Web Site

Computerit-solutions.com



» Computer » Computer network » Topics begins with E » Extensible Authentication Protocol


Page modified: Friday, June 23, 2006 20:28:28

Extensible Authentication Protocol, or EAP is Authentifizierungs minutes, which are often used with PPP, and different Authentifizierungsmechanismen supports. It is often used for the access supervision on networks.

The Aushandlung of the concretely used mechanism takes place thereby only during the Authentifizierungsphase, which permits the employment of a Authentifizierungsservers. A Authenticator is a user or a Client which at a Authentifizierungstelle to announce would like itself, in order for e.g. a connection to be authentifiziert. The Authenticator passes on thereby only in principle the Authentifizierungsnachrichten of the Peer to the server.

Also several mechanisms in consequence can be used. Control of it has the Authenticator, which determines the procedure in a Request. To the selection among other things identity inquiry (which is used e.g. with dial in connections, but not with dedicated lines) stands, MD5-challenge (corresponds majority to CHAP), One Time password, gene Eric token Cards,"…

After a Request package was sent by the Authenticator to the Peer, this answers with a Response package, that in the data field the respective Authentifizierung (identity, password, Hash value,"…) contains. Thereupon the Authenticator can dispatch further Request packages. The Authentifizierung with a Success/failure package of the Authenticator is locked.

Advantages

Several Authentifizierungsmechanismen (also in consequence) can be used, which must be negotiated not in the connection establishment phase.

Authentifizierungsverfahren

Identity

Identification, possibly by the user, i.e. by input of an user ID. In the Request package a request text can be sent, which is indicated to the user before the input of the ID.

Notification

In the data division of the package a message is transported to the user, who is indicated to this. e.g.: Authentifizierungsfehler, password run time,"…

NAK

This type may emerge only in a Response message. It is signaled with the fact that the Peer does not support the desired Authentifizierungsverfahren.

MD5-Challenge

This corresponds to CHAP with MD5 as hash algorithm. Into the Request Message a random value will transfer. The Response package contains the Hash value over this random value and only the two parties well-known password.

One Time password

The Request Message contains a OTP Challenge. In the Response package respective One Time password is located.

TLS

Around a Design from cryptographic minutes to here the Authentifizierungsdialog of TLS will avoid used.

Common the EAP-TLS procedure of which is far with all after 802.11i standardized WLAN components to be used can. The Authenticator (ACCESS POINT/rout) examines the Authentifizierungsinformationen conveyed by the potential network participant (Notebook) on a Authentifizierungsserver (RADIUS)

Further procedures

There are approx. 40 EAP procedures, among them are:

  • According to RFC: EAP-MD5, EAP-OTP, EAP-GTC, EAP-TLS, EAP-SIM, EAP-AKA
  • Manufacturer-specifically: EAP-TLS, EAP-SIM, EAP-AKA, PEAP, LEAP, EAP TTLS

Related links

  • RFC 3748 - Extensible Authentication Protocol (EAP)
  • RFC 2284 - PPP Extensible Authentication Protocol (EAP)
  • RFC 1938 - A One Time password system

Articles in category "Extensible Authentication Protocol"

We found here 4 articles.

E

» erlastkontrolle
» Enhanced Interior gateway Routing Protocol
» Extensible Authentication Protocol
» Exterior gateway minutes

Related Websites

We found here 6 related websites.

Page cached: Wednesday, July 5, 2006 14:10:24
Valid XHTML 1.0!  Valid CSS!

Page copy protected against web site content infringement by Copyscape