[Emu] Fwd: New Version Notification for draft-aura-eap-noob-00.txt

Mohit Sethi <mohit.m.sethi@ericsson.com> Mon, 08 February 2016 15:33 UTC

Return-Path: <mohit.m.sethi@ericsson.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A5871B2D41; Mon, 8 Feb 2016 07:33:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fwK1RIRlSCIg; Mon, 8 Feb 2016 07:33:57 -0800 (PST)
Received: from sessmg23.ericsson.net (sessmg23.ericsson.net [193.180.251.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4CDE81B2D3E; Mon, 8 Feb 2016 07:33:56 -0800 (PST)
X-AuditID: c1b4fb2d-f78fe6d00000163a-ba-56b8b5628d32
Received: from ESESSHC015.ericsson.se (Unknown_Domain [153.88.183.63]) by sessmg23.ericsson.net (Symantec Mail Security) with SMTP id FB.F4.05690.265B8B65; Mon, 8 Feb 2016 16:33:54 +0100 (CET)
Received: from nomadiclab.lmf.ericsson.se (153.88.183.153) by smtp.internal.ericsson.com (153.88.183.65) with Microsoft SMTP Server id 14.3.248.2; Mon, 8 Feb 2016 16:33:53 +0100
Received: from nomadiclab.lmf.ericsson.se (localhost [127.0.0.1]) by nomadiclab.lmf.ericsson.se (Postfix) with ESMTP id 41D774EF83; Mon, 8 Feb 2016 17:36:12 +0200 (EET)
Received: from [127.0.0.1] (localhost [127.0.0.1]) by nomadiclab.lmf.ericsson.se (Postfix) with ESMTP id 9A8D74E9B6; Mon, 8 Feb 2016 17:36:11 +0200 (EET)
From: Mohit Sethi <mohit.m.sethi@ericsson.com>
To: saag@ietf.org, emu@ietf.org
References: <20160208123035.1562.80507.idtracker@ietfa.amsl.com>
Message-ID: <56B8B561.8040300@ericsson.com>
Date: Mon, 08 Feb 2016 17:33:53 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.5.1
MIME-Version: 1.0
In-Reply-To: <20160208123035.1562.80507.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-Virus-Scanned: ClamAV using ClamSMTP
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrJLMWRmVeSWpSXmKPExsUyM2K7vW7S1h1hBm2blS2OrV/LYjGlv5PJ 4s3EjewOzB7HXy9m9Viy5CdTAFMUl01Kak5mWWqRvl0CV8bKe/UF56Uquq52MzcwzhHtYuTk kBAwkfhwdw87hC0mceHeerYuRi4OIYHDjBKzO9exgSSEBLYySjzaqgWRWMso8fJwPwuEM49R YsqBhWDtbAJ6Ep3njjN3MXJwCAu4Ssw/YgsSFhFQluhacp8ZYpCDxP6785lAbGYBKYkXZ9+C LeAV0JY4uH0+WA2LgIrEmalvwEaKCkRIHO7sYoeoEZQ4OfMJC4jNKeAosWD1aqg5FhIz559n hLDlJZq3zmaG+EZN4uq5TVB71SW2dhxgnMAoMgvJqFlI2mchaV/AyLyKUbQ4tbg4N93IWC+1 KDO5uDg/Ty8vtWQTIzACDm75rbuDcfVrx0OMAhyMSjy8BlO2hwmxJpYVV+YeYpTgYFYS4d3R uyNMiDclsbIqtSg/vqg0J7X4EKM0B4uSOO8a5/VhQgLpiSWp2ampBalFMFkmDk6pBsYZLz6X rpyaM8d0QtfpRcu2Hrp46tv6uc676xey22WyHntx+tf5tvuXbpWHBj7iyl/cL7x07s7AgB8t B5eGPd5j32v9LSL+7X0mh3DXy+5X22bIqFSuqEtrqb3s8NTmhkXxZfu1sWK1533LDKyLnD3n BW6Ql0hvfBR9+ZOSZWaNt6PkzfR5Vs1KLMUZiYZazEXFiQDKOkxLfAIAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/emu/R4hQdYbdS4qYMa9HCTrb_BPO-LU>
Cc: tuomas.aura@aalto.fi
Subject: [Emu] Fwd: New Version Notification for draft-aura-eap-noob-00.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Feb 2016 15:33:58 -0000

Dear all

We have just submitted a new IETF Draft titled “Nimble out-of-band 
authentication for EAP (EAP-NOOB)”.

The draft defines an EAP method where the authentication is based on a 
user-assisted out-of-band (OOB) channel between the server and peer. It 
is intended as a generic bootstrapping solution for Internet-of-Things 
devices which have no pre-configured authentication credentials and 
which are not yet registered on the authentication server. Consider 
devices you just bought or borrowed.

The EAP-NOOB method is more generic than most ad-hoc bootstrapping 
solutions in that it supports many types of OOB channels. We specify the 
exact in-band messages but only the OOB message contents and not the OOB 
channel details. Also, EAP-NOOB supports ubicomp devices with only 
output (e.g. display) or only input (e.g. camera). Moreover, it makes 
combined use of both secrecy and integrity of the OOB channel for more 
robust security than the ad-hoc solutions. We have put a lot of effort 
into designing a robust security protocol.

For one application example, we have used an earlier version of the 
protocol for bootstrapping security for ubiquitous displays: the user 
can configure wireless network access, link the device to a cloud 
service, and register ownership of the device for a specific cloud user 
– all in one simple step of scanning a QR code with a smart phone. There 
seemed to more potential to this idea than just using it for our own 
system, and thus we decided to write a generic EAP method for 
out-of-band authentication.

The draft is available here:
https://tools.ietf.org/html/draft-aura-eap-noob-00

Please see if you can make use of it. We look forward to your feedback 
and comments.

Regards
/--Mohit


-------- Forwarded Message --------
Subject: 	New Version Notification for draft-aura-eap-noob-00.txt
Date: 	Mon, 08 Feb 2016 04:30:35 -0800
From: 	internet-drafts@ietf.org
To: 	Tuomas Aura <tuomas.aura@aalto.fi>, Mohit Sethi <mohit@piuha.net>



A new version of I-D, draft-aura-eap-noob-00.txt
has been successfully submitted by Tuomas Aura and posted to the
IETF repository.

Name:		draft-aura-eap-noob
Revision:	00
Title:		Nimble out-of-band authentication for EAP (EAP-NOOB)
Document date:	2016-02-08
Group:		Individual Submission
Pages:		35
URL:https://www.ietf.org/internet-drafts/draft-aura-eap-noob-00.txt
Status:https://datatracker.ietf.org/doc/draft-aura-eap-noob/
Htmlized:https://tools.ietf.org/html/draft-aura-eap-noob-00


Abstract:
    Extensible Authentication Protocol (EAP) [RFC3748] provides support
    for multiple authentication methods.  This document defines the EAP-
    NOOB authentication method for nimble out-of-band (OOB)
    authentication and key derivation.  This EAP method is intended for
    bootstrapping all kinds of Internet-of-Things (IoT) devices that have
    a minimal user interface and no pre-configured authentication
    credentials.  The method makes use of a user-assisted one-directional
    OOB channel between the peer device and authentication server.

                                                                                   


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat