节点文献

基于IEEE 802.11i无线局域网安全技术研究与实现

Study and Implementation of WLAN Security Technology Based on IEEE 802.11i

【作者】 高巍

【导师】 任新华;

【作者基本信息】 太原理工大学 , 计算机应用技术, 2007, 硕士

【摘要】 无线局域网是新世纪无线通信领域最有发展前景的技术之一。无线技术正在改变着人们传统的工作学习方式,使人们能随时随地获得高质量的网络语音、数据和图像服务。然而,随着无线局域网应用的不断普及,无线局域网的安全问题也越来越突出。如果安全问题得不到妥善解决,势必会影响无线局域网的进一步发展。本文首先对无线局域网标准进行了回顾,对无线局域网存在的安全威胁和安全风险进行了分析;接着,着重阐述了无线局域网传统安全机制中WEP协议和认证机制所存在的严重安全缺陷;然后,从数据保密协议、认证和访问控制以及动态密钥管理这几个方面对IEEE 802.11i标准进行了深入剖析;最后,基于IEEE 802.1X协议、EAP-TLS认证方法和RADIUS协议,以Linux操作系统为平台,结合开源项目OpenSSL、Host AP、Open1x和FreeRadius,设计和实现了一个符合IEEE 802.11i RSNA安全框架所定义的无线局域网安全系统。为了验证所实现系统的安全性,还利用网上广泛使用的一款无线局域网破解软件WinAircrackPack,分别对基于WEP加密机制的传统WLAN系统和本文所实现的基于IEEE 802.11i标准的WLAN系统进行了密钥攻击实验。通过对前者的成功破解和对后者的无效性,表明WEP在安全上的脆弱性,同时也说明所实现系统能够有效抵御当前已知的密钥攻击手段。

【Abstract】 In this new era, Wireless LAN is one of the most promising technologies in the field of telecommunication. WLAN is changing our traditional ways of working and studying, and make it available to achieve high quality services of voice, data and image in any time at any place. However, with the constant popularization of WLAN, the security of WLAN has been becoming a hot topic in the research of present computer networks. If security problems are not solved properly, they will restrict the further development of WLAN.At first, this paper reviews WLAN standards and analyzes security threats and security risks in WLAN. Then severe flaws of security mechanisms based on WEP specified in IEEE 802.11 are addressed. It is also developed about authentication and access control, data privacy protocols and dynamic key management in IEEE 802.11i. Finally, according to IEEE 802.1X, EAP-TLS authentication method and RADIUS protocol, we designed and implemented a WLAN security system on Linux platform. It combines with Open Source Code Project including OpenSSL, Host AP, Open1x and FreeRADIUS, and can meet the demand of RSNA framework defined in IEEE 802.11i. We selected a WLAN attack tool, WinAircrackPack, which is readily available on the Internet, and tried to crack the keys used in traditional WLAN system and the system we implemented respectively. The results express the former can be cracked successfuly and the latter can not. It also proves that our system can defend against the known key attacks effectively.

  • 【分类号】TN925.93
  • 【被引频次】4
  • 【下载频次】572
节点文献中: 

本文链接的文献网络图示:

本文的引文网络