A Flexible Authentication Framework for the Transport Layer Security (TLS) Protocol using the Extensible Authentication Protocol (EAP)
draft-nir-tls-eap-13
Document | Type | Expired Internet-Draft (individual) | |
---|---|---|---|
Last updated | 2012-06-21 (latest revision 2011-12-19) | ||
Stream | (None) | ||
Intended RFC status | (None) | ||
Formats |
Expired & archived
plain text
pdf
html
bibtex
|
||
Stream | Stream state | (No stream defined) | |
Consensus Boilerplate | Unknown | ||
RFC Editor Note | (None) | ||
IESG | IESG state | Expired | |
Telechat date | |||
Responsible AD | (None) | ||
Send notices to | (None) |
https://www.ietf.org/archive/id/draft-nir-tls-eap-13.txt
Abstract
Many of today's Web security problems have their root in the widespread usage of weak authentication mechanisms bundled with the usage of password based credentials. Dealing with both of these problems is the basis of this publication. This document extends the Transport Layer Security (TLS) protocol with a flexible and widely deployed authentication framework, namely the Extensible Authentication Protocol (EAP), to improve security of Web- as well as non-Web-based applications. The EAP framework allows so-called EAP methods, i.e. authentication and key exchange protocols, to be plugged into EAP without having to re-design the underlying protocol. The benefit of such an easy integration is the ability to run authentication protocols that fit a specific deployment environment, both from a credential choice as well as from the security and performance characteristics of the actual protocol. This work follows the example of IKEv2, where EAP has been added to allow clients to seamlessly use different forms of authentication credentials, such as passwords, token cards, and shared secrets.
Authors
Yoav Nir
(ynir@checkpoint.com)
Yaron Sheffer
(yaronf.ietf@gmail.com)
Hannes Tschofenig
(Hannes.Tschofenig@gmx.net)
Peter Gutmann
(pgut001@cs.auckland.ac.nz)
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)