EAP Channel Bindings
90 likes | 114 Views
Explore how to address deception in AAA communications, secure information exchange post-user authentication, and derive benefits of improved roaming by implementing TLV in EAP within RADIUS protocols. Learn the solution to address lies in NAS communication and ensure data authenticity.
EAP Channel Bindings
E N D
Presentation Transcript
EAP Channel Bindings • TF-MNM • Lyon, February 16, 2011 Alan DeKok FreeRADIUS
The problem AAA AAA
It’s all lies • NAS can lie to end user • $0.02 per minute (really $0.10) • Visited provider can lie to home server • They used 10 hours (really 10 min)
Solution • Tell everyone what everyone else said • In a secure fashion
I told the user X The NAS told me X The Solution AAA AAA
How it works • Define a TLV in EAP to transport data • Likely RADIUS • RADIUS inside of EAP inside of TTLS inside of EAP inside of RADIUS • It’s a bit of a miracle that it works at all
Security • Exchange information after user has been authenticated • Using keys derived from the EAP session • Ensures authenticity and integrity of the data
Benefits • Increases the usefulness of roaming • I don’t know who the NAS is, but he’s asking to charge the user $0.02/min, and the user has agreed.