03.11.2012 Views

Medium Access Control (MAC) and Physical Layer (PHY) - CISE

Medium Access Control (MAC) and Physical Layer (PHY) - CISE

Medium Access Control (MAC) and Physical Layer (PHY) - CISE

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4-June-07 P1901_PRO_016_r0<br />

Figure 146: Encryption <strong>and</strong> Integrity process for all but the first packet<br />

The MIC is computed in both cases using CBC-<strong>MAC</strong>, which encrypts a starting block B0 <strong>and</strong> then successively<br />

XORs subsequent blocks <strong>and</strong> encrypts the result. Although the result is a MIC of 128 bits, the lower 96 bits are<br />

discarded, <strong>and</strong> a final 32-bit MIC is obtained.<br />

Once the MIC has been computed <strong>and</strong> appended to the plaintext data, the encryption takes place using Counter<br />

Mode (CTR).<br />

10.2 AAA protocol<br />

In section 9.1.3 the access method used in IEEE P1901 has been described. Nevertheless, for the sake of security,<br />

section 9.1.3 is to be complemented with the AAA protocol that is described in the present section.<br />

The access <strong>and</strong> authentication control system of IEEE P1901 follows closely the one described in IEEE802.1X<br />

which in turn relies on the Extensible Authentication Protocol (EAP) [RFC3748] over LAN (EAPOL). IEEE802.1X<br />

provides the description of EAPOL.<br />

The purpose of IEEE 802.1X is to implement access control at the point at which a user joins the network. In the<br />

process of application of IEEE 802.1X the network entities can take one of three roles: Supplicant, Authenticator<br />

<strong>and</strong> Authentication Server (AS).<br />

The device asking for connection to the network is known as the Supplicant <strong>and</strong> in IEEE P1901 can be either a CPE<br />

or a TDR. The Authenticator can be either the HE or a TDR. The Authentication Server will normally be<br />

centralized.<br />

The IEEE 802.1X access control mechanisms apply to the association between a CPE or TDR <strong>and</strong> a Master.<br />

Submission page 286 UPA-OPERA

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!