Doc.: IEEE 802.11-00/410 Submission November 2000 Duncan Kitchin, IntelSlide 1 A Network Enrollment Protocol Duncan Kitchin, Intel.

Slides:



Advertisements
Similar presentations
Doc.: IEEE /0413r0 Submission March 2009 Dan Harkins, Aruba NetworksSlide 1 A Study Group for Enhanced Security Date: Authors:
Advertisements

Doc.: IEEE /178 Submission July 2000 A. Prasad, A. Raji Lucent TechnologiesSlide 1 A Proposal for IEEE e Security IEEE Task Group.
Doc.: IEEE /087 Submission May, 2000 Steven Gray, NOKIA Jyri Rinnemaa, Jouni Mikkonen Nokia Slide 1.
Doc.: IEEE /0527r0 Submission March 2010 Slide 1 A Periodic 5 MHz Measurement Pilot for Channel Scan Date: Authors:
Doc.: IEEE /2456r0 Submission September 2007 Ganesh Venkatesan (Intel Corporation)Slide 1 What is Home CE Environment? Date: Authors:
Doc.: IEEE /39 Submission March 2000 Keith Amann, SpectraLink CorporationSlide MAC Enhancements: Additional Requirements Considerations.
Doc.: IEEE /351 Submission October 2000 Maarten Hoeben, Menzo Wentink, IntersilSlide 1 Enhance D-QoS through Virtual DCF Maarten Hoeben, Menzo.
Doc.: IEEE /1012r0 Submission September 2009 Dan Harkins, Aruba NetworksSlide 1 Suite-B Compliance for a Mesh Network Date: Authors:
Overview of the SDE Protocol Presented by Ken Alonge Chair,
IEEE P802 Handoff ECSG Submission July 2003 Bernard Aboba, Microsoft Detection of Network Attachment (DNA) and Handoff ECSG Bernard Aboba Microsoft July.
Doc.: IEEE /1043 Submission NameAffiliationsAddressPhone Giwon ParkLG Electronics LG R&D Complex 533, Hogye- 1dong, Dongan-Gu, Anyang, Kyungki,
Doc.:IEEE /1523r4 Submission November 2011 Access Delay Reduction for FILS: Network Discovery & Access congestion Improvements Slide 1 Authors:
Submission doc.: IEEE /1326r1 August 2011 Hiroki Nakano, Trans New Technology, Inc.Slide 1 Early Key Generation by ECDH and PKC Date:
Doc.: IEEE /039 Submission January 2001 Haverinen/Edney, NokiaSlide 1 Use of GSM SIM Authentication in IEEE System Submitted to IEEE
IEEE INFOCOM 2004 MultiNet: Connecting to Multiple IEEE Networks Using a Single Wireless Card.
Doc.: IEEE /380r0 Submission May 2002 Duncan Kitchin, IntelSlide WG Assigned Numbers Authority Duncan Kitchin Intel Corporation.
Doc.: IEEE /095r0 Submission January 2003 Dan Harkins, Trapeze Networks.Slide 1 Fast Re-authentication Dan Harkins.
Doc.: IEEE /689r0 Submission November 2002 Dan Harkins, Trapeze Networks.Slide 1 Re-authentication when Roaming Dan Harkins.
Doc.: IEEE /1125r0 Submission September 2010 Marc Emmelmann, Fraunhofer FOKUSSlide 1 How does the (new) Fast Initial Link Set- Up PAR address.
Doc.: IEEE /684R2 Submission November 2002 Martin Lefkowitz, Trapeze NetworksSlide 1 Extended Keymap ID Martin Lefkowitz Trapeze Networks.
Doc.: IEEE /1521r2 Submission January 2012 Marc Emmelmann, FOKUSSlide 1 AP and Network Discovery Enhancements Date: Authors:
Doc.: IEEE /0142r0 Submission January 2011 Nir Shapira, Celeno Communications DL MU-MIMO Support for non-AP STAs Date: Authors: Slide.
Doc.: IEEE /0877r0 Submission June WG Slide 1 TGs response to CN NB comments Date: Authors:
Doc.: r0-I Submission July 22, 2003 Paul Lambert, Airgo NetworksSlide 1 Enabling Encryption in Hotspots by Decoupling the Privacy Field from.
Doc.: IEEE k Submission September 2003 Martin Lefkowitz, Trapeze NetworksSlide 1 Directed Probe Request With No Response Option Martin.
Doc.: IEEE xxx g Submission March 2011 Kuor Hsin Chang, Bob Mason (Elster Solutions) Project: IEEE P Working Group for Wireless.
Doc.: IEEE /108r0 Submission January 2003 Adrian Stephens, IntelSlide 1 Some proposed motions for HT SG Adrian P Stephens
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Confidential 1 IEEE u Overview Klaas Wierenga TF-Mobility Loughborough, May 7, 2009.
Medium Access Control Onno W. Purbo
Doc.: IEEE /037 Submission March 2000 Duncan Kitchin, Jesse Walker, Intel NIDSlide 1 Proposal for Enhanced Encryption Duncan Kitchin Jesse Walker.
Doc.: IEEE /0081r0 Submission January 2012 Osama Aboul-Magd, Huawei TechnologiesSlide 1 On Traffic Stream Setup for Audio/Visual Bridging Date:
Doc.: IEEE /0060r1 Submission January 2011 Minyoung Park, Intel Corp.Slide 1 Low Power Capability Support for ah Date: Authors:
Doc.: IEEE r Submission November 2004 Bob Beach, Symbol TechnologiesSlide 1 Fast Roaming Using Multiple Concurrent Associations Bob.
Doc.: IEEE /1019r0 Submission September 2004 Soohong Daniel Park & Jaehwan Lee Access Router Identifier (ARID) for supporting L3 mobility Soohong.
Submission doc.: IEEE 11-12/0553r4 May 2012 Jarkko Kneckt, NokiaSlide 1 Response Criteria of Probe Request Date: Authors:
Submission Page 1 November 2002 doc.: IEEE /677r0 Daryl Kaiser, Cisco Systems Radio Measurement Actions Daryl Kaiser (Cisco Systems) 12 November.
Doc.: IEEE /2215r4 Submission August 2007 Ganesh Venkatesan, Intel CorporationSlide 1 Proposal –Radio Resource Measurement Capability Enabled.
Doc.: IEEE /0357r0 Submission March 2008 Michelle Gong, Intel, et alSlide 1 Enhancement to Mesh Discovery Date: Authors:
Doc.: IEEE /0027r0 Submission January 2006 Slide 1 WiNOT Consortium: Proposal for online enrollment cluster Notice: This document has been prepared.
Doc.: IEEE /109r1 Submission July 2002 J. Edney, H. Haverinen, J-P Honkanen, P. Orava, Nokia Slide 1 Temporary MAC Addresses for Anonymity Jon.
Doc.: IEEE /1000r1 Submission July 2011 Jihyun Lee, LG ElectronicsSlide 1 TGai FILS Proposal Date: Authors: NameAffiliationsAddressPhone .
Submission doc.: IEEE 11/ ak Jan 2013 Norman Finn, Cisco SystemsSlide Qbz–802.11ak Solutions: Station Subsetting Issue Date:
Doc.: IEEE /0896r0 SubmissionJae Seung Lee, ETRISlide 1 Probe Request Filtering Criteria Date: July 2012.
Doc.: IEEE /0059r1 SubmissionJae Seung Lee, ETRI Selection of the AP for Scanning Date: Slide 1.
Erik Nicholson COSC 352 March 2, WPA Wi-Fi Protected Access New security standard adopted by Wi-Fi Alliance consortium Ensures compliance with different.
Submission doc.: IEEE /1309r0 November 2012 Non-TIM Mode Negotiation Date: Slide 1 Authors: Kaiying Lv, ZTE.
Chapter-7 Basic Wireless Concepts and Configuration.
Doc.: IEEE /1115r2 Submission J Chhabra, A. R. Prasad, J. Walker, H. AokiSlide s Security concepts Jasmeet Chhabra, Intel
Doc.: IEEE /0294r2 Submission March 2012 Jonathan Segev (Intel)Slide 1 Active Scanning Reply Window Date: Authors:
Security for location determination at a Public Domain
Opportunistic Wireless Encryption
Consideration on WUR frame for Fast Scanning
Consideration on WUR frame for Fast Scanning
Multi-band Discovery Assistance
Uplink Broadcast Service
Enhancements to Mesh Discovery
Enhancement to Mesh Discovery
Multi-band Discovery Assistance
OCT based 6 GHz AP Operation Discussion
Low Power Sensor Broadcast Use Cases
Listen to Probe Request from other STAs
GPS Aided WLAN Network Finder
Month Year doc.: IEEE yy/xxxxr0
Duncan Kitchin Intel Wireless LAN Operation
Directed Probe Request Clarification
FTM Frame Exchange Authentication
Fast Roaming Using Multiple Concurrent Associations
Use of EAPOL-Key messages
November 2000 FEC for QoS Duncan Kitchin, Intel Duncan Kitchin, Intel.
TGu/TGv Joint Meeting Date: Authors: May 2008 Month Year
Presentation transcript:

doc.: IEEE /410 Submission November 2000 Duncan Kitchin, IntelSlide 1 A Network Enrollment Protocol Duncan Kitchin, Intel

doc.: IEEE /410 Submission November 2000 Duncan Kitchin, IntelSlide 2 Problem Statement requires per-node configuration –SSID –encryption keys, mechanisms This is too complex for many products and/or users –TVs, VCRs, DVD players (no keyboard…) –consumers expect these products to work out of the box Security implications –the greatest security flaw we could introduce is making the system too difficult to configure correctly

doc.: IEEE /410 Submission November 2000 Duncan Kitchin, IntelSlide 3 Proposed Solution – What the User Sees User sees press a button at either end enrollment –same as used for garage door openers, cordless phones, cordless mice, keyboards Pressing a button on the AP makes it temporarily open for enrollment Two buttons at station, scan and enroll –first illuminates APs, cycling through list –second attempts enrollment in last AP illuminated

doc.: IEEE /410 Submission November 2000 Duncan Kitchin, IntelSlide 4 New Packets Use new generic management type & subtype, with action enroll –subaction illuminate –subaction enroll request –subaction enroll response

doc.: IEEE /410 Submission November 2000 Duncan Kitchin, IntelSlide 5 Scanning Station determines available APs by existing active or passive scanning, and maintains a list Each time the scan button is pressed, sends an enroll/illuminate packet to the next AP on the list An AP receiving an enroll/illuminate packet emits an audible or visual indication

doc.: IEEE /410 Submission November 2000 Duncan Kitchin, IntelSlide 6 Enrollment Process Station and AP create a Diffie-Hellman tunnel –Station creates DH value, sends to AP –AP never advertises that it is open, but accepts an enrollment request if it is and responds with its own DH value and encrypted parameters The tunnel is then used by the AP to send back to the station: –credentials for future authentication –other configuration parameters such as SSID

doc.: IEEE /410 Submission November 2000 Duncan Kitchin, IntelSlide 7 Packet Formats See 00/xxx for generic management frame type enroll/illuminate –no additional contents enroll/request –Diffie-Hellman element enroll/response –Diffie-Hellman element –configuration data, plus encrypted-content security credential elements

doc.: IEEE /410 Submission November 2000 Duncan Kitchin, IntelSlide 8 Process Summary enroll/illuminate indication request enroll/request enroll/response