Shared Key Authentication

Steps 1 through 3 are the same

as for open authentication. << < >

i

4. Client sends an authentication request to access point (A). [ rf packet ]

4. Client sends an authentication request to access point (A). [ rf packet ]

5. Access point (A) send authentication response containing the unencrypted challenge text. [ rf packet]

6. Client encrypts the challenge text using one of its WEP keys and sends it to access point (A). [ rf packet ]

7. Access point (A) compares the encrypted challenge text with its copy of the encrypted challenge text. If the text is the same, the access point (A) will allow the client onto the WLAN. [ rf packet ]

Shared Key Authentication

The figure shows the wireless client using shared key authentication to attempt to associate with an access point. Steps 1 through 3 are the same as those for open authentication. These additional four steps are required for shared key authentication:

Step 1 The client sends an authentication request to access point A.

Step 2 Access point A sends an authentication response. The authentication response from the access point to the client is sent containing challenge text. This packet is unencrypted.

Step 3 The client then uses the text from the authentication response to form another authentication packet, which will be encrypted using one of the client WEP keys, and sends this as a response to the access point.

Step 4 Access point A will then compare the encrypted challenge text against the access point copy of the encrypted challenge text. If the encrypted text is the same, the access point allows the client on the WLAN.

Shared key authentication is considered less secure than open authentication because of the challenge text packet. Because this packet is sent unencrypted and then returned as an encrypted packet, it may be possible to capture both packets and determine the stream cipher.

© 2006 Cisco Systems, Inc. Securing LAN and WLAN Devices 3-71

Continue reading here: Authentication dictionary attacks

Was this article helpful?

0 0

Readers' Questions

  • tanja
    What is the first step in shared key authentication?
    10 months ago
  • The first step in shared key authentication is for the two communicating parties to generate a shared secret key, such as a password, passphrase, or code.