ZyXEL MAX-200M1 Series User’s Guide
221
In order to ensure network security, the access point and the RADIUS server use a shared
secret key, which is a password they both know. The key is not sent over the network. In
addition to the shared key, password information exchanged is also encrypted to protect the
network from unauthorized access.
Diameter
Diameter (RFC 3588) is a type of AAA server that provides several improvements over
RADIUS in efficiency, security, and support for roaming.
Security Association
The set of information about user authentication and data encryption between two computers
is known as a security association (SA). In a WiMAX network, the process of security
association has three stages.
• Authorization request and reply
The MS/SS presents its public certificate to the base station. The base station verifies the
certificate and sends an authentication key (AK) to the MS/SS.
• Key request and reply
The MS/SS requests a transport encryption key (TEK) which the base station generates
and encrypts using the authentication key.
• Encrypted traffic
The MS/SS decrypts the TEK (using the authentication key). Both stations can now
securely encrypt and decrypt the data flow.
CCMP
All traffic in a WiMAX network is encrypted using CCMP (Counter Mode with Cipher Block
Chaining Message Authentication Protocol). CCMP is based on the 128-bit Advanced
Encryption Standard (AES) algorithm.
‘Counter mode’ refers to the encryption of each block of plain text with an arbitrary number,
known as the counter. This number changes each time a block of plain text is encrypted.
Counter mode avoids the security weakness of repeated identical blocks of encrypted text that
makes encrypted data vulnerable to pattern-spotting.
‘Cipher Block Chaining Message Authentication’ (also known as CBC-MAC) ensures
message integrity by encrypting each block of plain text in such a way that its encryption is
dependent on the block before it. This series of ‘chained’ blocks creates a message
authentication code (MAC or CMAC) that ensures the encrypted data has not been tampered
with.
Содержание MAX-200M1 Series
Страница 1: ...MAX 200M1 Series IEEE 802 16e Simple Indoor CPE User s Guide Version 3 60 04 2007 Edition 1...
Страница 2: ......
Страница 26: ...ZyXEL MAX 200M1 Series User s Guide 26 List of Tables...
Страница 40: ...ZyXEL MAX 200M1 Series User s Guide 40 Chapter 2 Introducing the Web Configurator...
Страница 48: ...ZyXEL MAX 200M1 Series User s Guide 48 Chapter 3 Tutorial...
Страница 54: ...ZyXEL MAX 200M1 Series User s Guide 54 Chapter 4 Internet Setup Wizard...
Страница 58: ...ZyXEL MAX 200M1 Series User s Guide 58 Chapter 5 VoIP Wizard...
Страница 82: ...ZyXEL MAX 200M1 Series User s Guide 82 Chapter 7 WAN Setup...
Страница 96: ...ZyXEL MAX 200M1 Series User s Guide 96 Chapter 8 LAN...
Страница 116: ...ZyXEL MAX 200M1 Series User s Guide 116 Chapter 10 SIP Figure 66 VoIP SIP SIP Settings Advanced...
Страница 130: ...ZyXEL MAX 200M1 Series User s Guide 130 Chapter 11 Phone...
Страница 144: ...ZyXEL MAX 200M1 Series User s Guide 144 Chapter 13 Phone Book...
Страница 148: ...ZyXEL MAX 200M1 Series User s Guide 148 Chapter 14 Content Filter...
Страница 152: ...ZyXEL MAX 200M1 Series User s Guide 152 Chapter 15 Static Route...
Страница 162: ...ZyXEL MAX 200M1 Series User s Guide 162 Chapter 16 Remote MGMT...
Страница 176: ...ZyXEL MAX 200M1 Series User s Guide 176 Chapter 17 UPnP...
Страница 218: ...ZyXEL MAX 200M1 Series User s Guide 218 Appendix A...
Страница 245: ...ZyXEL MAX 200M1 Series User s Guide Appendix D 245...
Страница 246: ...ZyXEL MAX 200M1 Series User s Guide 246 Appendix D...
Страница 248: ...ZyXEL MAX 200M1 Series User s Guide 248 Appendix E...
Страница 252: ...ZyXEL MAX 200M1 Series User s Guide 252 Appendix F...