Doc.: IEEE 802.11-12/278r0 Submission NameAffiliationsAddressPhoneemail Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin.

Slides:



Advertisements
Similar presentations
Doc.: IEEE /1160 Submission NameAffiliationsAddressPhone George CherianQualcomm 5775 Morehouse Dr, San Diego, CA, USA
Advertisements

Doc.: IEEE /1160r1 Submission NameAffiliationsAddressPhone George CherianQualcomm 5775 Morehouse Dr, San Diego, CA, USA +1
Using Upper Layer Message IE in TGai
Doc.: IEEE /1436r0 Submission NameAffiliationsAddressPhone Robert Sun Huawei Technologies Co., Ltd. Suite 400, 303 Terry Fox Drive, Kanata,
Doc.: IEEE /0780r1 Submission NameAffiliationsAddressPhone Ping Fang Zhiming Ding Phillip Barber Rob Sun Huawei Technologies Co., Ltd. Bldg.
Doc.: IEEE /0041r1 Submission NameAffiliationsAddressPhone Robert Sun; Yunbo Li; Edward Au; Phillip Barber Huawei Technologies Co., Ltd.
Doc.: IEEE /0567r1 Submission May 2012 Huawei Slide 1 Multiple Frequency Channel Scanning Date: Authors: NameAffiliationsAddressPhone .
TGai FILS Authentication Protocol
Doc.: IEEE / ai Submission NameAffiliationsAddressPhone Phillip BarberHuawei Technologies Co., Ltd Alma Rd, Ste 500 Plano,
Submission doc.: IEEE ai May 2012 InterDigital, KDDI, Nokia, Huawei, Intel, Qcomm Slide 1 Proposed SFD Text for ai Passive Scanning.
Doc.: IEEE /0976r1 Submission July 2011 Hitoshi Morioka, ROOT INC.Slide 1 TGai Authentication Protocol Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1169r1 Submission January 2012 Jihyun Lee, LG ElectronicsSlide 1 FILS Association Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /933r6 Submission July 2012 Fang Xie (CMCC)Slide 1 Access Control Mechanism for FILS Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1042r3 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.: IEEE /1042 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang, Kyungki,
Doc.: IEEE /0249r0 Submission March 2012 Slide 1Lin Cai et al,Huawei. Differentiated Association Service Provisioning in WiFi Networks Date: 03/02/2012.
Doc.: IEEE /0039r0 Submission NameAffiliationsAddressPhone Robert Sun; Yunbo Li Edward Au; Phil Barber Junghoon Suh; Osama Aboul-Magd Huawei.
Doc.: IEEE /1054r0 Submission Sep Santosh Pandey (Cisco)Slide 1 FILS Reduced Neighbor Report Date: Authors:
Submission doc.: IEEE /1003r2 July 2011 Hiroki Nakano, Trans New Technology, Inc.Slide 1 Upper Layer Data on Management frames Date:
Submission doc.: IEEE 11-11/1414r2 November 2011 Katsuo Yunoki, KDDI R&D LaboratoriesSlide 1 Probe Request and Response in TGai Date: Authors:
Doc.: IEEE /0067r0 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 Active Scanning Time Notification Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0977r2 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA ROOT INC Tenjin, Chuo-ku, Fukuoka JAPAN
Submission doc.: IEEE ai March 2012 InterDigital, KDDI, Nokia, Huawei, IntelSlide 1 Proposed SFD Text for ai Passive Scanning Improvement.
Doc.: IEEE /0897r0 SubmissionJae Seung Lee, ETRISlide 1 Active Scanning considering Operating Status of APs Date: July 2012.
Doc.: IEEE / ai Submission Nov 2011 Huawei Technologies Co. LtdSlide 1 Broadcast Probe Response in TGai Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0061r1 SubmissionJae Seung Lee, ETRISlide 1 Probe Response frame transmission interval Date:
Doc.: IEEE /0547r1 Submission May 2012 Dapeng Liu, China MobileSlide 1 Extend 802.1X for higher layer configuration in FILS Date:
Doc.: IEEE /0158r2 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 Proposed Additions to SFD Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /01047r2 Submission NameAffiliationsAddressPhone Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin.
Doc.: IEEE / ai Submission NameAffiliationsAddressPhone Phillip BarberHuawei Technologies Co., Ltd Alma Rd, Ste 500 Plano,
Submission doc.: IEEE /1034r4 September 2012 Jeongki Kim, LG ElectronicsSlide 1 Enhanced scanning procedure for FILS Date: Authors:
Submission doc.: IEEE ai May 2012 Lei Wang, InterDigital CommunicationsSlide 1 Proposed SFD Text for ai AP/STA Initiated FILS Optimizations.
Doc.: IEEE /1042r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.: IEEE /0275r3 Submission March 2012 Hitoshi Morioka, Allied Telesis R&D CenterSlide 1 Higher Layer Configuration Function for TGai SFD Date:
Doc.: IEEE /1281r1 Submission NameAffiliationsAddressPhone Robert Sun;Huawei Technologies Co., Ltd. Suite 400, 303 Terry Fox Drive, Kanata,
Doc.: IEEE /1160r7 Submission NameAffiliationsAddressPhone George Cherian Santosh Abraham Hemanth Sampath Jouni Malinen Menzo Wentink Qualcomm.
Doc.: IEEE /0977r1 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA ROOT INC Tenjin, Chuo-ku, Fukuoka JAPAN
Doc.: IEEE /0080r0 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 AP Admission Control in TGai Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1000r1 Submission July 2011 Jihyun Lee, LG ElectronicsSlide 1 TGai FILS Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0568r0 Submission May 2012 Young Hoon Kwon, Huawei Slide 1 AP Discovery Information Broadcasting Date: Authors: NameAffiliationsAddressPhone .
Submission doc.: IEEE ai May 2012 InterDigital Slide 1 Passive Scanning Improvement Ad Hoc Report Date: Authors:
Submission doc.: IEEE 11-12/1051r2 Multi-channel information for AP discovery 1 September 2012 HTC Corp. NameAffiliationsAddressPhone Jing-Rong HsiehHTC.
Doc.: IEEE /0896r0 SubmissionJae Seung Lee, ETRISlide 1 Probe Request Filtering Criteria Date: July 2012.
Doc.: IEEE /01047r4 Submission NameAffiliationsAddressPhone Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin.
Doc.: IEEE /0042r1 Submission January 2013 Yongho Seok, LG ElectronicsSlide 1 Fast Moving Scan Channel Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1426r00 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi- tech District,
Doc.: IEEE /0158r0 Submission Jan 2012 Phillip Barber, HuaweiSlide 1 Proposed Additions to SFD Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1426r02 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District,
Doc.: IEEE /0269r1 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu,
Doc.: IEEE /0294r2 Submission March 2012 Jonathan Segev (Intel)Slide 1 Active Scanning Reply Window Date: Authors:
Month Year doc.: IEEE yy/xxxxr0 May 2012
AP discovery with FILS beacon
Discussions on FILS Authentication
FILS presentation on High Level Security Requirements
AP Discovery Information Broadcasting
EAP based Message Flow Optimization for FILS
TGai FILS Authentication Protocol
Using Upper Layer Message IE in TGai
AP discovery with FILS beacon
Scanning from Specific Channel
Access Control Mechanism for FILS
AP discovery with FILS beacon
AP discovery with FILS beacon
Using Upper Layer Message IE in TGai
Access Control Mechanism for FILS
Access Control Mechanism for FILS
Performance Analysis of authentication and authorization
Differentiated Association Service Provisioning in WiFi Networks
Month Year doc.: IEEE yy/xxxxr0 May 2012
Scanning from Specific Channel
Presentation transcript:

doc.: IEEE /278r0 Submission NameAffiliationsAddressPhone Ping Fang Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin Sourth 9, Nanshan District, Shenzhen, Guangdong, China, Rob Sun Huawei Technologies Co., Ltd. Suite 400, 303 Terry Fox Drive, Kanata, Ontario K2K 3J Zhiming Ding Huawei Technologies Co., Ltd. Bldg 7, Vision Software Park, Road Gaoxin Sourth 9, Nanshan District, Shenzhen, Guangdong, China, m FILS presentation on High Level Security Requirements Date: March 2012 Slide 1 Authors: Huawei

doc.: IEEE /278r0 Submission March 2012 Slide 2 Abstract From proposal 12/159r1 and 12/248r0, TGai shall include support of optimized EAP by concurrent association, authentication and key distribution to set up initial link and establish the FILS context, and the optimized FILS state machine which enable the parallel message processing. This document describes a technical proposal of the optimized EAP and the FILS state machine. Huawei

doc.: IEEE /278r0 Submission Conformance w/ Tgai PAR & 5C HuaweiSlide 3 Conformance QuestionResponse Does the proposal degrade the security offered by Robust Security Network Association (RSNA) already defined in ? No Does the proposal change the MAC SAP interface?No Does the proposal require or introduce a change to the architecture?No Does the proposal introduce a change in the channel access mechanism?No Does the proposal introduce a change in the PHY?No Which of the following link set-up phases is addressed by the proposal? (1) AP Discovery (2) Network Discovery (3) Link (re-)establishment / exchange of security related messages (4) Higher layer aspects, e.g. IP address assignment 3,4 March 2012

doc.: IEEE /278r0 Submission Why do we need FILS? Slide 4Huawei If a dual mode MS makes a seamless handoff from cellular network to WiFi network, the time of WiFi ILS should be minimized. 3GPP TS23.327(Mobility between 3GPP-WLAN, not support seamless HO yet) and WMF T37 (WiMAX WiFi Interworking, support seamless HO but effect is not proved, using pre-authentication) have supported this scenario. Internet Dual mode MS WiFi interface Cellular interface BS Cellular core HA AAA Cellular access AP WiFi access Hot-Spot Pass-Through Internet Access: Users on vehicle/train passing near an AP with a mobile phone must have the ability to access various Internet services in a few seconds to his/her e- mail/twitter/facebook or to offload traffic carried by other networks e.g. 3G. March 2012

doc.: IEEE /278r0 Submission Why keep EAP? Slide 5Huawei. In 3GPP TS ( SAE Security aspects of non-3GPP accesses ), it is specified: –Access authentication for non-3GPP access in EPS shall be based on EAP-AKA (IETF RFC 4187) or on EAP-AKA’ (IETF RFC 5448). In WiMAX NWG T37(WiMAX WiFi Interworking), EAP is also conducted by AAA server in WiMAX CSN during WiFi ILS. Considering the MIP keys are derived from EMSK which is an outcome of an EAP procedure in current network specifications (see 3GPP TS and WMF T32), the EAP should be kept in FILS. March 2012

doc.: IEEE /278r0 Submission March 2012 HuaweiSlide 6 Optimized full EAP with concurrent IP address assignment Optimized Full EAP is performed to setup initial link and EAP-ERP context and when EAP-ERP context expires. Step 1 & 2 : EAPoL-Start and EAP- Request/ID are optionally carried in Probe Request & Response. Step 6: ANonce from AP is carried to concurrently run the 4-way handshake with authentication. Step 7 is optional for SIM based device Step 9 : SNonce is carried and sent in Assoc-Req once STA get MSK. SME need to check the status of EAP. A MIC for whole MSDU protected by KCK are attached in Assoc-Req and Assoc-Resp. Step 10 & 12: AP caches MSDU MIC before PTK is available. And once PTK is received, AP verifies MSDU MIC. Step 15&16: DHCP is a optional example here. Other IP address allocation could be used, such as AP can be pre-assigned a IP pool. If IP address assignment server doesn’t respond within a certain period, then the AP may send Assoc Resp frame with indication of IP configuration unavailable/pending.

doc.: IEEE /278r0 Submission March 2012 HuaweiSlide 7 Modification to Authentication and Association State Machine Slide 7 State 1 Unauthenticated, Unassociated Class 1 Frames State 2 Authenticated, Unassociated Class 1 & 2 Frames State 3 Authenticated, Associated (Pending RSN Authentication) Class 1,2 & 3 Frames IEEE 802.1X Controlled Port Blocked State 4 Authenticated, Associated Class 1,2 & 3 Frames IEEE 802.1X Controlled Port UnBlocked Successful Authentication Successful (Re)Association –RSNA Required 4- way Handshake Successful Deauthentication Deassociation Deauthentication Unsuccessful (Re)Association (Non-AP STA) Successful Authentication Unsuccessful (Re)Association (Non-AP STA) Disassociation Successful Authentication Successful (Re) Association No RSNA required or Fast BSS Transitions State 5 FILS Authenticated/Unassociated Class 1 & 2 Frames With Selected Management & Data Frames FILS Authenticated/Unassociated Class 1 & 2 Frames With Selected Management & Data Frames Successful FILS Authentication FILS Deauthentication Successful FILS Association

doc.: IEEE /278r0 Submission March 2012 HuaweiSlide 8 Temporary State 5 (FILS Authenticated/Unassociated) Upon successful FILS authentication, both the STA and AP shall transition to FILS Authenticated/unassociated state STA at FILS Authenticated/Unassociated state, it allows Class 1,2 and selected Data frames piggybacked over Class 1 &2 frames to be transmitted Upon receipt of a De-authentication frame from either STA or AP STA with reasons, the STA at the FILS Authenticated/Unassociated state will be transitioned to State 1. STA transitioned back to State 1 may retry with FILS authentication or use the RSNA authentication Upon successful FILS Association, the STA shall transition to state 4 which allows full class 1, 2 and 3 frames to pass through. Selected Management Frames and Data Frames Reasons EAPOL message with EAP Packet To carry out the EAP full authentication IP assignment To enable the parallel IP assignment to take place

doc.: IEEE /278r0 Submission March 2012 HuaweiSlide 9 Appropriate FILS Authentication Properties Mandatory Properties i FILS Security Mutual Authentication with key agreement Yes Strong Confidentiality Yes RSNA Security Model Yes Key Confirmation Yes Key Derivation Yes Fast Re-authentication Yes Strong Session Key Yes Replay Attack Protection/MTIM protection/Dictionary Attack /Impersonation Attack Protection Yes Recommended Properties i FILS Security Fast and EfficientNo Yes Forward SecrecyImplementation Related Denial of Service ResistanceImplementation Related

doc.: IEEE /278r0 Submission March 2012 HuaweiSlide 10 Authentication Algorithm Number Field Insert the following FILS Authentication Algorithm Number – Authentication algorithm number = 0: Open System –Authentication algorithm number = 1: Shared Key –Authentication algorithm number = 2: Fast BSS Transition –Authentication algorithm number = 3: simultaneous authentication of equals (SAE) –Authentication algorithm number = 4: FILS Authentication –Authentication algorithm number = : Vendor specific use

doc.: IEEE /278r0 Submission Conclusion Proposal Summary –A optimized EAP authentication, in which 4-way handshake is carried out concurrently with authentication and association –A modified Authentication and Association State Machine, which enable the parallel message processing of existing authentication protocol Slide 11Huawei. March 2012

doc.: IEEE /278r0 Submission Questions & Comments Slide 12Huawei. March 2012