Wireless

19 Apr 2025


Extensible Authentication Protocol

EAP Types

EAP Types are specific authentication methods that operate within the Extensible Authentication Protocol (EAP) framework. EAP is a container or transport framework that supports multiple types of authentication, each defined as a "type."

EAP Over PPP

EAP over 802.1X

Housing Price Data
EAPOL Carrying EAP(credit https://en.wikipedia.org).

802.1X

802.1X components
802.1X components(credit https://www.enea.com).
802.1X
802.1X (credit www.ciscozine.com).

Once authenticated and port access is granted, data transmitted over the network can be encrypted by the Authenticator with WPA2/WPA3 to ensure confidentiality and integrity. When the supplicant wants to log off, an EAPOL-Logoff message can be sent to unauthorize the port.

WPA2/WPA3 with 802.1X

Tunneled and Non-tunneled EAP Types

802.1X Phases for wireless secure communication

4-way handshake with EAPOL

4 Way Handshake
4 Way Handshake (credit https://wirelessgnan.wordpress.com).

MSK (Master Session Key) derivation

PMK (Pairwise Master Key) derivation

GMK (Group Master Key) derivation

4-way handshake - Key derivaton

Keys generated during 4 Way Handshake

The Key Hierarchy is explained below:

Key Hierarchy
Key Hierarchy (credit www.wifi-professionals.com).

The Key generation is explained below:

Key Hierarchy
4 Way Handshake and Keys (credit www.wifi-professionals.com).

802.1X example with EAP-PEAP

PEAP
PEAP (credit www.thenetworkdna.com).

802.1X example with EAP-TLS

EAP TLS
EAP TLS (credit www.mrncciew.com).

WiFi Standards evolution

Security Evolution Alongside