Fast Authentication in TGai

Slides:



Advertisements
Similar presentations
Doc.: IEEE /1043 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang, Kyungki,
Advertisements

Doc.: IEEE /0255r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.: IEEE /1160 Submission NameAffiliationsAddressPhone George CherianQualcomm 5775 Morehouse Dr, San Diego, CA, USA
Doc.: IEEE /1160r1 Submission NameAffiliationsAddressPhone George CherianQualcomm 5775 Morehouse Dr, San Diego, CA, USA +1
Doc.:IEEE /0259r3 Submission March 2012 Reducing Probe Responses for faster AP discovery Slide 1 Authors: March 2012 NameAffiliationsAddressPhone .
Doc.: IEEE /0550 Submission NameAffiliationsAddressPhone Kiseon RyuLG Electronics10225 Willow Creek Rd, San Diego, CA, 92131, USA +1
Doc.: IEEE /1042r3 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.: IEEE /1042 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang, Kyungki,
Doc.: IEEE /0257r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.:IEEE /0259r4 Submission March 2012 Reducing Probe Responses for faster AP discovery Slide 1 Authors: March 2012 NameAffiliationsAddressPhone .
Submission doc.: IEEE /1034r4 September 2012 Jeongki Kim, LG ElectronicsSlide 1 Enhanced scanning procedure for FILS Date: Authors:
Doc.:IEEE /0258r7 Submission May 2012 Reducing Probe Responses for faster AP discovery Slide 1 Authors: May 2012 NameAffiliationsAddressPhone .
Doc.: IEEE /1042r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.:IEEE /0258r6 Submission May 2012 Reducing Probe Responses for faster AP discovery Slide 1 Authors: May 2012 NameAffiliationsAddressPhone .
Doc.: IEEE /0269r1 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu,
Access Control Mechanism for FILS
Omission of Probe Request
Month Year doc.: IEEE yy/xxxxr0 May 2012
AP discovery with FILS beacon
Proposed SFD Text for ai Link Setup Procedure
Discussions on FILS Authentication
TGai Guideline for Submissions to TGai Template Slides
Triggering the Broadcast Probe Response
FILS presentation on High Level Security Requirements
AP Discovery Information Broadcasting
Fast Authentication in TGai
Triggering the Broadcast Probe Response
Multi-channel information for AP discovery
Improvement on Active Scanning
Multiple Frequency Channel Scanning
FILS Association Date: Authors: Name Affiliations Address
MLME.SCAN-request Date: Authors: Nov 2012 Month Year
Scanning from Specific Channel
GAS procedure in TGai Date: Authors: Mar 2012 Month Year
Probe Request and Response in TGai
Access Control Mechanism for FILS
AP discovery with FILS beacon
Reducing Overhead in Active Scanning
Reducing the Probe Response transmission
Band adjustment for fasat AP discovery
Listen to Probe Request from other STAs
Fast Authentication in TGai : Updates to EAP-RP
Reducing Overhead in Active Scanning
Proposed SFD Text for ai Prioritized Active Scanning
Access Control Mechanism for FILS
Month Year doc.: IEEE yy/xxxxr0
Reducing Overhead in Active Scanning with Simulation Results
Prioritized Active Scanning in TGai
Access distribution in ai
Fast Authentication in TGai
AP Status Broadcast Date: Authors: November 2011
Access Control Mechanism for FILS
Reducing Overhead in Active Scanning with Simulation Results
Triggering the Broadcast Probe Response
Fast Authentication in TGai
Month Year doc.: IEEE yy/xxxxr0 May 2012
Differentiated Initial Link Setup (Follow Up)
Omission of Probe Request
Access distribution in ai
Proposed SFD Text for ai Prioritized Active Scanning
Month Year doc.: IEEE yy/xxxxr0
Scanning from Specific Channel
Fast passive scan for FILS
Multiple Frequency Channel Scanning
Reducing Overhead in Active Scanning
GAS procedure in TGai Date: Authors: May 2012 Month Year
Reducing Overhead in Active Scanning
MLME.SCAN-request Date: Authors: Nov 2012 Month Year
Reducing Probe Responses for faster AP discovery
Month Year doc.: IEEE yy/xxxxr0 May 2012
Presentation transcript:

Fast Authentication in TGai Month Year doc.: IEEE 802.11-yy/xxxxr0 Mar 2012 Fast Authentication in TGai Date: 2012-03-03 Authors: Name Affiliations Address Phone email Kiseon Ryu LG Electronics 10225 Willow Creek Rd, San Diego, CA, 92131, USA +1 (858)-635-5209 kiseon.ryu@lge.com Giwon Park LG R&D Complex 533, Hogye-1dong, Dongan-Gu, Anyang, Kyungki, 431-749, Korea +82-31-450-1879 giwon.park@lge.com Jaehyung Song +82-31-450-7898 jaehyung.song@lge.com Jinsam Kwak +82-31-450-7902 Jinsam.kwak@lge.com George Cherian Qualcomm 5775 Morehouse Dr., San Diego, CA 8586516645 gcherian@qualcomm.com Santosh Abraham Qualcomm Inc 858 651 6107 sabraham@qualcomm.com Kiseon Ryu, LG John Doe, Some Company

Month Year doc.: IEEE 802.11-yy/xxxxr0 Mar 2012 Abstract This document proposes optimization of the EAP-RP based fast authentication for FILS. Kiseon Ryu, LG John Doe, Some Company

Conformance w/ TGai PAR & 5C Month Year doc.: IEEE 802.11-yy/xxxxr0 Mar 2012 Conformance w/ TGai PAR & 5C Conformance Question Response Does the proposal degrade the security offered by Robust Security Network Association (RSNA) already defined in 802.11? No Does the proposal change the MAC SAP interface? Does the proposal require or introduce a change to the 802.1 architecture? Does the proposal introduce a change in the channel access mechanism? Does the proposal introduce a change in the PHY? Which of the following link set-up phases is addressed by the proposal? (1) AP Discovery (2) Network Discovery (3) Link (re-)establishment / exchange of security related messages (4) Higher layer aspects, e.g. IP address assignment 3 Kiseon Ryu, LG John Doe, Some Company

Background 11/1160r6 has proposed using EAP framework for FILS Month Year doc.: IEEE 802.11-yy/xxxxr0 Mar 2012 Background 11/1160r6 has proposed using EAP framework for FILS Uses the EAP-RP for fast authentication by using a pre-established FILS context (i.e., EMSK, rRK, and rIK) to improve the authentication time during association. STA can be disassociated with the AP due to several reasons (e.g., STA’s leaving the AP, STA’s inactivity, and etc.,) However, STA should perform full EAP or EAP-RP procedure whenever coming back to the AP Full EAP and EAP-RP requires communication between the STA and the authentication server Kiseon Ryu, LG John Doe, Some Company

Month Year doc.: IEEE 802.11-yy/xxxxr0 Mar 2012 Proposal STA/AP’s retaining the FILS context after disassociation for the specific time duration When the time duration has not been expired (i.e., FILS context is retained at both the STA and the AP) and the STA attempts to be associated with the AP, EAP-RP procedure can be omitted during association by using retained FILS context In this case, backbone signaling between AP and AS for EAP-RP is not necessary for re-authentication Kiseon Ryu, LG John Doe, Some Company

Optimization of EAP-RP based fast authentication Month Year doc.: IEEE 802.11-yy/xxxxr0 Mar 2012 Optimization of EAP-RP based fast authentication [step 1]. Full EAP authentication is performed between STA and AP1. [step 2]. STA disassociates from AP. [step 3]. STA/AP caches the STA/AP FILS contexts (i.e. PMK and rMSK, and etc.,) during specific time duration after STA’s disassociation/de-authentication. [step 4]. STA acquires Anonce via Beacon or probe response message. [step 5]. STA transmits the association request message with, MIC, EAPOL(Snonce, Anonce), If the STA is a previous associated STA and FILS contexts timer is not expired, AP re-use the STA’s FILS contexts (i.e., PMK, rMSK, and etc.,) and performs verification of association request message. If the association request message verification was failed, AP instructs STA to perform the full EAP authentication. [step 6]. If the association request message verification was successful, AP transmits the association response message to STA. If the STA successfully completed the message verification, it can access AP otherwise, STA shall perform the full EAP authentication procedure with authentication server. Kiseon Ryu, LG John Doe, Some Company

Optimization of EAP-RP based fast authentication Month Year doc.: IEEE 802.11-yy/xxxxr0 Mar 2012 Optimization of EAP-RP based fast authentication EAP-RP based fast authentication procedure can be optimized when: STA comebacks to the AP with which it was previously associated STA and AP retains the FILS contexts (e.g., PMK, rMSK, and etc.,) for the specific time duration (e.g., FILS context retain timer) after disassociation. If the FILS contexts is retained at both STA and AP, EAP procedure can be omitted during re-association. Kiseon Ryu, LG John Doe, Some Company

Month Year doc.: IEEE 802.11-yy/xxxxr0 Mar 2012 Motion for specification framework document (Voting at Hawaii F2F meeting) Motion Adopt the proposed text of contribution 11-12-0252-00-00ai or latest version. Yes No Abstain Kiseon Ryu, LG John Doe, Some Company