Wi-Fi Protected Access Authentication Flashcards
EAPOL
Extensible Authentication Protocol Over LAN
Inputs for the four-way handshake
- Pairwise Master Key (PMK)
- Authenticator Nonce (Anonce)
- Supplicant Nonce (Snonce)
- Authenticator Address (AA) – MAC address
- Supplicant Address (SA) – MAC address
Four way handshake, message 1
Authenticator sends ANonce
Supplicant creates Pairwise Transcient Key
Elements of Pairwise Transcient Key
- Key Confirmation Key
- Key Encryption Key
- Temporal Encryption Key
- Temporary MIC Key
Four way handshake, message 2
Supplicant sends SNonce with a Message Integrity Code (MIC)
Authenticator determines the PTK
Four way handshake, message 3
Authenticator sends the Group Temporal Key with a Message Integrity Code
Four way handshake, message 4
Supplicant sends an acknowledgement with a Message Integrity Code
WPA/WPA2 Enterprise
Supplicant talks to Authenticator, the Authenticator talks to an Authentication Server (RADIUS, TACACS+)
First the user is authenticated with Extensible Authentication Protocol, only then the 4-way handshake is initiated between the supplicant and the authenticator.
RADIUS
Remote Authentication Dial In User Service