Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Mobile/Wireless Computing
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Vendors make a wireless end run

Microsoft, Cisco and major wireless LAN hardware vendors plan to leapfrog the standards process and adopt new 802.11b security protocols by year's end.

September 23, 2002 12:00 PM ET

Computerworld - Microsoft Corp., Cisco Systems Inc. and major wireless LAN hardware manufacturers have joined forces to beef up security for 802.11b wireless LAN products through a project dubbed Safe Secure Networks, Computerworld has learned. An announcement is slated for next month.


The SSN project grew out of a multivendor initiative kicked off earlier this year to address known weaknesses in the Wired Equivalent Privacy protocol (see story), said Warren Barkley, lead program manager for wireless in Microsoft's Windows division. Building security beyond WEP into wireless LAN products would help users guard against hacker intrusions.


The SSN partners include semiconductor manufacturer Intersil Corp. and enterprise wireless LAN hardware makers Agere Systems Inc., Symbol Technologies Inc. and Proxim Corp. Barkley said the group plans to adopt a technology called Temporal Key Integrity Protocol ahead of its final approval by the Institute of Electrical and Electronics Engineers Inc.'s 802.i standards body. He added that the SSN partners have worked to ensure that the TKIP fix is compatible with the existing installed 802.11b, or Wi-Fi, hardware base. That's a key issue for businesses as well as home users, who have installed millions of wireless LAN access points and cards.


TKIP defeats hacking by providing users with dynamic keys that can be changed rapidly, rather than the static keys used in WEP. Not only are WEP keys static, but every user working with a particular wireless LAN access point receives the same key, allowing hackers using widely available key-cracking software to crack keys with relative ease.


Barkley said the SSN partners don't plan to wait until the IEEE issues its final version of the 802.i standard but will instead incorporate TKIP into their products as soon as possible. And rather than wait for the next Windows XP service pack release, Microsoft will incorporate TKIP into XP before the end of the year, he added.


Dennis Eaton, chairman of the Wireless Ethernet Compatibility Alliance (WECA), a wireless LAN industry trade group in Mountain View, Calif., said that final details on an industrywide SSN standard are "very close" and that the WECA plans to make a major announcement next month.


John Pescatore, an analyst at Gartner Inc., said plans by the industry to leapfrog the IEEE 802.1 standards body make sense because the IEEE process "moves very slowly" and the wireless LAN industry needs better security immediately.


Barkley said the first Windows XP service pack, released earlier this month (see story), includes support for Protected Extensible Authentication Protocol (PEAP), which fixes a known vulnerability in the new 802.1x standard that authenticates the identity of a user with a central server. Dan Bailey, director of wireless networking at NTRU Cryptosystems Inc. in Burlington, Mass., said PEAP can help rectify flaws in 802.1x that could possibly let a hacker "hijack a user authentication session" through what he called "a man-in-the-middle attack" on such a session.



Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Realizing Rapid ROI Through Mobility
Companies are reaping the benefits from mobile CRM, field service and sales force automation processes with the latest Research In Motion (RIM) offerings....  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

CIO's Guide to Fixed Mobile Convergence
Organizations seeking solutions that provide high-performance access while addressing security needs can leverage fixed mobile convergence (FMC) systems to enhance communication. This document...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

SIP Trunking Is Key to Accelerating Unified Communications Deployments
Companies today are undergoing a significant transformation to a more global Anywhere Enterprise™. Unified communications (UC) is a crucial component in this evolution...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

Seamless Communications: Simplicity, Efficiency, and Transparency Achieved Through Integrated Wireline and Wireless Services
This IDC White Paper provides analysis of the convergence between wireline and wireless technologies and the opportunities this evolution offers to enterprises looking...  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

BlackBerry ROI Calculator
(Source: RIM) This ROI calculator will help you work through the components of calculating an estimated ROI for the deployment of BlackBerry® in...  

Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....