FILS presentation on High Level Security Requirements

Slides:



Advertisements
Similar presentations
Doc.: IEEE /1436r0 Submission NameAffiliationsAddressPhone Robert Sun Huawei Technologies Co., Ltd. Suite 400, 303 Terry Fox Drive, Kanata,
Advertisements

Doc.: IEEE /0780r1 Submission NameAffiliationsAddressPhone Ping Fang Zhiming Ding Phillip Barber Rob Sun Huawei Technologies Co., Ltd. Bldg.
Submission doc.: IEEE ai May 2012 InterDigital, KDDI, Nokia, Huawei, Intel, Qcomm Slide 1 Proposed SFD Text for ai Passive Scanning.
Submission doc.: IEEE ai March 2012 InterDigital, KDDI, Nokia, Huawei, IntelSlide 1 Proposed SFD Text for ai Passive Scanning Improvement.
Doc.: IEEE /0547r1 Submission May 2012 Dapeng Liu, China MobileSlide 1 Extend 802.1X for higher layer configuration in FILS Date:
Doc.: IEEE /0158r2 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 Proposed Additions to SFD Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE / ai Submission NameAffiliationsAddressPhone Phillip BarberHuawei Technologies Co., Ltd Alma Rd, Ste 500 Plano,
Submission doc.: IEEE ai May 2012 Lei Wang, InterDigital CommunicationsSlide 1 Proposed SFD Text for ai AP/STA Initiated FILS Optimizations.
Doc.: IEEE /278r0 Submission NameAffiliationsAddressPhone Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin.
Doc.: IEEE /0080r0 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 AP Admission Control in TGai Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0269r1 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu,
Access Control Mechanism for FILS
Omission of Probe Request
Month Year doc.: IEEE yy/xxxxr0 May 2012
AP discovery with FILS beacon
Proposed SFD Text for ai Link Setup Procedure
Discussions on FILS Authentication
TGai Guideline for Submissions to TGai Template Slides
Triggering the Broadcast Probe Response
AP Discovery Information Broadcasting
Fast Authentication in TGai
Triggering the Broadcast Probe Response
Differentiated Initial Link Setup (Follow Up)
EAP based Message Flow Optimization for FILS
Multi-channel information for AP discovery
TGai FILS Authentication Protocol
Using Upper Layer Message IE in TGai
Improvement on Active Scanning
Multiple Frequency Channel Scanning
FILS Association Date: Authors: Name Affiliations Address
Fast Authentication in TGai
AP discovery with FILS beacon
MLME.SCAN-request Date: Authors: Nov 2012 Month Year
Scanning from Specific Channel
GAS procedure in TGai Date: Authors: Mar 2012 Month Year
Access Control Mechanism for FILS
AP discovery with FILS beacon
AP discovery with FILS beacon
Reducing the Probe Response transmission
Band adjustment for fasat AP discovery
Listen to Probe Request from other STAs
Using Upper Layer Message IE in TGai
Discussion for 11ah Functional Requirements
Proposed SFD Text for ai Prioritized Active Scanning
Access Control Mechanism for FILS
Reducing Overhead in Active Scanning with Simulation Results
Prioritized Active Scanning in TGai
Access distribution in ai
Fast Authentication in TGai
Access Control Mechanism for FILS
Performance Analysis of authentication and authorization
Reducing Overhead in Active Scanning with Simulation Results
Differentiated Association Service Provisioning in WiFi Networks
Triggering the Broadcast Probe Response
Traffic Information Dissemination Use Case
Fast Authentication in TGai
Month Year doc.: IEEE yy/xxxxr0 May 2012
Differentiated Initial Link Setup (Follow Up)
Omission of Probe Request
Access distribution in ai
Proposed SFD Text for ai Prioritized Active Scanning
Scanning from Specific Channel
Fast passive scan for FILS
Multiple Frequency Channel Scanning
Reducing Overhead in Active Scanning
GAS procedure in TGai Date: Authors: May 2012 Month Year
Reducing Overhead in Active Scanning
MLME.SCAN-request Date: Authors: Nov 2012 Month Year
Reducing Probe Responses for faster AP discovery
Month Year doc.: IEEE yy/xxxxr0 May 2012
Presentation transcript:

FILS presentation on High Level Security Requirements Month Year doc.: IEEE 802.11-yy/xxxxr0 March 2012 FILS presentation on High Level Security Requirements Date: 2012-03-14 Authors: Name Affiliations Address Phone email Rob Sun Huawei Technologies Co., Ltd. Suite 400, 303 Terry Fox Drive, Kanata, Ontario K2K 3J1 +1 613 2871948 Rob.sun@huawei.com Ping Fang Bldg 7, Vision Software Park, Road Gaoxin Sourth 9, Nanshan District, Shenzhen, Guangdong, China, 518057 +86 755 36835101 ping.fang@huawei.com Zhiming Ding +86 755 36835837 dingzhiming@huawei.com Huawei John Doe, Some Company

Month Year doc.: IEEE 802.11-yy/xxxxr0 March 2012 Abstract This document proposes text to be inserted in TGai Specification Framework Document (SFD) regarding FILS state machine. Huawei John Doe, Some Company

Conformance w/ Tgai PAR & 5C April 2009 doc.: IEEE 802.19-09/xxxxr0 March 2012 Conformance w/ Tgai PAR & 5C Conformance Question Response Does the proposal degrade the security offered by Robust Security Network Association (RSNA) already defined in 802.11? No Does the proposal change the MAC SAP interface? Does the proposal require or introduce a change to the 802.1 architecture? Does the proposal introduce a change in the channel access mechanism? Does the proposal introduce a change in the PHY? Which of the following link set-up phases is addressed by the proposal? (1) AP Discovery (2) Network Discovery (3) Link (re-)establishment / exchange of security related messages (4) Higher layer aspects, e.g. IP address assignment 3 Huawei Rich Kennedy, Research In Motion

Re-caps of related contributions March 2012 Re-caps of related contributions 12/39r2 FILS Authentication Protocol Modified 802.11 Authentication and Association State Machine for FILS Huawei

Modification to 802.11 Authentication and Association State Machine March 2012 Modification to 802.11 Authentication and Association State Machine State 1 Unauthenticated, Unassociated Class 1 Frames FILS Deauthentication Deauthentication Successful 802.11 Authentication Successful FILS Authentication State 2 Authenticated, Unassociated Class 1 & 2 Frames Successful (Re)Association –RSNA Required Deassociation State 5 Unsuccessful (Re)Association (Non-AP STA) FILS Authenticated/Unassociated Class 1 & 2 Frames With Selected Management & Data Frames State 3 Authenticated, Associated (Pending RSN Authentication) Class 1 ,2 & 3 Frames IEEE 802.1X Controlled Port Blocked Successful 802.11 Authentication Deauthentication Successful FILS Association 4- way Handshake Successful Unsuccessful (Re)Association (Non-AP STA) Deauthentication State 4 Disassociation Authenticated, Associated Class 1 ,2 & 3 Frames IEEE 802.1X Controlled Port UnBlocked Successful 802.11 Authentication Successful (Re) Association No RSNA required or Fast BSS Transitions Slide 5 Huawei

Temporary State 5 (FILS Authenticated/Unassociated) March 2012 Temporary State 5 (FILS Authenticated/Unassociated) Upon successful FILS authentication, both the STA and AP shall transition to FILS Authenticated/unassociated state STA at FILS Authenticated/Unassociated state , it allows Class 1,2 and selected Data frames piggybacked over Class 1 &2 frames to be transmitted Upon receipt of a De-authentication frame from either STA or AP STA with reasons, the STA at the FILS Authenticated/Unassociated state will be transitioned to State 1. STA transitioned back to State 1 may retry with FILS authentication or use the RSNA authentication Upon successful FILS Association, the STA shall transition to state 4 which allows full class 1, 2 and 3 frames to pass through. Selected Management Frames and Data Frames Reasons EAPOL message with EAP Packet To carry out the EAP full authentication IP assignment To enable the parallel IP assignment to take place Huawei

Motion for proposed text for SFD March 2012 Motion for proposed text for SFD Motion: Add the following text (proposed in 248r0 ) to Clause 3 “Security Framework” of TGai SFD, 12/0151 R.3.A: The draft specification shall include support for the optimized 802.11 FILS state machine to enable the FILS authentication and other data frame parallel processing. Moved: Seconded: Results: Yes No Abstain Huawei