Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSv0)

Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSv0)
复制标题

DOI:
10.17487/rfc5281
复制
发表时间:
2008-08
期刊:
RFC
影响因子:
--
通讯作者:
P. Funk;S. Blake-Wilson
P. Funk;S. Blake-Wilson
中科院分区:
其他
文献类型:
--
作者:
P. Funk;S. Blake-Wilson

文献摘要

被引文献

相似文献

EAP- ttls是一种EAP(可扩展身份验证协议)方法,它封装了一个TLS(传输层安全)会话,由握手阶段和数据阶段组成。在握手阶段,使用标准的TLS过程对服务器进行客户端身份验证(或客户端和服务器相互身份验证),并生成密钥材料,以便为后续数据阶段的信息交换创建加密安全隧道。在数据阶段,使用封装在安全隧道内的任意身份验证机制对客户端进行服务器身份验证(或客户端和服务器相互身份验证)。封装的身份验证机制本身可以是EAP,也可以是其他身份验证协议,如PAP、CHAP、MS-CHAP或MS-CHAP - v2。因此,EAP-TTLS允许对现有身份验证数据库使用基于密码的遗留身份验证协议,同时保护这些遗留协议的安全性,防止窃听、中间人攻击和其他攻击。数据阶段也可用于附加的、任意的数据交换。本备忘录为互联网社区提供信息。
EAP-TTLS is an EAP (Extensible Authentication Protocol) method that encapsulates a TLS (Transport Layer Security) session, consisting of a handshake phase and a data phase. During the handshake phase, the server is authenticated to the client (or client and server are mutually authenticated) using standard TLS procedures, and keying material is generated in order to create a cryptographically secure tunnel for information exchange in the subsequent data phase. During the data phase, the client is authenticated to the server (or client and server are mutually authenticated) using an arbitrary authentication mechanism encapsulated within the secure tunnel. The encapsulated authentication mechanism may itself be EAP, or it may be another authentication protocol such as PAP, CHAP, MS-CHAP, or MS- CHAP-V2. Thus, EAP-TTLS allows legacy password-based authentication protocols to be used against existing authentication databases, while protecting the security of these legacy protocols against eavesdropping, man-in-the-middle, and other attacks. The data phase may also be used for additional, arbitrary data exchange. This memo provides information for the Internet community.