Improved EAP keying framework for a secure mobility access service

  • Authors:
  • Rafa Marin Lopez;Antonio Gomez Skarmeta;Julien Bournelle;Maryline Laurent-Maknavicus;Jean Michel Combes

  • Affiliations:
  • University of Murcia, Murcia, Spain;University of Murcia, Murcia, Spain;GET/INT, Evry, France;GET/INT, Evry, France;France Telecom R&D, Issy-les-Moulineaux Cedex, France

  • Venue:
  • Proceedings of the 2006 international conference on Wireless communications and mobile computing
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Users roaming is an important feature to be provided by current ISPs. The goal is to allow users to access to the Internet from everywhere without the need to have multiple subscriptions.A suitable authentication and key distribution mechanism between different domains involved is required to provide a secure network access service. The IETF solution for this is the Extensible Authentication Protocol (EAP) which supports various authentication methods while defining a keying framework. However, this framework suffers from some limitations in roaming scenario, specially in a mobility context. The reason is that each time the visited network needs to reauthenticate the client, the home domain must be contacted. This may introduce some consequent delay if the client is far from it.This paper proposes a new design which improves the current EAP keying distribution framework. The basic idea is to allow the visited domain to play a more active role in the key distribution. For this, we introduce a new level in the key hierarchy defined in the EAP keying framework. Thanks to this one, a new key can be used between the mobile and the visited network. This brings better performance during reauthentication as the home domain is no longer solicited.