%% You should probably cite rfc9140 instead of this I-D. @techreport{ietf-emu-eap-noob-00, number = {draft-ietf-emu-eap-noob-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-emu-eap-noob/00/}, author = {Tuomas Aura and Mohit Sethi}, title = {{Nimble out-of-band authentication for EAP (EAP-NOOB)}}, pagetotal = 62, year = , month = , day = , abstract = {Extensible Authentication Protocol (EAP) provides support for multiple authentication methods. This document defines the EAP-NOOB authentication method for nimble out-of-band (OOB) authentication and key derivation. The EAP method is intended for bootstrapping all kinds of Internet-of-Things (IoT) devices that have no pre-configured authentication credentials. The method makes use of a user-assisted one-directional OOB message between the peer device and authentication server to authenticate the in-band key exchange. The device must have an input or output interface, such as a display, microphone, speakers or blinking light, which can send or receive dynamically generated messages of tens of bytes in length.}, }