Also known as pre-RSN IEEE 802.11, IEEE 802.11 technologies that rely on Wired Equivalent Privacy (WEP) have several well-documented security problems that can be exploited to circumvent or adversely impact access control and authentication, confidentiality, integrity, and availability. To address these, IEEE amended IEEE 802.11 with 802.11i, which was approved in July 2004.
The IEEE 802.11i specification introduces the concept of a Robust Security Network (RSN), which is a wireless network that allows the creation of RSN associations (RSNA) only. RSNAs are logical connections between communicating IEEE 802.11 entities established through the IEEE 802.11i 4-Way Handshake. RSNAs allow for the protection of data frames and provide enhanced security relative to the flawed WEP. RSNAs provide the following security features for IEEE 802.11 WLANs:
+ Enhanced User and Message Authentication Mechanisms. The Extensible Authentication Protocol (EAP) provides the authentication framework for IEEE 802.11 RSNs that use IEEE 802.1X port-based access control. To accomplish mutual authentication between an AP and a STA, the IEEE 802.1X standard defines an additional entity, an authentication server (AS). IEEE 802.1X allows the client to authenticate to the network through the use of the AS. If the
authentication succeeds, the AP receives the resulting Pairwise Master Key (PMK).
EAP defines the stages of an EAP conversation that includes one or more EAP methods. The EAP methods perform the authentication transaction and generate cryptographic keying material. While the basic rules of the EAP conversation are common to all EAP implementations, the EAP methods can vary from one implementation to another, and EAP can be adapted to new
authentication methods as they become available. This flexibility has benefits, but it may also introduce risk. Therefore, organizations should select EAP methods based on a risk assessment of the target environment. Only some EAP methods, such as certain Transport Layer Security- based methods (e.g., EAP-TLS, EAP-Tunneled TLS [EAP-TTLS], Protected EAP [PEAP], EAP Flexible Authentication via Secure Tunneling [EAP-FAST]), can satisfy the security
requirements for WLANs.
Before organizations select WLAN equipment, they should review their existing identity management infrastructure, authentication requirements, and security policy to determine the EAP method or methods that are most appropriate in their environment, then purchase systems that support the chosen EAP methods. Many EAP methods are currently defined only in IETF Internet-drafts and thus are not yet official standards. Organizations are encouraged to obtain the latest available information before making final determinations on their IEEE 802.11 RSN authentication architecture and product procurement.
+ Cryptographic Key Management. RSNAs use several cryptographic keys to support key generation, encryption, authentication, and integrity functions. The IEEE 802.11i specification defines two key hierarchies for RSNAs: the Pairwise Key Hierarchy, which is designed for unicast data traffic protection, and the Group Key Hierarchy, which is intended for
multicast/broadcast traffic protection. In the Pairwise Key Hierarchy, keys may be installed in RSNA devices (ASs and STAs) through two methods:
–
Delivering a pre-shared key (PSK) through an out-of-band mechanism. The IEEE 802.11 standard does not specify how PSKs are to be generated or distributed, so these decisions are left to organizations implementing IEEE 802.11 networks. As a result, organizations should review any PSK approach carefully for possible vulnerabilities and evaluate its performance implications. Distributing PSKs in a large network might be infeasible.–
Delivering an authentication, authorization, and accounting (AAA) key through EAP during authentication. Decisions on the appropriate EAP authentication methods are left toorganizations implementing STAs and ASs. As a result, organizations should carefully review any EAP authentication methods for possible vulnerabilities.
Most organizations choose to implement EAP for authentication instead of using PSKs because of the resources needed for proper PSK administration. EAP authentication requires an
organization to use an AS, which may necessitate the use of a public key infrastructure (PKI). Organizations that already have ASs for Web, e-mail, file and print services, and other
authentication needs, should consider integrating this technology into their RSN solutions. Most leading network operating systems and directory solutions offer the support needed for RSN integration.
Robust Enciphering and Data Integrity Mechanisms. IEEE 802.11 defines WEP as a data
confidentiality and integrity protocol. The IEEE 802.11i amendment defines two additional protocols for RSNAs: Temporal Key Integrity Protocol (TKIP) and Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP). Federal agencies are required to use Federal
Information Processing Standards (FIPS)-approved cryptographic algorithms that are contained in FIPS- validated cryptographic modules. Of WEP, TKIP, and CCMP, only CCMP uses a core cryptographic algorithm that is FIPS-approved, the Advanced Encryption Standard (AES). For other security features, CCMP offers the same or stronger implementations than WEP and TKIP. Accordingly, NIST requires the use of CCMP for securing Federal agencies’ IEEE 802.11-based WLANs. For legacy IEEE 802.11 equipment that does not provide CCMP, auxiliary security protection is required; one possibility is the use of an IPsec VPN, using FIPS-approved cryptographic algorithms.
IEEE 802.11i also uses a function known as IEEE 802.1X port-based access control. The IEEE 802.1X framework specified by the IEEE 802.11i amendment provides the means to block user access to the DS until authentication is successful, thereby controlling access to network resources. The technique used to block access is known as port-based access control; it involves the AP distinguishing between EAP and non-EAP frames, then passing EAP frames through an uncontrolled port and non-EAP frames through a controlled port, which can block access.