Download presentation
Presentation is loading. Please wait.
1
PMF, take one A simple 802.11i extension
March 2005 PMF, take one A simple i extension Fabrice Stevens, Sébastien Duré France Telecom March 2005 Fabrice Stevens, Sébastien Duré
2
Goals of this presentation
March 2005 Goals of this presentation This is not a proposal! Show that a very simple extension of i could provide some security features in a post i scheme Fabrice Stevens, Sébastien Duré
3
Overall mechanism 802.11i derives PTK, GTK
March 2005 Overall mechanism 802.11i derives PTK, GTK Use them! GTK used in encrypting/signing broadcast management frames Keys derived from PTK used in encrypting/signing unicast management frames Define a new management frame type Define a new IE Fabrice Stevens, Sébastien Duré
4
More specifically… Define a new IE
March 2005 More specifically… Define a new IE EID Length ANonce Signature Add this IE to management frames that only need integrity/authenticity (and replay protection) For confidentiality, one possibility: Define a new management frame, that encapsulates an encrypted management frame Frame body ANonce (counter incremented by 1 at every frame) Encrypted management frame Signature of the whole frame (brings integrity/authenticity too…) Fabrice Stevens, Sébastien Duré
5
Other security features
March 2005 Other security features Replay protection last_ANonce set to 0 after i exchange When client receives a PMF If (ANonce > last_ANonce) If the signature is valid, update ANonce Else drop the frame Else Drop the frame Fabrice Stevens, Sébastien Duré
6
Pros and cons Pros Cons Simple, very limited changes to 802.11
March 2005 Pros and cons Pros Simple, very limited changes to Data origin authentication, confidentiality, and replay protection provided Cons Limitation : assumes i was performed before… No initial protection for management frames Of course has a lot of open issues… Once again, it's not a proposal! Fabrice Stevens, Sébastien Duré
7
March 2005 Conclusion Post i solutions benefit from existing keying material Proposals for k have been presented, e.g. Radio Measurement Action Protection – /685r0 & 686r1, Jesse Walker Frame Encapsulation – /737r0, Mike Moreton On the other hand, there is no existing pre i solution at this point. This leaves a lot of work to do… Fabrice Stevens, Sébastien Duré
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.