Thursday, 2 February 2012

IEEE 802.11i
Counter-Mode /CBC-MAC Protocol (CCMP)
It is a data-confidentiality protocol that handles packet authentication as well as encryption. CCMP uses a 128-bit key in IEEE 802.11i. It can prevent some problems that are not encrypted. Moreover, IEEE 802.11i uses additional authentication data (AAD) frame to protect. AAD includes the packets source and destination and protects against attackers replaying packets to different destinations.


IEEE 802.11r
The 802.11r standard applies to a 3-tier mention architecture that divides the access network into mobility zones. A mobility zone is defined as the collection of lightweight access points connected to a central management unit, here after referred to as controller. Generally, neighbouring access points covering a certain geographic zone are grouped into a single mobility zone.
When a 802.11r compliant station enters a mobility zone, it first performs authentication using EAP. The resulting MSK is used by the station and the controller to derive a key called PMK-R0. PMK-R0 is then used to derive per-access-point PMKs. The name for such keys is PMK-R1. The controller finally sends the PMK-R1 keys to their corresponding access points. The mobility zone controller that holds the PMK-R0 key is called R0 Key Holder (R0KH), while the access points to which PMK-R1 keys are delivered are R1 Key Holder(R1KH).


IEEE 802.11k
IEEE 802.11k provides Radio Resource Management. That can enable STAs to understand the radio environment in which they exist. The Radio Resource Management service includes measurements that extends the capability, reliability, and the maintainability of WLANs by providing standard measurement s across vendors, and provides the resulting measurement data to upper layers in the communications stack.

IEEE 802.11w.
The IEEE 802.11w wireless encryption standard builds on the 802.11i framework to protect against subtle attacks on wireless LAN (WLAN) management frames .IEEE 802.11w defines enhancements such as data integrity, data origin authenticity, replay protection, and data confidentiality.