Vendors make a wireless end run
Microsoft, Cisco and major wireless LAN hardware vendors plan to leapfrog the standards process and adopt new 802.11b security protocols by year's end.
September 23, 2002 12:00 PM ETComputerworld -
Microsoft Corp., Cisco Systems Inc. and major wireless LAN hardware manufacturers have joined forces to beef up security for 802.11b wireless LAN products through a project dubbed Safe Secure Networks, Computerworld has learned. An announcement is slated for next month.
The SSN project grew out of a multivendor initiative kicked off earlier this year to address known weaknesses in the Wired Equivalent Privacy protocol (see story), said Warren Barkley, lead program manager for wireless in Microsoft's Windows division. Building security beyond WEP into wireless LAN products would help users guard against hacker intrusions.
The SSN partners include semiconductor manufacturer Intersil Corp. and enterprise wireless LAN hardware makers Agere Systems Inc., Symbol Technologies Inc. and Proxim Corp. Barkley said the group plans to adopt a technology called Temporal Key Integrity Protocol ahead of its final approval by the Institute of Electrical and Electronics Engineers Inc.'s 802.i standards body. He added that the SSN partners have worked to ensure that the TKIP fix is compatible with the existing installed 802.11b, or Wi-Fi, hardware base. That's a key issue for businesses as well as home users, who have installed millions of wireless LAN access points and cards.
TKIP defeats hacking by providing users with dynamic keys that can be changed rapidly, rather than the static keys used in WEP. Not only are WEP keys static, but every user working with a particular wireless LAN access point receives the same key, allowing hackers using widely available key-cracking software to crack keys with relative ease.
Barkley said the SSN partners don't plan to wait until the IEEE issues its final version of the 802.i standard but will instead incorporate TKIP into their products as soon as possible. And rather than wait for the next Windows XP service pack release, Microsoft will incorporate TKIP into XP before the end of the year, he added.
Dennis Eaton, chairman of the Wireless Ethernet Compatibility Alliance (WECA), a wireless LAN industry trade group in Mountain View, Calif., said that final details on an industrywide SSN standard are "very close" and that the WECA plans to make a major announcement next month.
John Pescatore, an analyst at Gartner Inc., said plans by the industry to leapfrog the IEEE 802.1 standards body make sense because the IEEE process "moves very slowly" and the wireless LAN industry needs better security immediately.
Barkley said the first Windows XP service pack, released earlier this month (see story), includes support for Protected Extensible Authentication Protocol (PEAP), which fixes a known vulnerability in the new 802.1x standard that authenticates the identity of a user with a central server. Dan Bailey, director of wireless networking at NTRU Cryptosystems Inc. in Burlington, Mass., said PEAP can help rectify flaws in 802.1x that could possibly let a hacker "hijack a user authentication session" through what he called "a man-in-the-middle attack" on such a session.
Wireless Technologies
Additional Resources



White Papers & Webcasts
Streamline Your Business with Innovative Tools
Download This White Paper Now!
Key Strategies for Managing Data Growth
What are you storage challenges?
Inquiry Insights: Enterprise Mobility, Q1 2009
Learn what Forrester has uncovered in their latest report on Enteprise Mobility trends.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Comparing Research In Motion and Microsoft Mobile Solutions
This paper compares the Research In Motion BlackBerry solution with the Microsoft® mobile solution by analyzing features of the user experience and the...
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
True Convergence Demands a Communication Service Provider that Embraces a Customer-Centric Approach
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
SIP Trunking Is Key to Accelerating Unified Communications Deployments
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
