FMS Attack-Resistant WEP Implementation Is Still Broken

  • Toshihiro Ohigashi
  • Yoshiaki Shiraishi
  • Masakatu Morii
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 3802)


In this paper, we present an attack to break WEP that avoids weak IVs used in the FMS attack. Our attack is a known IV attack that doesn’t need the specific pattern of the IVs. This attack transforms most IVs of WEP into weak IVs. If we attempt to avoid all weak IVs used in our attack, the rate at which IVs are avoided is too large to use practical. When using a 128-bit session key, the efficiency of our attack is 272.1 in the most effective case. This implies that our attack can recover a 128-bit session key within realistically possible computational times.


Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.


  1. 1.
    IEEE Computer Society. Wireless Lan Medium Access Control (MAC) and Physical Layer (PHY) Specifications, IEEE Std 802.11 (1999) (Edition) Google Scholar
  2. 2.
    Fluhrer, S., Mantin, I., Shamir, A.: Weaknesses in the key scheduling algorithm of RC4. In: Vaudenay, S., Youssef, A.M. (eds.) SAC 2001. LNCS, vol. 2259, pp. 1–24. Springer, Heidelberg (2001)CrossRefGoogle Scholar
  3. 3.
    NIST, FIPS PUB 180-2 Secure Hash Standard (August 2002)Google Scholar
  4. 4.
    Schneier, B.: Applied Cryptography. Wiley, New York (1996)Google Scholar
  5. 5.
    Wi-Fi Alliance, Wi-Fi Protected Access, available at
  6. 6.
    Stubblefield, A., Loannidis, J., Rubin, A.D.: A key recovery attack on the 802.11b wired equivalent privacy protocol (WEP). ACM Trans. Inf. Syst. Secur. 7(2), 319–332 (2004)CrossRefGoogle Scholar

Copyright information

© Springer-Verlag Berlin Heidelberg 2005

Authors and Affiliations

  • Toshihiro Ohigashi
    • 1
  • Yoshiaki Shiraishi
    • 2
  • Masakatu Morii
    • 3
  1. 1.The University of TokushimaTokushimaJapan
  2. 2.Kinki UniversityHigashi-OsakaJapan
  3. 3.Kobe UniversityKobeJapan

Personalised recommendations