provided to an entity outside the EAP

server or


peer, nor is it permitted to pass any quantity to an

entity outside

the EAP
server or peer from which the EMSK could be computed


without breaking

some cryptographic assumption, such as inverting a one-way

function."






--
------------------------------------------------------
Rafael Marin Lopez
Faculty of Computer Science-University of Murcia
30071 Murcia - Spain
Telf: +34968367645    e-mail: rafa [at] dif.um.es
------------------------------------------------------

_________________________________________________________________
To unsubscribe or modify your subscription options, please visit:
http://lists.frascone.com/mailman/listinfo/eap

Arhives: http://lists.frascone.com/pipermail/eap









--
------------------------------------------------------
Rafael Marin Lopez
Faculty of Computer Science-University of Murcia
30071 Murcia - Spain
Telf: +34968367645    e-mail: rafa [at] dif.um.es
------------------------------------------------------


Results generated by Tiger Technologies using MHonArc.