Hi Ashok,

According to RFC 3748: “the authentication conversation can continue until the 
authenticator determines that successful authentication has occurred, in which 
case the authenticator MUST transmit an EAP Success (Code 3).”

Without changing RFC 3748, I do not think we can design an EAP method that does 
not use EAP Success.

Yoshihiro Ohba

From: Raja ashok [mailto:raja.as...@huawei.com]
Sent: Thursday, December 01, 2016 6:06 PM
To: ohba yoshihiro(大�� �x洋 TEA Advanced Technical Marketing Department); 
basavaraj.pa...@nokia.com; alper.ye...@yegin.org; jari.ar...@piuha.net; 
Subject: Regarding the optimization scope in EAP-PSK with PANA

Hi All,

Currently EAP-PSK with PANA takes 5RTT. I am felling this should be optimized 
for wiresless sensor network in mesh topology.

EAP-PSK 3rd and 4th message contains Protected channel (PCHANNEL). This is a 
secure channel formed between client and server with EAX algorithm. But as per 
my knowledge this channel is not required if EAP-PSK is used with PANA. Because 
anyway PANA session keys are there with that we can exchange information 
securely using Encrypt-Encapsulate AVP and Auth AVP.

So if we define a simplified EAP-PSK mechanism without PCHANNEL, we can omit 1 
RTT message. This has been explained below

PAR/EAP-PSK 1st msg
[Flags||RAND_S||ID_S]                               --->
                                PAN/EAP-PSK 2nd msg
<---                        [Flags||RAND_S||RAND_P||MAC_P||ID_P]
                PAR’C’/EAP-PSK 3rd msg
[Flags||RAND_S||MAC_S]                         --->

Here we can omit EAP-Success msg also in PAR’C’ msg, because PANA result code 
AVP is there. I hope that is sufficient. So we can send EAP-PSK 3rd msg in PAR 
‘C’ msg directly.

This saves 1 RTT in handshake. And also the EAX algorithm is not required, so 
this saves some flash memory in constraint environment. But this simplified 
EAP-PSK cannot be used alone. This can be used only with PANA.

Please provide your comments on it.



Raja Ashok V K
Huawei Technologies
Bangalore, India
This e-mail and its attachments contain confidential information from HUAWEI, 
is intended only for the person or entity whose address is listed above. Any 
use of the
information contained herein in any way (including, but not limited to, total 
or partial
disclosure, reproduction, or dissemination) by persons other than the intended
recipient(s) is prohibited. If you receive this e-mail in error, please notify 
the sender by
phone or email immediately and delete it!

Pana mailing list

Reply via email to