Security protocols in wirelessman
Manton M. Matthews, Sen Xu · 2008
This dissertation overviews the IEEE 802.16 standard and analyzes the vulnerabilities in its security protocols. Various attacks are found in all versions of the Privacy and Key Management (PKM) protocols which are designed in the security sublayer of IEEE 802.16 MAC layer. Those typical attacks include the man-in-the-middle attack on PKMv1, the Simple Replay attack and the Multiplicity attack on PKMv1, Intel-Nonce version and PKMv2, and the Interleaving attack on PKMv2. We propose counter-attack solutions and present revised protocols that resist to those attacks. Some other security issues are also addressed, such as secure roaming protocols. Secure multicast is further studied and the weakness of the Multicast and Broadcast Rekeying Algorithm (MBRA) in IEEE 802.16e is addressed. We revised MBRA as a more efficient protocol for Intra-BS multicast. We also proposed Adaptive Inter-BS multicast protocol which takes advantage of several popular secure multicast protocols. Furthermore, we designed a family of secure multicast protocols for handover procedures in WiMAX. We also perform formal analysis and verification on those PKM protocols using several popular formal methods, including BAN logic, extended MB logic, and CasperFDR. Most of the attacks we found before have been rediscovered using those methods and the revised protocols are verified to be correct and safe from known attacks.