{"title":"IEEE 802.11无线局域网的逐包认证","authors":"Muhammad Junaid, M. Akbar, M. Mufti","doi":"10.1109/INMIC.2008.4777737","DOIUrl":null,"url":null,"abstract":"Wireless Networks call for enhanced confidentiality, integrity and authenticaton services because of their inherent weakness of ubiquitous signals. Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) has been recently employed to provide security to IEEE 802.11 Wireless LANs. It has been shown in our earlier published work that CCMP is vulnerable to Time Memory Trade off (TMTO) attack. To overcome the said vulnerability, this paper presents a design and description of strengthening the security of WLAN packets using Per-Packet security mechanism. The architecture of Per-Packet security mechanism involves introduction of Per-Packet Authentication and Secret Nonce. The proposed Per-Packet Authentication protocol is a continuous challenge response process operating throughout the session. The Per-Packet authentication promptly secures the connection against unauthorized access by immediately discarding the packet if Per-Packet Authentication fails. We have proposed to derive the Nonce from the session key and keep it secret. Since the nonce is unique and secret, it provides freshness and unpredictability. The freshness provides protection against replay attacks, the unpredictability of Nonce prevents pre-computation attack. Same Nonce is used as a challenge-text from authenticator to supplicant. Per packet Security mechanism strengthens the security of authentication mechanism and counter mode operation irrespective of the security of causal encryption algorithm.","PeriodicalId":112530,"journal":{"name":"2008 IEEE International Multitopic Conference","volume":"30 4","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Per Packet Authentication for IEEE 802.11 wireless LAN\",\"authors\":\"Muhammad Junaid, M. Akbar, M. Mufti\",\"doi\":\"10.1109/INMIC.2008.4777737\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Wireless Networks call for enhanced confidentiality, integrity and authenticaton services because of their inherent weakness of ubiquitous signals. Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) has been recently employed to provide security to IEEE 802.11 Wireless LANs. It has been shown in our earlier published work that CCMP is vulnerable to Time Memory Trade off (TMTO) attack. To overcome the said vulnerability, this paper presents a design and description of strengthening the security of WLAN packets using Per-Packet security mechanism. The architecture of Per-Packet security mechanism involves introduction of Per-Packet Authentication and Secret Nonce. The proposed Per-Packet Authentication protocol is a continuous challenge response process operating throughout the session. The Per-Packet authentication promptly secures the connection against unauthorized access by immediately discarding the packet if Per-Packet Authentication fails. We have proposed to derive the Nonce from the session key and keep it secret. Since the nonce is unique and secret, it provides freshness and unpredictability. The freshness provides protection against replay attacks, the unpredictability of Nonce prevents pre-computation attack. Same Nonce is used as a challenge-text from authenticator to supplicant. Per packet Security mechanism strengthens the security of authentication mechanism and counter mode operation irrespective of the security of causal encryption algorithm.\",\"PeriodicalId\":112530,\"journal\":{\"name\":\"2008 IEEE International Multitopic Conference\",\"volume\":\"30 4\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2008-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2008 IEEE International Multitopic Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/INMIC.2008.4777737\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 IEEE International Multitopic Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/INMIC.2008.4777737","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Per Packet Authentication for IEEE 802.11 wireless LAN
Wireless Networks call for enhanced confidentiality, integrity and authenticaton services because of their inherent weakness of ubiquitous signals. Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) has been recently employed to provide security to IEEE 802.11 Wireless LANs. It has been shown in our earlier published work that CCMP is vulnerable to Time Memory Trade off (TMTO) attack. To overcome the said vulnerability, this paper presents a design and description of strengthening the security of WLAN packets using Per-Packet security mechanism. The architecture of Per-Packet security mechanism involves introduction of Per-Packet Authentication and Secret Nonce. The proposed Per-Packet Authentication protocol is a continuous challenge response process operating throughout the session. The Per-Packet authentication promptly secures the connection against unauthorized access by immediately discarding the packet if Per-Packet Authentication fails. We have proposed to derive the Nonce from the session key and keep it secret. Since the nonce is unique and secret, it provides freshness and unpredictability. The freshness provides protection against replay attacks, the unpredictability of Nonce prevents pre-computation attack. Same Nonce is used as a challenge-text from authenticator to supplicant. Per packet Security mechanism strengthens the security of authentication mechanism and counter mode operation irrespective of the security of causal encryption algorithm.