Presentation is loading. Please wait.

Presentation is loading. Please wait.

Doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 1 2004 802.11s Security concepts Jasmeet Chhabra, Intel

Similar presentations


Presentation on theme: "Doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 1 2004 802.11s Security concepts Jasmeet Chhabra, Intel"— Presentation transcript:

1 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 1 2004 802.11s Security concepts Jasmeet Chhabra, Intel (jasmeet.chhabra@intel.com)jasmeet.chhabra@intel.com Anand R Prasad, DoCoMo Euro-Labs (prasad@docomolab-euro.com )prasad@docomolab-euro.com Jesse Walker, Intel (jesse.walker@intel.com )jesse.walker@intel.com Hindenori Aoki, NTT DoCoMo (aokihid@nttdocomo.co.jp )aokihid@nttdocomo.co.jp

2 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 2 2004 Outline Goals Requirements Assumptions Basic security model Distributed Authentication Centralized Authentication Conclusion

3 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 3 2004 Goals/Requirements Reuse/build on top of current 802.11i techniques –802.11s PAR, Clause 18: “The amendment shall utilize IEEE 802.11i security mechanisms, or an extension thereof...” Other requirements –Allow peer-to-peer association/authentication between mesh points/mesh APs –Protect mesh management and control messages exchanged between mesh points/mesh APs (e.g. routing and topology info) –Allow mesh nodes to broadcast to all its neighbors : needed by routing services etc. –Maintain 11i data security for data delivery across multi-hop mesh path –Credentials issued might have to differentiate between a mesh point and a non-mesh point –Allow for both distributed and centralized authentication schemes

4 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 4 2004 Assumptions Authenticated Mesh Points in an administrative domain can be trusted for faithful forwarding of messages. –No selective forwarding like attacks –No eavesdropping

5 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 5 2004 Background 802.11i “Figure 16—Example 4-Way Handshakes in an IBSS”

6 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 6 2004 Basic security model New mesh point ESS Mesh Security bubble Supplicant Authenticator Group key is used for broadcast communications Pair-wise keys are used for unicast communications Authentication server could be distributed or centralized –Does not effect basic security model

7 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 7 2004 Basic security model (Contd.) Each mesh point supports both supplicant and authenticator functionality Each mesh point acts as supplicant and authenticator for each of its neighbors –Similar to IBSS security model in 802.11i After authentication/authorization/4-way handshake: –Mesh point uses its own group key to broadcast/multicast – Pair-wise key for unicast Number of keys is O (num_neighbors)

8 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 8 2004 Advantages Minimal changes required to 802.11i –Mainly language changes –Re-uses the strong and well debated solution Builds on top of current 802.11i standard Key management Complexity is controlled –O(num_neighbors)

9 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 9 2004 Authenticator Security model with stations ESS Mesh Security bubble Supplicant Access Point No change in the current STA operation

10 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 10 2004 Authentication Schemes IEEE 802.11i does not specify where the authentication server resides. –Can be on the AP/Node itself –Only specifies functionality needed As mentioned earlier, the authentication scheme could be –Distributed or –Centralized

11 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 11 2004 Distributed authentication Completely distributed: automatic or manual configuration of nodes Elect: Requires solution for the case where elected AS becomes unavailable –A node is assigned as AS at random –The first node becomes AS –Some other mechanism is used Select: The user selects a node as AS

12 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 12 2004 Centralized Authentication The centralized method involves a ESS mesh AP that has access to a AS The AS could either reside locally or could be placed elsewhere in the network All other ESS mesh APs and STAs will be authenticated via the AP connected to the AS

13 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 13 2004 Open questions 802.11i does not provide management frame security –Could effect routing, topology traffic etc. security –Should align with management frame security study group: Need to submit requirements to the group before November Only language changes needed to 802.11i –Do we need to do any other changes in 802.11i? Are there changes needed for allowing distributed authentication?

14 doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 14 2004 Conclusion Security model builds on top of 802.11i –Minimal language changes Manageable key complexity –O(num_neighbors) Need to submit requirements to the management frame security group


Download ppt "Doc.: IEEE 802.11-04/1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide 1 2004 802.11s Security concepts Jasmeet Chhabra, Intel"

Similar presentations


Ads by Google