Presentation is loading. Please wait.

Presentation is loading. Please wait.

Doc.: IEEE 802.11-12/0269r1 Submission NameAffiliationsAddressPhoneemail ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu,

Similar presentations


Presentation on theme: "Doc.: IEEE 802.11-12/0269r1 Submission NameAffiliationsAddressPhoneemail ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu,"— Presentation transcript:

1 doc.: IEEE 802.11-12/0269r1 Submission NameAffiliationsAddressPhoneemail ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu, China +86-28- 85342869 feng.chengyan@zte.com.cn Li ZhuZTE CorporationE3048,Bibo Rd,Pudong,shanghai, China +86-21- 68896274 zhu.li8@zte.com.cn Bo SunZTE CorporationJ4, ZTE Building, #10 Sth Tangyan Rd., Xi'an, China +86-29- 88458058 sun.bo1@zte.com.cn Fast Security Setup Mar 2012 ZTE CorporationSlide 1 Authors:

2 doc.: IEEE 802.11-12/0269r1 Submission Abstract This document proposes an optimization for EAP-RP based re-authentication for FILS. Mar 2012 ZTE CorporationSlide 2

3 doc.: IEEE 802.11-12/0269r1 Submission Conformance w/ Tgai PAR & 5C Mar 2012 ZTE CorporationSlide 3 Conformance QuestionResponse Does the proposal degrade the security offered by Robust Security Network Association (RSNA) already defined in 802.11? No Does the proposal change the MAC SAP interface?No Does the proposal require or introduce a change to the 802.1 architecture?No Does the proposal introduce a change in the channel access mechanism?No Does the proposal introduce a change in the PHY?No Which of the following link set-up phases is addressed by the proposal? (1) AP Discovery (2) Network Discovery (3) Link (re-)establishment / exchange of security related messages (4) Higher layer aspects, e.g. IP address assignment 3

4 doc.: IEEE 802.11-12/0269r1 Submission Background 11/1160r6 has proposed that –Use of optimized full EAP in 11/1047r6 when EAP-RP context is not setup, or has expired; –Otherwise use EAP-RP based fast authentication in 11/1160r46 Our view: –It is a good idea to combine full EAP authentication with EAP re- authentication; –It could cover both initial security setup case and re-authentication case; –It could provide fast security setup effectively. Mar 2012 ZTE CorporationSlide 4

5 doc.: IEEE 802.11-12/0269r1 Submission Our Concern In 11/1160r6 it is proposed that ANonce is transmitted in Beacon or Probe Rsp in EAP-RP procedure. Beacon is a broadcast message. Probe Response could be broadcast sometimes. While ANonce shall be different per STA in RSNA. ANonce is used to derive PTK together with Snonce generated by STA. There is security compromise if ANonce is sent in broadcast message. Mar 2012 ZTE CorporationSlide 5 AP STA2 STA3STA1 ANonce1 ANonce2 ANonce3 AP STA2 STA3STA1 ANonce1 ANonce transmission in original RSNA ANonce transmission in 11/1160r6

6 doc.: IEEE 802.11-12/0269r1 Submission Proposal Introduction SNonce is transmitted in unicast Authentication Req message. ANonce is transmitted in unicast Authentication Rsp message. Mar 2012 ZTE CorporationSlide 6

7 doc.: IEEE 802.11-12/0269r1 Submission Proposed Fast Security Setup Procedure-EAP-RP Mar 2012 ZTE CorporationSlide 7

8 doc.: IEEE 802.11-12/0269r1 Submission Straw Poll Do you agree to add the following sentence to TGai SFD, 12/0151r3 SNonce is transmitted in Authentication Req message and ANonce is transmitted in Authentication Rsp message when EAP-RP is used. Yes: No: Abstain: Mar 2012 ZTE CorporationSlide 8


Download ppt "Doc.: IEEE 802.11-12/0269r1 Submission NameAffiliationsAddressPhoneemail ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu,"

Similar presentations


Ads by Google