login

SECURITY ANALYSIS AND IMPROVEMENTS FOR IEEE 802.11I

Published 1 January 2005
Changhua He, John C. Mitchell
Citations221

TL;DR

Under the threat model, 802.11i appears to provide effective data confidentiality and integrity when CCMP is used, and may provide satisfactory mutual authentication and key management, although there are some potential implementation oversights that may cause severe problems.

Abstract

This paper analyzes the IEEE 802.11i wireless networking standard with respect to data confidentiality, integrity, mutual authentication, and availability. Under our threat model, 802.11i appears to provide effective data confidentiality and integrity when CCMP is used. Furthermore, 802.11i may provide satisfactory mutual authentication and key management, although there are some potential implementation oversights that may cause severe problems. Since the 802.11i design does not emphasize availability, several DoS attacks are possible. We review the known DoS attacks on unprotected management frames and EAP frames, and discuss ways of mitigating them in 802.11i. The practicality of a DoS attack against Michael MIC Failure countermeasure is discussed and improvements are proposed. Two new DoS attacks and possible repairs are identified: RSN IE Poisoning and 4-Way Handshake Blocking. Finally some tradeoffs in failure-recovery strategies are discussed and an improved variant of 802.11i is proposed to address all the discussed vulnerabilities. 1

Keywords

Computer ScienceEngineering