Wednesday, 31 October 2012

0 Wimax PKM in WiMAX Technology

PKM (Privacy Key Management) Protocol in WiMAX Technology

Wimax CPE (Customer Premise Equipment) make use of the Privacy Key Management (PKM) Protocol to gain authorization and traffic keying material from the Wimax Base Station (BS), and to maintain periodic reauthorization and key refresh. The Privacy Key Management (PKM) protocol uses X.509 digital certificates, and two-key triple Data Encryption Standard (DES) to secure key exchanges between a given Wimax CPE (Customer Premise Equipment) andWimax Base Station (BS), following the client-server model. Here, the Wimax CPE (Customer Premise Equipment) as the client requests keying material while the Wimax Base Station (BS) as the server act in response to those requests, ensuring individual Wimax CPE (Customer Premise Equipment) clients receive only the keying material for which they are authorized. The Privacy Key Management (PKM) Protocol first creates an Authorization Key (AK), which is a secret symmetric key shared between the Wimax CPE (Customer Premise Equipment) and BS. The AK is then used to protect subsequent Privacy Key Management (PKM) Protocol exchanges of Traffic Encryption Keys (TEK). The use of the AK and a symmetric key cryptosystem reduces the overhead due to the computationally expensive public key functions. (Sen Xu, Chin-Tser Huang)
 
Wimax Base Station (BS) authenticates a Wimax CPE (Customer Premise Equipment) during the primary authorization exchange. The Wimax CPE (Customer Premise Equipment) device certificate would enclose the RSA public key and other device specific information, such as its MAC address, serial number, and manufacturer ID. Within the authorization exchange, the Wimax CPE (Customer Premise Equipment) would then send a copy of this device certificate to the Wimax Base Station (BS). The Wimax Base Station (BS) must then authenticate the syntax and information in the Wimax CPE (Customer Premise Equipment) certificate, and possibly carry out certificate path validation checks. If properly verified, the Wimax Base Station (BS) as part of its replies to the Wimax CPE (Customer Premise Equipment) would encrypt the Authorization Key (AK) using the public key of the Wimax CPE (Customer Premise Equipment) that could be found within the received certificate from the Subscriber station. Since only the Wimax CPE (Customer Premise Equipment) device contains the matching private key, only the Wimax CPE (Customer Premise Equipment) device can de-crypt the message and obtain the AK assigned to it. (Sen Xu, Chin-Tser Huang)

0 comments:

Post a Comment

 

Our Technology For ever
Created By K.seetha rama raju
Powered by blogger