60 likes | 809 Views
Race condition. Tim Moore Microsoft. Race condition. Race condition between supplicant installing Pairwise key and Group update message 1 arriving from AP 802.1X message check in Tx pseudo code Enables 802.1X messages to be protected by Group key only. Changes.
E N D
Race condition Tim Moore Microsoft Tim Moore, Microsoft
Race condition • Race condition between supplicant installing Pairwise key and Group update message 1 arriving from AP • 802.1X message check in Tx pseudo code • Enables 802.1X messages to be protected by Group key only Tim Moore, Microsoft
Changes • Add MLME.SetProtection.Request (MAC address, Tx/Rx) • Enables protection for Tx or Rx or both for a specific MAC address • Protection reset only on 802.11 (re-)association • Used by EAPOL-Key authentication state machine • Used by Supplicant StaProcesseEAPOL-Key Tim Moore, Microsoft
Supplicant (Pairwise) • Installs Pairwise key before sending message 4 • Sets protection for Rx before sending message 4 of 4-way handshake • Sets protection for Tx & Rx after sending message 4 of 4-way handshake Tim Moore, Microsoft
Authenticator (Pairwise) • Installs protection for Tx & Rx after receiving message 4 of 4-way handshake Tim Moore, Microsoft
Group • Supplicant • Install protection for Tx & Rx after sending group update ack • Authenticator • Install protection for Tx & Rx after receiving group update ack Tim Moore, Microsoft