| 1. A method of communication involving a supplicant, an authenticator, and an authentication server having an established
security association based on a first key, the supplicant and the authenticator having an established security association
based on a second key, the method being implemented in the authenticator and comprising:
receiving a challenge response from the supplicant over an air interface in response to transmitting a first challenge to
the supplicant over the air interface, wherein the challenge response includes a second challenge generated by the supplicant
and a first message authentication code determined using the first key, the first challenge, and the second challenge;
if the challenge response from the supplicant is valid, modifying the second key using the first key, the first challenge,
and the second challenge.
|