Cisco Wireless Security
WPA – Wireless Protected Access
WPA, includes TKIP
WPA2, includes AES
WPA3, removes older standards like TKIP
Authentication, abstracted
Courtesy of BRKEWN-3004.
sequenceDiagram
participant S as Supplicant<br/>Phone, PC, Laptop, Etc.
participant A as Authenticator<br/>(WLC)
participant AS as Authentication Server<br/>(ISE)
A->>S: Association Response
A->>S: Identity Request
S->>A: Identity Response
A->>AS: Identity Response
S<<->>AS: EAP Type Negotiation
S<<->>AS: Authentication Sequence
AS->>A: EAP Success
A->>S: EAP Success
Encryption, abstracted
Courtesy of BRKEWN-3004.
PTK — Pairwise Transient Key
GTK — Group Transient Key
PMK — Pairwise Master Key
STA — Station
Anonce – Authenticator nonce, a random value generated by the authenticator
Snonce — Supplicant nonce, a random value generated by the supplicant
\(PTK = SHA(PMK + ANonce + SNonce + AP MAC + STA MAC)\)
sequenceDiagram
participant S as Supplicant
participant A as Authenticator<br/>(WLC)
participant AS as Authentication Server<br/>(ISE)
Note over AS: PMK
AS->>A: EAP Success (PMK)
A->>S: EAP Success
Note over S: PMK
rect rgb(235, 245, 235)
Note over S,A: Four-Way Handshake
A->>S: ANonce
S->>A: SNonce, MIC
Note over S,A: PTK, GTK derived
A->>S: ANonce, MIC, GTK, Sequence #
S->>A: ACK
end
References
Cisco Live - Understanding Wireless Security - Mark Krischer - BRKEWN-3004