Introduces protected management frames in 802.11w, explains IGTK and BIP integrity protocols, details SA teardown protection and associated procedures, and summarizes prerequisites and restrictions for deploying 802.11w.
A protected management frame is a wireless security feature that
-
uses the 802.11w protocol to safeguard management frames
-
prevents spoofing and forgery of authentication, de-authentication, association, and disassociation frames, and
-
enhances the overall security of Wi-Fi networks by protecting key network management actions from attack.
While data frames can be encrypted, management frames were traditionally sent in the clear, making them vulnerable to interception and forgery. The 802.11w standard addresses this vulnerability by requiring cryptographic protection for certain management frames between client and access point.
Types of management frames protected by 802.11w
The 802.11w protocol protects certain management frames by using the Protected Management Frames (PMF) service. These frames are classified as robust management frames and include:-
Disassociation frames
-
De-authentication frames
-
Robust Action frames
-
Spectrum Management
-
Quality of Service (QoS)
-
Direct Link Setup (DLS)
-
Block acknowledgement
-
Radio Measurement
-
Fast Basic Service Set (BSS) Transition
-
Security Association (SA) Query
-
Protected Dual of Public Action
-
Vendor-specific Protected
Protections offered by 802.11w
When 802.11w is implemented, these protections are provided:
-
Client protection: The AP adds cryptographic protection to de-authentication and dissociation frames, preventing spoofing in DOS attacks.
-
Infrastructure protection: Security Association (SA) teardown protection is implemented using Association Comeback Time and SA-Query procedures to prevent spoofed association requests from disconnecting connected clients.