External DPSK RADIUS Attribute Value Pairs
The RADIUS Attribute Value Pairs (AVP) and Vendor Specific Attributes (VSA) used in
external DPSK generation are listed in the following table.
The following parameters are used in access-request messages.
Access-Request Message Parameters
| Parameter | AVP / VSA Name | Comment | |
|---|---|---|---|
| 1 | SSID | Ruckus-SSID | Since DPSK passphrases are bound to SSIDs, it's expected that AAA server will have the PMK lists indexed by SSID value. |
| 2 | MAC address of UE | User-Name | This AVP chosen for backward compatibility with MAC Authentication use case. The AAA server can override this value with a real (human or account) user-name when User-Name AVP is included in an Access-Accept or Access-Reject message. |
| 3 | BSSID of AP | Ruckus-BSSID | Note: the AAA Interface Document needs to be updated. Currently it states, "BSSID for each WLAN in each radio"; however, only a single BSSID (the one the client has associated with) is included in the VSA. |
| 4 | Anonce | Ruckus-DPSK-params | This is a new RUCKUS VSA, defined below. |
| 5 | Snonce | Ruckus-DPSK-params | The Snonce is parsed from the EAPOL Key Frame field of Ruckus-dpsk-params. |
| 6 | MIC | Ruckus-DPSK-params | The MIC is parsed from the EAPOL Key Frame field of Ruckus-dpsk-params. |
| 7 | 4WHS-M2 EAPOL Key frame | Ruckus-DPSK-params | The EAPOL-Key-Frame is used for the MIC calculation. |
| 8 | Cipher | Ruckus-DPSK-params | If the UE has negotiated TKIP-based encryption (this would be a really old device), then the key integrity algorithm is different than AES (Advance Encryption Standard, the encryption algorithm currently in use). In this case, AAA server also has to use the same algorithm as the UE in order to properly identify the PMK. TKIP is indicated according to the Cipher octet (see below). Note that two different integrity algorithms are used: HMAC-SHA1 ands HMAC-MD5. |
| 9 | AKM Suite | Ruckus-DPSK-params | The use of the AES key integrity and key hierarchy is indicated by the AKM Suite value. If the UE has negotiated FT encryption (FT - fast transition, aka 802.11r), generating the PTK from the PMK uses a different algorithm than AES. In this case, AAA server also has to use the same algorithm as the UE in order to properly identify the PMK. The AKM Suite value indicates whether FT is used. |
The following parameters are used in access-accept/access-reject messages.