Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Литература / 802.16-2001+.pdf
Скачиваний:
27
Добавлен:
16.04.2013
Размер:
2.61 Mб
Скачать

AIR INTERFACE FOR FIXED BROADBAND WIRELESS ACCESS SYSTEMS IEEE Std 802.16-2001

 

Table 131—TEK-parameters subattributes

 

 

Attribute

Contents

 

 

TEK

TEK, encrypted with the KEK

 

 

Key-Lifetime

TEK Remaining Lifetime

 

 

Key-Sequence-Num-

TEK Sequence Number

ber

 

 

 

CBC-IV

Cipher Block Chaining (CBC) Initialization Vector

 

 

11.2.9 CBC-IV

Description: This Attribute contains a value specifying a Cipher Block Chaining Initialization Vector (CBC-IV). A summary of the CBC-IV attribute format is shown below. The fields are transmitted from left to right.

Type

Length

Value (string)

 

 

 

15

Equal to Block length of cipher

CBC-IV

 

 

 

11.2.10 Error code

Description: This Attribute contains a one-byte error code providing further information about an Authorization Reject, Key Reject, Authorization Invalid, or TEK Invalid. A summary of the Error-Code Attribute format is shown below. Table 132 lists code values for use with this Attribute. The BS may employ the nonzero error codes (1–6) listed below; it may, however, return a code value of zero (0). Error code values other than those defined in Table 132 shall be ignored. Returning a code value of zero sends no additional failure information to the SS; for security reasons, this may be desirable.

Type

Length

Value (uint8)

 

 

 

 

 

16

1

Error-Code

Authorization Reject,

 

 

 

Authorization Invalid, Key

 

 

 

Reject, TEK Invalid

 

 

 

 

Copyright © 2002 IEEE. All rights reserved.

283

IEEE Std 802.16-2001 LOCAL AND METROPOLITAN AREA NETWORKS—PART 16:

Table 132—Error-code attribute code values

Error Code

Messages

Description

 

 

 

0

All

No information

 

 

 

1

Auth Reject, Auth Invalid

Unauthorized SS

 

 

 

2

Auth Reject, Key Reject

Unauthorized SAID

 

 

 

3

Auth Invalid

Unsolicited

 

 

 

4

Auth Invalid, TEK Invalid

Invalid Key Sequence Number

 

 

 

5

Auth Invalid

Message (Key Request) authentication failure

 

 

 

6

Auth Reject

Permanent Authorization Failure

 

 

 

Error Code 6 (Permanent Authorization Failure) is used to indicate a number of different error conditions affecting the PKM authorization exchange. These include:

a)an unknown manufacturer; i.e., the BS does not have the CA certificate belonging to the issuer of an SS certificate

b)SS certificate has an invalid signature

c)ASN.1 parsing failure during verification of SS certificate

d)SS certificate is on the “hot list”

e)inconsistencies between certificate data and data in accompanying PKM attributes

f)SS and BS have incompatible security capabilities

The common property of these error conditions is that the failure condition is considered permanent; any reattempts at authorization would continue to result in Authorization Rejects. Details about the cause of a Permanent Authorization Failure may be reported to the SS in an optional Display-String Attribute that may accompany the Error-Code Attribute in Authorization Reject messages. Note that providing this additional detail to the SS should be administratively controlled within the BS. The BS may log these Authorization failures, or even trap them to an SNMP manager.

11.2.11 CA certificate

Description: This Attribute is a string attribute containing an X.509 CA Certificate, as defined in 7.6. A summary of the CA-Certificate Attribute format is shown below. The fields are transmitted from left to right.

Type

Length

Value (string)

 

 

 

17

Variable.

X.509 CA Certificate (DER-encoded ASN.1)

 

Length shall not cause resulting MAC management

 

 

message to exceed the maximum allowed size.

 

 

 

 

284

Copyright © 2002 IEEE. All rights reserved.

AIR INTERFACE FOR FIXED BROADBAND WIRELESS ACCESS SYSTEMS

IEEE Std 802.16-2001

11.2.12 SS certificate

Description: This Attribute is a string attribute containing an SS’s X.509 User Certificate, as defined in 7.6. A summary of the SS-Certificate Attribute format is shown below. The fields are transmitted from left to right.

Type

Length

Value (string)

 

 

 

18

Variable.

X.509 SS Certificate (DER-encoded ASN.1)

 

Length shall not cause resulting MAC management

 

 

message to exceed the maximum allowed size.

 

 

 

 

11.2.13 Security capabilities

Description: The Security-Capabilities Attribute is a compound attribute whose subattributes identify the version of PKM an SS supports and the cryptographic suite(s) an SS supports.

Type

Length

Value (compound)

 

 

 

19

variable

The Compound field contains the subattributes as

 

 

defined in Table 133

 

 

 

Table 133—Security-capabilities subattributes

Attribute

Contents

 

 

Cryptographic-Suite-List

list of supported cryptographic suites

 

 

Version

version of Privacy supported

 

 

11.2.14 Cryptographic suite

Type

Length

 

Value (uint8,uint8,uint8)

 

 

 

 

 

20

3

A 24-bit

integer identifying the

cryptographic suite

 

 

properties.

The most significant

byte, as defined in

 

 

Table 134, indicates the encryption algorithm and key

 

 

length. The middle byte, as defined in Table 135 indicates

 

 

the data authentication algorithm. The least significant byte,

 

 

as defined in Table 136, indicates the TEK Encryption

 

 

Algorithm.

 

 

 

 

 

 

 

Copyright © 2002 IEEE. All rights reserved.

285

IEEE Std 802.16-2001

LOCAL AND METROPOLITAN AREA NETWORKS—PART 16:

Table 134—Data encryption algorithm identifiers

Value

Description

 

 

0

No data encryption

 

 

1

CBC-Mode, 56-bit DES

 

 

2-255

reserved

 

 

Table 135—Data authentication algorithm identifiers

Value

Description

 

 

0

No data authentication

 

 

1–255

reserved

 

 

Table 136—TEK encryption algorithm identifier

Value

Description

 

 

0

reserved

 

 

1

3-DES EDE with 128-bit key

 

 

2–255

reserved

 

 

The allowed cryptographic suites are itemized in Table 137.

 

Table 137—Allowed cryptographic suites

 

 

 

Value

 

Description

 

 

 

0x000001

 

No data encryption, no data authentication & 3-DES,128

 

 

 

0x010001

 

CBC-Mode 56-bit DES, no data authentication & 3-DES,128

 

 

 

all remaining values

 

reserved

 

 

 

11.2.15 Cryptographic-Suite-List

This parameter contains a list of supported Cryptographic-Suites.

Type

Length

Value (compound)

 

 

 

21

5*n, where n equals number of

A list of Cryptographic Suites

 

cryptographic suites listed

 

 

 

 

286

Copyright © 2002 IEEE. All rights reserved.

Соседние файлы в папке Литература