. , , ,

,,,

Wi-Fi —

Wi-Fi

: 6097

. .

2005


802.11

802.11

-

802.11

-

WEP-

WEP-

LAN 802.11

:

:

:

:

AES


802.11 , , . , , . , , , .

- , 802.11 , , . .

                   , LAN. , LAN.

                   , . .

.1 , , . .


. 1.

802.11 WEP, . , , WEP- WEP- . WEP 802.11, .

 

, . .

                   () .

                   .

, (key stream), . , , , . , .

, . , 15- 200- . . 2 . , . RC4, WEP.

, , . , . , , . . 3 . , , , . , , .

. 2.


. 3.

, , (Electronic Code Book, ). , . , - .

.

                   (initialization vectors, IV).

                   (feedback modes).

 

, , . , . , . . 4 . . DATA 12345 AHGHE. , , . , . 802.11 (on a per-frame basis). , , , .

1.

1.


2.

. 4.

 


 

, , .

 

802.11

802.11 WEP. RC4. RC4 , WEP- 40 104 . WEP , . 802.11 , 1997 . , LAN, (application-specific devices, ASD). -, (tablet PC) 802.11. , , , ASD . WEP - , 30 . , , .

, WEP 24- , RC4. . 5 , WEP .

. 5. , WEP

IV-. , WEP-, . . , . LAN.

802.11 , WEP- , , . , .

WEP- . WEP 802.11.

                   (payload).

                   (integrity check value, ICV).

. , ICV. . 6 , , WEP.

802.11 32- , . , .

32- (CRC-32). - ICV. ICV , WEP, "" . , ICV ICV . , , . , . . 7 ICV.


. 6.

 

. 7. ICV

 

802.11

802.11 , WLAN.

                   (open authentication).

                   (shared key authentication).

(null authentication algorithm). . , , , 802.11. .

WEP- . , . WEP, BSS . BSS, .

. , , , , . - BSS (. 8).


. 8. WEP-

, , WEP WEP-. .

1. .

2. (challenge frame), .

3. .

4. , .

5. WLAN.

, , , , , WEP- . , , . . 9 .

. 9.

 

-

- 802.11. . - - , (. 10). - , 802.11, , . , . BSS WEP-, . 802.11, -.

. 10. -

 

802.11

, 802.11. , , 802.11, . 802.11 , 802.11 WEP.

 

. , WEP-. , WEP , WLAN. , - !

 


, , . , .

, . , . , . , " " (XOR). , : , WEP-, (. 11).

, . " ", . , , , , , , . . 12 , .

. 11.

 

. 12.

 

-

- 802.11, . LAN. -, , "" - "" -.

- 802.11, - (universally administered address, UAA) - (locally administered address, LAA). -, . BSS - , , -.

 

WEP-

802.11 (Fluhrer), (Mantin) (Shamir). , WEP- , LAN.

, WEP (key scheduling algorithm, KSA) RC4. ( IV weak IV) . AT&T Rice , WEP- 40 104 4 . LAN 802.11b , , 104- WEP-. WEP .

, BSS . , , , , WEP-, . BSS .

, , , WEP (, ). , , : .

, " WEP-" . , , , . LAN, , .

( " ", bit flipping) (ICV). CRC-32. . CRC-32 ICV, .

, 802.11 . , . (. 13).

1.                LAN.

2.                (flips random bits) .

3.                ICV ( ).

4.                .

5.                ( ) ICV .

6.                ICV , ICV .

7.                .

8.                ( -).

9.                3 , 3 .

10.           IP .

11.           LAN, .

12.           , , IV.

ICV . ICV WEP ; , , , ? . 14 " " ICV.

1. (F1) ICV, 1.

2. (F2) , F1.

. 13.

3. " " F1 F2 F3.

4. ICV F3 (2).

5. " " 1 2 ICV .



. 14. ICV

 

WEP-

802.11 . WEP , . 802.11 , , , . , "" - .

, . , . , .

 

LAN 802.11

802.11. , , , IEEE 802.11, . 802.11i. 802.11i , Wi-Fi (Wi-Fi Alliance) , 802.11i, " Wi-Fi" (Wi-Fi Protected Access, WPA). 802.11i WPA.

, WEP , LAN. .

                   (authentication framework). , , .

                   . , .

                   . .

                   (data integrity algorithm). , , .

:

802.11 802.11. , . 802.11 , , , LAN.

802.11 , ( ).

                   , .

                   .

                   .

                   .

, , . , , , . , 802.11. , , (authentication, authorization, and accounting, AAA), . RADIUS, , .

, , : . , , LAN . , , . , . - , , .

. "" , , . . , , , 802.11 , . "" . . 15 , .


. 15.

802.11 IEEE , . I 802.11 , , 802.11i.

IEE 802.11 , 802.1X. 802.1X IEEE, 802 , . 802.1X , "-" (Point-to-Point Protocol, PPP), (Extensible Authentication Protocol, EAP). , 802.1X 2. 802.11i 802.1X, , . . 16 802.1X 802.

. 16. 802.1X

(RFC 2284) 802.1X . 802.1X, . 802.11 ( (supplicant)), -. , .

-.

                   (EAP-transport layer security, EAP-PEAP). (secure sockets layer, SSL). SSL- , .

                   EAP-Message Digest 5 (EAP-MD5). (challenge handshake authentication protocol, CHAP), EAP-MD5 .

                   EAP-Cisco. - EAP-Cisco, LEAP, , LAN. EAP-Cisco .

802.1X .

                   . LAN.

                   (authenticator). .

                   . RADIUS.

, . 802.11 , (AID). : . 802.1X. , . . 17 802.1X


. 17. 802. 1X

 

:

802.11i WPA , , 802.1X.

802.11i, WPA , , , . EAP-Cisco. , Cisco LEAP, , LAN.

EAP-Cisco , . EAP-Cisco, , , . EAP-Cisco , LAN, .

                   , .

                   .

                   .

- , . , .

 

:

WEP 802.11 IEEE . 802.11, ?

IEEE , 802.11i ( WPA) (temporal key integrity protocol, TKIP).

WEP, , 802.11, , . , TKIP, .

                   . WEP- , .

                   (message integrity check, MIC). .

, IV, , , IV. WEP-, , , .

IEEE , (per-frame keying). ( (per-packet keying) (fast packet keying).) , , , IV, - WEP- . 104- WEP- 24- IV.

IEEE 24- 48- IV. , IV. . 18 48- IV , IV .

. 18. IV

.

1.                WEP- ( 802.1X) 32 48- IV (32- 0-4 294 967 295) - . 1- (phase 1 key). 1- (. 19).

2.                1- IV - () .

3.                (IV), , 16 (16- 0-65 535). 8 , .

4.                WEP- .

5.                16- IV , 1- 32 1. ( IV 12, 13.)

6.                , 2.

. 19.

, 16- IV . 16- IV , , . IV, 1- 32 IV 1 .

WEP , . , ( TKIP ) WEP 802.11. , . 802.11 TKIP, WEP/TKIP , (advanced encryption standard, AES).

 

:

, (ICV) 802.11, (MIC). MIC , , . IEEE , Michael (), ICV 802.11.

MIC , , . - - , , .

MIC .

1. .

2. .

3. , , 60 , .

4. , , 802.1X.

5. .

MIC MIC. , . 802.11 .

 

802.11 RADIUS , . , , , . 802.11i WPA - (master key). ( -, , . pairwise master key), 802.1X. , - (painvise transient key, PTK), .

- () () . , . , . ( BSS, ) , , .

. - (group master key, GMK) .

-, , - Gnonce (, ) , 256- (group transient key, GTK). GTK 128- / , 64- MIC (transmit MIC key) 64- MIC (MIC receive key).

, , - ().

, - BSS. MIC, , .

 

AES

, , 802.11, . IEEE WPA WEP TKIP 802.11i, LAN 802.11. IEEE . IEEE AES , 802.11i. WPA AES. WPA, , 802.11i AES.

AES , (NIST) . IEEE AES, LAN. (Cipher Block Chaining Counter Mode, CBC-CTR) (Cipher Block Chaining Message Authenticity Check, CBC-MAC), AES-CCM. CBC-CTR -. .

CBC-CTR . . . 16- . , , . .

- , , . 128- 64 .

- , , . " " .


, 802.11 1997 , . , WEP-, . TKIP WEP- , 802.1X AES .

Wi-Fi : 6097 . .

 

 

 

! , , , .
. , :