Extension for EAP Authentication in IKEv2 (draft-eronen-ipsec-ikev2-eap-auth-00) - PowerPoint PPT Presentation

About This Presentation
Title:

Extension for EAP Authentication in IKEv2 (draft-eronen-ipsec-ikev2-eap-auth-00)

Description:

... for methods that provide mutual authentication and keys. Avoid unnecessary PKIs ... First draft explores various alternatives how to implement this in IKEv2 ... – PowerPoint PPT presentation

Number of Views:26
Avg rating:3.0/5.0
Slides: 7
Provided by: PasiE7
Learn more at: https://www.ietf.org
Category:

less

Transcript and Presenter's Notes

Title: Extension for EAP Authentication in IKEv2 (draft-eronen-ipsec-ikev2-eap-auth-00)


1
Extension for EAP Authentication in
IKEv2(draft-eronen-ipsec-ikev2-eap-auth-00)
  • Pasi EronenHannes Tschofenig

2
Background
  • IKEv2 supports EAP authentication
  • But requires that EAP is always used together
    with public-key signature authentication of
    responder (gateway)
  • Vital for EAP methods that dont do mutual
    authentication

3
Overview
  • This document explores how to do EAP-only
    authentication in IKEv2
  • Obviously, only for methods that provide mutual
    authentication and keys
  • Avoid unnecessary PKIs
  • Allows both initiator and responder
    authentication to be extensible

4
Examples
  • EAP-AKA for 3GPP WLAN interworking
  • GSS-API EAP method instead of KINK?

5
Security Considerations
  • Lying NAS problem and other stuff also present
    in 802.11
  • Worth noting although EAP payloads are encrypted
    integrity protected, this does not really offer
    any extra protection

6
Status
  • First draft explores various alternatives how to
    implement this in IKEv2
  • Comments are very welcome!
Write a Comment
User Comments (0)
About PowerShow.com