Thread Links Date Links
Thread Prev Thread Next Thread Index Date Prev Date Next Date Index

Re: [STDS-802-11-TGBP] PDT security 11-26/1552r8 and 11-26/1554r5 review request



Hi Hui, 
Please see attached my comments on 1552. I am still reviewing 1554

On Wed, Sep 16, 2026 at 11:17 PM Hui Luo <0000594db8d8d1cb-dmarc-request@xxxxxxxxxxxxxxxxx> wrote:

Dear 11bp security experts,

 

I have incorporated all received comments and updated the following PDT security documents (presented yesterday).

 

1552r8, PMK generation protocol, https://mentor.ieee.org/802.11/dcn/26/11-26-1552-08-00bp-pdt-amp-security-pmk-generation.docx

1554r5, Authentication protocol, https://mentor.ieee.org/802.11/dcn/26/11-26-1554-05-00bp-pdt-amp-security-data-exchange.docx

 

Please review them and let me know if you have any further comments. If I have not heard anything by tomorrow lunch, I will request Bo to queue them in the PDT SP list.

 

To help saving time in review, I listed the main changes below.

 

In 1552r8 PMK generation protocol (https://mentor.ieee.org/802.11/dcn/26/11-26-1552-08-00bp-pdt-amp-security-pmk-generation.docx).

  1. Enabling PMK generation/updating protocol to proceed into the secure communication mode, which means all types of AMP frames that need to be protected are encrypted and/or authenticated with a MIC after the protocol finished successfully.
  2. Updating the write-up of 12.18.2.2 by removing the reference to “a special AP”.
  3. Changing the AEAD cipher’s nonce input description from “uplink PN” and “downlink PN” to “uplink PN and uplink related information” and “downlink PN and downlink related information”, such that we do not need to indicate uplink/downlink using the MSB of PN, and more details could be included in “uplink related information” and “downlink related information” later.
  4. Adding GTK delivery.
  5. Removing the format-related description such as “AAD data starts from where to where, encrypted data is placed where, etc.”
  6. Change subclause 12.18.2.1 as “PMK Generation based on shared secret” and make corresponding clarifications.

In 1554r5 “Authentication protocol” (https://mentor.ieee.org/802.11/dcn/26/11-26-1554-05-00bp-pdt-amp-security-data-exchange.docx).

  1. Enabling authentication protocol to proceed into a secure communication mode, which means all types of AMP frames that need to be protected are encrypted and/or authenticated with a MIC after the full protocol finished successfully.
  2. Changing the AEAD cipher’s nonce input description from “uplink PN” and “downlink PN” to “uplink PN and uplink related information” and “downlink PN and downlink related information”, such that we do not need to indicate uplink/downlink using the MSB of PN, and more details could be included in “uplink related information” and “downlink related information” later.
  3. Adding GTK delivery.
  4. Removing the format-related description such as “AAD data starts from where to where, encrypted data is placed where, etc.”

Thanks and best regards,

Hui

 


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1


To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1

Attachment: 11-26-1552-08-00bp-pdt-amp-security-pmk-generation_GK.docx
Description: application/vnd.openxmlformats-officedocument.wordprocessingml.document