Thread Links Date Links
Thread Prev Thread Next Thread Index Date Prev Date Next Date Index

Re: [STDS-802-11-TGBP] PDT Security General Update



Hi Hui,

Thanks for your explanation.

I am not a security expert, so I would largely rely on your inputs here. However in my understanding, even for the second use "as the input for a keyed challenge and response authentication protocol", the core is still to avoid collision and repeat of Nonce. As long as each time the Nonce generation is "fresh enough", I do not see an issue and the numerical analysis provides the odds. Maybe I missed something here?


I am open to have more than 64 bits though, but also try to make sure we do not overkill.

Thanks,
Sam



From: Hui Luo <0000594db8d8d1cb-dmarc-request@xxxxxxxxxxxxxxxxx>
Sent: Wednesday, September 2, 2026 1:43 PM
To: STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx <STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx>
Subject: Re: [STDS-802-11-TGBP] PDT Security General Update

Hi Sam,

 

Thanks for your comments!

 

ANonce and SNonce have two uses in 4-way handshake. The first use is to avoid generating identical PTKs by a given PMK. Your collision probability analysis is applicable here. The second use is to serve as the input for a keyed challenge and response authentication protocol. I have been trying to find some quantitative analysis on the second use, but so far inconclusive. I also chatted with other experts. It seems people only feel qualitatively the size of these nonces cannot be too small. That’s why I suggest these nonces to be 128 bits each, jointly making a 256-bit entropy as the input for the authentication purpose. However, the strength of 4-way handshake authentication (keyed challenge and response) is mainly dependent of the key size and the MIC size. It seems CCMP-128’s 64-bit authentication tag could be the MIC in our case. So 256-bit input entropy might be a bit too much for a 64-bit MIC. Again, I have no quantitative reasoning to support such feeling.

 

Best regards,

 

Hui

 

 

 

From: Sam Shi <Sam.Shi@xxxxxxxxxxxxxxxx>
Sent: Wednesday, September 2, 2026 3:35 AM
To: STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx
Subject: Re: [STDS-802-11-TGBP] PDT Security General Update

 

Caution: This e-mail originated outside Infineon Technologies. Please be cautious when sharing information or opening attachments especially from unknown senders. Refer to our intranet guide to help you identify Phishing email.

 

Hi Guy and Hui,

 

In one paper earlier this year, I made some analysis on the length of nonce. The analysis showed 64 bits would be sufficient for AMP case:

  • Nonces provide freshness and uniqueness. They are transmitted in clear text. I do not see a reason to attack "Nonce".
  • For uniqueness, my previous paper gave calculation that 64 bits already provide sufficient protection against Nonce collision.
  • Also, given the (short) lifetime of AMP devices, there is no reason to use regular length of Nonce, i.e. 256bits.
  • Recall that AMP is designed for low energy/energy harvesting scenario; every bit has cost. If we put Nonce to 32 Octets, then only Anonce + Snonce would be 64 Octets. This is too much for AMP scenarios.

 

In my opinion, 64 bits would be enough and if we are really concerned, 128 bits would be definitely sufficient.

 

P.S. The numerical analysis shown in 11-26/0604:

 

 

~50% collision 

Probability of one repeat after 1 million use

64-bit Nonce

after 2^32 (4.3 billion) uses

P≈2.71×10^(-8)

128-bit Nonce

after 2^64 uses

P≈1.47×10^(-27)

 

 

Thanks,

Sam

 

 


From: Guy-Armand Kamendje <guy-armand@xxxxxxxx>
Sent: Tuesday, September 1, 2026 6:57 AM
To:
STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx <STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx>
Subject: Re: [STDS-802-11-TGBP] PDT Security General Update

 

I am afraid that Sam's analysis does not consider offline dictionary attacks.  I think 8 octets nonces might enable feasible offline dictionary attacks (more evidence is certainly needed to support this claim).

Sixteen or 32-octet nonces would put us on the safe side. My preference goes for 32 octets. Given that handshake is not expected to be a regular operation, the impact on the overal airtime might be limited. 

G

 

On Tue, Sep 1, 2026 at 3:22AM Rojan Chitrakar <00002005fb56ded7-dmarc-request@xxxxxxxxxxxxxxxxx> wrote:

Hi Hui,

 

“I have not found meaningful quantitative analysis about nonce size vs security performance, but there is good reason to worry about real-time attacks if the nonce size is too small, given that currently one piece SHA256 HW accelerator such as Antminer S21 series can compute hash value 2x10^14 times per second.”

 

Sam had contributed on the topic in the past:

 

https://mentor.ieee.org/802.11/dcn/26/11-26-0604-00-00bp-secure-amp-communication-with-reduced-length-anonce-and-snonce.pptx

 

Best Regards,

Rojan Chitrakar

 

From: Hui.Luo@xxxxxxxxxxxx <Hui.Luo@xxxxxxxxxxxx>
Sent: Friday, August 28, 2026 9:14 AM
To: Rojan Chitrakar <
rojan.chitrakar@xxxxxxxxxx>; STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx
Subject: RE: [STDS-802-11-TGBP] PDT Security General Update

 

Hi Rojan,

 

Thanks for the comments. Please see my responses to most of your comments in the attached document.

 

Best regards,

 

Hui

 

From: Rojan Chitrakar <00002005fb56ded7-dmarc-request@xxxxxxxxxxxxxxxxx>
Sent: Wednesday, August 26, 2026 5:50 AM
To:
STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx
Subject: Re: [STDS-802-11-TGBP] PDT Security General Update

 

Caution: This e-mail originated outside Infineon Technologies. Please be cautious when sharing information or opening attachments especially from unknown senders. Refer to our intranet guide to help you identify Phishing email.

 

Hi Hui,

 

Thanks for the PDT. Added some comments on top of Amichai’s.

 

Best Regards,

Rojan Chitrakar

 

From: Amichai Sanderovich <00003126a116a6ee-dmarc-request@xxxxxxxxxxxxxxxxx>
Sent: Monday, August 24, 2026 5:13 PM
To:
STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx
Subject: Re: [STDS-802-11-TGBP] PDT Security General Update

 

Thank you Hui,

 

Please see attached some comments

 

Best Regards

Amichai

 

From: Hui Luo <0000594db8d8d1cb-dmarc-request@xxxxxxxxxxxxxxxxx>
Date: Saturday, 15 August 2026 at 22:45
To:
STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx <STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx>
Subject: [STDS-802-11-TGBP] PDT Security General Update

Hi All,

I have suggested some updates on PDT Security General in order to resolve TBDs in this subclause and better prepare the subsequent subclauses. Please review it at https://mentor.ieee.org/802.11/dcn/26/11-26-1060-02-00bp-pdt-amp-security-general.docx.

Hi Bo,

Please queue it for PDT presentation.

Thanks,

Hui

 


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://protect.checkpoint.com/v2/r01/___https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1___.YzJ1OndpbGlvdDI6YzpvOjY1ZTIyZGI4YjY5ZjU5NDkxNTkzYjAwZmUzMDQ2YTI0Ojc6ZjY5OTplOGZlOGQ1OGNiYzVkMDU4NDg1YzBiMTA0NTRkYTM5Mzk2MjYzZWQwM2FhZTQyZjU0YWM1YjRkNzY1NjIxODRhOnQ6VDpG


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1