Doc.: IEEE 802.11-13/0026r0 Submission January 2013 Yongho Seok, LG ElectronicsSlide 1 Security Procedure for Long Sleeper Date: 2013-01-13 Authors: NameAffiliationsAddressPhoneEmail.

Slides:



Advertisements
Similar presentations
Doc.: IEEE /0507r0 Submission Synch Frame Follow Up Date: Authors: May 2013 NameAffiliationsAddressPhone Young Hoon KwonHuawei.
Advertisements

Doc.: IEEE /2441r2 Submission SA Teardown Protection for w Date:
NDP Type PS-Poll Frame Date: Authors: July 2012 Month Year
Doc.: IEEE /0612r0 Submission Serivice Type Indication in Association Date: xx Authors: May 2012 Wu Tianyu, HuaweiSlide 1 NameAffiliationsAddressPhone .
Doc.: IEEE /2913r0 Submission November 2007 Kapil Sood, Intel CorporationSlide 1 Protecting Associations Attacks – Some Considerations Date:
Restricted Access Window Signaling for Uplink Channel Access
Doc.: IEEE /1000r0 Submission July 2011 Jihyun Lee, LG ElectronicsSlide 1 TGai FILS Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1169r1 Submission January 2012 Jihyun Lee, LG ElectronicsSlide 1 FILS Association Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0550 Submission NameAffiliationsAddressPhone Kiseon RyuLG Electronics10225 Willow Creek Rd, San Diego, CA, 92131, USA +1
Doc.: IEEE /0816r0 Submission July 2012 Channel Selection for ah Date: Slide 1 Name AffiliationsAddressPhone Huai-Rong Shao.
TGah Submission Doc: ah July, 2012 Sectorization for hidden node mitigation NameAffiliationsAddressPhone George Calcev Huawei3601 Algonquin.
Doc.: IEEE /0130r0 Submission January 2012 Seunghee Han, LG ElectronicsSlide 1 Beacon Reception of Long Sleeper Date: Authors:
Submission doc.: IEEE /0834r0 Speed Frame Exchange Date: Slide 1 Authors: July 2012 Eric Wong, Broadcom NameAffiliationsAddressPhone .
Doc.: IEEE /0508r0 Submission May 2013 Ron Porat, Broadcom Modulation Accuracy Date: Authors: Name AffiliationsAddressPhone Ron.
Doc.: IEEE /1302r0 Submission November 2012 Yongho Seok, LG ElectronicsSlide 1 TXOP Truncation Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0257r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
TGah Submission Doc: ah May, 2012 Non-TIM Stations in 11ah NameAffiliationsAddressPhone George Calcev Huawei3601 Algonquin Road, Rolling.
Doc.: IEEE /0089r0 Submission Listen interval update Jan 2013 Slide 1 Date: Authors: Jinsoo Choi, LG Electronics.
Doc.:IEEE /01122r0 September 2012 Simone Merlin Short MAC Header Signaling Slide 1 Authors:
Doc.: IEEE /0831r0 Submission July 2012 Yongho Seok, LG ElectronicsSlide 1 Uplink Channel Access General Procedure Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1093r0 Submission September 2012 Jeongki Kim, LG ElectronicsSlide 1 System information update procedure for 11 ah Date:
Doc.: IEEE /1089r0September 2012 Submission Qi Wang, BroadcomSlide 1 Frame Classification Based on MAC Header Content Date: Authors:
Doc.: IEEE /1378r0 Submission November 2008 Darwin Engwer, Nortel NetworksSlide 1 Improving Multicast Reliability Date: Authors:
Doc.: IEEE /1042r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Submission doc.: IEEE /0656r1 Slide 1Panasonic September 2012 Extended Sleep mode for battery powered STAs Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0830r0 Submission July 2012 Yongho Seok, LG ElectronicsSlide 1 NDP Probing Date: Authors: NameAffiliationsAddressPhone .
Submission January 2014doc.:IEEE /0157r0 Menzo Wentink, Qualcomm CID 1551: CCMP Header Compression Date: 22 Jan Slide 1 NameCompanyAddressPhone .
Doc.: IEEE /0869r0 SubmissionJae Seung Lee, ETRISlide 1 Active Scanning for 11ah Date: July 2012 Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1000r1 Submission July 2011 Jihyun Lee, LG ElectronicsSlide 1 TGai FILS Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0306r0 Submission Sector Discovery for 11ah Date: Authors: March 2013 NameAffiliationsAddressPhone Minho CheongETRI.
Doc.: IEEE /1061r0 Submission September 2013 Jeongki Kim, LG ElectronicsSlide 1 Multicast Transmission for HEW Date: Authors: NameAffiliationsAddressPhone .
Doc: ah - Sensor Only BSS September 2012 Submission Sensor Only BSS Date: Huawei Technologies Inc. Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0519r0 SubmissionSlide 1 Speed Frame Exchange Using NDP Frames Date: Authors: Shoukang Zheng, I2R May 2013 NameAffiliationsAddressPhone .
Doc.: IEEE /1333r0 Submission November 2012 Sameer Vermani, Qualcomm Mandatory Optional PHY Features for 11ah Date: Authors: Name AffiliationsAddressPhone .
Doc.: IEEE /0042r1 Submission January 2013 Yongho Seok, LG ElectronicsSlide 1 Fast Moving Scan Channel Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1304r0 Submission November 2012 Yongho Seok, LG ElectronicsSlide 1 AID Assignment Protocol Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /891r0 Submission July 2012 AID reassignment for TIM and non-TIM modes switching Date: Slide 1 Authors: Betty Zhao, et.
Submission doc.: IEEE /0867r0 July 2012 Slide 1 Date: Authors: Non-TIM Allocation Hyoungjin Kwon, ETRI NameAffiliationsAddressPhone .
Doc.: IEEE /0525r1 SubmissionSlide 1 OBSS Mitigation Date: Authors: Chao-Chun Wang, MediaTek May 2013 NameAffiliationsAddressPhone .
Doc.: IEEE /0290r0 SubmissionSlide 1 RAW Operation Improvement Date: Authors: NameAffiliationAddressPhone Yuan ZhouI2R1 Fusionopolis.
Doc.: IEEE /0618r0 Submission Listen interval for sensor devices May 2012 Slide 1 Date: Authors: Jinsoo Choi, LG Electronics.
Doc.: IEEE /0080r0 Submission January 2013 Yongho Seok, LG ElectronicsSlide 1 Backoff Procedure in RAW Date: Authors: NameAffiliationsAddressPhone .
RAW Assignment follow up
Uplink Data Delivery Date: Authors: Month Year
Duplicate Bandwidth and Operation
OBSS Mitigation Date: Authors: May 2013 Month Year
Periodic Channel Access
Active Scanning for 11ah Follow Up 2
Active Scanning for 11ah Follow Up
19, Yangjae-daero 11gil, Seocho-gu, Seoul , Korea
Comments on Relay Date: Authors: Month Year
Page Scheduling Date: Authors: May 2013 Name Affiliation
SFD Proposal on Retransmission
SIG Field of NDP Probe Request
Duplicate Detection of Short MAC Frame
Consideration on multi-AP coordination for EHT
Directed Multicast Service (DMS)
PPDU Recovery Procedure
Sensor Only BSS Date: Authors: Name Affiliations Address
Prioritized Active Scanning in TGai
TIM and Page Segmentation
AID update procedure for TDLS peer STA
LG R&D Complex Anyang-Shi, Kyungki- Do, Korea
19, Yangjae-daero 11gil, Seocho-gu, Seoul , Korea
PAPR Reduction for MCS0 Rep 2
TGah Awards Date: Authors: July 2017
Directed Multicast Service (DMS)
Channelization Selection for ah
Traffic Filter based Wakeup Service
Month Year doc.: IEEE yy/xxxxr0 May 2012
Presentation transcript:

doc.: IEEE /0026r0 Submission January 2013 Yongho Seok, LG ElectronicsSlide 1 Security Procedure for Long Sleeper Date: Authors: NameAffiliationsAddressPhone Yongho SeokLG Electronics LG R&D Complex Anyang-Shi, Kyungki- Do, Korea Minyoung ParkIntelHillsboro, OR Jinsoo ChoiLG Electronics Jeongki KimLG Electronics Hangyu ChoLG Electronics Matthew Eric WongBroadcomSunnyvale, CA Tom TetzlaffIntel Emily QiIntel Simone MerlinQualcommSan Diego, CA Amin JafarianQualcomm Bin TianQualcomm Santosh AbrahamQualcomm Menzo WentinkQualcomm Hemanth SampathQualcomm VK jonesQualcomm

doc.: IEEE /0026r0 SubmissionSlide 2 NameAffiliationsAddressPhone Hongyuan ZhangMarvell Sudhir SrinivasaMarvell George CalcevHuaweiRolling Meadows, IL, USA m Osama Aboul MagdHuawei Young Hoon KwonHuawei Betty ZhaoHuawei David YangxunHuawei Bin ZhenHuawei ChaoChun WangMediaTek James WangMediaTek Jianhan LiuMediaTek Vish PonnampalamMediaTek James YeeMediaTek Huai-Rong Shao Samsung Electronics Chiu NgoSamsung Electronics Minho CheongETRI Jae Seung LeeETRI Hyoungjin KwonETRI Jaewoo ParkETRI Sok-kyu LeeETRI Sun, Bo ZTE Lv, Kaiying ZTE Authors: Yongho Seok, LG Electronics January 2013

doc.: IEEE /0026r0 SubmissionYongho Seok, LG ElectronicsSlide 3 Authors: NameAffiliationsAddressPhone Sayantan ChoudhuryNokia Klaus DopplerNokia Chittabrata GhoshNokia Esa TuomaalaNokia Ken MoriPanasonic Rojan ChitrakarPanasonic Haiguang WangI2R Shoukang ZhengI2R Yeow Wai LeongI2R Zander LeiI2R Jaya ShankarI2R Anh Tuan HoangI2R Joseph Teo Chee MingI2R Anna PantelidouRenesas Mobile Juho PirskanenRenesas Mobile Timo KoskelaRenesas Mobile Liwen ChuSTMicroelectronics George VlantisSTMicroelectronics January 2013

doc.: IEEE /0026r0 Submission Introduction IEEE w is a standard for supporting a protected management frame Wi-Fi Alliance also provides a certification program for the protected management frame as one of core programs –Protected Management Frames: Wi-Fi CERTIFIED WPA2 with Protected Management Frames provides a WPA2-level of protection for unicast and multicast management action frames, One of mandatory features of the protected management frame is a Security Association (SA) Query procedure January 2013 Yongho Seok, LG ElectronicsSlide 4

doc.: IEEE /0026r0 Submission Background of SA Query Procedure If an AP has a valid security association for a non-AP STA –The SME shall reject the Association Request by generating an MLME- ASSOCIATE.response primitive with ResultCode “Association request rejected temporarily; try again later.” –The SME shall include in the MLME-ASSOCIATE.response primitive a Timeout Interval element with Timeout interval type set to 3 (Association Comeback time), specifying a comeback time when the AP would be ready to accept an association with this STA. –Following this, the SME shall issue one MLME-SAQuery.request primitive addressed to the STA every dot11AssociationSAQueryRetryTimeout TUs until a matching MLME- SAQuery.confirm primitive is received or dot11AssociationSAQueryMaximumTimeout TUs from the beginning of the SA Query procedure have passed. January 2013 Yongho Seok, LG ElectronicsSlide 5

doc.: IEEE /0026r0 Submission Background of SA Query Procedure Security Association Query Procedure Example January 2013 Yongho Seok, LG ElectronicsSlide 6 AP STA Attacker Association Request Association Response SA Query Request SA Query Response Association Request Association Response AP and STA have a valid security association Result Code: “Association requested rejected temporarily: try again later.” Association Comeback Time dot11AssociationSAQuery MaximumTimeout Result Code: “Association requested rejected temporarily: try again later.”

doc.: IEEE /0026r0 Submission Background of SA Query Procedure Security Association Query Procedure Example January 2013 Yongho Seok, LG ElectronicsSlide 7 Association Comeback Time dot11AssociationSAQuery MaximumTimeout AP STA Attacker Association Request Association Response SA Query Request Association Request Association Response AP and STA have a valid security association Result Code: “Association requested rejected temporarily: try again later.” Result Code: “Success.” SA Query Request STA is recovered from a failure

doc.: IEEE /0026r0 Submission Problem Definition Low power STA may wake up with very long interval (e.g., 10 minutes) So, long sleepers may not received SA Query Request frame even though they have a valid security association –If an MLME-SAQuery.confirm primitive with an outstanding transaction identifier is not received within dot11AssociationSAQueryMaximumTimeout period, the SME shall allow the association process to be started without starting an additional SA Query procedure. dot11AssociationSAQueryMaximumTimeout specifies the number of time units (TUs) that an AP can wait, from the scheduling of the first SA Query Request to allow association process to be started without starting additional SA Query procedure if a successful SA Query Response is not received. And a default value is 1 second. January 2013 Yongho Seok, LG ElectronicsSlide 8

doc.: IEEE /0026r0 Submission Problem Definition Because STA does not reply to SA Query Request frame, an attacker can be associated with AP and it destroys the security association of the STA. January 2013 Yongho Seok, LG ElectronicsSlide 9 AP STA Attacker Association Request Association Response SA Query Request Association Request Association Response Result Code: “Association requested rejected temporarily: try again later.” Association Comeback Time dot11AssociationSAQuery MaximumTimeout Result Code: “Success.” SA Query Request

doc.: IEEE /0026r0 Submission Proposal AP Behavior –For protecting a security association from DoS attack, AP should provide dot11AssociationSAQueryMaximumTimeout value to a non-AP STA STA Behavior –For protecting DoS attack, the non-AP STA shall wake to listen to SA Query Request frame with the interval of dot11AssociationSAQueryMaximumTimeout January 2013 Yongho Seok, LG ElectronicsSlide 10

doc.: IEEE /0026r0 Submission Conclusion In this contribution, we propose a security association procedure for a long sleeper –For protecting DoS attack, AP needs to provide dot11AssociationSAQueryMaximumTimeout value to its associated STA January 2013 Yongho Seok, LG ElectronicsSlide 11

doc.: IEEE /0026r0 Submission Straw Poll Do you support that an AP include dot11AssociationSAQueryMaximumTimeout in Association Response frame or Re-association Response frame with status code set to success? January 2013 Yongho Seok, LG ElectronicsSlide 12