draft-badra-eap-double-tls-04.txt - PowerPoint PPT Presentation

1 / 2
About This Presentation
Title:

draft-badra-eap-double-tls-04.txt

Description:

Authentication with shared key, based on the TLS standard resume mode ... Main idea: Ensuring user's anonymity. A second TLS handshake or AVP mechanism may be used ... – PowerPoint PPT presentation

Number of Views:14
Avg rating:3.0/5.0
Slides: 3
Provided by: packa63
Category:
Tags: badra | double | draft | eap | idea | tls | txt

less

Transcript and Presenter's Notes

Title: draft-badra-eap-double-tls-04.txt


1
draft-badra-eap-double-tls-04.txt
 EAP-Double-TLS Authentication
Protocol  Pascal.Urien_at_enst.fr
2
Goal news
  • Authentication with shared key, based on the TLS
    standard resume mode
  • Session-id client login
  • Master-secret client shared secret
  • EAP-ID session-id or session-id_at_server.com
  • Main idea Ensuring users anonymity
  • A second TLS handshake or AVP mechanism may be
    used to modify the tuple (session-id,
    master-secret)
  • What is new
  • Draft clarification
  • First byte of the SessionID is used as second
    phase discriminator
  • struct opaque random_byteslt0..24gt
  • SecondPhaseExchange second_phase_exchangelt1..8gt
  • SessionID
  • SecondPhaseExchange None 0x00
  • SecondPhaseExchange TLS 0x01
  • SecondPhaseExchange TLS_RSA_anon 0x02
  • SecondPhaseExchange TLS_DH_anon 0x03
  • SecondPhaseExchange AVP 0x04
Write a Comment
User Comments (0)
About PowerShow.com