While Wi - Fi makes
information much more
accessible and does away
with the complexities of wiring and
cabling, it brings along with it a plethora
of security issues that need attention.
Wi-Fi Networks are usually open and can
be accessed by non registered users easily.
Due to this any hacker can gain access to
the internal network leading to data loss
and theft through eavesdropping,
interception and modification of data in
transit, spoofed e-mail messages for social
engineering and malware insertion
attacks, service disruption, bandwidth
loss etc. The lax security measures on part
of users as well as Internet service
providers, present cyber criminals with a
cakewalk. Basically they take advantage
of the fact that there are no proper security
systems and practices, all of which help
them erase their trails.
The deployment of security through
different Wi-Fi settings, be it home,
businesses or hotspots, is the first step towards ensuring security. However there
is a need to have greater security measures
taken at the operators end.
It is now
mandatory by
law to offer secure
Wi-Fi services via
802.1x and
WPA/ WPA2
based methods
and
keep track of
wifi usage.
Looking into these security issues it is now
mandatory by law to offer secure Wi-Fi
services via 802.1x and WPA/ WPA2
based methods and keep track of Wi-Fi
usage. Service providers offering Wi-Fi
services at public places such as hotels,
restaurant, airport malls, railway stations,
shops or residential use and enterprise
network on leased lines need to have a
Central Authentication Mechanism
Provisioning and subscriber management
for secure Wi-Fi networks.
The Government of India - has
introduced significant new compliance
requirements for all ISPs providingWi-Fi
services at
- Public hotspots including airports,
Malls, cafes, schools, hotels, etc
- Enterprises and offices that use leased
lines and install their own Wi-Fi
routers also need to be secured
- Residential & Retail Subscribers
Rolling out a secure Wi-Fi Network
as perDOTRequirements
Public Wi-Fi
All public Wi-Fi access points
whether offered free or paid need to
be encrypted and secured, the user
can register and login through a
temporary username password auto
generated from the system for that
session or till the expiration of
numbers of hours purchased.
The ssdervice provider also needs to
ensure a controlled distribution of
service through pre creation of login
ids at each Wi-Fi hotspot, which get
authenticated at the centralized
server.
The registration and tracking of usage
will happen at a central
authentication server, centrally for all
the hotspots by the service provider. It
is mandatory to keep photo identity
and mobile number for records.
For Enterprise &
Residential Wi-Fi
Service providers must
offer central
authentication
mechanism - Each
subscriber (Office,
Residential) must be able
to access Wi-Fi service
through their unique
login id & password that
will be authenticated at
the centralized server deployed by the
ISP.
The system should be able to track
each subscriber's sessions and usage
with records that must include IP
address & location where / when an
authorized user accessed a specified
Internet resource which need to be
maintained for a year.
As per the new law multiple logins
cannot be issued to a single user, But
can be give for different accounts to
same subscriber. For new subscribers,
service activation would happen only
after registration for central
authentication.
These guidelines issued by DoT will
definitely secure the network and stop
unlawful use by anti social elements.
Elitecore Offers EliteAAA to
centrally manage the subscriber's
authentication & authorizes them for
appropriate level of service, and
centralized subscriber management.
EliteAAA for Wi-Fi is vendor
agnostic and standards-based
solution offering encryption and key
rotation based on IEEE 802.1x and
Wi-Fi Protected Access (WPA/
WPA2). EliteAAA supports EAP
TLS, EAP TTLS, EAP FAST, EAP
MD5 and PEAP – MS – CHAPv2
security methods. A lot of Service
providers have realized the
importance of secure Wi-Fi, We are
working on various cases related to
Wi-Fi Security offering a centralized
authentication server and other
security features that are needed to
protect the Wi-Fi Networks as per
guidelines laid down by DoT. A
secure Wi-Fi service experience is
paving way for the next revolution of
internet experience.