The long wait for 802.11i

The long wait for 802.11i

Jen Hubley, Associate Editor
For the past year, at least, we've been hearing that 802.11i will be available in a few months. Like mañana, however, a few months from now never seems to come.

This isn't much of a surprise for those of us who follow emerging standards. The IEEE is better known for thoroughness than for speed, and in truth most wireless networking professionals would rather wait a bit longer and get a standard that addresses the weaknesses of WEP and improves on WPA. Our mobile security expert Kevin Beaver is

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

currently predicting that 802.11i will arrive in mid-2004.

The question, of course, is what that will mean to companies currently running wireless LANs (or considering future implementations). Kevin cites several benefits to upgrading to 802.11i from WPA or WEP, including support for AES encryption, mandatory 128-bit encryption keys, and strong authentication via EAP, PEAP, and LEAP. On the downside, 802.11i will require some hardware upgrades.

Lisa Phifer, SearchMobileComputing.com's wireless expert, offers further caveats: "Even when 802.11i is completed, it will only address link-layer security -- that is, controlling access to the WLAN itself and preventing eavesdropping and modification of frames over the air. True network security requires much more -- you'll still need firewalls to separate the WLAN from wired networks, authentication servers to verify wireless client identity, intrusion detection systems to spot potential attacks, etc."

In other words, 802.11i may be a big improvement over existing standards, but it won't solve all our WLAN security woes, no matter when it arrives.

This was first published in March 2004

Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.