In ALLJOYN_SRP_KEYX auth mechnism, how do clients know password?

I'm reading following link, and I have a question about ALLJOYN_SRP_KEYX.


Provider app may read password from an text file.

Consumer app may read password from client user.

Should both passwords be same? If so, how do clients know password?

Should clients check password from devices' LCD or something like that?

you might try on the core mailing list. https://lists.allseenalliance.org/mailman/listinfo/allseen-core

ry.jones ( 2015-08-07 20:56:23 -0700 )

1 answer

Yes. For Secure Remote Password (SRP) protocol based authentication to be successful, passwords at both end should be identical.

The clients are expected to know the password via out-of-band mechanism (for eg. prior knowledge / agreement).

Note: If you do not want to use any prior agreement, you will have to go for a public-key based authentication mechanism viz. ALLJOYN_ECDHE_ECDSA.

