Credential provisioning and device configuration with EAP

S Boire, T Akgün, P Ginzboorg, P Laitinen… - Proceedings of the 19th …, 2021 - dl.acm.org
S Boire, T Akgün, P Ginzboorg, P Laitinen, S Tamrakar, T Aura
Proceedings of the 19th ACM International Symposium on Mobility Management …, 2021dl.acm.org
The Extensible Authentication Protocol (EAP) is used for authenticating client devices to
WiFi networks, and it is designed to be extensible with new authentication methods. We look
at ways to extend the protocol to support credential provisioning and configuration of new
client devices. As large numbers of IoT devices are deployed, the task will be simplified by
combining the network connectivity, identity and certificate provisioning, and application-
layer connectivity to one process. The solution will also allow the use of a one-time …
The Extensible Authentication Protocol (EAP) is used for authenticating client devices to WiFi networks, and it is designed to be extensible with new authentication methods. We look at ways to extend the protocol to support credential provisioning and configuration of new client devices. As large numbers of IoT devices are deployed, the task will be simplified by combining the network connectivity, identity and certificate provisioning, and application-layer connectivity to one process. The solution will also allow the use of a one-time credential for the initial authentication, so that the long-term device certificate is issued automatically after the first connection to the network. The paper analyzes the requirements and architectural design options that implement such a user experience. We consider solutions that transfer short bootstrapping data inside the EAP session and then implement the provisioning and configuration with web APIs over HTTPS. This allows future flexibility and speed of development in the provisioning and configuration steps. We designed and implemented several architecturally different solutions and present the comparison results and also compare with previous proposals that have similar goals.
ACM Digital Library
Showing the best result for this search. See all results