标签芯片 | 读写器 | 天线 | 中间件 | 智能卡 | 生物识别 | 条码 | 制造设备 | 物流 | 零售 | 防伪 | 交通 | 停车 | 资产管理 | 动物 | 身份识别 | 军事 | 航空 | 门禁 | 一卡通
供求商机 资讯中心 产品中心 企业资料 人才招聘
 
 首页 >> 技术中心>> 正文 添加到百度搜藏 添加到百度搜藏 添加到雅虎收藏+
802.11i Strengthens Wi-Fi Security
来源:EWeek   2005-6-29 9:07:52
关键词: WiFi  security  80211i  质检  防伪  应用  


提要802.11i Strengthens Wi-Fi Security

With the recent ratification of 802.11i, and the certification and availability of products enabled for the wireless security specification, the time seems right for enterprises to feel safe in adopting wireless networking en masse. However, eWEEK Labs has found that issues ranging from incompatible legacy hardware to uneven migration strategies may slow adoption of 802.11i technology.

To be sure, 802.11i is a huge step forward—it's the first standardized wireless security solution with which government and businesses can be comfortable.

Built upon strong AES-CCMP (Advanced Encryption Standard-Counter Mode/ CBC-MAC Protocol)-based encryption, 802.11i avoids the IV (initialization vector) and MIC (Message Integrity Check) flaws that doomed the WEP (Wired Equivalent Privacy) security standard. By relying on AES-CCMP, a block cipher, 802.11i ensures not only that the packet data payload is encrypted but also that selected packet header fields are protected.

802.11i includes a complex series of communications and key exchanges designed to mutually authenticate wireless clients and access points and to reduce as much as possible the impact on back-end authentication systems.

In response to a requesting client's probe, an 802.11i-enabled access point responds with an RSN (Robust Secure Network) Information Element that advertises the network's enabled authentication suites and ciphers. The client then selects a mutually compatible setting and initiates an open system authentication to the access point, which verifies the compatible settings and completes the association request. At this time, 802.1x authentication begins.

eWEEK.com Special Report: Securing Wi-Fi

Similar to WPA (Wi-Fi Protected Access)—a stopgap solution based on Draft 3 of the 802.11i specification—802.11i provides port-based authentication to a RADIUS server to provide user authentication. However, 802.11i streamlines WPA's key exchange process among the client, access point and authorization server by requiring fewer messages.

Once a user has successfully authenticated to the RADIUS server, the authentication server creates a PMK (pairwise master key) that is moved to the access point and then exchanged with the client. This key controls both devices' access to the 802.11 channel (no matter which band) and is used to derive the PTK (pairwise transient key), which is actually a collection of keys that help mutually identify the devices and secure the data traffic.

The PMK is unique to the client/access point conversation, so the 802.1x authentication process must occur again when a client roams to a new access point. Because the authentication process causes some latency, devices running time-sensitive applications may falter during a roam.

The 802.11r task group is working on a fast-roaming amendment to the 802.11 wireless specification, but the 802.11i security specification also includes some optional components that may alleviate roaming latency.

For example, with PMK caching, clients and access points may indicate that they have cached a PMK from a previous association. If both the access point and client have the PMK cached, the client may skip a full 802.1x authentication.

Another optional 802.11i component for alleviating roaming dropouts is pre-authentication, where a client authenticates to access points within range in the background while maintaining an association with another access point. However, vendor support may be limited.

802.11i also offers scaled-down security for small networks without a RADIUS server. Based on a preshared key that must be configured identically on the client and access points, this method is potentially vulnerable to offline dictionary attacks if the key is too short or is not changed often enough, and there is no provision for user-level authentication.

802.11i technology is attracting much interest, but few companies have embarked on widespread deployments at this time. With myriad deployment complexities and the hardware costs involved with deploying 802.11i, actual adoption of the technology may crawl before it walks, despite the marketing claims we hear that wireless security is "solved" with 802.11i.

Many vendors began shipping AES-capable products intended to work with 802.11i well before the specification was approved by the IEEE. However, the Wi-Fi Alliance only started 802.11i certification testing in September, with the first products bearing WPA2 certification—the Wi-Fi Alliance moniker for interoperability certification for a subset of 802.11i features—in October.

However, the computational overhead from AES encryption means many legacy access points and client hardware devices may not be upgradable to 802.11i. As a rule of thumb, we've found that access points that currently support 802.11g and 802.1x will likely be firmware-upgradable to 802.11i. Administrators should check with their vendors' Web site for more information.

For client hardware, we focused our investigation on Wi-Fi clients embedded in laptop computers, a model that has become increasingly common during the last few years.

Intel Corp.'s 802.11b/g and a/b/g adapters (Intel Pro/Wireless models 2200 and 2915) will support WPA2. Dell Inc. and Hewlett-Packard Co. offer 802.11i-enabled drivers for these adapters on their support Web sites, and IBM expects to add WPA2 via its Access Connections software this quarter. However, it appears unlikely that Intel's 802.11b-only embedded adapters (Intel Pro/Wireless 2100) will be upgradable to 802.11i.

We've also found only a limited number of client supplicants that will work with 802.11i. Funk Software Inc.'s Odyssey client and the Intel ProSet application both work well, but Microsoft has not announced when its WPA2 supplicant will be available.

作者:Andrew Garcia

      
推荐 】【 打印 】【 发表评论 】【 加入收藏
最新评论 全部评论 

 相关文章
· 基于ZigBee和WiFi相结合的楼宇监测系统
· 物联网技术在工业领域的应用研究
· 无线射频识别(RFID)技术的发展
· WIFI串口即时通信使物联网成为现实
· 基于WiFi的RFID可扩展AMR车位检测系统
· RFID防伪标签在部队车辆管理中的应用
· 无线技术提高采矿效率的研究
· 基于RFID的防伪物流管理系统研究
· WiFi在智能家居控制领域应用
· RFID技术在五粮液酒防伪中的应用
 最新供求
·天津图书馆RFID标签采购项目成交公告
·南京晓庄学院数字化校园一卡通系统采购项目
·浙江大学城市学院监控系统及门禁系统竞争性
·邢台市图书馆RFID系统项目采购招标公告
·辽阳市图书馆RFID电子图书标签采购项目招标
·人民武装部营院信息化系统集成建设项目招标
·贺兰县文广局自助图书馆及RFID图书标签招标
·深圳市宝安区政府采购中心关于图书馆藏书整
·二代居民身份证阅读器和银行卡读卡器采购项
·武汉市城市管理局数字化城管系统通信服务政
 相关关键词搜索
·资讯中心WiFi  security  80211i  质检  防伪  应用  
·技术中心WiFi  security  80211i  质检  防伪  应用  
 
 
 
业界资讯 纵深报道 技术学院
国际资讯 | 国内资讯 | 国内企业 | 国外企业 | Global News
  重点专题
· RFID与亚运会 · 2010年RFID展会面面观
· RFID保驾上海世博会 · RFID与监狱
· 2009RFID行业发展回顾 · 智能卡与一卡通
· RFID与食品安全 · RFID与物联网
· NFC手机与支付 · RFID联盟产业园建设介绍
· RFID与智能交通 · 各国RFID频段标准与政策
· 出租车停运以及解决办法 · 863计划RFID专项
· RFID与医疗卫生
  相关产品

433MHz无线传输模块
JT506系列便携式-USBKey HF RFID读写器
UHF超高频电子标签一体机
JT900F桌面式UHF发卡器|915MHZ读写器
超高频手持机
Alien读写器四口读写器ALR9900+
JT500系列多协议RFID读写器
UHF超高频电子标签一体机
上海国感有源腕带式RFID标签
  推荐文章
· 律师事务所采用RFID技术监管单页机密文件
· 华盛顿公园棒球赛采用RFID门票
· Tagstand提供NFC解决方案
· 波士顿New Balance鞋店的RFID应用
· 韩国Hanmi采用RFID解决方案自动分拣药品
· 奢侈品服装制造商采用超高频RFID纺织标签
· 迪斯尼采用RFID服装库存管理及追踪系统
· 巴塞罗那服装店的试衣“魔镜”
· 欧洲轮胎制造商Goodyear对轮胎进行追踪
· Virtual Chemistry公司采用RFID对试验动物
  相关案例和方案
· 浅析物联网技术在生活垃圾收运处置中的应用
· 基于μ-Chip芯片RFID防伪票证系统的设计
· 城市农场中的物联网应用
· 医药公司利用RFID和生物识别技术进行防伪
· RFID防伪管理系统
· 出租车RFID电子标签防伪系统解决方案
  相关资讯文章
· 物联网最新行业前沿技术
· 抛开概念做应用 物联网需要要务实发展
· 茅台酒采用99DNA技术防伪溯源 项目已启动
· 物联网投资“外热内冷”
· 赛迪顾问:光物联成物联网应用新宠
· 物联网扶持基金扩大规模 应用安全或率先破
快 报 论 坛
· 新人报到
· [求助]Token 天线如何用HFSS仿真?
· 让家长放心,让学校安心 RFID 家校通系统
· 北京创羿RFID技术咨询,产品介绍
· 东陆高科RFID
· [求助]哪里有做监狱犯人防拆腕带的公司?
快 报 问 吧
· 基于中国余数定理的RFID认证算法
· 国内关于RFID、物联网等行业的协会有哪些?
· RFID物联网行业前途到底有多大?
· 请问山东有哪几家企业的标签封装比较好
· RFID的最新研究方向是?
· 山东有没有RFID试衣装置?
快 报 博 客
· 过滤设备解决了水质污染难题
· 天津小蜜蜂RFID酒店资产管理系统解决方案
· 天津小蜜蜂RFID防伪追溯技术在药品中的应用
· 有品位的男人
· 韵味女人与品位男人
· 人生就像一杯酒

关于我们 | 广告服务 | 帮助中心 | 联系我们 | 友情链接 | 版权申明
客服电话:0531-82679002   编辑部电话:0531-82679069   节假日电话:0531-89180705  
客服QQ:651127860 QQ群:41109672  47658979  MSN:RFIDinfo@126.com 厂商投稿:edit.rfidinfo@gmail.com
版权所有©2003-2009  RFID射频快报 鲁ICP备09066303号 增值电信业务经营许可证鲁B2-20050166号