And WPA Authentication and Key Management Overview

The primary difference in WPA is in the initial association request (probe request) that the client and access point send. The client and access point must agree to a security capability during association.

After initial association and exchange of security capabilities, the client and authentication servers proceed with standard 802.1x authentication.

After successful authentication, the server derives and distributes a master key to the access point. The same master key is derived at the client.

With these master keys, the access point and the client perform a four-way handshake to validate the access point, and the client validates the group or broadcast key using a two-way handshake.

Unicast Keys: Four-Way Handshake

Before the WPA handshake can occur, the pairwise master key (PMK, a 256-bit key) is generated as a result of the 802.1x authentication process between the client and the authentication server, or the process uses the 64-hexadecimal character preshared key (or a key stream derived from the preshared key phrase).

Step 1 The access point sends a nonce or random number to the client.

Step 2 The client responds to the access point with its own nonce or random number, along with the WPA information element, pairwise transient key (PTK), and MIC key information.

Step 3 The access point sends the nonce again, along with the information element, PTK, MIC key information, and install message. The re-sending of this information validates that the client and access point share common authentication information.

6-56 Optimizing Converged Cisco Networks (ONT) v1.0 © 2006 Cisco Systems, Inc.

Step 4 The client sends MIC key information and the PTK to the access point for acknowledgment.

Note A pseudorandom function (PRF) is used to compute the PTK as a function of client and access point random numbers and the MAC addresses of the access point and client.

Group Key Handshake

The group master key (GMK) is either generated using a random number function or is initialized by the first PTK that the access point uses.

When the access point has the GMK, a group random number is generated. This random number is used to derive a group transient key (GTK). Inputs are a PRF that uses the random number and the access point address.

The GTK is used to provide a group key as well as MIC keys, which may be used to verify the integrity of the key data.

WPA Key Management Phases

As part of WPA compliance, an access point must be capable of advertising security capabilities in its 802.11 beacons. This process describes the unicast, multicast, and authentication types supported. From the capabilities advertised by the access point, the client selects the "best" supported security type for its authentication.

After the client has determined its authentication type, it proceeds with open authentication, using either 802.1x to a RADIUS server or using a preshared key between the access point and the client. This process has the advantage of mutual authentication of client and server, as well as providing a centralized resource for client admission control.

Upon completion of standard 802.1x or EAP messaging between the client and server, a master key is independently generated at the server and client. This master key is then used to derive a PTK that is used in the authentication of the encryption key components used between the access point and the client.

© 2006 Cisco Systems, Inc. Implement Wireless Scalability 6-57

Continue reading here: Data is not secure between the access point and the client

Was this article helpful?

0 0