Feedback

Faculté des Sciences appliquées
Faculté des Sciences appliquées
MASTER THESIS

OpenRoaming : Evaluation of the potential of e-ID as an Identity Provider in the OpenRoaming federation and implementation of a prototype

Download
Maes, Marie ULiège
Promotor(s) : Donnet, Benoît ULiège
Date of defense : 24-Jan-2025 • Permalink : http://hdl.handle.net/2268.2/22432
Details
Title : OpenRoaming : Evaluation of the potential of e-ID as an Identity Provider in the OpenRoaming federation and implementation of a prototype
Translated title : [fr] OpenRoaming : Évaluation du potentiel d'e-ID en tant que fournisseur d'identité dans la fédération OpenRoaming et mise en œuvre d'un prototype
Author : Maes, Marie ULiège
Date of defense  : 24-Jan-2025
Advisor(s) : Donnet, Benoît ULiège
Committee's member(s) : Brinckman, Bart 
Leduc, Guy ULiège
Mathy, Laurent ULiège
Language : English
Number of pages : 119
Keywords : [en] OpenRoaming
[en] e-ID
[en] Identity Provider
[en] Wi-Fi
Discipline(s) : Engineering, computing & technology > Computer science
Funders : Cisco
Target public : Researchers
Professionals of domain
Student
Institution(s) : Université de Liège, Liège, Belgique
Degree: Master : ingénieur civil en informatique, à finalité spécialisée en "computer systems security"
Faculty: Master thesis of the Faculté des Sciences appliquées

Abstract

[en] In an era of growing need for network connectivity, the traditional public Wi-Fi infrastructures face
major limitation as they are either insecure or inconvenient if they require manual logins. To address
these security and accessibility challenges, many Wi-Fi networks are now integrating with Identity
Providers (IDP) and Access Network Providers (ANP). The IDP securely manages user identities
and credentials, enabling more reliable and secure Wi-Fi access using user authentication, while
the ANP manages network resources. OpenRoaming is a federation that enables easy Wi-Fi access
across IDPs and ANPs.
The goal of this project is to evaluate how e-ID, the Belgian electronic identity card, can become
an IDP in the OpenRoaming federation so that citizens can get seamless and secure Wi-Fi access
using their e-ID credentials. This integration enables citizens who authenticate with their e-ID
credentials via a mobile application to gain secure Wi-Fi access in government buildings and private
venues without any manual configuration or interaction with their phone’s Wi-Fi settings.
The project consists of three phases: (1) a theoretical study of OpenRoaming, e-ID, and related
technologies, (2) the evaluation of potential approaches to integrate e-ID as an IDP, and finally
(3) the development of a prototype. The components involved in this prototype include (a) a
mobile application for the user to authenticate with e-ID, (b) an access point for managing Wi-Fi
connections and forwarding authentication requests from the users, (c) a AAA server that includes
an EAP/RADIUS server to communicate with the access point and a back-end server that will
communicate with the IDP, and finally, (d) the IDP.
The final prototype demonstrates a secure and user-friendly system in which an Android device,
after successfully being authenticated via the mobile application, seamlessly connects to previously
unknown Wi-Fi networks in a safe environment. This is achieved through a robust configuration
involving WPA2 Enterprise, EAP-TTLS with PAP over a RADSEC tunnel, OpenID Connect, and
the use of certificates across all components.
This project successfully highlights how e-ID can become a reliable IDP in the OpenRoaming
federation, addressing modern connectivity challenges while ensuring a secure user experience.


File(s)

Document(s)

File
Access OpenRoaming_TFE.pdf
Description: Report for the OpenRoaming Thesis
Size: 5.06 MB
Format: Adobe PDF

Author

  • Maes, Marie ULiège Université de Liège > Master ing. civ. inf. fin. spéc. comp. syst. secur

Promotor(s)

Committee's member(s)

  • Brinckman, Bart
  • Leduc, Guy ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Réseaux informatiques
    ORBi View his publications on ORBi
  • Mathy, Laurent ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Systèmes informatiques répartis et sécurité
    ORBi View his publications on ORBi








All documents available on MatheO are protected by copyright and subject to the usual rules for fair use.
The University of Liège does not guarantee the scientific quality of these students' works or the accuracy of all the information they contain.