eap-10----Page:13
1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  16  17  18 

Solution Approaches
Add Binding Phase to EAP base protocol or Tunnel Protocol
Already need for protected success/failure indication identified
Binding Phase exchange can also include the protected success/failure indication
Method Key export interface available
Cryptographic binding can give stronger keys
Add Policy rules to Client and Server
Provides fix for non-key deriving methods
PPT Version