Doc.: Submission, Slide 1 Project: IEEE P802.15 Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Securing the 802.15.4 Network.

Slides:



Advertisements
Similar presentations
Doc.: IEEE xxxxx Submission doc. : IEEE Slide 1 Junbeom Hur and Sungrae Cho, Chung-Ang University Project: IEEE P
Advertisements

Doc.: IEEE a-Updating-15-7-security Submission May 2015 Robert Moskowitz, HTT ConsultingSlide 1 Project: IEEE P Working Group for.
Doc.: Submission, Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [LB97 PICS Scrub] Date Submitted:
Doc.: IEEE s Submission January 2015 Mineo Takai, Space-Time EngineeringSlide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE xxxxx Submission doc. : IEEE doc. : IEEE pac Nov 2012 Slide 1 Project: IEEE P Working.
Doc.: IEEE xxxxx Submission doc. : IEEE Nov 2012 Slide 1 Project: IEEE P Working Group for Wireless Personal Area.
Doc.: IEEE Submission, Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Reply.
Doc.: IEEE /0136r0 Submission March 2006 Abbie Mathew, NewLANS Project: IEEE P Working Group for Wireless Personal Area Networks Submission.
Doc.: IEEE Hop-Discuss Submission July 2014 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE PC_pc-opening-report Submission Mar 15, 2004 Glyn Roberts, STMicroelectronics, Inc & Brian Mathews (AbsoluteValue Systems)Slide.
July 2004 Jay Bain, Fearn Consulting doc.: IEEE /0379r0 Submission Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs)
Doc.: IEEE Submission November 2012 Sunggeun Jin (ETRI)Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks.
Doc.: IEEE HIP-over-TG9 Submission May 2012 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE Submission doc. : IEEE March 2009 Project: IEEE P Working Group for Wireless Personal Area Networks.
Doc.: IEEE l2r Submission September 2012 Norman Finn [Cisco] Slide 1 Project: IEEE P Working Group for Wireless Personal Area.
Doc.: IEEE /436r0 Submission November 2003 Vijay DhingraSlide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs)
Doc.: IEEE Submission January 2016 Ed Callaway, ARM, Inc.Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs)
Doc.: IEEE kmp Submission September 2011 Robert Moskowitz, Verizon Slide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE Submission September 2013 Li, Hernandez, Dotlic, Miura, NICT Slide 1 Project: IEEE P Working Group for Wireless.
November 2011 Jin-Meng Ho and David Davenport. doc.: IEEE Slide 1Submission Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE xxxxx Submission doc. : IEEE Slide 1 Junbeom Hur and Sungrae Cho, Chung-Ang University Project: IEEE P
Doc.: IEEE Submission, Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Communicating.
Doc.: wng0> Submission Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Using Host.
Doc.: IEEE g TG4g Presentation Jan 2010 C.S. Sum1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs)‏
Doc.: IEEE c Submission July, 2005 Skafidas,Pollock,Saleem, NICTASlide 1 Project: IEEE P Working Group for Wireless Personal.
Doc.: IEEE e Submission July 2009 Andy Summers, Skip Ashton, EmberSlide 1 Project: IEEE P Working Group for Wireless Personal.
<November 2003> doc.: IEEE /486r0 <November 2003>
<month year> doc.: IEEE /271r0 September, 2000
Project: IEEE Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposals for adding a version number and for the treatment.
Project: IEEE Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposals for adding a frame version number and for the.
Submission Title: [Add name of submission]
<month year> doc.: IEEE < e> <Mar 2016>
June 2006 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposed Scenarios for Usage Model Document.
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Call for Proposals] Date Submitted:
doc.: IEEE <doc#>
October 2017 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [AES-256 for ] Date Submitted: [17.
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Call for Proposals] Date Submitted:
October 2017 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [AES-256 for ] Date Submitted: [17.
<month year> <doc.: IEEE doc> May 2015
<month year> <doc.: IEEE doc> January 2013
doc.: IEEE <doc#>
Project: IEEE Wireless Personal Area Networks (WPANs)
December 2, 2018 doc.: IEEE r0 May, 2004
March 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Toumaz response to TG6 Call for Applications]
March 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Call for Proposals] Date Submitted:
<May,2009> doc.: IEEE <doc .....> <July 2009>
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Submission Title: [Common rate resolution]
January 16, 2019 doc.: IEEE r0 September, 2004
<month year> doc.: IEEE < e> <November 2018>
January 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [SG SECN Call for Proposals] Date Submitted:
平成31年2月 doc.: IEEE /424r1 November 2007
Submission Title: [IEEE WPAN Mesh Reference Model]
July 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Extensions to IEEE in support of.
doc.: IEEE /XXXr0 Sep 19, 2007 June 2009
Submission Title: [Frame and packet structure in ]
November 2006 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Simplified geometry for the usage model.
<month year> doc.: IEEE < e> <November 2018>
July 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Extensions to IEEE in support of.
doc.: IEEE <doc#>
April 19 July 2010 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: WNG Closing Report for San Diego.
平成31年5月 doc.: IEEE /424r1 September 2007
doc.: IEEE <doc#>
Submission Title: [LB 28 Results] Date Submitted: [14 March 2005]
September 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Suggested TG3c PAR Changes] Date Submitted:
平成31年7月 doc.: IEEE /424r1 March 2007 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [TG3c Call.
平成31年7月 doc.: IEEE /424r1 November 2007
Doc.: IEEE Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Summary.
Submission Title: [Common rate resolution]
Presentation transcript:

doc.: Submission, Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Securing the Network Access x over ] Date Submitted: [11 May 2011] Source: [Jonathan Hui and Wei Hong] Company [Cisco Systems, Inc.] Address [170 West Tasman Drive, San Jose, CA USA] Voice:[ ], Re: [WNG] Abstract:[Problem statement and Call to action for supporting 802.1x over ] Purpose:[Presentation to WNG] Notice:This document has been prepared to assist the IEEE P It is offered as a basis for discussion and is not binding on the contributing individual(s) or organization(s). The material in this document is subject to change in form and content after further study. The contributor(s) reserve(s) the right to add, amend or withdraw material contained herein. Release:The contributor acknowledges and accepts that this contribution becomes the property of IEEE and may be made publicly available by P

doc.: Submission Securing the Network Access – 802.1x Over Jonathan Hui Wei Hong Cisco Systems, Inc., Slide 2

doc.: Submission IEEE Security Frame Security –Data confidentiality, Data authenticity, Replay protection Network Access Control –Defer to upper layer based on MAC address Security Suites –CCM* mode encryption and authentication transformation –AES block cipher What is specified today?

doc.: Submission IEEE Security Secure Network Access Control Architecture –Supplicant, Authenticator, and Authentication Server Protocols –Security Capabilities Discovery –Authentication –Secure Association/Key management Existing deployments use no or proprietary secure network access What is not specified today?

doc.: Submission IEEE Knows Network Access Control Well-defined Architecture –Supplicant, Authenticator, and Authentication Server Security Capabilities Discovery –RSN Information Element Authentication –Carry Extensible Authentication Protocol (EAP) in EAP over LAN (EAPoL) frames Secure Association/Key Management –EAP-derived PMK  PTK –Use PTK to communicate GTK Leverage IEEE 802.1x and IEEE i

doc.: Submission Typical 802.1x Architecture Authentication Server Authenticator Enforcement Point e.g. RADIUSEAPoL Auth Server: handles access requests from authenticators Access Point: device that performs authentication negotiations and acts as an Enforcement Point Supplicant: a device that wishes gain access to the network Supplicant

doc.: Submission What Needs to be Done Map EAPoL to IEEE frames Define operation where Supplicant and Authenticator are not within direct communication

doc.: Submission Extended for Multihop Networks Authentication Server Authenticator e.g. RADIUSEAPoL over 15.4 EAPoL Tunnel over IP Auth Server: handles access requests from authenticators Authenticator: device that performs authentication negotiations Enforcement Point: a device that has already been admitted into the network by the authenticator Supplicant: a device that wishes gain access to the network Supplicant Enforcement Point

doc.: Submission Why Not PANA? Architectural Issues –Enable (restricted) network-layer communication before allowing link-layer access Still need key management (e.g i) –4-way handshake for PMK  PTK derivation –2-way handshake for GTK distribution No wide-spread deployments

doc.: Submission Summary Problem –Need secure Network Access Control for IEEE Approach –Apply proven IEEE 802.1x and i techniques for: Security Capabilities Discovery Authentication Using EAP Secure Association/Key Management

doc.: Submission Call to Action Specify EAPoL for –Within IEEE ? –Leverage PHY adaptation layer in 15.4k for fragmentation? Specify link operation of Enforcement Point and Authenticator –Within IEEE 802.1? Specify EAPoL Tunnel over IP –Within IETF?

doc.: Submission End