Re: Issue on eap-keying: PMK naming
From: Jari Arkko (jari.arkkopiuha.net)
Date: Mon, 4 Oct 2004 17:14:52 -0400 (EDT)
Florent Bersani wrote:
Description of issue: possible confusion between PMK naming and PMKID

Submitter name: Florent Bersani

Submitter email address: florent.bersani [at] francetelecom.com

Date first submitted: 10/04/2004

Document: Keying Framework

Comment type: 'E'ditorial

Priority: '1' Should fix

Section: 2.4 and 3.4.1

Rationale/Explanation of issue:

I find the following confusing. In section 2.4, I read

"PMK Name

      The PMK has no name of its own, and is only identified by the AAA-
      Key from which it is derived."

but in Section 3.4.1, I find "PMKID (security association identifier)"... so it seems to me that the PMK has no name but has an identifier (defined in clause 8.5.1.2 of IEEE 802.11i IIRC). I guess it could be worth clarifying this subtlety, wouldn't it?

Requested change

Would our 802.11i experts approve the following:
"PMK Name

The PMK may be named by its identifier PMKID defined in clause 8.5.1.2 of [IEEE80211i]."

I agree that the current text is confusing. On the other hand, there's a distinction between what the keying framework documents and what additional things may be done by link layers. Here's a slightly modified text suggestion:

PMK Name

    This document does not specify any naming scheme for the PMK.
    The PMK is only identified by the AAA-Key from which it is
    derived.

    Note: IEEE 802.11i names the PMKID for the purposes
    of being able to refer to it in the Secure Association
    protocol; this naming is based on a hash of the PMK itself
    as well as some other parameters (see Section 8.5.1.2 [ref]).

--Jari

Results generated by Tiger Technologies using MHonArc.