cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3493
Views
0
Helpful
5
Replies

What's the difference between CKIP and TKIP?

shh5455
Level 3
Level 3

Cisco APs offer CKIP and TKIP. What's the difference?

Also what's the difference between MIC and CMIC?

Which are part of 802.11i and which are Cisco proprietary?

5 Replies 5

ebreniz
Level 6
Level 6

CKIP is Cisco Key Integrity Protocol. Cisco's WEP key permutation technique based on an early algorithm presented by the IEEE 802.11i security task group.

TKIP is Temporal Key Integrity Protocol. Also referred to as WEP key hashing. A security feature that defends against an attack on WEP in which the intruder uses the initialization vector (IV) in encrypted packets to calculate the WEP key. TKIP removes the predictability that an intruder relies on to determine the WEP key by exploiting IVs.

MIC is Message integrity check. MIC prevents bit-flip attacks on encrypted packets. During a bit-flip attack, an intruder intercepts an encrypted message, alters it slightly, and retransmits it, and the receiver accepts the retransmitted message as legitimate. The client adapter's driver must support MIC functionality, and MIC must be enabled on the access point.

CMIC is Cisco Message Integrity Check. MIC prevents bit-flip attacks on encrypted packets. During a bit-flip attack, an intruder intercepts an encrypted message, alters it slightly, and retransmits it, and the receiver accepts the retransmitted message as legitimate. The client's adapter driver must support MIC functionality, and MIC must be enabled on the access point.

For more details

http://www.cisco.com/en/US/products/sw/cscowork/ps3915/products_user_guide_chapter09186a00801f7dbc.html

Ok, they both sound very similar. What are the differences?

ebreniz already gave a perfect description of what they do - In short, CKIP and CMIC are Cisco's pre-802.11i ratification and pre-WPA spec implementations of TKIP and MIC which are now standard. A part of cisco's continuing policy of pushing out new features and technology before the (often slow) standards bodies' ratification process completes. If you intend to have full WPA/802.11i compatibility you want to use TKIP & MIC.

I guess I am just not understanding. Cisco has come up with CKIP and CMIC which are proprietary to Cisco equipment and based on early information given by 802.11i. Is that correct?

In terms of operation how are they different from TKIP and MIC? The definitions I've seen both describe the same thing.

One final question. Which of these is correct:

802.11i = CKIP + CMIC

802.11i = TKIP + MIC

Thank you

802.11i = TKIP + MIC and AES encryption with key management

WPA = TKIP + MIC

Review Cisco Networking for a $25 gift card