An EAP Authentication Method Based on the Encrypted Key Exchange Protocol
RFC 6124, “An EAP Authentication Method Based on the Encrypted Key Exchange Protocol”, is an Informational document published in February 2011 by Y. Sheffer, G. Zorn, H. Tschofenig, S. Fluhrer. The canonical text is published by the RFC Editor.
Abstract
The Extensible Authentication Protocol (EAP) describes a framework that allows the use of multiple authentication mechanisms. This document defines an authentication mechanism for EAP called EAP-EKE, based on the Encrypted Key Exchange (EKE) protocol. This method provides mutual authentication through the use of a short, easy to remember password. Compared with other common authentication methods, EAP-EKE is not susceptible to dictionary attacks. Neither does it require the availability of public-key certificates. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 6124 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6123 Inclusion of Manageability Sections in Path Computation Element Working Group Drafts
- RFC 6125 Representation and Verification of Domain-Based Application Service Identity within Internet Public Key Infrastructure Using X.509 Certificates in the Context of Transport Layer Security
- RFC 6122 Extensible Messaging and Presence Protocol : Address Format
- RFC 6126 The Babel Routing Protocol
- RFC 6121 Extensible Messaging and Presence Protocol : Instant Messaging and Presence
- RFC 6127 IPv4 Run-Out and IPv4-IPv6 Co-Existence Scenarios
- RFC 6120 Extensible Messaging and Presence Protocol : Core
- RFC 6128 RTP Control Protocol Port for Source-Specific Multicast Sessions