RE: Security requirements for LWAPP?
From: Pat R. Calhoun (pcalhounairespace.com)
Date: 17 Jul 2003 18:12:22 -0000
> Authentication: AP to AR and AR to AP (counters masquerading AR's and 
> rogue AP's)
yes

> Integrity: All packets (prevents injections and modification attacks)
yes, but the question is whether the data packets also need protection.

> Confidentiality: Not sure if this is needed
yes. Sensitive keying information is passed down to the AP if encryption is 
performed in the AP itself. 

> Key Management: Something beyond EAPoL-key needed?
See previous answer (yes)

PatC




Results generated by Tiger Technologies using MHonArc.