90 likes | 187 Views
EAP Channel Bindings. TF-MNM Lyon, February 16, 2011. Alan DeKok FreeRADIUS. The problem. AAA. AAA. It’s all lies. NAS can lie to end user $0.02 per minute (really $0.10) Visited provider can lie to home server They used 10 hours (really 10 min). Solution.
E N D
EAP Channel Bindings • TF-MNM • Lyon, February 16, 2011 Alan DeKok FreeRADIUS
The problem AAA AAA
It’s all lies • NAS can lie to end user • $0.02 per minute (really $0.10) • Visited provider can lie to home server • They used 10 hours (really 10 min)
Solution • Tell everyone what everyone else said • In a secure fashion
I told the user X The NAS told me X The Solution AAA AAA
How it works • Define a TLV in EAP to transport data • Likely RADIUS • RADIUS inside of EAP inside of TTLS inside of EAP inside of RADIUS • It’s a bit of a miracle that it works at all
Security • Exchange information after user has been authenticated • Using keys derived from the EAP session • Ensures authenticity and integrity of the data
Benefits • Increases the usefulness of roaming • I don’t know who the NAS is, but he’s asking to charge the user $0.02/min, and the user has agreed.