首页> 外文会议>Sarnoff Symposium, 2009. SARNOFF '09 >Making the case for EAP channel bindings
【24h】

Making the case for EAP channel bindings

机译:EAP通道绑定的理由

获取原文

摘要

In current networks that use EAP and AAA for authenticated admission control, such as WiFi, WiMAX, and various 3G internetworking protocols, a malicious base station can advertise false information to prospective users in an effort to manipulate network access in some way. This paper identifies and discusses the resulting threats (e.g. the lying NAS problem in enterprise networks and the newly identified lying provider problem in roaming environments) and shows how these threats can be exploited for a number of attacks, including traffic herding, denial of service, cryptographic downgrade attacks, and forced roaming. Finally, the paper presents how an EAP channel binding protocol can thwart the identified attacks by allowing a client to inform the EAP server about the unauthenticated information it received during the network selection process. The back-end server can then ensure the consistency of the advertised information with its configured policy. As a result, EAP channel bindings enable an end-to-end validation of network properties, which is otherwise infeasible in existing AAA infrastructures. Standardization activities currently exist within the IETF to implement this technique.
机译:在当前使用EAP和AAA进行身份验证的接入控制的网络中,例如WiFi,WiMAX和各种3G互联协议,恶意基站可以向潜在用户通告虚假信息,以某种方式操纵网络访问。本文确定并讨论了由此产生的威胁(例如,企业网络中的说谎的NAS问题以及漫游环境中新发现的说谎的提供商问题),并说明了如何利用这些威胁进行多种攻击,包括流量聚集,拒绝服务,加密降级攻击和强制漫游。最后,本文介绍了EAP通道绑定协议如何通过允许客户端向EAP服务器通知在网络选择过程中收到的未经身份验证的信息来阻止已识别的攻击。然后,后端服务器可以确保广告信息与其配置的策略的一致性。结果,EAP通道绑定启用了网络属性的端到端验证,而这在现有AAA基础结构中是不可行的。目前,IETF中存在标准化活动,以实施此技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号