Appendix A WiMAX Security
User’s Guide
269
the network. In addition to the shared key, password information exchanged is
also encrypted to protect the network from unauthorized access.
Diameter
Diameter (RFC 3588) is a type of AAA server that provides several improvements
over RADIUS in efficiency, security, and support for roaming.
Security Association
The set of information about user authentication and data encryption between two
computers is known as a security association (SA). In a WiMAX network, the
process of security association has three stages.
• Authorization request and reply
The MS/SS presents its public certificate to the base station. The base station
verifies the certificate and sends an authentication key (AK) to the MS/SS.
• Key request and reply
The MS/SS requests a transport encryption key (TEK) which the base station
generates and encrypts using the authentication key.
• Encrypted traffic
The MS/SS decrypts the TEK (using the authentication key). Both stations can
now securely encrypt and decrypt the data flow.
CCMP
All traffic in a WiMAX network is encrypted using CCMP (Counter Mode with Cipher
Block Chaining Message Authentication Protocol). CCMP is based on the 128-bit
Advanced Encryption Standard (AES) algorithm.
‘Counter mode’ refers to the encryption of each block of plain text with an
arbitrary number, known as the counter. This number changes each time a block
of plain text is encrypted. Counter mode avoids the security weakness of repeated
identical blocks of encrypted text that makes encrypted data vulnerable to
pattern-spotting.
‘Cipher Block Chaining Message Authentication’ (also known as CBC-MAC) ensures
message integrity by encrypting each block of plain text in such a way that its
encryption is dependent on the block before it. This series of ‘chained’ blocks
creates a message authentication code (MAC or CMAC) that ensures the encrypted
data has not been tampered with.
Summary of Contents for MAX-306M1
Page 2: ......
Page 8: ...Safety Warnings User s Guide 8...
Page 10: ...Contents Overview User s Guide 10...
Page 24: ...List of Figures User s Guide 24...
Page 30: ...30...
Page 63: ...63 PART II Basic Screens The Main Screen 38 The Setup Screens 65...
Page 64: ...64...
Page 72: ...72...
Page 84: ...Chapter 7 The LAN Configuration Screens User s Guide 84...
Page 96: ...Chapter 8 The WAN Configuration Screens User s Guide 96...
Page 108: ...Chapter 9 The VPN Transport Screens User s Guide 108...
Page 118: ...Chapter 10 The NAT Configuration Screens User s Guide 118...
Page 130: ...130...
Page 148: ...Chapter 12 The Service Configuration Screens User s Guide 148...
Page 158: ...Chapter 13 The Phone Screens User s Guide 158...
Page 164: ...Chapter 14 The Phone Book Screens User s Guide 164...
Page 166: ...166...
Page 188: ...Chapter 15 The Certificates Screens User s Guide 188...
Page 198: ...Chapter 16 The Firewall Screens User s Guide 198...
Page 218: ...Chapter 19 QoS User s Guide 218...
Page 234: ...Chapter 20 The Logs Screens User s Guide 234...
Page 247: ...247 PART VI Troubleshooting and Specifications Troubleshooting 249 Product Specifications 257...
Page 248: ...248...
Page 256: ...Chapter 22 Troubleshooting User s Guide 256...
Page 264: ...Chapter 23 Product Specifications User s Guide 264...
Page 266: ...266...
Page 298: ...Appendix B Setting Up Your Computer s IP Address User s Guide 298...
Page 308: ...Appendix C Pop up Windows JavaScripts and Java Permissions User s Guide 308...
Page 352: ...Appendix E Importing Certificates User s Guide 352...
Page 354: ...Appendix F SIP Passthrough User s Guide 354...
Page 370: ...Appendix I Customer Support User s Guide 370...
Page 376: ...Index User s Guide 376...