WLAN Security in Neutral

執筆者
Dennis Fisher
Dennis Fisher
Published: Dec 31, 2001
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

As the process for developing a replacement for a leading wireless security protocol drags on, new questions are arising about the effectiveness of the replacement and whether WLAN vendors will even implement it once its ready.

With sales of 802.11b gear brisk, most vendors are reluctant to implement a replacement to the WEP (Wired Equivalent Privacy) protocol, which would require expensive re-engineering. Meanwhile, wireless networking companies are continuing to tweak wireless LAN security in the hope that interim fixes can keep users comfortable until the standards issue is resolved.

The result: Despite academic advancements, the security of WLANs in the real world is unlikely to improve any time soon.

The Institute of Electrical and Electronics Engineers Task Group I has been working for months on enhancements to the security in 802.11b WLANs.

While the initial focus of the group was to replace WEP with a backward-compatible version dubbed WEP2, the scope of the IEEEs work has expanded to include a new authentication mechanism. The new protocol will likely be based on the new AES (Advanced Encryption Standard), which addresses more security problems than either WEP or WEP2.

This shift, however, is problematic for wireless networking vendors that have invested much in products configured to work with WEP and the cryptographic stream cipher known as RC4.

“The security of wireless LANs, to a large degree, is a victim of their success,” said William White, director of cryptographic research at security vendor Ntru Inc., of Waltham, Mass., and a member of the IEEE Task Group. “Vendors dont want to deploy anything that will break whats out there, but the security of these things is so broken it needs to be completely rebuilt. RC4 is going to be there for the time being.”

WLAN users say that security should be the top concern for vendors. “Its in the wireless vendors best interests to implement the new IEEE security protocol,” said Gary Moore, assistant dean for IS at the Hofstra University School of Law, in Hempstead, N.Y. “[WLANs] may be selling well now, but many universities and businesses are probably holding off on large-scale wireless implementations due to security concerns.”

Researchers from RSA Security Inc. and Hifn Inc. in December unveiled a technology that addresses one of the main security problems with WEP, a weakness in the implementation of RC4 used in the protocol.

Advertisement

The vulnerability enables an attacker to sniff a small number of packets on a WLAN and then guess the private encryption key thats being used. Known as “fast packet keying,” the new technology is essentially a firmware patch for existing WLAN gear.

“I expect [fast packet keying] to be part of near-term wireless LAN security solutions, and I expect AES to be part of long-term wireless LAN security solutions,” said Russ Housley, senior consulting architect at RSA Laboratories, in Herndon, Va., and co-author of the new modification.

Dennis Fisher

Dennis Fisher

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。