| Thread Links | Date Links | ||||
|---|---|---|---|---|---|
| Thread Prev | Thread Next | Thread Index | Date Prev | Date Next | Date Index |
|
Hi Hui,
Thanks for your explanation.
I am not a security expert, so I would largely rely on your inputs here. However in my understanding, even for the second use "as the input for a keyed challenge and response authentication protocol", the core is still to avoid collision and repeat of Nonce. As long as each time the Nonce generation is "fresh enough", I do not see an issue and the numerical analysis provides the odds. Maybe I missed something here?
I am open to have more than 64 bits though, but also try to make sure we do not overkill.
Thanks,
Sam
From: Hui Luo <0000594db8d8d1cb-dmarc-request@xxxxxxxxxxxxxxxxx>
Sent: Wednesday, September 2, 2026 1:43 PM To: STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx <STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx> Subject: Re: [STDS-802-11-TGBP] PDT Security General Update Hi Sam,
Thanks for your comments!
ANonce and SNonce have two uses in 4-way handshake. The first use is to avoid generating identical PTKs by a given PMK. Your collision probability analysis is applicable here. The second use is to serve as the input for a keyed challenge and response authentication protocol. I have been trying to find some quantitative analysis on the second use, but so far inconclusive. I also chatted with other experts. It seems people only feel qualitatively the size of these nonces cannot be too small. That’s why I suggest these nonces to be 128 bits each, jointly making a 256-bit entropy as the input for the authentication purpose. However, the strength of 4-way handshake authentication (keyed challenge and response) is mainly dependent of the key size and the MIC size. It seems CCMP-128’s 64-bit authentication tag could be the MIC in our case. So 256-bit input entropy might be a bit too much for a 64-bit MIC. Again, I have no quantitative reasoning to support such feeling.
Best regards,
Hui
From: Sam Shi <Sam.Shi@xxxxxxxxxxxxxxxx>
Hi Guy and Hui,
In one paper earlier this year, I made some analysis on the length of nonce. The analysis showed 64 bits would be sufficient for AMP case:
In my opinion, 64 bits would be enough and if we are really concerned, 128 bits would be definitely sufficient.
P.S. The numerical analysis shown in 11-26/0604:
Thanks, Sam
From: Guy-Armand Kamendje <guy-armand@xxxxxxxx>
I am afraid that Sam's analysis does not consider offline dictionary attacks. I think 8 octets nonces might enable feasible offline dictionary attacks (more evidence is certainly needed to support this claim). Sixteen or 32-octet nonces would put us on the safe side. My preference goes for 32 octets. Given that handshake is not expected to be a regular operation, the impact on the overal airtime might be limited. G
On Tue, Sep 1, 2026 at 3:22 AM Rojan Chitrakar <00002005fb56ded7-dmarc-request@xxxxxxxxxxxxxxxxx> wrote:
To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1 To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1 To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1 To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1 |