Re: Issue: Use of a label in derivation of keys from the MSK
From: Joseph Salowey (jsalowey) (jsaloweycisco.com)
Date: Mon, 19 Nov 2007 17:14:35 -0800 (PST)
While I agree this is good practice, I think we have to be careful about
relying upon this to always be the case.  Not all uses of the MSK may
currently use a label (I'm not sure if PANA does).  Since this rule has
not been around for long a particular lower layer should not assume that
using a key label will have any effect on guaranteeing uniqueness from
any keys it doesn't control the derivation of.  It will help in
guaranteeing uniqueness in keys that it does control the derivation of. 

 

> -----Original Message-----
> From: Bernard_Aboba [at] hotmail.com [mailto:Bernard_Aboba [at] hotmail.com] 
> Sent: Friday, November 16, 2007 6:48 AM
> To: 'eap-WG'
> Subject: [eap] Issue: Use of a label in derivation of keys 
> from the MSK
> 
> To date, EAP lower layers utilizing the MSK have often 
> utilized a label within the PRF used for deriving other keys 
> in order to ensure uniqueness of key branches.  This includes 
> 802.11i, 802.11r, and now 802.1af.  
>  
> However, this "unwritten rule" has not been included the EKMF 
> document.  This seems like a fairly important omission. 
> 

Results generated by Tiger Technologies using MHonArc.