• DocumentCode
    2657816
  • Title

    Per Packet Authentication for IEEE 802.11 wireless LAN

  • Author

    Junaid, Muhammad ; Akbar, M. ; Mufti, Muid

  • Author_Institution
    Multidiscipline Degree Program, NUST, Karachi
  • fYear
    2008
  • fDate
    23-24 Dec. 2008
  • Firstpage
    207
  • Lastpage
    212
  • Abstract
    Wireless Networks call for enhanced confidentiality, integrity and authenticaton services because of their inherent weakness of ubiquitous signals. Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) has been recently employed to provide security to IEEE 802.11 Wireless LANs. It has been shown in our earlier published work that CCMP is vulnerable to Time Memory Trade off (TMTO) attack. To overcome the said vulnerability, this paper presents a design and description of strengthening the security of WLAN packets using Per-Packet security mechanism. The architecture of Per-Packet security mechanism involves introduction of Per-Packet Authentication and Secret Nonce. The proposed Per-Packet Authentication protocol is a continuous challenge response process operating throughout the session. The Per-Packet authentication promptly secures the connection against unauthorized access by immediately discarding the packet if Per-Packet Authentication fails. We have proposed to derive the Nonce from the session key and keep it secret. Since the nonce is unique and secret, it provides freshness and unpredictability. The freshness provides protection against replay attacks, the unpredictability of Nonce prevents pre-computation attack. Same Nonce is used as a challenge-text from authenticator to supplicant. Per packet Security mechanism strengthens the security of authentication mechanism and counter mode operation irrespective of the security of causal encryption algorithm.
  • Keywords
    IEEE standards; data integrity; message authentication; telecommunication security; ubiquitous computing; wireless LAN; IEEE 802.11 wireless LAN; authenticaton services; counter mode cipher block chaining message authentication code protocol; data integrity; enhanced confidentiality; per packet security; per-packet authentication; per-packet security; replay attacks; secret nonce; time memory trade off attack; ubiquitous signals; wireless networks; Authentication; Counting circuits; Cryptography; Data security; Educational institutions; Military computing; Pervasive computing; Protection; Protocols; Wireless LAN; CCMP Protocol; IEEE 802.11; authentication; security; wireless networks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Multitopic Conference, 2008. INMIC 2008. IEEE International
  • Conference_Location
    Karachi
  • Print_ISBN
    978-1-4244-2823-6
  • Electronic_ISBN
    978-1-4244-2824-3
  • Type

    conf

  • DOI
    10.1109/INMIC.2008.4777737
  • Filename
    4777737