<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-roamops-roamsec" target="https://datatracker.ietf.org/doc/html/draft-ietf-roamops-roamsec-02">
   <front>
      <title>End-to-End Security in Roaming</title>
      <author initials="B." surname="Aboba" fullname="Dr. Bernard D. Aboba">
         <organization>Microsoft</organization>
      </author>
      <author initials="P. R." surname="Calhoun" fullname="Pat R. Calhoun">
         <organization>Sun Microsystems</organization>
      </author>
      <date month="July" day="24" year="1998" />
      <abstract>
	 <t>As noted in Roaming Requirements, there is a need for end-to-end secu-
     rity in roaming, including end-to-end integrity protection, and confi-
     dentiality.  In roaming implementations based on proxy chaining, pack-
     ets are routed between the NAS and home server  through  a  series  of
     proxies.   Current  roaming  implementations  provide  only hop-by-hop
     security, guarding only against modification  of  packets  in  transit
     between  hops.  This makes it possible for untrusted proxies to modify
     packets sent between a NAS and a home  server  without  detection,  as
     well  as  to decrypt PAP passwords, Tunnel passwords, and other hidden
     attributes which are available to it in cleartext.
 
     This document provides a framework for end-to-end security in roaming,
     making  it  possible  to  provide  end-to-end  message  integrity  and
     attribute hiding through addition of three new attributes.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-roamops-roamsec-02" />
   
</reference>
