DCN: sec Title: Option III: EAP to conduct service authentication and MIH packet protection (Summary) Date Submitted: August 31, 2010 Present at IEEE meeting in August teleconference Authors or Source(s): Fernando Bernal, Rafa Marín-López Abstract: Summary of document sec .

Comment [LLC6]: Are these the same random numbers as used in MI-PMK derivation? They should not be? Response [LLC6]: Yes, they are the same random numbers to generate MIIK and MIEK. NOTE: The MI-PMK has been removed from the key hierarchy for simplicity. MSK or rMSK MIIK MIEK Using the MSK or rMSK provided by the EAP authentication other session keys are derived: MIIK, this key is used to provide integrity protection to the MIH protocol. MIEK, used to provide confidentiality to the MIH protocol by encrypting MIH data.

Comment [LLC9]: We need to discuss what algorithms will be used for MIH message protection and how the data is protected… Confidentiality algorithms Reference ENCR_DES_IV64 RFC1827 ENCR_DES RFC2405 ENCR_3DES RFC2451 ENCR_RC5 ENCR_IDEA ENCR_CAST ENCR_BLOWFISH ENCR_3IDEA ENCR_DES_IV32 RFC2410 ENCR_AES_CBC RFC3602 ENCR_AES_CTR RFC3664 ENCR_NULL Confidentiality and Integrity algorithms ENCR_INTR_AES_CCM Integrity algorithms Reference INTR_HMAC_MD5_96 RFC2403 INTR_HMAC_SHA1_96 RFC2404 INTR_KPDK_MD5 RFC1826 INTR_DES_MAC INTR_AES_XCBC_96 RFC3566 INTR_NULL KDF algorithms Reference PRF_HMAC_MD5 RFC2104 PRF_HMAC_SHA1 PRF_HMAC_SHA256 PRF_HMAC_TIGER PRF_AES128_XCBC RFC3664

9 Bundle option WI#1 option B

10 Key Hierarchy Comment [LLC6]: Are these the same random numbers as used in MI-PMK derivation? They should not be? Response [LLC6]: Yes, they are the same random numbers to generate MIIK and MIEK. The MS-ROOT has been added to the key hierarchy as root key for deriving MS-PMKs.

