Re: [Pana] Regarding the optimization scope in EAP-PSK with PANA

2016-12-01 Thread yoshihiro.ohba
Hi Ashok,

According to RFC 3748: “the authentication conversation can continue until the 
authenticator determines that successful authentication has occurred, in which 
case the authenticator MUST transmit an EAP Success (Code 3).”

Without changing RFC 3748, I do not think we can design an EAP method that does 
not use EAP Success.

Regards,
Yoshihiro Ohba



From: Raja ashok [mailto:raja.as...@huawei.com]
Sent: Thursday, December 01, 2016 6:06 PM
To: ohba yoshihiro(大�� �x洋 TEA Advanced Technical Marketing Department); 
basavaraj.pa...@nokia.com; alper.ye...@yegin.org; jari.ar...@piuha.net; 
Pana@ietf.org
Subject: Regarding the optimization scope in EAP-PSK with PANA

Hi All,

Currently EAP-PSK with PANA takes 5RTT. I am felling this should be optimized 
for wiresless sensor network in mesh topology.

EAP-PSK 3rd and 4th message contains Protected channel (PCHANNEL). This is a 
secure channel formed between client and server with EAX algorithm. But as per 
my knowledge this channel is not required if EAP-PSK is used with PANA. Because 
anyway PANA session keys are there with that we can exchange information 
securely using Encrypt-Encapsulate AVP and Auth AVP.

So if we define a simplified EAP-PSK mechanism without PCHANNEL, we can omit 1 
RTT message. This has been explained below

Client  
  Server
--- 
   
PAR/EAP-PSK 1st msg
[Flags||RAND_S||ID_S]   --->

PAN/EAP-PSK 2nd msg

<---[Flags||RAND_S||RAND_P||MAC_P||ID_P]
PAR’C’/EAP-PSK 3rd msg
[Flags||RAND_S||MAC_S] --->


Here we can omit EAP-Success msg also in PAR’C’ msg, because PANA result code 
AVP is there. I hope that is sufficient. So we can send EAP-PSK 3rd msg in PAR 
‘C’ msg directly.

This saves 1 RTT in handshake. And also the EAX algorithm is not required, so 
this saves some flash memory in constraint environment. But this simplified 
EAP-PSK cannot be used alone. This can be used only with PANA.

Please provide your comments on it.

Regards,
Ashok


[Company_logo]

Raja Ashok V K
Huawei Technologies
Bangalore, India
http://www.huawei.com

本邮件及其附件含有华为公司的保密信息,仅限于发送给上面地址中列出的个人或群组。禁
止任何其他人以任何形式使用(包括但不限于全部或部分地泄露、复制、或散发)本邮件中
的信息。如果您错收了本邮件,请您立即电话或邮件通知发件人并删除本邮件!
This e-mail and its attachments contain confidential information from HUAWEI, 
which
is intended only for the person or entity whose address is listed above. Any 
use of the
information contained herein in any way (including, but not limited to, total 
or partial
disclosure, reproduction, or dissemination) by persons other than the intended
recipient(s) is prohibited. If you receive this e-mail in error, please notify 
the sender by
phone or email immediately and delete it!

___
Pana mailing list
Pana@ietf.org
https://www.ietf.org/mailman/listinfo/pana


[Pana] Regarding the optimization scope in EAP-PSK with PANA

2016-12-01 Thread Raja ashok
Hi All,

Currently EAP-PSK with PANA takes 5RTT. I am felling this should be optimized 
for wiresless sensor network in mesh topology.

EAP-PSK 3rd and 4th message contains Protected channel (PCHANNEL). This is a 
secure channel formed between client and server with EAX algorithm. But as per 
my knowledge this channel is not required if EAP-PSK is used with PANA. Because 
anyway PANA session keys are there with that we can exchange information 
securely using Encrypt-Encapsulate AVP and Auth AVP.

So if we define a simplified EAP-PSK mechanism without PCHANNEL, we can omit 1 
RTT message. This has been explained below

Client  
  Server
--- 
   
PAR/EAP-PSK 1st msg
[Flags||RAND_S||ID_S]   --->

PAN/EAP-PSK 2nd msg

<---[Flags||RAND_S||RAND_P||MAC_P||ID_P]
PAR’C’/EAP-PSK 3rd msg
[Flags||RAND_S||MAC_S] --->


Here we can omit EAP-Success msg also in PAR’C’ msg, because PANA result code 
AVP is there. I hope that is sufficient. So we can send EAP-PSK 3rd msg in PAR 
‘C’ msg directly.

This saves 1 RTT in handshake. And also the EAX algorithm is not required, so 
this saves some flash memory in constraint environment. But this simplified 
EAP-PSK cannot be used alone. This can be used only with PANA.

Please provide your comments on it.

Regards,
Ashok


[Company_logo]

Raja Ashok V K
Huawei Technologies
Bangalore, India
http://www.huawei.com

本邮件及其附件含有华为公司的保密信息,仅限于发送给上面地址中列出的个人或群组。禁
止任何其他人以任何形式使用(包括但不限于全部或部分地泄露、复制、或散发)本邮件中
的信息。如果您错收了本邮件,请您立即电话或邮件通知发件人并删除本邮件!
This e-mail and its attachments contain confidential information from HUAWEI, 
which
is intended only for the person or entity whose address is listed above. Any 
use of the
information contained herein in any way (including, but not limited to, total 
or partial
disclosure, reproduction, or dissemination) by persons other than the intended
recipient(s) is prohibited. If you receive this e-mail in error, please notify 
the sender by
phone or email immediately and delete it!

___
Pana mailing list
Pana@ietf.org
https://www.ietf.org/mailman/listinfo/pana