Security Standards. IEEE 802.11 IEEE 802 committee for LAN standards IEEE 802.11 formed in 1990’s – charter to develop a protocol & transmission specifications.

Slides:



Advertisements
Similar presentations
Mobile IP and Wireless Application Protocol
Advertisements

Web security: SSL and TLS
Spring 2012: CS419 Computer Security Vinod Ganapathy SSL, etc.
Lecture 6: Web security: SSL
TLS Introduction 14.2 TLS Record Protocol 14.3 TLS Handshake Protocol 14.4 Summary.
Cryptography and Network Security
Secure Socket Layer.
17.1 Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display. Chapter 17 Security at the Transport Layer: SSL and TLS.
Socket Layer Security. In this Presentation: need for web security SSL/TLS transport layer security protocols HTTPS secure shell (SSH)
7-1 Chapter 7 – Web Security Use your mentality Wake up to reality —From the song, "I've Got You under My Skin“ by Cole Porter.
An Introduction to Secure Sockets Layer (SSL). Overview Types of encryption SSL History Design Goals Protocol Problems Competing Technologies.
Cryptography and Network Security Chapter 17 Fifth Edition by William Stallings Lecture slides by Lawrie Brown.
IEEE i IT443 Broadband Communications Philip MacCabe October 5, 2005
Transport Layer Security (TLS) Protocol Introduction to networks and communications(CS555) Prof : Dr Kurt maly Student:Abhinav y.
CSE  Wired Equivalent Privacy (WEP) ◦ first security protocol defined in  Wi-Fi Protected Access (WPA) ◦ defined by Wi-Fi Alliance 
Wireless LAN Security Jerry Usery CS 522 December 6 th, 2006.
Cryptography and Network Security Chapter 17
Wireless Application Protocol and i-Mode By Sridevi Madduri Swetha Kucherlapati Sharrmila Jeyachandran.
Wired Equivalent Privacy (WEP)
CSCE 790: Computer Network Security Chin-Tser Huang University of South Carolina.
WAP-Wireless application Protocol
Mobile IP and Wireless Application Protocol
WAP: Wireless Application Protocol Mike Mc Ardle ACSG April, 2005.
Chapter 8 Web Security.
WPA2 By Winway Pang. Overview  What is WPA2?  Wi-Fi Protected Access 2  Introduced September 2004  Two Versions  Enterprise – Server Authentication.
Wireless Application Protocol (WAP) Reference: Chapter 12, section 2, Wireless Communications and Networks, by William Stallings, Prentice Hall.
Network and Internet Security
Wireless Network Security. Wireless Security Overview concerns for wireless security are similar to those found in a wired environment concerns for wireless.
Announcement Final exam: Wed, June 9, 9:30-11:18 Scope: materials after RSA (but you need to know RSA) Open books, open notes. Calculators allowed. 1.
Wireless security & privacy Authors: M. Borsc and H. Shinde Source: IEEE International Conference on Personal Wireless Communications 2005 (ICPWC 2005),
Secure Systems Research Group - FAU Wireless Web Services Security Christopher Lo.
Comparative studies on authentication and key exchange methods for wireless LAN Authors: Jun Lei, Xiaoming Fu, Dieter Hogrefe and Jianrong Tan Src:
Investigators have published numerous reports of birds taking turns vocalizing; the bird spoken to gave its full attention to the speaker and never vocalized.
Secure Socket Layer (SSL)
Behzad Akbari Spring 2012 (These slides are based on lecture slides by Lawrie Brown)
Data Security and Encryption (CSE348)
Chapter 5 WIRELESS NETWORK SECURITY
Lectured By: Vivek Dimri Assistant Professor, CSE Dept. SET, Sharda University, Gr. Noida.
Security in WAP and WTSL By Yun Zhou. Overview of WAP (Wireless Application Protocol)  Proposed by the WAP Forum (Phone.com, Ericsson, Nokia, Motorola)
Network Security Essentials Chapter 5
Cryptography and Network Security (CS435) Part Fourteen (Web Security)
Web Security : Secure Socket Layer Secure Electronic Transaction.
Cryptography and Network Security (SSL)
IEEE i WPA2. IEEE i (WPA2) IEEE i, is an amendment to the standard specifying security mechanisms for wireless networks. The.
WIRELESS APPLICATION PROTOCOL Definition It is universal, open standard developed by the WAP Forum to provide mobile users of wireless phones and other.
Link-Layer Protection in i WLANs With Dummy Authentication Will Mooney, Robin Jha.
Lecture 24 Wireless Network Security
Wireless Security: The need for WPA and i By Abuzar Amini CS 265 Section 1.
WAP Architecture Presented by, Nithya Inbamani. WAP Background Wireless Application Protocol – secure specification. Wireless Application Protocol – secure.
Lecture slides prepared for “Computer Security: Principles and Practice”, 3/e, by William Stallings and Lawrie Brown, Chapter 24 “Wireless Network Security”.
Web Security Web now widely used by business, government, individuals but Internet & Web are vulnerable have a variety of threats – integrity – confidentiality.
Gold Coast Campus School of Information Technology 2003/16216/3112INT Network Security 1Copyright © Griffith University, INT / 3112INT Network.
CSCE 715: Network Systems Security Chin-Tser Huang University of South Carolina.
@Yuan Xue CS 285 Network Security Secure Socket Layer Yuan Xue Fall 2013.
Cryptography CSS 329 Lecture 13:SSL.
Lecture 7 (Chapter 17) Wireless Network Security Prepared by Dr. Lamiaa M. Elshenawy 1.
EECS  Wired Equivalent Privacy (WEP) ◦ first security protocol defined in  Wi-Fi Protected Access (WPA) ◦ defined by Wi-Fi Alliance 
Page 1 of 17 M. Ufuk Caglayan, CmpE 476 Spring 2000, SSL and SET Notes, March 29, 2000 CmpE 476 Spring 2000 Notes on SSL and SET Dr. M. Ufuk Caglayan Department.
Wireless Protocols WEP, WPA & WPA2.
Cryptography and Network Security
Mobile IP and Wireless Application Protocol
Network Security Essentials Chapter 6
Cryptography and Network Security Chapter 17
Cryptography and Network Security
SSL (Secure Socket Layer)
Cryptography and Network Security Chapter 17
Cryptography and Network Security
Presentation transcript:

Security Standards

IEEE IEEE 802 committee for LAN standards IEEE formed in 1990’s – charter to develop a protocol & transmission specifications for wireless LANs (WLANs) since then demand for WLANs, at different frequencies and data rates, has exploded hence seen ever-expanding list of standards issued

IEEE 802 Terminology

Wi-Fi Alliance b first broadly accepted standard Wireless Ethernet Compatibility Alliance (WECA) industry consortium formed 1999 – to assist interoperability of products – renamed Wi-Fi (Wireless Fidelity) Alliance – created a test suite to certify interoperability – initially for b, later extended to g – concerned with a range of WLANs markets, including enterprise, home, and hot spots

IEEE 802 Protocol Architecture

Network Components & Architecture

IEEE Services

Wireless LAN Security wireless traffic can be monitored by any radio in range, not physically connected original spec had security features – Wired Equivalent Privacy (WEP) algorithm – but found this contained major weaknesses i task group developed capabilities to address WLAN security issues – Wi-Fi Alliance Wi-Fi Protected Access (WPA) – final i Robust Security Network (RSN)

802.11i RSN Services and Protocols

802.11i RSN Cryptographic Algorithms

802.11i Phases of Operation

802.11i Discovery and Authent- ication Phases

IEEE 802.1X Access Control Approach

802.11i Key Manage- ment Phase

802.11i Protected Data Transfer Phase have two schemes for protecting data Temporal Key Integrity Protocol (TKIP) – s/w changes only to older WEP – adds 64-bit Michael message integrity code (MIC) – encrypts MPDU plus MIC value using RC4 Counter Mode-CBC MAC Protocol (CCMP) – uses the cipher block chaining message authentication code (CBC-MAC) for integrity – uses the CRT block cipher mode of operation

IEEE i Pseudorandom Function

Wireless Application Protocol (WAP) a universal, open standard developed to provide mobile wireless users access to telephony and information services have significant limitations of devices, networks, displays with wide variations WAP specification includes: – programming model, markup language, small browser, lightweight communications protocol stack, applications framework

WAP Programming Model

WAP Infra- structure

Wireless Markup Language describes content and format for data display on devices with limited bandwidth, screen size, and user input capability features include: – text / image formatting and layout commands – deck/card organizational metaphor – support for navigation among cards and decks a card is one or more units of interaction a deck is similar to an HTML page

WAP Architecture

WTP Gateway

WAP Protocols Wireless Session Protocol (WSP) – provides applications two session services – connection-oriented and connectionless – based on HTTP with optimizations Wireless Transaction Protocol (WTP) – manages transactions of requests / responses between a user agent & an application server – provides an efficient reliable transport service Wireless Datagram Protocol (WDP) – adapts higher-layer WAP protocol to comms

Wireless Transport Layer Security (WTLS)  provides security services between mobile device (client) and WAP gateway provides data integrity, privacy, authentication, denial-of-service protection  based on TLS more efficient with fewer message exchanges use WTLS between the client and gateway use TLS between gateway and target server  WAP gateway translates WTLS / TLS

WTLS Sessions and Connections secure connection – a transport providing a suitable type of service – connections are transient – every connection is associated with 1 session secure session – an association between a client and a server – created by Handshake Protocol – define set of cryptographic security parameters – shared among multiple connections

WTLS Protocol Architecture

WTLS Record Protocol

WTLS Higher-Layer Protocols Change Cipher Spec Protocol – simplest, to make pending state current Alert Protocol – used to convey WTLS-related alerts to peer – has severity: warning, critical, or fatal – and specific alert type Handshake Protocol – allow server & client to mutually authenticate – negotiate encryption & MAC algs & keys

Handshake Protocol

Cryptographic Algorithms WTLS authentication – uses certificates X.509v3, X9.68 and WTLS (optimized for size) – can occur between client and server or client may only authenticates server WTLS key exchange – generates a mutually shared pre-master key – optional use server_key_exchange message for DH_anon, ECDH_anon, RSA_anon not needed for ECDH_ECDSA or RSA

Cryptographic Algorithms cont Pseudorandom Function (PRF) – HMAC based, used for a number of purposes – only one hash alg, agreed during handshake Master Key Generation – of shared master secret – master_secret = PRF( pre_master_secret, "master secret”, ClientHello.random || ServerHello.random ) – then derive MAC and encryption keys Encryption with RC5, DES, 3DES, IDEA

WAP End-to-End Security have security gap end-to-end – at gateway between WTLS & TLS domains

WAP2 End-to- End Security

Summary have considered: – IEEE Wireless LANs protocol overview and security – Wireless Application Protocol (WAP) protocol overview – Wireless Transport Layer Security (WTLS)