EP1902543A1 - Methods of protecting management frames exchanged between two wireless equipments, and of receiving and transmitting such frames, computer programs, and data media containing said computer programs - Google Patents
Methods of protecting management frames exchanged between two wireless equipments, and of receiving and transmitting such frames, computer programs, and data media containing said computer programsInfo
- Publication number
- EP1902543A1 EP1902543A1 EP06769356A EP06769356A EP1902543A1 EP 1902543 A1 EP1902543 A1 EP 1902543A1 EP 06769356 A EP06769356 A EP 06769356A EP 06769356 A EP06769356 A EP 06769356A EP 1902543 A1 EP1902543 A1 EP 1902543A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- frame
- client
- frames
- equipment
- numerical value
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000000034 method Methods 0.000 title claims abstract description 36
- 238000004590 computer program Methods 0.000 title claims description 9
- 238000007620 mathematical function Methods 0.000 claims abstract description 10
- 238000004422 calculation algorithm Methods 0.000 claims description 3
- 230000004044 response Effects 0.000 description 31
- 230000006870 function Effects 0.000 description 10
- 239000000523 sample Substances 0.000 description 9
- 230000007704 transition Effects 0.000 description 6
- 238000010586 diagram Methods 0.000 description 4
- 238000004364 calculation method Methods 0.000 description 3
- 230000008859 change Effects 0.000 description 2
- 230000015654 memory Effects 0.000 description 2
- 101100234002 Drosophila melanogaster Shal gene Proteins 0.000 description 1
- 235000015076 Shorea robusta Nutrition 0.000 description 1
- 244000166071 Shorea robusta Species 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000003993 interaction Effects 0.000 description 1
- 230000007787 long-term memory Effects 0.000 description 1
- 230000001960 triggered effect Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the present invention relates to a method of protecting management frames exchanged between two wireless equipments, in particular for Wi-Fi frames.
- the invention also relates to a method of transmitting management frames and to a method of receiving such frames, and also to computer programs for implementing said methods, and to data media containing such computer programs.
- the invention is involved during interaction between two wireless equipments seeking to connect to each other. These two equipments are often referred to as a "client” and as an "access point".
- the access point may be a terminal, for example when two computers are connecting to each other in order to exchange data, or it may be a gateway enabling a client to access the Internet or a business network.
- the IEEE 802.11 state machine is already known and, for its operation, it requires various management frames.
- beacon frame which is a broadcast frame transmitted regularly by an access point in order to inform clients of its presence and to send them a set of characteristics specific to the access point (e.g. a network name);
- a probe request frame which is likewise a broadcast frame, seeking to discover access points and transmitted by a client in order to discover what access points are available and to obtain a set of characteristics specific to each of said access points;
- a probe response frame which, in response to a probe request, is a unicast frame notifying the client of the presence of an access point and conveying a set of characteristics specific to the access point
- - an authentication request frame which is an unicast frame attempting to authenticate a client with an access point
- an authentication response frame which, in responses to an authentication request, is a unicast notification frame sent to the client by the access point, and containing the result: "success” or "failure”
- an association request frame which is a unicast frame attempting to associate a client with an access point: this frame conveys information about the client (e.g. available data rates) and the service set identifier (SSID) of the network with which the client wishes to be associated
- an association response frame which, in response to an association request, is a unicast notification frame sent to the client by the access point, and containing the result: "association accepted” or "association rejected”;
- a reassociation request frame which is a unicast frame attempting to make an association with an access point by a client already associated via a first access point; reassociation occurs when the client moves away from the first access point or when traffic over the first access point becomes too great (a load balancing function);
- a reassociation response frame which, in response to a reassociation request, is a unicast notification frame sent to the client by the access point, and containing the result: "reassociation accepted” or "reassociation rejected”;
- a disassociation frame which is a unicast frame sent either by the client or by the access point to notify the destination equipment that the client is no longer associated;
- a de-authentication frame which is a unicast frame sent either by the client or by the access point to notify the destination equipment that the client is no longer authenticated.
- each equipment (client or access point) contains an IEEE 802.11 state machine having the function of representing the instantaneous state of the equipment in the wireless network.
- Management frame exchanges cause equipments to pass from one state to another and perform overall management of the wireless network.
- the IEEE 802.11 state machine does not protect the network against usurper management frames sent by an attacker in order to terminate in unauthorized manner a wireless connection between a client and an access point, e.g. by usurping the MAC address of one of those two equipments. Nevertheless, such an attack could lead to a denial of service on equipments using the wireless network.
- An object of the invention is to protect the users of wireless networks against usurper management frames.
- the invention provides a method of protecting management frames exchanged between two wireless equipments, the method being characterized in that it comprises, for the first management frame sent by a first equipment and received by a second equipment, a step of inserting in said first management frame a parameter f(X()) that is an image of a predetermined numerical value XQ as obtained by means of a mathematical function f that is difficult to invert and that is known to both equipments, and for each k m management frame sent by the first equipment and received by the second equipment:
- hashing functions e.g. secure hash algorithm 1 (SHAl, cf. IETF Standard RFC3174).
- the access point By means of the invention, if the client (or the access point) integrates the parameter in any sent management frame, then subsequently if the client (or the access point) integrates the numerical value corresponding to the image of the parameter as inverted by the function fin a management frame sent later than the preceding frame, then the access point (or the client) has proof that it is the same client (or access point) that sends both frames. The subsequent frame can therefore be taken into account. Otherwise, it can be ignored or any appropriate processing can be triggered, e.g. to combat an attacker.
- each numerical value X ⁇ is generated by an algorithm for generating pseudo-random numbers, for example by a Blum Blum Shub (BBS) generator.
- BBS Blum Blum Shub
- the parameter is integrated in at least one authentication request frame, authentication response frame, association request frame, association response frame, reassociation request frame, or reassociation response frame
- the numerical value is integrated in at least one disassociation frame or de-authentication frame. Integrating the numerical value in a de-authentication frame serves to verify that the frame was indeed sent by the equipment that originated an earlier authentication request frame or authentication response frame, and integrating the numerical value in a disassociation frame serves to verify that the frame was indeed sent by the equipment that originated an earlier association request frame, or association response frame, or reassociation request frame, or reassociation response frame, and not by an attacker usurping the identity of the equipment.
- Another object of the invention is to protect all successive management frames exchanged between two wireless equipments, even without knowing in advance the number of management frames that are to be exchanged, and to do so with a limited amount of calculation for each pair of frames that are exchanged.
- the invention as set out above protects only a second frame subsequent to a first frame, and then possibly a fourth frame subsequent to a third frame, but does not prevent an attacker from sending a usurping frame immediately after the second frame and before the third frame.
- an attack such as the "man-in-the-middle" attack (where the attacker passes itself off as the client with the access point and as the access point with the client), the attacker is to be found between the access point and the client and can intercept all of the communications between those two entities.
- the above-described steps are reiterated, assuming that each new management frame, subsequent to a given management frame, is a second management frame, and the given management frame is a first management frame.
- an access point does not accept an association request or a reassociation request that does not include the expected numerical value.
- an association request or a reassociation request coming from an already-associated client causes said client to be deassociated. Consequently, such a request coming from an attacker leads to a denial of service for the client.
- the present implementation provides protection against such attacks.
- the invention also provides a method of receiving management frames by a wireless equipment, characterized in that, for a mathematical function f that is difficult to invert and that is known to the equipment:
- the invention also provides a method of sending management frames by a wireless equipment, the method being characterized in that, for a mathematical function f that is difficult to invert and that is known to the equipment: • a parameter that is an image of a numerical value as obtained by the function f is integrated in a first transmitted management frame; and
- the invention also provides computer programs for receiving management frames on a wireless equipment and for sending management frames from a wireless equipment, the programs being characterized in that each of them comprises a series of instructions for implementing the corresponding method.
- the invention also provides a data medium containing a computer program for receiving management frames on a wireless equipment and a data medium containing a computer program for sending management frames from a wireless equipment.
- Figure 1 is a diagram showing state transitions in the IEEE 802.11 state machine in the prior art
- Figure 2 is a diagram showing the exchanges of frames between a client and an access point using a method constituting a first implementation of the invention
- Figure 3 is a diagram showing the exchanges of disassociation and de- authentication frames from a client using the same method as in Figure 2;
- Figure 4 is a diagram showing the exchanges of disassociation and de- authentication frames from an access point using the same method as in Figure 2.
- the prior art IEEE 802.11 state machine shown in Figure 1, has three states: • state 101 : the equipment is neither authenticated nor associated;
- Such a state machine is present in each wireless equipment, and in particular in a client and in an access point.
- the client sends an authentication equipment frame to the access point. If the authentication equipment is accepted by the access point, then the access point returns an authentication response frame to the client containing the result "success", and both the access point and the client pass to state 102.
- the access point and the client perform the transition
- the client sends an association request frame (or a reassociation request frame). If the association request frame is accepted by the access point, then the access point sends an association response frame to the client containing the result "association accepted” (or "reassociation accepted"), and both the access point and the client pass to state 103.
- the client or the access point seeks to make the reverse transition 106 going back to state 102, it sends a disassociation frame.
- the client or the access point When the client or the access point seeks to make the transition 107 going back to state 101, it sends a de-authentication frame.
- the client or the access point may also perform the transition 108 from state 103 to state 101 directly by sending solely a de-authentication frame while it is in state 103.
- the invention proposes using certain parameters of management frames in order to act in simple and effective manner to ensure that the management frames do indeed originate from the expected equipment (access point or client) and not from a usurper equipment.
- Figure 2 shows the frames exchanged during a connection by a client to an access point in a first implementation:
- the client sends a probe request specifying the enhanced service set identifier (ESSID) of the network to which the client wishes to be connected.
- ESSID enhanced service set identifier
- the access point sends a probe response frame to the client.
- the client then generates in pseudo-random manner a numerical value Xautb an( * men calculates f(Xauth)-
- the client sends an authentication request frame to the access point with a parameter f(Xauth)-
- the access point receives this frame, associates the parameter f(X aum ) with the connection, and in pseudo-random manner generates a numerical value Y au th > and then calculates f(Y a uth)-
- the access point sends an authentication response frame to the client containing the parameter f(Y a uth)-
- the client receives this frame, associates the parameter f(Y a uth) w ⁇ m me connection, and generates in pseudo-random manner a numerical value X ass , and then calculates f(X ass ).
- the client then sends an association request frame to the access point containing the parameter f(X a ss)-
- the access point receives this frame, associates the parameter f(Xass) w ⁇ h- this connection, and in pseudo-random manner generates a numerical value Y ass , and then calculates f(Yass)-
- the access point sends an association response frame to the client containing the parameter f(Yass)-
- the client associates the parameter f(Yass) w * m the connection.
- the client To disassociate, the client includes the numerical value X ass in the disassociation frame. 8) To de-authenticate, the client integrates the numerical value X aum in the de-authentication frame.
- the access point receives a disassociation request frame (or a de- authentication request frame) containing as its source address the MAC address of the client and as its destination address its own MAC address, then it verifies whether the frame contains a properly completed field X ass (or X aum ) :
- disassociation or de-authentication
- disassociation or de-authentication
- the origin of a de-authentication frame or a disassociation frame is indeed verified. Nevertheless, as already emphasized, in this implementation, only de- authentication and disassociation frames are protected. In a second implementation, the protection method protects not only de- authentication or disassociation frames, but also authentication request or response frames, association request or response frames, and reassociation request or response frames, e.g. against the denial of service that an attacker might attempt by sending authentication, association, or reassociation frames.
- a numerical value X n . ⁇ is associated with the parameter f(X n ) when sending any management frame, the numerical value X n . ⁇ corresponding to sending the preceding management frame and the parameter f(X n ) corresponding to the numerical value X n that is to be associated on sending the next management frame.
- the client When the client (or the access point) receives a management frame, it can be found in one of the following circumstances, depending on the received management frame:
- the equipment must be capable of associating itself with another equipment with which it has already had exchanges, even in the event of the machine accidentally being turned off.
- the reassociation frames are also protected.
- the client sends a reassociation request frame to a new access point with a completed field f(X a ss0; me access point then verifies whether the client is already associated therewith: a) if it already knows the client, i.e.
- the access point recovers the field f(X a ss0 an( ⁇ men sen ds an association response to the client including therein the field f(Y a ss0 at ⁇ d associates f(X ass >) with the connected user.
- the client on receiving the frame, associates the received f(Y a ss0 w i tn ⁇ e connection.
- management frames used are management frames of the IEEE 802.11 Standard. This Standard allows for optional so-called "tagged" parameters to be added in the management frames, thus making it possible to specify parameters such as X and f(X).
- the method can easily be integrated by Wi-Fi access points and clients since only a few parameters are added in some of the management frames of the IEEE 802.11 state machine. It is thus possible to activate the invention on presently- existing equipment merely by adding software.
- the invention is not limited to the implementations described above, but on the contrary covers any variant using equivalent means to reproduce its essential characteristics.
- the present description is based on the IEEE 802.11 Standard. Nevertheless, the invention also applies in non-limiting manner to the WPA and 802.1 Ii Standards, in which the authentication and association stages are the same and the problem of lack of protection for management frames is likewise present.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0507266A FR2888432A1 (en) | 2005-07-07 | 2005-07-07 | METHODS FOR PROTECTING MANAGEMENT FRAMES EXCHANGED BETWEEN TWO WIRELESS EQUIPMENT, RECEIVING AND TRANSMITTING SUCH FRAMES, COMPUTER PROGRAMS AND DATA CARRIERS CONTAINING THESE COMPUTER PROGRAMS |
| PCT/LT2006/000005 WO2007008052A1 (en) | 2005-07-07 | 2006-07-10 | Methods of protecting management frames exchanged between two wireless equipments, and of receiving and transmitting such frames, computer programs, and data media containing said computer programs |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1902543A1 true EP1902543A1 (en) | 2008-03-26 |
Family
ID=36123291
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP06769356A Withdrawn EP1902543A1 (en) | 2005-07-07 | 2006-07-10 | Methods of protecting management frames exchanged between two wireless equipments, and of receiving and transmitting such frames, computer programs, and data media containing said computer programs |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP1902543A1 (en) |
| JP (1) | JP2009500943A (en) |
| FR (1) | FR2888432A1 (en) |
| WO (1) | WO2007008052A1 (en) |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5751812A (en) * | 1996-08-27 | 1998-05-12 | Bell Communications Research, Inc. | Re-initialization of an iterated hash function secure password system over an insecure network connection |
| US20020078352A1 (en) * | 2000-12-15 | 2002-06-20 | International Business Machines Corporation | Secure communication by modification of security codes |
-
2005
- 2005-07-07 FR FR0507266A patent/FR2888432A1/en active Pending
-
2006
- 2006-07-10 WO PCT/LT2006/000005 patent/WO2007008052A1/en not_active Ceased
- 2006-07-10 JP JP2008520198A patent/JP2009500943A/en not_active Withdrawn
- 2006-07-10 EP EP06769356A patent/EP1902543A1/en not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2007008052A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2007008052A1 (en) | 2007-01-18 |
| FR2888432A1 (en) | 2007-01-12 |
| JP2009500943A (en) | 2009-01-08 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10412083B2 (en) | Dynamically generated SSID | |
| EP1841260B1 (en) | Authentication system comprising a wireless terminal and an authentication device | |
| US7783756B2 (en) | Protection for wireless devices against false access-point attacks | |
| US8787572B1 (en) | Enhanced association for access points | |
| JP4575679B2 (en) | Wireless network handoff encryption key | |
| US7673146B2 (en) | Methods and systems of remote authentication for computer networks | |
| JP4405360B2 (en) | Firewall system and firewall control method | |
| CN102480729B (en) | Method for preventing fake user in wireless access network and access point | |
| US8726019B2 (en) | Context limited shared secret | |
| US20060059344A1 (en) | Service authentication | |
| KR20080093431A (en) | Authentication Methods for Clients on a Wireless Network | |
| Lamers et al. | Securing home Wi-Fi with WPA3 personal | |
| JP2008537644A (en) | Method and system for fast roaming of mobile units in a wireless network | |
| EP2106591B1 (en) | Solving pana bootstrapping timing problem | |
| Gollier et al. | SSID confusion: Making wi-fi clients connect to the wrong network | |
| US20080126455A1 (en) | Methods of protecting management frames exchanged between two wireless equipments, and of receiving and transmitting such frames, computer programs, and data media containing said computer programs | |
| CN114268499B (en) | Data transmission method, device, system, equipment and storage medium | |
| JP2007538470A (en) | Method for managing access to a virtual private network of a portable device without a VPN client | |
| JP2009033585A (en) | Wireless LAN terminal connection method and wireless LAN system using the method | |
| CN101610509B (en) | Method, device and system for protecting communication security | |
| CN117296296A (en) | Method and associated system for defending against attempts to disconnect two entities | |
| Haitao et al. | The security issues and countermeasures in Mobile IP | |
| WO2007008052A1 (en) | Methods of protecting management frames exchanged between two wireless equipments, and of receiving and transmitting such frames, computer programs, and data media containing said computer programs | |
| KR100440061B1 (en) | Method For Relaying RADIUS Message In The Packet Data Network | |
| Hudda | Uninterrupted VPN Connection Service with Mobility Management and Dead Peer Detection |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20080131 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC NL PL PT RO SE SI SK TR |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20080610 |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: DUFFAU, ROLAND Inventor name: FRANCFORT, STANISLAS Inventor name: RAZNIEWSKI, JEROME |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20100529 |