发表机构
RPTU Kaiserslautern-Landau; German Research Center for Artificial Intelligence (DFKI)(莱茵兰-普法尔茨应用技术大学凯泽斯劳滕-兰道分校; 德国人工智能研究中心)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对EAP认证无法区分受损凭据的问题,提出基于批量PLD的重新验证步骤集成到TEAP/RADIUS/802.11认证链,在hostap 2.12中实现,实验验证了其安全性与可靠性权衡。
AI 中文摘要
基于凭据的可扩展认证协议(EAP)认证无法区分合法凭据持有者和使用受损凭据的对手。物理层欺骗(PLD)通过在主传输上暴露欺骗性主对象,同时让独立的恢复对象在辅助信道上以差异化可靠性传输,从而补充基于凭据的认证。据我们所知,现有PLD研究仍停留在物理/链路模型层面;将PLD的激活/停用机制用作认证门控会产生认证特定的设计需求,因为全停用尝试不会执行任何恢复路径。我们为企业Wi-Fi的TEAP/RADIUS/IEEE 802.11认证链提出了一种基于批量PLD的重新验证步骤,并在开源hostap 2.12代码库中跨服务器、接入点和设备端到端实现。每次尝试包含三轮,至少一轮处于激活状态,且没有专用的激活标志。在总计1593次尝试的四次活动中,原型评估了批量恢复行为,在所有30次尝试中拒绝了所实现的朴素凭据携带型攻击者,测量了成功路径延迟,并在两种建模恢复机制下评估了一轮、两轮和三轮激活的安全-可靠性权衡。该评估直接测试了协议和软件MAC行为,并在软件恢复模型下分析了知情攻击者和重试寻求型攻击者。
英文摘要
Credential-based Extensible Authentication Protocol (EAP) authentication cannot distinguish a legitimate credential holder from an adversary using compromised credentials. Physical Layer Deception (PLD) complements credential-based authentication by exposing a deceptive primary object over a primary transport while a separate recovery object travels with differentiated reliability over a secondary channel. Existing PLD studies remain, to our knowledge, at the physical/link-model level; using PLD's activation/deactivation mechanism as an authentication gate creates an authentication-specific design requirement, since an all-inactive attempt would exercise no recovery path. We present a batched PLD-based re-verification step for Enterprise Wi-Fi's TEAP/RADIUS/IEEE 802.11 authentication chain, implemented end to end across the server, access point, and device in the open-source hostap 2.12 codebase. Each attempt carries three rounds, at least one active, with no dedicated activation flag. Across four campaigns totaling 1593 attempts, the prototype evaluates batched recovery behavior, rejects the implemented naive credential-bearing attacker in all 30 attempts, measures successful-path latency, and evaluates the security-reliability trade-off for one, two, and three active rounds under two modeled recovery regimes. The evaluation exercises the protocol and software-MAC behavior directly and analyzes informed and retry-seeking attackers under the software recovery model.