About
Subscribe
  • Home
  • /
  • Networking
  • /
  • RSA Security helps create solution to secure wireless LANs

RSA Security helps create solution to secure wireless LANs

Johannesburg, 07 Jan 2002

RSA Security has announced that it has helped create a secure solution for the broken encryption standard in WEP (Wireless Equivalent Privacy) environments. The IEEE 802.11 committee has accepted the new `Fast Packet Keying` technology created by RSA Security and Hifn, a market leader in network security and flow classification. The solution is customised to the hardware environment of wireless LAN products, designed to allow vendors to offer the highest levels of data protection without replacing wireless LAN hardware and to preserve interoperability.

`Fast Packet Keying`, a new technology based on the RC4 algorithm, is designed to help organiations securely fix the WEP encryption standard. This new WEP solution, developed by RSA Security, Hifn and other members of the 802.11 committee, is designed to generate a unique RC4 key for each data packet sent over the wireless LAN. It is intended to be distributed as a software or firmware patch by wireless LAN vendors, allowing their customers to quickly update the existing vulnerable equipment.

It has been widely reported that the WEP protocol - the standard that outlines how data will be encrypted on the 802.11 wireless LAN - was implemented in a way that makes it vulnerable to attack. This poses serious risks for businesses that have deployed wireless LANs because any confidential data such as financial transactions, credit card numbers and a company`s proprietary information that is flowing over these networks can be compromised or exposed.

According to Peter Burgess, territory manager: sub-Saharan Africa at RSA Security, WEP implementations currently deployed in wireless LAN hardware today use RSA Security`s RC4 algorithm for encryption.

"The attacks against WEP were not a result of a weakness of the RC4 algorithm, but instead a weakness in how WEP derived RC4 keys for different data packets from a secret shared between wireless clients and access points. Simply put, the keys for different packets were too similar. Hackers could exploit this similarity to extract information about the shared secret after analysing a modest number of packets. Once the shared secret was discovered, a malicious hacker could decrypt data packets being passed along the exposed network. `Fast Packet Keying` is designed to avoid the similarities in the packet keys by providing a rapid way to derive unrelated RC4 keys from a shared secret," he says.

For more specific technical information on the solution, please go to www.rsasecurity.com/rsalabs/index.html.

Share

RSA Security Inc.

 

RSA Security Inc., the most trusted name in e-security, helps organisations build secure, trusted foundations for e-business through its RSA SecurID two-factor authentication, RSA ClearTrust authorisation, RSA BSAFE encryption and RSA Keon digital certificate management product families. With approximately one billion RSA BSAFE-enabled applications in use worldwide, more than ten million RSA SecurID authentication users and almost 20 years of industry experience, RSA Security has the proven leadership and innovative technology to address the changing security needs of e-business and bring trust to the online economy. RSA Security can be reached at www.rsasecurity.com.

Editorial contacts

Bernard Binns
Third Wave Communications
(011) 804 5271
3rdwave@global.co.za