5.1.2 Security services
Security services in IEEE Std 802.11 are provided by the authentication service and the CCMP and BIPmechanisms. The scope of the security services provided is limited to station-to-station data and robust
management frame transmissions. When CCMP is used, the data confidentiality service is provided for data
frames and individually addressed robust management frames. For the purposes of this standard, CCMP is
viewed as a logical service located within the MAC sublayer as shown in the reference model, Figure 4-14
(in 4.9). Actual implementations of CCMP are transparent to the LLC and other layers above the MAC
sublayer.
The security services provided by CCMP in IEEE Std 802.11 are as follows:
a) Data Confidentiality;
b) Authentication; and
c) Access control in conjunction with layer management.
BIP provides message integrity and access control for group addressed robust management frames.
During the authentication exchange, both parties exchange authentication information as described in
Clause 11 and Clause 12.
The MAC sublayer security services provided by CCMP and BIP rely on information from nonlayer-2
management or system entities. Management entities communicate information to CCMP and BIP through a
set of MAC sublayer management entity (MLME) interfaces and MIB attributes; in particular, the decision
tree for CCMP and BIP defined in 11.8 is driven by MIB attributes.
The use of WEP for confidentiality, authentication, or access control is deprecated. The WEP algorithm is
unsuitable for the purposes of this standard.
The use of TKIP is deprecated. The TKIP algorithm is unsuitable for the purposes of this standard.
A STA that has associated with management frame protection enabled shall not use pairwise cipher suite
selectors WEP-40, WEP-104, TKIP, or “Use Group cipher suite.”
A mesh STA with dot11MeshSecurityActivated equal to true shall not use the pairwise cipher suite selectors
WEP-40, WEP-104, or TKIP.
No comments:
Post a Comment