EAP Key Derivation for Multiple Applications

Document Type Expired Internet-Draft (individual)
Authors Joseph Salowey  , Pasi Eronen 
Last updated 2003-10-27
Stream (None)
Intended RFC status (None)
Expired & archived
pdf htmlized (tools) htmlized bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


The Extensible Authentication Protocol (EAP) provides an extensible interface to various authentication mechanisms. Some EAP methods derive cryptographic material between the EAP peers; these keys can be used, for instance, with IEEE 802.11i encryption. This document proposes a mechanism that can be used to derive cryptographically separate keys for more than one cryptographic application, such as protecting subsequent EAP messages, distributing credentials for re- authentication, or handoff mechanisms involving multiple WLAN access points.


Joseph Salowey (jsalowey@cisco.com)
Pasi Eronen (pe@iki.fi)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)