ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile working Toolkit

802.11i - designed to integrate

Rupert Goodwins ZDNet.co.uk

Published: 10 Apr 2003 09:22 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

802.1x also specifies how keys are passed back to the client to be used in further network traffic -- how these keys are used is not specified, but how they are transferred securely is. It also sets a per-packet authentication key that can't be faked by a third party, maintaining authentication if the client roams to another port and preventing interception and taking over of a session by an intruder.

In installations where there's no authentication server -- probably the case in most homes and many small businesses -- 802.1x can be used in pre-shared key mode, where every node has its keys set up explicitly by hand. The rest of the 802.1x features work, with the proviso that if the shared keys are ever compromised the security of the network is lost.

When 802.1x was started, wireless networking wasn't nearly as prominent as it is now, so the standard is designed for a variety of wired networks only -- hence the need to incorporate it into 802.11i before it can be used for radio.

802.11i's data security additions include various encryption processes such as TKIP (Temporal Key Integrity Protocol) and CCMP (Counter with Cipher Block Chaining Message Authentication Code Protocol). TKIP's main attraction is a frequent update of the encryption key,

TKIP can be added to an existing 802.11 interface by upgrading its software, while a version of the TKIP mechanism called SSN (Safe Secure Networks), has already been adopted by the WiFi industry group prior to the approval of 802.11i. This is a temporary measure due to the need for a fast fix to the broken WEP standard. CCMP is designed for future wireless LANs, as it needs more processing power than most adaptors and access points currently have to spare -- it uses a version of the Advanced Encryption Standard (AES), the current US Government approved method of encrypting data in transit.

802.11i remains under development
With most of the technicalities decided but some areas -- such as fast roaming between access points -- still receiving attention. Such is the pressure for secure wireless LANs that some systems are already available with pre-approval versions of the standard. These are better than non 802.11i systems, but deploying them without a guaranteed upgrade path to the finished standard has interoperability and security risks of its own. By the end of the year, the standard should be finalised and equipment available: then the IEEE will have done its part, and it will be down to system deployers and managers to configure and maintain adequate security. 802.11i is just the kit of parts to do the job -- network security only works when people do it right.

For a weekly round-up of the enterprise IT news, sign up for the Enterprise newsletter.

Tell us what you think in the Enterprise Mailroom.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
134 out of 234 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:


















Related Jobs

Cisco Pre-Sales Network Consultant/Engineer : CCNP/CCDP/CCIE

Cisco Gold Partner now seeks a Pre-Sales Network Consultant/Engineer. They seek a client-facing profile with accreditation to at least CCNP or CCDP ...

Operations Manager (Technical pre-sales team)/ IT Manager- Abingdon, Oxfordshire

Operations Manager (Technical pre-sales team)/ IT Manager- Abingdon, Oxfordshire An opportunity for an operations manager with IT experience to move ...

SCOM SCCM Consultant-Microsoft,MOM - Pre-sales

SCOM SCCM Consultant-Microsoft infrastructure ,MOM,ISA - Pre-Sales My client a Microsoft Gold Partner is looking for a pre-sales SCOM/SCCM consultant ...

On The Road Blog

Challenges of Nigeria mobile Banking

Mobile Banking refers to provision of banking and financial services with the help of mobile telecommunication devices. The scope of offered services may include facilities to conduct... More

Post a comment

Mobile marketing innovations will driv...

Farmed out License Holder, Etisalat Nigeria sure understand how to engage the subscribers in the 3G Era. During the launch of the Network last week in Lagos, the company spokesperson... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters