Voice over 802.11

802.11: Security Measures Beyond WEP

802.11 Security Measures Beyond WEP

Wi-Fi Protected Access

In November 2002, the Wi-Fi Alliance announced the Wi-Fi Protected Access (WPA) security standard [5, pp. 81 86]. It replaced the comparably weak WEP standard previously offered for Wi-Fi equipment.

WPA uses the Temporal Key Integrity Protocol (TKIP), a more hardened encryption scheme than that used in WEP. TKIP uses key hashing (KeyMix) and a nonlinear message integrity check (MIC). TKIP also uses a rapid-rekeying (ReKey) protocol that changes the encryption key about every 10,000 packets. However, TKIP does not eliminate fundamental flaws in Wi-Fi security. If one can hack TKIP, one not only breaks confidentiality, but also access control and authentication.

WPA will work in two different ways, depending on the type of network. In homes and small offices lacking authentication servers, the technology will work in a so-called "preshared" key mode. Users simply enter the network key to gain access.

In the managed mode, it will work with authentication servers and will require the support of 802.1x and EAP. The 802.1x/EAP combination enables a client network adapter to negotiate via an access point with a back-end authentication server using securely encrypted transactions to exchange session keys.

Every device on a wireless network must be upgraded to WPA in order for it to work. If a network is sewn together from several manufacturers' devices and the WPA upgrade for one of the manufacturers is not available yet, the user will have to wait to be able to...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: WiFi and WiMAX Wireless Chips
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.