Re: [Emu] [saag] Fwd: New Version Notification for draft-aura-eap-noob-00.txt

Aura Tuomas <tuomas.aura@aalto.fi> Thu, 18 February 2016 16:27 UTC

Return-Path: <tuomas.aura@aalto.fi>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D32FF1B2CE9; Thu, 18 Feb 2016 08:27:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.205
X-Spam-Level:
X-Spam-Status: No, score=-4.205 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.006] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QmvViX06hDui; Thu, 18 Feb 2016 08:27:32 -0800 (PST)
Received: from smtp-out-02.aalto.fi (smtp-out-02.aalto.fi [130.233.228.121]) by ietfa.amsl.com (Postfix) with ESMTP id 430AD1AD059; Thu, 18 Feb 2016 08:27:30 -0800 (PST)
Received: from smtp-out-02.aalto.fi (localhost.localdomain [127.0.0.1]) by localhost (Email Security Appliance) with SMTP id 41AE82710CD_6C5F0F1B; Thu, 18 Feb 2016 16:27:29 +0000 (GMT)
Received: from EXHUB02.org.aalto.fi (exhub02.org.aalto.fi [130.233.222.119]) by smtp-out-02.aalto.fi (Sophos Email Appliance) with ESMTP id B52A22710AA_6C5F0F0F; Thu, 18 Feb 2016 16:27:28 +0000 (GMT)
Received: from EXMDB01.org.aalto.fi ([169.254.2.222]) by EXHUB02.org.aalto.fi ([130.233.222.119]) with mapi id 14.03.0224.002; Thu, 18 Feb 2016 18:27:28 +0200
From: Aura Tuomas <tuomas.aura@aalto.fi>
To: Abhijan Bhattacharyya <abhijan.bhattacharyya@tcs.com>, Mohit Sethi <mohit.m.sethi@ericsson.com>
Thread-Topic: [saag] Fwd: New Version Notification for draft-aura-eap-noob-00.txt
Thread-Index: AQHRYmyDaEz8z8wkLU+ZyRerPC0UrZ8iJdqAgAp5WICAAFk8kA==
Date: Thu, 18 Feb 2016 16:27:28 +0000
Message-ID: <7F9C975440487E49BBD35F4FB088ED74CFCDBBAD@EXMDB01.org.aalto.fi>
References: <20160208123035.1562.80507.idtracker@ietfa.amsl.com> <56B8B561.8040300@ericsson.com> <OF7E755D92.2E628249-ON65257F5A.00275705-65257F5A.002945DB@tcs.com>
In-Reply-To: <OF7E755D92.2E628249-ON65257F5A.00275705-65257F5A.002945DB@tcs.com>
Accept-Language: fi-FI, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [85.76.33.105]
Content-Type: multipart/alternative; boundary="_000_7F9C975440487E49BBD35F4FB088ED74CFCDBBADEXMDB01orgaalto_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/emu/nB4m1MKqGtpk-Bm7PAW1Ny9FxpE>
Cc: "'t2trg@irtf.org'" <t2trg@irtf.org>, "saag@ietf.org" <saag@ietf.org>, "'core@ietf.org'" <core@ietf.org>, "emu@ietf.org" <emu@ietf.org>
Subject: Re: [Emu] [saag] Fwd: New Version Notification for draft-aura-eap-noob-00.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Feb 2016 16:27:35 -0000

Hi Abhijan,

Thank you for the questions.

There is a one-to-one mapping between the EAP server and authenticator. The EAP server is determined by how the authenticator or local AAA server is configured. That is, the local network administrators can route access requests for “@eap-noob.org” to any server they choose.

In our own setup, we have configured the RADIUS server at our local wireless network to trust another, remote RADIUS server for NAIs that end “@eap-noob.org”. That remote server handles EAP-NOOB for all the stations in our wireless network.

Tuomas

P.S. Sorry about the cross-posting. Let’s send the follow-ups only to saag@ietf.org<mailto:saag@ietf.org>.



From: Abhijan Bhattacharyya [mailto:abhijan.bhattacharyya@tcs.com]
Sent: Monday, 15 February, 2016 09:31
To: Mohit Sethi <mohit.m.sethi@ericsson.com>
Cc: saag@ietf.org; emu@ietf.org; Aura Tuomas <tuomas.aura@aalto.fi>; 'core@ietf.org' <core@ietf.org>; 't2trg@irtf.org' <t2trg@irtf.org>
Subject: Re: [saag] Fwd: New Version Notification for draft-aura-eap-noob-00.txt

Hi Mohit,
I was going through your draft. Looks to be a promising proposition. However, I have got a few questions first hand.

The authenticator acts as a transparent node and forwards the packets to the server soon after the first message for EAP Identity request. In a typical network would a single authenticator map to several servers or the assumption is that there is always one to one mapping between server and authenticator?

How does the authenticator associate itself to the server at the first place?

What is the assumption regarding the  underlying physical network and how the authenticator maps to the different nodes in the network (e.g. a router in a WiFi like setup)?

Regards
Abhijan Bhattacharyya
Associate Consultant
Scientist, Innovation Lab, Kolkata, India
Tata Consultancy Services
Mailto: abhijan.bhattacharyya@tcs.com<mailto:abhijan.bhattacharyya@tcs.com>
Website: http://www.tcs.com<http://www.tcs.com/>
____________________________________________
Experience certainty.        IT Services
                       Business Solutions
                       Consulting
____________________________________________




From:        Mohit Sethi <mohit.m.sethi@ericsson.com<mailto:mohit.m.sethi@ericsson.com>>
To:        <saag@ietf.org<mailto:saag@ietf.org>>, <emu@ietf.org<mailto:emu@ietf.org>>
Cc:        tuomas.aura@aalto.fi<mailto:tuomas.aura@aalto.fi>
Date:        02/08/2016 09:10 PM
Subject:        [saag] Fwd: New Version Notification for draft-aura-eap-noob-00.txt
Sent by:        "saag" <saag-bounces@ietf.org<mailto:saag-bounces@ietf.org>>
________________________________



Dear all

We have just submitted a new IETF Draft titled “Nimble out-of-band
authentication for EAP (EAP-NOOB)”.

The draft defines an EAP method where the authentication is based on a
user-assisted out-of-band (OOB) channel between the server and peer. It
is intended as a generic bootstrapping solution for Internet-of-Things
devices which have no pre-configured authentication credentials and
which are not yet registered on the authentication server. Consider
devices you just bought or borrowed.

The EAP-NOOB method is more generic than most ad-hoc bootstrapping
solutions in that it supports many types of OOB channels. We specify the
exact in-band messages but only the OOB message contents and not the OOB
channel details. Also, EAP-NOOB supports ubicomp devices with only
output (e.g. display) or only input (e.g. camera). Moreover, it makes
combined use of both secrecy and integrity of the OOB channel for more
robust security than the ad-hoc solutions. We have put a lot of effort
into designing a robust security protocol.

For one application example, we have used an earlier version of the
protocol for bootstrapping security for ubiquitous displays: the user
can configure wireless network access, link the device to a cloud
service, and register ownership of the device for a specific cloud user
– all in one simple step of scanning a QR code with a smart phone. There
seemed to more potential to this idea than just using it for our own
system, and thus we decided to write a generic EAP method for
out-of-band authentication.

The draft is available here:
https://tools.ietf.org/html/draft-aura-eap-noob-00

Please see if you can make use of it. We look forward to your feedback
and comments.

Regards
/--Mohit


-------- Forwarded Message --------
Subject:                  New Version Notification for draft-aura-eap-noob-00.txt
Date:                  Mon, 08 Feb 2016 04:30:35 -0800
From:                  internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>
To:                  Tuomas Aura <tuomas.aura@aalto.fi<mailto:tuomas.aura@aalto.fi>>, Mohit Sethi <mohit@piuha.net<mailto:mohit@piuha.net>>



A new version of I-D, draft-aura-eap-noob-00.txt
has been successfully submitted by Tuomas Aura and posted to the
IETF repository.

Name:                                  draft-aura-eap-noob
Revision:                 00
Title:                                  Nimble out-of-band authentication for EAP (EAP-NOOB)
Document date:                 2016-02-08
Group:                                  Individual Submission
Pages:                                  35
URL:https://www.ietf.org/internet-drafts/draft-aura-eap-noob-00.txt
Status:https://datatracker.ietf.org/doc/draft-aura-eap-noob/
Htmlized:https://tools.ietf.org/html/draft-aura-eap-noob-00


Abstract:
   Extensible Authentication Protocol (EAP) [RFC3748] provides support
   for multiple authentication methods.  This document defines the EAP-
   NOOB authentication method for nimble out-of-band (OOB)
   authentication and key derivation.  This EAP method is intended for
   bootstrapping all kinds of Internet-of-Things (IoT) devices that have
   a minimal user interface and no pre-configured authentication
   credentials.  The method makes use of a user-assisted one-directional
   OOB channel between the peer device and authentication server.




Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat



_______________________________________________
saag mailing list
saag@ietf.org<mailto:saag@ietf.org>
https://www.ietf.org/mailman/listinfo/saag

=====-----=====-----=====
Notice: The information contained in this e-mail
message and/or attachments to it may contain
confidential or privileged information. If you are
not the intended recipient, any dissemination, use,
review, distribution, printing or copying of the
information contained in this e-mail message
and/or attachments to it are strictly prohibited. If
you have received this communication in error,
please notify us by reply e-mail or telephone and
immediately and permanently delete the message
and any attachments. Thank you