Lightweight Authentication Mode with Header Authentication IEEE 802.16 Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-08/907r1.

Slides:



Advertisements
Similar presentations
Reduced Signaling Overhead for Retransmissions on the UL of m IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-07/250.
Advertisements

ProjectIEEE Broadband Wireless Access Working Group TitleUplink Pilot Structure for IEEE802.16m Date Submitted
Interference Mitigation by Initial Configuration for Femtocell Access Points in IEEE802.16m Network IEEE Presentation Submission Template (Rev.
802.16m Frame Structure: Uplink Subframe Aggregation IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-08/099 Date Submitted:
Relative Timing of Super-Frames in the Legacy-Support Mode IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-08/244.
Macro Diversity for E-MSB IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-08/981r1 Date Submitted: Source:
IEEE C802.16m-08/539 Coding for IEEE802.16m Document Number: IEEE C802.16m-08/539 Date Submitted: Source: Mohammed Nafie, Cairo University Ahmed.
Common Header design in m IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/0178 Date Submitted: Source:
1 Assignment A-MAP for Multicarrier Operation (AWD-MCDG) Document Number: C80216m-09/1222 Date Submitted: Source: Lei Huang Panasonic Singapore.
8Tx Dedicated Pilot Pattern Simulation Results IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/0805 Date Submitted:
8Tx Pilot Pattern Performance for IEEE m IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/0544 Date Submitted:
Analysis of BR preamble selection strategies in 5-step BR procedure IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C80216m-10_1249r1.
Proposed Feature Rapporteur Group Timelines and Call for contributions IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/0762r2.
1 Idle mode operation for supporting FemtoCells Document Number: IEEE C802.16m-08/1433 Date Submitted: Source: Giwon Park, Rony Yongho Kim,
Network Entry Procedure with Multi-Carrier Support Document Number: IEEE C802.16m-09/0966 Date Submitted: 2009/04/27 Source: I-Kang Fu, Yih-Shen Chen,
Text Proposals of HR-MS Forwarding in 16n Network IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16n-11/0074 Date Submitted:
Extended MAC Header for System Information Update Notification ( ) Document Number: IEEE C80216m-10/0212 Date Submitted: Source: Yih-Shen.
Uplink Pilot Structure for IEEE802.16m Document Number: IEEE C802.16m-08/293r4 Date Submitted: Source: Mohammed Nafie, Cairo University Mohamed.
Sleep Mode Configuration via BR Header ( ) Document Number: IEEE C80216m-09/2297 Date Submitted: Source: Yih-Shen Chen, Kelvin Chou,
1 Proposal for Multicarrier Uplink Control Structure IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-08/303r3 Date.
Uplink Control Information Content for Bandwidth Request Channel IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/0401.
Notice: This document does not represent the agreed views of the IEEE Working Group or any of its subgroups. It represents only the views of the.
MAC Header Design Analysis for Upper MAC IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-08/896 Date Submitted:
Bit selection and repetition IEEE Presentation Submission Template (Rev. 9) Document Number: C80216m-08_1271 Date Submitted: Source:
Preamble Requirements in IEEE802.16m IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-08/485 Date Submitted:
1 DL Unicast Service Control Channel Structure and High Level Design Document Number: IEEE C80216m-08/1270 Date Submitted: Source: Yi Hsuan,
C80216m-08_216 ProjectIEEE Broadband Wireless Access Working Group TitleDownlink Physical Resource Allocation Unit Date Submitted.
Multiple-User Unsolicited Grant Service (UGS) Slot IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-07/261 Date Submitted:
New Fast Power Control IE for CLPC Document Number: IEEE S802.16maint-08/068 Date Submitted: Source: Jungnam Yun
Notice: This document does not represent the agreed views of the IEEE Working Group or any of its subgroups. It represents only the views of the.
Synchronization Drafting Group Schedule Document Number: IEEE C802.16m-09/0379 Date Submitted: Source: Paul Cheng
Femtocell Over-The-Air Signaling Supported by Relay Link Document Number: IEEE C802.16m-09/0809 Date Submitted: 2009/04/24 Source: Hung-Yu Wei, Shih-Lung.
MCS Adaptation and Feedback Mechanism in m MBS IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S80216m-08/1151 Date Submitted:
Backward Compatible FDD m Frame Structure for Full-Duplex and Half-Duplex MS Operations Document Number: S802.16m-08/031r2 Date Submitted: January.
Group Sleep Mode in IEEE m IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-08/591r3 Date Submitted:
DL Preamble Design for m Document Number: IEEE S802.16m-08/385 Date Submitted: Source: Sun Changyin, Liu Min, Wang Wenhuan,Yao
TDD frame structure for m with legacy support IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S80216m-07/215r1 Date Submitted:
Session #57 Security Contribution Summary IEEE Presentation Submission Template (Rev. 9) Document Number: C802.16m-08/1223r2 Date Submitted:
HARQ Buffer Management for Aggressive HARQ transmission IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-09/0891r1.
Definition of Device Collaboration Mode for Low Power Consumption IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16p-10_0030.
Hybrid ARQ for synchronous allocation in distributed subcarrier mode Document Number: S80216m-08_290r1 Date Submitted: Source: Alexei Davydov.
Proposal on Full L3 Relay Document Number: IEEE S802.16m-09_2443 Date Submitted: Source: Yuqin Chen, Mary Chion, Yang Liu
Performance Evaluation of Transformation Codebook for 8TX IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/2731.
TDD Frame Structures for Legacy Support in 16m IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-07/242r1, TDD Frame.
Femto BS coexistence with WiFi-AP IEEE Presentation Submission Template (Rev. 9) Document Number: [IEEE C802.16m-08/1309r1] Date Submitted: [ ]
1 Power Saving Considerations for IEEE m Femtocell IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-08/1411 Date.
Collaborative uplink MIMO techniques for IEEE m Document Number: C80216m-08/638 Date Submitted: 7/7/2008 Source: Mohamed Abdallah Mohammed Nafie.
Multi-Level Codes Sequence for Simultaneous MCS Feedback IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S80216m-08/1152 Date.
Project Planning Committee (PPC): Session #70 WG Opening Plenary Report IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE.
1 Modifications on Subband (SB) Partitioning Equations ( and ) IEEE Presentation Submission Template (Rev. 9) Document Number:
Dynamic Subcarrier/Subchannel Allocation for Interference Mitigation in IEEE802.16m Networks IEEE Presentation Submission Template (Rev. 9) Document.
Clarification on Temporary Identifier of Idle AMS IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/0839r2 Date Submitted:
[A Reliable Multicast Service in m]
Uplink Pilot Structure for IEEE802.16m
Discussion of Explicit vs. Implicit PC-A-MAP IE Assignment (15.2.3)
A transmission scheme of DL Control information
IEEE Presentation Submission Template (Rev. 9) Document Number:
IEEE Presentation Submission Template (Rev. 9) Document Number:
Project Planning Committee Opening Report
MCS signaling for reducing MAP overhead
Uplink Subframe Aggregation
Resource Shifting in Persistent Scheduling
Uplink Subframe Aggregation
Compressed MAC PDU Overhead
IETF 16ng Working Group Update
Network Coding Retransmission Design with Common Feedback Channel
Bandwidth Request Indicator
Network Synchronization Considerations for n
Text Proposals of PHY Control Structure for 16n Direct Communication
ARQ protocol in m IEEE Presentation Submission Template (Rev. 9)
Presentation transcript:

Lightweight Authentication Mode with Header Authentication IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-08/907r1 Date Submitted: Source: Susan Hartman Intel Corporation David Johnston Intel Venue: Call for Contributions, IEEE m-08/033 Base Contribution: Re: MAC: Security Purpose: To improve the signaling overhead in management traffic introduced by integrity protection mechanisms. Notice: This document does not represent the agreed views of the IEEE Working Group or any of its subgroups. It represents only the views of the participants listed in the “Source(s)” field above. It is offered as a basis for discussion. It is not binding on the contributor(s), who reserve(s) the right to add, amend or withdraw material contained herein. Release: The contributor grants a free, irrevocable license to the IEEE to incorporate material contained in this contribution, and any modifications thereof, in the creation of an IEEE Standards publication; to copyright in the IEEE’s name any IEEE Standards publication even though it may include portions of this contribution; and at the IEEE’s sole discretion to permit others to reproduce in whole or in part the resulting IEEE Standards publication. The contributor also acknowledges and accepts that this contribution may be made public by IEEE Patent Policy: The contributor is familiar with the IEEE-SA Patent Policy and Procedures: and. Further information is located at and.

Lightweight Authentication Mode with Header Authentication Susan Hartman, Intel Corporation David Johnston, Intel Corporation Background and Motivation: Security in 16m is necessary but has cost (bandwidth usage). In particular, the CMAC TLV provides authentication but adds 15 bytes to most management messages. In 16e the signaling headers do not include CMAC for authentication, thus leaving the system open to Denial-of- Service attacks. The minimum 16e radio resource allocation for MAC messages is 6 bytes leaving no room for CMAC. MAC Signalling headers are employed with no integrity protection. This creates a number of serious DoS opportunities. E.G. by spoofing incorrect information on the channel quality. From a security standpoint there are essentially two system operating modes: Under Attack Not Under Attack This proposal has two related security ideas: 1.Take advantage of the two operating modes and use a Partial CMAC TLV when Not Under Attack. When Under Attack, use the full CMAC TLV. 2.Add a CMAC TLV or Partial CMAC TLV to the MAC signaling headers. The necessary details are explained in the following text.

Reminder: the 16e CMAC Tuple Value Notice that there is a small terminology issue here with the term “CMAC Value”. Table 603 shows “Value” portion of Type, Length, Value, and the last item in the table is also called “CMAC Value”.

Proposed Partial CMAC Tuple Type and Value, omit LengthType and Value, omit Length Include partial (12 bits) CMAC Value in messageInclude partial (12 bits) CMAC Value in message (BSID never needed)(BSID never needed) Could also possibly shorten Packet Number CounterCould also possibly shorten Packet Number Counter Total length of TV: 7 bytesTotal length of TV: 7 bytes

PARTIAL CMAC TV IN SIGNALING HEADERS Assume that the 16m MAC signaling headers provide 12 data bytes: The proposed 16m Physical Resource Unit (PRU) has 18 subcarriers x 6 symbols. 6 subcarriers are pilots, which are allocated per stream. Assuming 2 streams for the baseline, there are 12 pilot subcarriers per PRU. As a result there are 18*6 = 108 subcarriers in a PRU and (18- 2)*6=96 data subcarriers per PRU. Using QPSK(1/2) as the Modulation and Coding Scheme (MCS) for transmission, then each subcarrier effectively carries 1 bit. The PRU carries 96 bits or 12 bytes = 5,  there are 5 bytes available for signaling header

SIGNALING AND OPERATION Security Operating Mode is indicated in BCH Under Attack: Full CMAC TV (Type, Value) MAC signaling headers are 2 PRUs (24 bytes) and have full CMAC TV Not Under Attack: Partial CMAC TV (Type, Value) – different type is used MAC signaling headers are 1 PRU (12 bytes) and have Partial CMAC TV Detecting Attacks: In management messages: if CRC is valid but Partial CMAC TV is invalid. In signaling headers: HCS is valid but Partial CMAC TV is invalid. BS can periodically check for continuing attack and resume Not Under Attack when it finds that attack does not continue.

SDD TEXT - Security Insert the following text into Medium Access Control Security section (Chapter 12): Text Start x System Security Operating Modes IEEE m has two system security operating modes: –Under Attack –Not Under Attack An authentication field is required in some MAC management messages (FFS) and all MAC signaling headers. IEEE802.16m provides an authentication field to use when under attack and a shorter version of the same authentication field to use when not under attack. BSs and MSs determines if an attack is in progress by noticing messages with correct CRC but incorrect authentication field. Similarly, BSs notices MS signaling headers with correct HCS but incorrect authentication field. MS informs BS about attack in progress and BS determines which authentication field shall be used. BS periodically tests to see if the attack has stopped and if it is OK to return to not under attack operation. BS includes logic so that it does not change back to not under attack such that the system constantly switches back and forth between the modes. BS indicates the security operating mode in the BCH. When not under attack, MAC signaling headers use partial CMAC tuple ; when under attack, MAC signaling headers use full CMAC tuple. A station may always choose to use the full CMAC tuple, even if the BS is signaling the Not Under Attack mode. The compressed message authentication tuple is as follows: Text End