60 likes | 222 Views
TKIP with 48-bit IVs. Doug Whiting, HiFn Russ Housley, RSA Labs Niels Ferguson, MacFergus BV. Introduction. Key management is hard Yesterday’s discussion clearly shows it While key management cannot be eliminated, we can increase the life span of each key
E N D
TKIP with 48-bit IVs Doug Whiting, HiFn Russ Housley, RSA Labs Niels Ferguson, MacFergus BV Whiting, Housley, Ferguson
Introduction • Key management is hard • Yesterday’s discussion clearly shows it • While key management cannot be eliminated, we can increase the life span of each key • Longer life span will allow us to use simple and straightforward key management Whiting, Housley, Ferguson
Longer Key Life Span • IV space sets the maximum life span • “Big enough” IV can avoid rekey; however, we still need to establish keys at the beginning of the association • Maximum packets per key: 248 [281,474,976,710,656 packets per key] (At 10K packets/sec, rekey in 100 years) Whiting, Housley, Ferguson
The Concept Whiting, Housley, Ferguson
Frame Format • Need a location in the frame for the four additional IV octets • Should use the same solution for TKIP and AES Whiting, Housley, Ferguson
Recommendation • Adopt the longer IV size Whiting, Housley, Ferguson