Home > Ask the Networking Experts > Wireless networking Questions & Answers > When is there going to be a standard that has inherent security features?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

When is there going to be a standard that has inherent security features?

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 31 January 2004
I have read a number of articles that specifically stated numerous conferences were being hacked by individuals accessing their wireless LANs.

The question I have is when is there going to be a standard that has inherent security features built into the transfer and validation of the user? It seems that 802.1x (using Radius to authenticate the user) is a valid choice but there is another standard that I am hearing about called 802.1u, which incorporates encryption and authentication into one known standard.


>
Wireless vendors like to monitor the air at conferences to illustrate security alerts, but conference WLANs are not at all representative of corporate WLANs. Conference WLANs are usually intended only for demonstration and free public access. They don't even try to restrict access. And to make getting on-line easy for everyone, they rarely use WEP/WPA encryption. In short, those WLANs are security-free zones, so users should protect themselves with personal firewalls and VPNs.

On the other hand, corporate WLAN operators do take steps to restrict access and hide both credentials and data sent over the air. The 802.1X standard defines a framework for port-based access control based on the Extensible Authentication Protocol (EAP). As you note, 802.1X does not itself use cryptography to secure the authentication process and exchange of credentials. 802.1X leaves that up to EAP. The 802.1aa standard now underway provides corrections and improvements to 802.1X.

Some EAP types have built-in security. For example, EAP-TLS provides mutual authentication based digital signatures (I.E., certificates, smart cards), negotiated over an encrypted TLS session. Protected EAP (PEAP) authenticates the server by digital signature, launches an encrypted TLS session, and authenticates the user over that secure session by another method (I.E., passwords, tokens). There are other EAP types that offer weak security, including EAP-MD5 and Cisco LEAP, so it's important to choose an EAP type that meets your security needs. EAP types are defined by the IETF, not the IEEE. To learn more, visit the IETF's EAP working group status page.

IEEE 802.1u provides corrections and updates to the 802.1Q standard on Virtual LANs (VLANs). The only relationship that I can see is that VLANs can be used with 802.1X and RADIUS to supply a wireless station with a specific VLAN tag, based on authenticated identity and access rights defined in the user database. But I don't think 802.1u is the standard with built-in security that you've been hearing about -- perhaps you meant 802.11i, which is another standard underway to improve the security built into all 802.11 wireless LANs. To learn more about 802.11i, visit the IEEE 802.11 TGi Update page.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Wireless networking
Why is my network adapter not working after a Vista Business upgrade?
How many wireless base stations can connect to 802.11g access points?
APs drop connection in WLAN configured as a wireless mesh network
How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?
Can wireless adapters operate as client access points to make SoftAPs?
Will using a VPN protect me against fake wireless hotspots?
WLAN QoS and SLA monitoring with 7/24 Wireless Quality Assurance costs
How can I hide my WLAN's SSID in an Aruba AP-61?
How radio frequency (RF) of microwaves alter wireless signal strength
Stolen laptop recovery using remote access and wireless network SSIDs

Wireless LAN Implementation
University tackles large-scale 802.11n wireless network management
Why is my network adapter not working after a Vista Business upgrade?
How many wireless base stations can connect to 802.11g access points?
802.11n wireless APs bring IP video to sprawling Illinois high school
No data cable? Wireless mesh networking the answer for Wi-Fi backhaul
Integrated wireless and wired LAN: Brocade-Motorola deal ups the ante
802.11n WLAN architecture strategies: The 2.4 vs. 5 GHz band debate
802.11n upgrade: College ditches legacy network for new vendor
802.11n ratification will drive down wireless LAN prices
How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
802.11a  (SearchNetworking.com)
Asynchronous Pulsed Radiated Incident Light  (SearchNetworking.com)
beamforming  (SearchNetworking.com)
cognitive radio  (SearchNetworking.com)
direct sequence spread spectrum  (SearchNetworking.com)
frequency-hopping spread spectrum  (SearchNetworking.com)
patch antenna  (SearchNetworking.com)
phase-locked loop  (SearchNetworking.com)
radio frequency  (SearchNetworking.com)
wireless mesh network  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts