eap-9----Page:10
1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  16 

Protected OTP Computation Client Side
OTP
Salt* | Pepper | AuthData*
PBKDF2-SHA256
Iteration Count*
K_Mac | K_Enc | MSK | EMSK
16 | 16 | 64 | 64
EAP Request Message
SHA256
HMAC-SHA256
msg_hash1
AuthMac[16]*
Key Len=160
• All * values sent in response
• OTP and Pepper values not sent, Pepper bit length sent
PKCS #5 V2.0
PPT Version