Um Mecanismo de Autenticação Baseado em ECDH para Redes IEEE 802.11

Eduardo Ferreira de SouzaPaulo André da S. Gonçalves

In networks that use the protocols WPA, WPA2 or IEEE 802.11i and these protocols enhanced by the amendment IEEE 802.11w, the keys that compose the PTK (Pairwise Transient Key) allow network devices to exchange messages with proper encryption and integrity check. Because of its importance, the PTK should be kept in secret by the protocol. However, in all of aforementioned protocols, the 4-Way Handshake is flawed when the personal authentication method is used, allowing malicious entities that possess the PSK (Pre-Shared Key) of the network to reproduce the process of deriving the PTK key of all authenticated clients. In this paper, we propose and evaluate a new handshake protocol, which is based on the ECDH (Elliptic Curve Diffie-Hellman) protocol and solves the problem of undue PTK derivation. We also present a solution to provide automatic authentication on open networks, allowing encrypted traffic information to be exchanged without the need of providing keys by the users.

