Advertisement
Promo

Mobile working Toolkit in association with http://marketing.ianywhere.com/forms/EMEA09SUPSybaseMobilityLeadership-IDC

Better ways emerge to protect wireless data

Brien M Posey

Published: 20 Aug 2003 15:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

For several years now, the primary security mechanism used between wireless access points and wireless clients has been WEP encryption. The problem is that although WEP encryption strength has increased a few times since Wi-Fi was introduced, the WEP protocol is still fundamentally weak because it uses a static encryption key. As a result, motivated attackers can easily crack WEP encryption by using freely available hacking tools.

Fortunately, some standard alternatives to WEP are emerging. The Institute of Electrical and Electronics Engineers (IEEE) has defined an expansion to the 802.11 protocol that will allow for increased security. Unfortunately, the standard is presently in draft form and isn't expected to be ratified until the end of 2003. In the meantime, though, most of the Wi-Fi manufacturers have agreed to use a temporary standard for enhanced security called Wi-Fi Protected Access (WPA). Although WPA is a temporary protocol and isn't recognised by IEEE, it is very similar to the revised IEEE standard expected by the end of the year. Therefore, administrators that manage wireless LANs should become familiar with WPA.

802.1X authentication
If you have been using Wi-Fi for a while, you are probably familiar with the 802.1X authentication protocol. This protocol allows users to authenticate into a wireless network by means of a Radius Server. In standard Wi-Fi, 802.1X authentication is optional. However, 802.1X authentication is a requirement for WPA.

If your environment does not have a Radius server in place, you can still use WPA in spite of the 802.1X requirement. As an alternative to Radius, WPA supports the use of a pre-shared key.

WPA key management
One of the biggest drawbacks to traditional WEP security is that changing the encryption key is optional. Even if you do switch encryption keys from time to time, there is no option for globally re-keying all access points and all wireless NICs. Instead, re-keying is a tedious manual process and is completely impractical for large organisations. After all, the instant you re-key an access point, none of the clients will be able to access it until they are also re-keyed.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
194 out of 317 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

Video icon

Video

On The Road Blog

On the Saving Edge: New Tech in Disast...

By Matthew Cordell A new report commissioned by the UN Foundation and Vodafone Foundation has found the intersection between two incredible trends -- the significant uptick in disasters... More

Post a comment

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV licence?... More

Post a comment

Linux is shipped on a third of all net...

A third of netbooks shipped in 2009 came with GNU/Linux rather than Windows preinstalled, according to analysis from ABI Research. The firm's figures strongly contradict Microsoft's... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters