02.11.2012 Views

Handover mechanisms in next generation heterogeneous wireless ...

Handover mechanisms in next generation heterogeneous wireless ...

Handover mechanisms in next generation heterogeneous wireless ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SECURITY FOR HANDOVER ACROSS HETEROGENEOUS WIRELESS NETWORKS<br />

value is used to authenticate the reply from the RADIUS server, and is used <strong>in</strong> the<br />

password hid<strong>in</strong>g algorithm. The IETF specification for RADIUS [49] suggests that the<br />

response authenticator that is <strong>in</strong>cluded <strong>in</strong> Access-Accept, Access-Reject, and Access-<br />

Challenge messages can be calculated us<strong>in</strong>g one-way MD5 hash:<br />

ResponseAuth = MD5(Code, ID, Length, Request Authenticator, Attributes,<br />

Shared secret)<br />

Figure 3.8 RADIUS message format<br />

The transmission of EAP messages over a AAA protocol can be supported by another<br />

specification - RADIUS support for EAP (RFC 3579, [59]). The EAP-RADIUS<br />

framework allows EAP messages to be embedded <strong>in</strong>side RADIUS attributes. Two new<br />

attributes, EAP-Message and Message-Authenticator, have been <strong>in</strong>troduced <strong>in</strong> the EAP-<br />

RADIUS specification [59] for such purpose. The basic mechanism of carry<strong>in</strong>g EAP<br />

messages over RADIUS is expla<strong>in</strong>ed as follows. The EAP request from a RADIUS<br />

server to a supplicant is <strong>in</strong>cluded <strong>in</strong> a RADIUS Access-Challenge message by<br />

encapsulation. The NAS decapsulates the RADIUS Access-Challenge, and obta<strong>in</strong>s the<br />

EAP request, which is then sent to the supplicant through l<strong>in</strong>k layer protocols. The EAP<br />

response can be delivered to the RADIUS server us<strong>in</strong>g a RADIUS Access-Request<br />

message <strong>in</strong> the same manner.<br />

- 49 -

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!