194 Software Networks
Schematically, an EAP card provides the following four services:
– multiple-identity management: the card holder can use several
wireless networks. Each of those networks requires an authentication
triplet: EAP-ID (value delivered in the message EAPRESPONSE.IDENTITY), EAP-Type (type of authentication protocol
supported by the network) and cryptographic credits – i.e. the set of
keys or parameters used by a particular protocol (EAP-SIM, EAPTLS, MS-CHAP-V2, etc.). Each triplet is identified by a name (the
identity), which can have multiple interpretations (SSID, account
username, mnemonic, etc.);
– assignment of an identity to the card: the card’s identity is
contingent upon the host network. Internally, the card may possess
several identities, and adapt to the network to which the PC and the
smartcard are connected;
– processing of EAP messages: as the smartcard possesses a
processor and memory, it can execute code and process the EAP
messages received and send such messages in response;
– calculation of the unicast key: once the authentication session has
been completed, the EAP tunnel can be used for the transmission of
diverse types of information, such as keys or profiles. It is possible to
transmit a session key, for example, and make it available to the
terminal wishing to access the resources of the wireless network.
Figure 7.3 illustrates an authentication procedure between an
authentication server and an EAP smartcard. The flow of commands
passes through the software programs on the PC – i.e. first the EAP
software entity, which simply transmits the EAP packets to the
RADIUS server, on the one hand, and to the smartcard, on the other –
followed by the machine’s operating system, which handles the
interface with the smartcard, and finally the IEEE 802.11 interface of
the wireless link.
To improve security, it is possible to insert chip cards on the server
end as well, so that the EAP-TLS algorithm from the authentication
server is also run on the chip card. With new chip cards that can store
up to 1 Gb, it is possible to memorize the logs needed for traceability.
www.it-ebooks.info
Schematically, an EAP card provides the following four services:
– multiple-identity management: the card holder can use several
wireless networks. Each of those networks requires an authentication
triplet: EAP-ID (value delivered in the message EAPRESPONSE.IDENTITY), EAP-Type (type of authentication protocol
supported by the network) and cryptographic credits – i.e. the set of
keys or parameters used by a particular protocol (EAP-SIM, EAPTLS, MS-CHAP-V2, etc.). Each triplet is identified by a name (the
identity), which can have multiple interpretations (SSID, account
username, mnemonic, etc.);
– assignment of an identity to the card: the card’s identity is
contingent upon the host network. Internally, the card may possess
several identities, and adapt to the network to which the PC and the
smartcard are connected;
– processing of EAP messages: as the smartcard possesses a
processor and memory, it can execute code and process the EAP
messages received and send such messages in response;
– calculation of the unicast key: once the authentication session has
been completed, the EAP tunnel can be used for the transmission of
diverse types of information, such as keys or profiles. It is possible to
transmit a session key, for example, and make it available to the
terminal wishing to access the resources of the wireless network.
Figure 7.3 illustrates an authentication procedure between an
authentication server and an EAP smartcard. The flow of commands
passes through the software programs on the PC – i.e. first the EAP
software entity, which simply transmits the EAP packets to the
RADIUS server, on the one hand, and to the smartcard, on the other –
followed by the machine’s operating system, which handles the
interface with the smartcard, and finally the IEEE 802.11 interface of
the wireless link.
To improve security, it is possible to insert chip cards on the server
end as well, so that the EAP-TLS algorithm from the authentication
server is also run on the chip card. With new chip cards that can store
up to 1 Gb, it is possible to memorize the logs needed for traceability.
www.it-ebooks.info
