ZyXEL Communications PLA-470 V2 - V3.0.5 Przewodnik Instalacji Strona 100

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 349
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 99
RADIUS and Diameter
802.1x does not define a particular authentication protocol on the server side. Two cli-
ent-server authentication protocols, RADIUS and Diameter, can be used. The simplest one,
RADIUS, has become the default server of any 802.1x architecture. The main constraint of
diameter is that it is based on the SCTP (Stream Control Transmission Protocol) transport
layer which is not implemented as much as TCP.
EAP (Extensible Authentication Protocol)
EAP was defined originally for the PPP (point-to-point protocol) as an extension to
the existing PAP (password authentication protocol) and CHAP (challenge hand-
shake authentication protocol). Compared with these two protocols, EAP provides
many authentication methods in a relatively simple way. This simplicity is due to
the fact that EAP is only an envelope for the transport of these authentication
methods.
Within the framework of a 802.1x PLC architecture, five EAP authentication
methods are used:
EAP-MD5. This solution is based on the hash function (MD5). For authenti-
cation, the user gives a login-password, the MD5 digest of which is transmit-
ted for authentication purposes to the server. This solution is deemed not to be
very reliable though only the digest is transmitted over the network and not
the login-password. It is no longer supported by Windows XP SP1.
EAP-TLS. TLS (transport layer security) is a mechanism used to implement a
secured connection. The mutual authentication between the client and the
server, the data encryption, and the dynamic management of keys constitute
its functionalities. TLS is the basis of SSL 3.0, which is found in HTTPS, a pro-
tocol used by many Web sites (banks, online reservation sites, and so forth).
IEEE 802.1x and Improvements to PLC Network Security 81
Figure 4.13 IEEE 802.1x authentication architecture
Przeglądanie stron 99
1 2 ... 95 96 97 98 99 100 101 102 103 104 105 ... 348 349

Komentarze do niniejszej Instrukcji

Brak uwag