Doc.: IEEE 802.11-11/1160r2 Submission NameAffiliationsAddressPhoneemail George Cherian Santosh Abraham Hemanth Sampath Qualcomm 5775 Morehouse Dr, San.

Slides:



Advertisements
Similar presentations
Doc.: IEEE /1186r0 Submission October 2004 Aboba and HarkinsSlide 1 PEKM (Post-EAP Key Management Protocol) Bernard Aboba, Microsoft Dan Harkins,
Advertisements

Doc.: IEEE /1043 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang, Kyungki,
Doc.:IEEE /1523r4 Submission November 2011 Access Delay Reduction for FILS: Network Discovery & Access congestion Improvements Slide 1 Authors:
Doc.: IEEE /0255r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Submission doc.: IEEE /0789r3 NameAffiliationsAddressPhone George Cherian Santosh Abraham Jouni Malinen Qualcomm 5775 Morehouse Dr, San Diego,
Doc.: IEEE /0093r2 Submission NameAffiliationsAddressPhone Hitoshi MORIOKAAllied Telesis R&D Center Tenjin, Chuo-ku, Fukuoka
Doc.: IEEE /1160 Submission NameAffiliationsAddressPhone George CherianQualcomm 5775 Morehouse Dr, San Diego, CA, USA
Doc.: IEEE /1160r1 Submission NameAffiliationsAddressPhone George CherianQualcomm 5775 Morehouse Dr, San Diego, CA, USA +1
Doc.: IEEE /1160r5 Submission NameAffiliationsAddressPhone George Cherian Santosh Abraham Hemanth Sampath Jouni Malinen Menzo Wentink Qualcomm.
Doc.: IEEE /1160r9 Submission NameAffiliationsAddressPhone George Cherian Santosh Abraham Hemanth Sampath Jouni Malinen Menzo Wentink Qualcomm.
Doc.: IEEE /0786r2 Submission Differentiated Initial Link Setup (Follow Up) July 2012 Lin Cai et al,Huawei.Slide 1 Authors: NameAffiliationsAddressPhone .
Submission doc.: IEEE /1167r0 August 2011 Hiroki Nakano, Trans New Technology, Inc.Slide 1 Upper Layer Data IE Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1521r2 Submission January 2012 Marc Emmelmann, FOKUSSlide 1 AP and Network Discovery Enhancements Date: Authors:
Doc.:IEEE /0259r3 Submission March 2012 Reducing Probe Responses for faster AP discovery Slide 1 Authors: March 2012 NameAffiliationsAddressPhone .
Doc.: IEEE /0059r3 Submission January 2010 Hiroki Nakano, Trans New Technology, Inc.Slide 1 An Example Protocol for FastAKM Date: Authors:
Doc.: IEEE /0119r00 Submission January 2011 Marc Emmelmann, Fraunhofer FokusSlide 1 Requirements for FILS Submissions coming from PAR & 5C Date:
Doc.: IEEE /0032r0 Submission NameAffiliationsAddressPhone Hitoshi MORIOKAAllied Telesis R&D Center Tenjin, Chuo-ku, Fukuoka
Doc.: IEEE /0780r1 Submission NameAffiliationsAddressPhone Ping Fang Zhiming Ding Phillip Barber Rob Sun Huawei Technologies Co., Ltd. Bldg.
Doc.: IEEE /0976r1 Submission July 2011 Hitoshi Morioka, ROOT INC.Slide 1 TGai Authentication Protocol Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0976r3 Submission July 2011 Hitoshi Morioka, ROOT INC.Slide 1 TGai Authentication Protocol Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0976r0 Submission July 2011 Hitoshi Morioka, ROOT INC.Slide 1 TGai Authentication Protocol Proposal Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /1042r3 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.: IEEE /1042 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang, Kyungki,
Submission doc.: IEEE /1003r2 July 2011 Hiroki Nakano, Trans New Technology, Inc.Slide 1 Upper Layer Data on Management frames Date:
Doc.: IEEE /0977r2 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA ROOT INC Tenjin, Chuo-ku, Fukuoka JAPAN
Doc.: IEEE /0547r1 Submission May 2012 Dapeng Liu, China MobileSlide 1 Extend 802.1X for higher layer configuration in FILS Date:
Submission doc.: IEEE /1034r4 September 2012 Jeongki Kim, LG ElectronicsSlide 1 Enhanced scanning procedure for FILS Date: Authors:
Submission doc.: IEEE ai May 2012 Lei Wang, InterDigital CommunicationsSlide 1 Proposed SFD Text for ai AP/STA Initiated FILS Optimizations.
Doc.: IEEE /1042r1 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang,
Doc.: IEEE /0275r3 Submission March 2012 Hitoshi Morioka, Allied Telesis R&D CenterSlide 1 Higher Layer Configuration Function for TGai SFD Date:
Doc.: IEEE /1160r7 Submission NameAffiliationsAddressPhone George Cherian Santosh Abraham Hemanth Sampath Jouni Malinen Menzo Wentink Qualcomm.
Doc.: IEEE /0977r1 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA ROOT INC Tenjin, Chuo-ku, Fukuoka JAPAN
Doc.: IEEE /0568r0 Submission May 2012 Young Hoon Kwon, Huawei Slide 1 AP Discovery Information Broadcasting Date: Authors: NameAffiliationsAddressPhone .
Doc.: IEEE /0977r6 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA Allied Telesis R&D Center Tenjin, Chuo-ku, Fukuoka
Doc.: IEEE /1426r00 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi- tech District,
Doc.:IEEE /1523r1 Submission November 2011 Access Delay Reduction for FILS: Network Discovery & Access congestion Improvements Slide 1 Authors:
Doc.: IEEE /1160r8 Submission NameAffiliationsAddressPhone George Cherian Santosh Abraham Hemanth Sampath Jouni Malinen Menzo Wentink Qualcomm.
Doc.: IEEE /0977r4 Submission NameAffiliationsAddressPhone Hitoshi MORIOKA Allied Telesis R&D Center Tenjin, Chuo-ku, Fukuoka
Doc.: IEEE /1244r0 Submission Sep 2011 Hiroshi Mano, Root, Inc.Slide 1 11ai overview (PAR, Scope and current status) Date: Authors:
Doc.: IEEE /1426r02 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District,
Doc.: IEEE /484r0 Submission NameAffiliationsAddressPhone George Cherian Santosh Abraham Qualcomm 5775 Morehouse Dr, San Diego, CA, USA +1.
Doc.: IEEE /0269r1 Submission NameAffiliationsAddressPhone ChengYan FengZTE Corporation No.800, Middle Tianfu Avenue, Hi-tech District, Chengdu,
Month Year doc.: IEEE yy/xxxxr0 May 2012
Proposed SFD Text for ai Link Setup Procedure
Discussions on FILS Authentication
Fast Authentication in TGai
Fast Authentication in TGai
Fast Authentication in TGai
Triggering the Broadcast Probe Response
EAP based Message Flow Optimization for FILS
Fast Authentication in TGai
Fast Authentication in TGai
GAS procedure in TGai Date: Authors: Mar 2012 Month Year
Reducing the Probe Response transmission
Band adjustment for fasat AP discovery
Fast Authentication in TGai
Fast Authentication in TGai : Updates to EAP-RP
Month Year doc.: IEEE yy/xxxxr0
Reducing Overhead in Active Scanning with Simulation Results
Fast Authentication in TGai
Access Control Mechanism for FILS
Reducing Overhead in Active Scanning with Simulation Results
Triggering the Broadcast Probe Response
Fast Authentication in TGai
Month Year doc.: IEEE yy/xxxxr0 May 2012
Differentiated Initial Link Setup (Follow Up)
Month Year doc.: IEEE yy/xxxxr0
Fast passive scan for FILS
GAS procedure in TGai Date: Authors: May 2012 Month Year
Month Year doc.: IEEE yy/xxxxr0 May 2012
Presentation transcript:

doc.: IEEE /1160r2 Submission NameAffiliationsAddressPhone George Cherian Santosh Abraham Hemanth Sampath Qualcomm 5775 Morehouse Dr, San Diego, CA, USA +1 (858) (858) (858) Jouni MalinenQualcomm Hermiankatu 6-8 D Tampere, Finland Menzo WentinkQualcomm Straatweg 66-S, Breukelen, Netherlands Hitoshi MORIOKAROOT INC Tenjin, Chuo-ku, Fukuoka JAPAN Hiroshi ManoROOT INC Nishi-Gotanda, Shinagawa-ku, Tokyo JAPAN Mark RISONCSRCambridge Business Park, Cowley Road, Cambridge CB4 0WZ UK Marc EmmelmannFraunhofer FOKUSKaiserin-Augusta-Alle Berlin Germany Fast Authentication in TGai Date: Sept 2011 Slide 1 Authors: Qualcomm

doc.: IEEE /1160r2 Submission Sept2011 Slide 2 Abstract This document proposes EAP-RP based Fast authentication and simultaneous IP address acquisition for FILS Qualcomm

doc.: IEEE /1160r2 Submission Conformance w/ TGai PAR & 5C Sept 2011 Qualcomm.Slide 3 Conformance QuestionResponse Does the proposal degrade the security offered by Robust Security Network Association (RSNA) already defined in ? No Does the proposal change the MAC SAP interface?May be Does the proposal require or introduce a change to the architecture?No Does the proposal introduce a change in the channel access mechanism?No Does the proposal introduce a change in the PHY?No Which of the following link set-up phases is addressed by the proposal? (1) AP Discovery (2) Network Discovery (3) Link (re-)establishment / exchange of security related messages (4) Higher layer aspects, e.g. IP address assignment 3, 4

doc.: IEEE /1160r2 Submission Background Previous contributions such as 11/0976r3 to 11ai for FILS feature: –Single pair of messages of authentication –Use of Beacon/ProbeResp to send Anonce –Use of Association Req/Resp to send ULI Other contributions such as 11/1047 have proposed using EAP framework for FILS We propose EAP-RP based Fast authentication and simultaneous IP address acquisition for FILS Sept 2011 QualcommSlide 4

doc.: IEEE /1160r2 Submission Introduction Key principles followed in this contribution: –Use of DHCP Use of DHCP Rapid commit DHCP is widely used for obtaining the IP address (also see 1047r2) DHCP exchanges must be protected –Use of EAP Builds on existing EAP framework in Retains currently standardized 802.1x security architecture See additional advantages of using EAP in a later slide –STA will execute full EAP authentication as part of the initial setup/provisioning Full EAP authentication can be considered as “out-of-the-box setup procedure” EAP-RP based re-authentication is used for FILS when the STA visits that network How to reduce the message rounds –Use of EAP-RP (EAP Reauthentication protocol) –Concurrent use of EAP-RP & DHCP Rapid Commit Sept 2011 QualcommSlide 5

doc.: IEEE /1160r2 Submission An example of how the solution is applied for FILS Sept 2011 QualcommSlide 6 Use case: Hot-spot pass through: A user passes by (several, non overlapping) publicly accessible WiFi hot-spots (e.g. ATTwifi at Starbucks) While having connectivity, the user up-&downloads s, twitter / facebook messages etc Step-1: User buys an STA, performs full EAP authentication as part of initial setup with a network (say, ATTwifi ) –In this example, let’s say, the network allows the EAP session to be maintained for one year Step-2 [this step repeated afterwards]: The user passes by (several, non overlapping) publicly accessible WiFi hot- spots (e.g. ATTwifi at Starbucks) –STA will perform Fast-Initial-Link setup with the ATTwifi network using EAP-RP

doc.: IEEE /1160r2 Submission High Level Concept* Sept 2011 QualcommSlide 7 STA AP 4-way handshake, no security 4-way handshake, no security.11i authentication.11i key setup Existing.11 STA AP Fast Authentication & Upper Layer Setup (DHCP).11ai 4 phases into 1. No need to process sequentially. These can be processed simultaneously. 4 phases into 1. No need to process sequentially. These can be processed simultaneously. Upper Layer Setup (i.e. DHCP) Upper Layer Setup (i.e. DHCP) * Slide merged from 11/0976r3

doc.: IEEE /1160r2 Submission Advantages of using EAP EAP allows multiple authentication protocols to be supported without having to pre-negotiate a specific one Allows authentication server to control which authentication protocol is used without the authenticator being fully configured –Authenticator can act as a “pass through” –Authenticator acts only on the outcome of authentication (say, deny access etc.) Simplifies credential management –Stored between authentication server and client EAP is required for interworking with 3GPP EPC and WiMAX –Pointed out in 1047r2 Sept 2011 QualcommSlide 8

doc.: IEEE /1160r2 Submission Use of EAP for FILS What is the issue in using EAP for FILS? –EAP authentication typically requires a minimum of two roundtrips Proposed Solution –Use of EAP-RP (EAP Reauthentication protocol) for FILS RFC 5295/5296 Preserves all the benefits of EAP Re-authentication is completed using a single pair of messages Can interwork with cellular technologies when single credential is used (for WiFi and cellular) to access the network Sept 2011 QualcommSlide 9

doc.: IEEE /1160r2 Submission Overview of EAP-RP Sept 2011 QualcommSlide 10 STAAuth1 Full EAP Method Exchange Auth2 MSK, EMSK rRK, rIK AS MSK, EMSK rRK, rIK EAP Success (MSK) EAP Success Initial EAP Exchange MSK EAP Req/Identity EAP Resp/Identity EAP Re-auth Initiate (authenticated with rIK) EAP Re-auth Finish (authenticated with rIK) rMSK EAP-RP Exchange (rMSK) rMSK EAP Re-auth Finish (authenticated with rIK)

doc.: IEEE /1160r2 Submission Key Hierarchy for ERP Sept 2011 QualcommSlide 11 rRK, rIK is maintained by Authentication Server and STA (not passed to Access Point) rMSK is passed to AP during ERP

doc.: IEEE /1160r2 Submission Fast Reauthentication with IP address assignment Sept 2011 QualcommSlide 12 [Step-0] Full authentication may happen using an AP or using a cellular system. [step 2] AP transmits the Beacon/Probe Resp. which includes.11ai capability indicator for ERP & simultaneous IP addr assignment. AP changes Anonce frequent enough [step-3] STA generates rMSK using [RFC 5296] before sending Assoc-Req rMSK = KDF (K, S), where K = rRK and S = rMSK label | "\0" | SEQ | length [step-4] STA packs the following messages as IEs of Association-Request –EAP Re-auth Initiate [Message Integrity using rIK] –DHCP Discover with Rapid Commit [Encrypted using KEK] –EAPOL-Key (Snonce, Anonce) [step-4] STA applies message integrity on the combined payload that include EAP-Re-Auth, DHCP-Discover & EAPOL-Key using KCK [step-5] AP holds the DHCP & EAPOL-Key message until it receives rMSK from AS [step 8b] AP performs MIC for DHCP & EAPOL Key messages and decrypt DHCP

doc.: IEEE /1160r2 Submission Appendix Sept 2011 QualcommSlide 13

doc.: IEEE /1160r2 Submission Why not just use r? Scalability –11r is used primarily in the context of fast-handoff from one AP to another –STA may have a large interval (with no WiFi connectivity) after leaving the first AP (where the STA had a connectivity) before it connects to a new AP –Caching the information for a large number of STAs over a large period of time is not scalable Interworking with cellular network –If the STA had used cellular system for IP connectivity and then move to WiFi, 11r will not be helpful to expedite the link-setup Sept 2011 QualcommSlide 14