Presentation is loading. Please wait.

Presentation is loading. Please wait.

Doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 1 March 2004 WLAN Backend System Security and WLAN Interworking Security Andrew Myers British.

Similar presentations


Presentation on theme: "Doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 1 March 2004 WLAN Backend System Security and WLAN Interworking Security Andrew Myers British."— Presentation transcript:

1 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 1 March 2004 WLAN Backend System Security and WLAN Interworking Security Andrew Myers British Telecommunications (WNG-SC) 18 th March 2004

2 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 2 March 2004 Introduction Backend System Security WLAN Interworking Security Security of WLANs when interworking with external networks such as 3GPP etc...

3 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 3 March 2004 WLAN Interworking Security WLAN Interworking Security The purpose of this presentation is to stimulate discussion on common approaches to securing backend systems within IEEE 802.11 for the development of WLAN platforms and the security of WLAN interworking Why? …. A common security approach was adopted in the cellular or mobile networks with the primary reason to provide roaming capability which has proved to be very successful. A common security approach is one criteria for establishing partnerships between operators. Security is often a key aspect of Service Level Agreements Therefore the question is, does a common security approach need to be considered for guidance on developing WLANs?

4 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 4 March 2004 HSSP A Customer Inbound Access Point C Firewall HSSP A Wireless LAN Hot Spot 802.11 Network Layer HSSP A Core Network Internet Other Services Corporate A VPN Data Centre FW WLAN Back End System Security

5 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 5 March 2004 Data Centre & Core Network Nodes Access Points AAA Server –Diameter –Radius Node Billing –TAP Records Data Centre Network Components –Service Selection Gateways –Network Management Systems –Service Management Systems –Internal Firewalls Access Point Controller [CAPWAP]?

6 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 6 March 2004 Security Mechanisms 802.1X authentication for service segregation? VPN Tunnels –IPSec –SSL End User Management –Link Layer Key Management –Mechanisms for immediate Service Termination

7 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 7 March 2004 Generic Security Considerations Computer Installations Computer Viruses Cryptography Data Comms and Networks Computer Development & Support Failure & Disaster Protection Interconnection Internet & Intranet Passwords & UserIDs PC Security Product Protection Information Management Data Protection Computer Media Handling Telecomms Fraud Alliances and Joint Ventures

8 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 8 March 2004 HSSP A Customer Inbound Access Point C Firewall HSSP A Wireless LAN Hot Spot IPSec Application Layer 802.11 Network Layer HSSP A Core Network HSSP A Customer Outbound Data Centre Access Point C Firewall Partner HSSP Wireless LAN Hot Spot 802.11 Network Layer Partner HSSP Core Network Other Services Internet Other Services Corporate A VPN Internet Data Centre WLAN Interworking Security

9 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 9 March 2004 Open Questions What consideration has been given by IEEE 802.11 to the security measures and mechanisms that need to be applied to the various network nodes on a WLAN platform? Are there any other network nodes or security mechanisms that should be included? Is the interworking scenario likely or feasible (especially in terms of security and scalability)? Will / should the WIEN Study Group be addressing end to end security as well as interworking security?

10 doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 10 March 2004 Summary End to End Security –platform –service WLAN Interworking Security Security of interworking WLAN with other platforms e.g. GPRS, 3GPP etc...


Download ppt "Doc.: IEEE 802.11-04/0407r0 Submission Andrew Myers, BT Slide 1 March 2004 WLAN Backend System Security and WLAN Interworking Security Andrew Myers British."

Similar presentations


Ads by Google