Presentation is loading. Please wait.

Presentation is loading. Please wait.

Martin Lefkowitz Trapeze Networks

Similar presentations


Presentation on theme: "Martin Lefkowitz Trapeze Networks"— Presentation transcript:

1 Martin Lefkowitz Trapeze Networks
November 2002 Extended Keymap ID Martin Lefkowitz Trapeze Networks Martin Lefkowitz, Trapeze Networks

2 Extended Keymap ID Current Encryption key Technology
Month 2000 doc.: IEEE /xxx November 2002 Extended Keymap ID Current Encryption key Technology Only 2 bits for 4 different key slots leaving a total of 4 keys per BSS per STA Only 2 bits for 4 different key slots leaving a total of 4 keys per BSS for multicast/broadcast Martin Lefkowitz, Trapeze Networks John Doe, His Company

3 Month 2000 doc.: IEEE /xxx November 2002 What if? We added a mechanism whereby we could use more than 4 keys per STA for either Unicast or Broadcast traffic. A STA can receive secure multicast traffic based on application while still able to respond to multicast IP traffic like arp. Martin Lefkowitz, Trapeze Networks John Doe, His Company

4 Why Premium Subscriptions in the WISP, or carrier area
November 2002 Why Premium Subscriptions in the WISP, or carrier area Pay Per view Subscription broadcast data service An Administrator can determine if errors are caused by configured events or unconfigured events. A heterogenous environment can support multiple group keys for a more graceful transition to stronger encryption. Martin Lefkowitz, Trapeze Networks

5 November 2002 How Add a field to the EAPOL Key Descriptor that indicates the value of the 12 bit field in the encryption header of the MPDU format. EAPOL Key messages have an 8 byte field that is reserved to zero. 802.1x already has a Key ID f field that is used for multiple group keys. Proposal is to make two of those bytes the Key ID fields Martin Lefkowitz, Trapeze Networks

6 November 2002 How Assign some reserved bits in the encryption header to map a Key Id to a particular encryption key There are 12 bits available between the key ID and TSC/IV fields of TKIP and CCMP WRAP would need to change WRAP needs to change anyway to be consistent with the other RSN modes. Martin Lefkowitz, Trapeze Networks

7 How Add Key Id field to MPDU format.
November 2002 How Add Key Id field to MPDU format. There are enough bits in the reserved field with 48 bit counter format Noted Differences between CCMP and TKIP Martin Lefkowitz, Trapeze Networks

8 KID EX = Key ID Extension
November 2002 TKIP MPDU Format KID EX = Key ID Extension Martin Lefkowitz, Trapeze Networks

9 November 2002 CCMP MPDU Format Martin Lefkowitz, Trapeze Networks

10 November 2002 How Add SNMP MIB: dot11numKeymapID Number of different key map IV a STA needs to keep track of. dot11recievedFramesNoKeymap Indicates how many frames a STA has received for which it did not have the keymap ID. A normal situation. Add appropriate logic to Pseudo code after the key has been looked up if that entry contains a key that is null discard the frame body and increment dot11WEPUndecryptableCount else if there is no key entry for keymap field in MPDU Increment dot11recievedFramesNoKeymap attempt to decrypt with that key, incrementing dot11WEPICVErrorCount if the ICV check fails Martin Lefkowitz, Trapeze Networks

11 November 2002 Conclusion Key IDs can be exended for both broadcast and unicast traffic with little change to the current SSN/TGI implementations Martin Lefkowitz, Trapeze Networks


Download ppt "Martin Lefkowitz Trapeze Networks"

Similar presentations


Ads by Google