
Appendix A WiMAX Security
User’s Guide
281
the network. In addition to the shared key, password information exchanged is
also encrypted to protect the network from unauthorized access.
Diameter
Diameter (RFC 3588) is a type of AAA server that provides several improvements
over RADIUS in efficiency, security, and support for roaming.
Security Association
The set of information about user authentication and data encryption between two
computers is known as a security association (SA). In a WiMAX network, the
process of security association has three stages.
• Authorization request and reply
The MS/SS presents its public certificate to the base station. The base station
verifies the certificate and sends an authentication key (AK) to the MS/SS.
• Key request and reply
The MS/SS requests a transport encryption key (TEK) which the base station
generates and encrypts using the authentication key.
• Encrypted traffic
The MS/SS decrypts the TEK (using the authentication key). Both stations can
now securely encrypt and decrypt the data flow.
CCMP
All traffic in a WiMAX network is encrypted using CCMP (Counter Mode with Cipher
Block Chaining Message Authentication Protocol). CCMP is based on the 128-bit
Advanced Encryption Standard (AES) algorithm.
‘Counter mode’ refers to the encryption of each block of plain text with an
arbitrary number, known as the counter. This number changes each time a block
of plain text is encrypted. Counter mode avoids the security weakness of repeated
identical blocks of encrypted text that makes encrypted data vulnerable to
pattern-spotting.
‘Cipher Block Chaining Message Authentication’ (also known as CBC-MAC) ensures
message integrity by encrypting each block of plain text in such a way that its
encryption is dependent on the block before it. This series of ‘chained’ blocks
creates a message authentication code (MAC or CMAC) that ensures the encrypted
data has not been tampered with.
Содержание MAX-306
Страница 2: ......
Страница 8: ...Safety Warnings User s Guide 8...
Страница 10: ...Contents Overview User s Guide 10...
Страница 30: ...30...
Страница 36: ...Chapter 1 Getting Started User s Guide 36...
Страница 46: ...Chapter 2 Introducing the Web Configurator User s Guide 46...
Страница 64: ...Chapter 4 VoIP Connection Wizard User s Guide 64...
Страница 65: ...65 PART II Basic Screens The Main Screen 40 The Setup Screens 67...
Страница 66: ...66...
Страница 74: ...74...
Страница 88: ...Chapter 6 The LAN Configuration Screens User s Guide 88...
Страница 112: ...Chapter 8 The Wi Fi Configuration Screens User s Guide 112...
Страница 134: ...Chapter 10 The NAT Configuration Screens User s Guide 134...
Страница 145: ...145 PART IV Voice Screens The Service Configuration Screens 147 The Phone Screens 165 The Phone Book Screens 175...
Страница 146: ...146...
Страница 164: ...Chapter 12 The Service Configuration Screens User s Guide 164...
Страница 180: ...Chapter 14 The Phone Book Screens User s Guide 180...
Страница 182: ...182...
Страница 202: ...Chapter 15 The Certificates Screens User s Guide 202...
Страница 212: ...Chapter 16 The Firewall Screens User s Guide 212...
Страница 226: ...Chapter 18 The Remote Management Screens User s Guide 226...
Страница 242: ...Chapter 19 The Logs Screens User s Guide 242...
Страница 252: ...Chapter 20 The UPnP Screen User s Guide 252...
Страница 265: ...265 PART VI Troubleshooting and Specifications Troubleshooting 267 Product Specifications 275...
Страница 266: ...266...
Страница 274: ...Chapter 22 Troubleshooting User s Guide 274...
Страница 278: ...278...
Страница 310: ...Appendix B Setting Up Your Computer s IP Address User s Guide 310...
Страница 336: ...Appendix D Pop up Windows JavaScripts and Java Permissions User s Guide 336...
Страница 380: ...Appendix F Importing Certificates User s Guide 380...
Страница 382: ...Appendix G SIP Passthrough User s Guide 382...
Страница 398: ...Appendix J Customer Support User s Guide 398...
Страница 405: ...Index User s Guide 405...