Dear 11bp security experts,
I have incorporated all received comments and updated the following PDT security documents (presented yesterday).
1552r8, PMK generation protocol,
https://mentor.ieee.org/802.11/dcn/26/11-26-1552-08-00bp-pdt-amp-security-pmk-generation.docx
1554r5, Authentication protocol,
https://mentor.ieee.org/802.11/dcn/26/11-26-1554-05-00bp-pdt-amp-security-data-exchange.docx
Please review them and let me know if you have any further comments. If I have not heard anything by tomorrow lunch, I will request Bo to queue them in the PDT SP list.
To help saving time in review, I listed the main changes below.
In 1552r8 PMK generation protocol (https://mentor.ieee.org/802.11/dcn/26/11-26-1552-08-00bp-pdt-amp-security-pmk-generation.docx).
-
Enabling PMK generation/updating protocol to proceed into the secure communication mode, which means all types of AMP frames that need to be protected are encrypted and/or authenticated with a MIC
after the protocol finished successfully.
-
Updating the write-up of 12.18.2.2 by removing the reference to “a special AP”.
-
Changing the AEAD cipher’s nonce input description from “uplink PN” and “downlink PN” to “uplink PN and uplink related information” and “downlink PN and downlink related information”, such that we
do not need to indicate uplink/downlink using the MSB of PN, and more details could be included in “uplink related information” and “downlink related information” later.
-
Adding GTK delivery.
-
Removing the format-related description such as “AAD data starts from where to where, encrypted data is placed where, etc.”
-
Change subclause 12.18.2.1 as “PMK Generation based on shared secret” and make corresponding clarifications.
In 1554r5 “Authentication protocol” (https://mentor.ieee.org/802.11/dcn/26/11-26-1554-05-00bp-pdt-amp-security-data-exchange.docx).
-
Enabling authentication protocol to proceed into a secure communication mode, which means all types of AMP frames that need to be protected are encrypted and/or authenticated with a MIC after the
full protocol finished successfully.
-
Changing the AEAD cipher’s nonce input description from “uplink PN” and “downlink PN” to “uplink PN and uplink related information” and “downlink PN and downlink related information”, such that we
do not need to indicate uplink/downlink using the MSB of PN, and more details could be included in “uplink related information” and “downlink related information” later.
-
Adding GTK delivery.
-
Removing the format-related description such as “AAD data starts from where to where, encrypted data is placed where, etc.”
Thanks and best regards,
Hui
To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1