Authentication and Authorization of Wireless Users

The 802.11 standard supports different types of authentication. The two most generic types are open and shared-key authentication. In most wireless networks, a service set ID (SSID) is specified to identify the wireless network. The basic mechanisms of 802.11 augment the identification by using SSIDs with authentication mechanisms that prevent the client from sending data to and receiving data from the access point unless the client has the correct shared key. One of the most basic wireless authentication protocols is the wired equivalent privacy (WEP) standard. The following section describes WEP in detail.

WEP, an optional encryption standard in 802.11 that most vendors support, is implemented in the MAC layer. WEP-enabled devices encrypt the payload of each 802.11 frame before transmission by using an RC4 stream cipher. The packets are then decrypted in the wireless access point. WEP encrypts only data between 802.11 stations. After the frame enters the wired side of the network, WEP no longer applies.

During the encryption process, WEP arranges a key schedule (otherwise known as a seed) by concatenating the shared secret key supplied by the user of the sending station with a random-generated 24-bit initialization vector (IV). The IV lengthens the life of the secret key because the station can change the IV for each frame transmission. WEP inputs the resulting seed into a pseudorandom number generator that produces a key-stream equal to the length of the frame payload plus a 32-bit integrity check value (ICV), as illustrated in Figure 8-4.

Figure 8-4 WEP Process

Readers' Questions

  • kauko paija
    What is the message integrity check (mic) within wpa used for?
    2 months ago
  • The Message Integrity Check (MIC) is a feature used within Wi-Fi Protected Access (WPA) to ensure the integrity and authenticity of network data packets. It is primarily used to prevent unauthorized modifications or tampering of data during transmission. When a device sends a data packet over a WPA-protected network, it calculates a MIC for that packet using a cryptographic algorithm, such as HMAC-SHA1. This MIC is appended to the packet before being transmitted. On the receiving end, the recipient device also calculates the MIC for the received packet using the same algorithm. It then compares this calculated MIC with the one received along with the packet. If they match, it means that the packet has not been altered during transmission and can be trusted. The MIC provides assurance that the data packets have not been modified, forged, or tampered with while traversing the wireless network. This helps to maintain the integrity and security of the transmitted data, ensuring that only authorized parties can access and modify it.
    • sabrina gottlieb
      What is the message integrity check (mic) within wpa used for?
      3 months ago
    • The Message Integrity Check (MIC) in Wi-Fi Protected Access (WPA) is used for ensuring the integrity and authenticity of data transmitted over a wireless network. It verifies that the data packets have not been tampered with or altered during transmission. The MIC is generated by applying a cryptographic algorithm (usually using the Advanced Encryption Standard, AES) to the payload and some additional information within the data packet. This algorithm calculates a unique hash value based on the data, which is then added to the packet. At the receiving end, the same cryptographic algorithm is applied to the received data, including the MIC. If the calculated MIC matches the one received with the packet, it means that the data has not been modified or tampered with during transmission. However, if the MIC does not match, it indicates that the data might have been modified, and the packet could be discarded to prevent any potential security risks. By incorporating the MIC, WPA aims to provide protection against certain types of attacks, such as the insertion or modification of data packets by unauthorized individuals. It helps to ensure the integrity and authenticity of the transmitted data, enhancing the security of the wireless network.
      • Mehari
        Which version of wired equivalent privacy (wep) uses a 104bit key size?
        3 months ago
      • The version of Wired Equivalent Privacy (WEP) that uses a 104-bit key size is called WEP-104. It is an older security protocol designed to secure wireless networks. However, it is now considered weak and insecure, as it is susceptible to various attacks. It is recommended to use stronger and more secure encryption protocols like WPA or WPA2 instead.
        • robert
          What is the message integrity check (mic) within wpa used for?
          4 months ago
        • Message integrity checks (MICs) within WPA are used to authenticate messages sent across the wireless network. They are designed to protect against intrusion by ensuring that the transmitted message has not been tampered with or corrupted in transit. The MIC uses a cryptographic hash algorithm to produce a code which is sent with each message. This code acts as a digital signature which is used to verify the integrity of the message.
          • libby
            How does the receiving station on a network use the crc to verify that it received accurate data?
            5 months ago
          • The receiving station on a network uses the Cyclic Redundancy Check (CRC) to verify that the data it receives is accurate. The CRC is a mathematical algorithm used to check whether the data received is the same as the data sent. The receiver calculates the CRC checksum using the same algorithm as the sender and compares it with the corresponding checksum received. If the two checksums match, the data is considered to be accurate; if they don’t match, then the data is considered to be corrupted and needs to be sent again.
            • Anna
              What is the message integrity check (mic) within wpa used for?
              5 months ago
            • The Message Integrity Check (MIC) is a cryptographic integrity check within the WPA protocol designed to detect message alterations that may have occurred during the transmission of data. The MIC generates a unique cryptographic hash of the message content to detect any modifications during transmission, protecting against malicious attacks such as man-in-the-middle attacks.
              • tewelde semere
                What is the message integrity check (mic) within wpa used for?
                6 months ago
              • The Message Integrity Check (MIC) within WPA is used to ensure that data has not been altered or tampered with in transit and to verify the authenticity of the message sender. It is a cryptographic checksum that is generated using a secret key known only by the sender and receiver. The MIC is then appended to the data packet and used to verify the integrity of the message when it is received by the receiver.
                • feaven
                  What is the message integrity check (mic) within wpa used for?
                  7 months ago
                • Message Integrity Check (MIC) is used to ensure that data has not been modified during transmission between two devices on a wireless network. It verifies that the data has not been corrupted in any way, preventing an attacker from reading or tampering with the data.
                  • Xavier
                    Which ieee standard defines authentication and authorization in wireless networks?
                    8 months ago
                  • IEEE 802.11x is the standard that defines authentication and authorization in wireless networks.
                    • guido trentini
                      What is the message integrity check (mic) within wpa used for?
                      8 months ago
                    • The Message Integrity Check (MIC) within WPA is used to ensure that frames have not been modified or tampered with during transmission. It is a security feature that prevents attackers from making changes to the data frames.
                      • Emmi Muukkonen
                        What is the message integrity check (mic) within wpa used for?
                        9 months ago
                      • The Message Integrity Check (MIC) within WPA is used to ensure the integrity of data packets transmitted across the network. It does this by generating a hash for each data packet and validating it against a key. If the hash does not match the key, then the data packet has been tampered with, and the network connection is terminated.
                        • malcolm
                          What is the message integrity check (mic) within wpa used for?
                          10 months ago
                        • The Message Integrity Check (MIC) within WPA is used to authenticate the received messages between two parties. It ensures that the packets sent between two parties have not been tampered with or altered in any way, thus providing additional security.
                          • camelia
                            What is the message integrity check (mic) within wpa used for?
                            10 months ago
                          • The Message Integrity Check (MIC) within WPA is used for ensuring the integrity of data transfer by verifying that the transmitted data has not been altered during transmission. The MIC verifies that the data packets have not been changed in any way by performing a calculation on the data and encrypting the result. If the result of the calculation on the received packet matches the MIC sent with the packet, the data is considered valid and uncorrupted.
                            • anneli
                              What is the message integrity check (mic) within wpa used for?
                              10 months ago
                            • The Message Integrity Check (MIC) within WPA is used to verify that a message is not altered during transmission. The MIC provides automatic protection against certain types of malicious attacks and is utilized as a mechanism to protect the integrity of message authentication codes (MAC), ensuring that a user's authentication information is not tampered with.
                              • daniel
                                What is the message integrity check (mic) within wpa used for?
                                10 months ago
                              • The Message Integrity Check (MIC) within WPA is used to detect integrity of a message or data. It ensures that the data has not been modified or tampered with while in transit. The MIC is used to verify the authenticity of the data, which helps prevent malicious attacks such as man-in-the-middle.
                                • luciana
                                  What is the size of the secret key used in wep encryption?
                                  10 months ago
                                • The secret key used in WEP encryption is typically 40 bits or 104 bits.
                                  • bisirat semhar
                                    What is the message integrity check (mic) within wpa used for?
                                    10 months ago
                                  • The Message Integrity Check (MIC) within WPA is used to verify that the data transmitted between devices has not been modified or tampered with in any way. It is a cryptographic integrity check between the two communicating parties to ensure the data is consistent, accurate, and secure.
                                    • riley gibson
                                      Which of the following protocols or mechanisms is used to provide security on a wireless network?
                                      10 months ago
                                    • maria
                                      Which is true about wireless authentication methods?
                                      10 months ago
                                    • Wireless authentication methods provide a secure way to access a network without the need for cables.

                                      Initialization

                                      Vector (IV)

                                      Shared Key —

                                      WEP

                                      Sequence

                                      PRNG

                                      Seed

                                      Plain Text Message

                                      Plain Text Message

                                      The following steps are illustrated in Figure 8-4:

                                      1 The ICV is calculated using CRC-32 and concatenated to the plaintext message.

                                      2 A random IV and the shared secret key are also concatenated producing the seed.

                                      3 This seed is the input to the WEP Pseudorandom Number Generator (PRNG). WEP uses RC4 PRNG of RSA Data Security to produce a pseudorandom sequence.

                                      4 The message is encrypted by using an XOR operation with the sequence generated in the previous step.

                                      5 The encrypted message is sent to the other end.

                                      The ICV is a check sum that the receiving station eventually recalculates and compares to the one sent by the sending station to determine whether the transmitted data underwent any form of tampering while in transient. If the receiving station calculates an ICV that does not match the one found in the frame, the receiving station can reject the frame or flag the user.

                                      NOTE WEP shared secrets use 40-bit, 64-bit, or 128-bit keys.

                                      WEP has some limitations and has undergone extensive examination and criticism over the past years. In short, WEP is vulnerable because of its relatively short IVs and keys that remain static. For a large, busy network, this reoccurrence of IVs can happen within an hour or so. Because of this, you will have many frames or packets with similar key-streams. Technically, an attacker can gather frames based on the same IV to determine the shared values among the wireless devices. This information can be key-stream or the shared secret key. The static nature of the shared secret keys emphasizes this problem. In many cases, system administrators and users use the same keys for months or even years. This gives mischievous culprits plenty of time to monitor and attack the WEP-enabled networks. Now some vendors deploy dynamic key distribution solutions based on 802.1X, which definitely improves the security of wireless LANs.

                                      Many now recommend the use of IP security (IPsec) to ensure data confidentiality, integrity, and authenticity. The only caveat is that when you deploy IPsec in a WLAN environment, you need to install an IPsec software client on every machine that connects to the wireless network.

                                      WEP has several enhancements. The first one is the use of the Temporal Key Integrity Protocol (TKIP).

                                      NOTE TKIP is often referred to as WEP Version 2.

                                      The second enhancement is the use of the Advanced Encryption Standard (AES) encryption protocol instead of RC4, which is used in older WEP implementations.

                                      The Wi-Fi Protected Access (WPA) standard uses TKIP to provide additional security features. WPA is discussed in the next section.

                                      WPA (using TKIP) includes a per-packet keying (PPK) and message integrity check (MIC) and an extension of the initialization vector from 24 bits to 48 bits. WPA mitigates the WEP threat by implementing different keys on a per-packet basis. It does this by hashing the IV and WEP keys to produce a temporal key. This temporal key is then combined with the IV and fed to an XOR operation with the plaintext message.

                                      Today WPA combines TKIP and user authentication via IEEE 802.1x and the EAP (Extensible Authentication Protocol). This combination mitigates vulnerabilities from several angles and represents a significant security upgrade over WEP.

                                      NOTE The following site includes a whitepaper with detailed information about WEP, WPA, and other authentication mechanisms:

                                      http://www.cisco.com/en/US/netsol/ns340/ns394/ns348/ns386/ networking_solutions_white_paper09186a00800b469f.shtml

                                      Continue reading here: On Wireless Networks

                                      Was this article helpful?

                                      0 0