Extensible Authentication Protocol (EAP) Authentication Using Only a Password

Dan Harkins, Glen Zorn · 2010

This memo describes an Extensible Authentication Protocol (EAP) method, EAP-pwd, which uses a shared password for authentication. The password may be a low-entropy one and may be drawn from some set of possible passwords, like a dictionary, which is available to an attacker. The underlying key exchange is resistant to active attack, passive attack, and dictionary attack. This document is not an Internet Standards Track specification; it is published for informational purposes.

Read the paper · More papers on PaperTik