External DPSK RADIUS Attribute Value Pairs

The RADIUS Attribute Value Pairs (AVP) and Vendor Specific Attributes (VSA) used in external DPSK generation are listed in the following table.

The following parameters are used in access-request messages.

Access-Request Message Parameters

  Parameter AVP / VSA Name Comment
1 SSID Ruckus-SSID Since DPSK passphrases are bound to SSIDs, it's expected that AAA server will have the PMK lists indexed by SSID value.
2 MAC address of UE User-Name This AVP chosen for backward compatibility with MAC Authentication use case. The AAA server can override this value with a real (human or account) user-name when User-Name AVP is included in an Access-Accept or Access-Reject message.
3 BSSID of AP Ruckus-BSSID Note: the AAA Interface Document needs to be updated. Currently it states, "BSSID for each WLAN in each radio"; however, only a single BSSID (the one the client has associated with) is included in the VSA.
4 Anonce Ruckus-DPSK-params This is a new RUCKUS VSA, defined below.
5 Snonce Ruckus-DPSK-params The Snonce is parsed from the EAPOL Key Frame field of Ruckus-dpsk-params.
6 MIC Ruckus-DPSK-params The MIC is parsed from the EAPOL Key Frame field of Ruckus-dpsk-params.
7 4WHS-M2 EAPOL Key frame Ruckus-DPSK-params The EAPOL-Key-Frame is used for the MIC calculation.
8 Cipher Ruckus-DPSK-params If the UE has negotiated TKIP-based encryption (this would be a really old device), then the key integrity algorithm is different than AES (Advance Encryption Standard, the encryption algorithm currently in use). In this case, AAA server also has to use the same algorithm as the UE in order to properly identify the PMK. TKIP is indicated according to the Cipher octet (see below). Note that two different integrity algorithms are used: HMAC-SHA1 ands HMAC-MD5.
9 AKM Suite Ruckus-DPSK-params The use of the AES key integrity and key hierarchy is indicated by the AKM Suite value. If the UE has negotiated FT encryption (FT - fast transition, aka 802.11r), generating the PTK from the PMK uses a different algorithm than AES. In this case, AAA server also has to use the same algorithm as the UE in order to properly identify the PMK. The AKM Suite value indicates whether FT is used.

The following parameters are used in access-accept/access-reject messages.

Access-accept/Access-reject Message Parameters

  Parameter RADIUS AVP or VSA name Mandatory / Optional Comment
1 MS-MPPE-Recv-Key MS-MPPE-Recv-Key Mandatory Included whenever the AAA server has found a matching PMK (for either bound or unbound case).
2 PMK-time Session-Timeout Mandatory Included whenever the AAA server has found a matching PMK, this is PMK expired time for the controller. Its range could be 0-14400 minutes.
3 User-name User-name Optional Included if admin desires the username to be included in syslog events generated by the controller.
4 VLAN assignment The following triplet of AVPs:
  1. Tunnel-Type
  2. Tunnel-Medium-Type
  3. Tunnel-Private-Group-Id
Optional Included if admin requires dynamic VLAN assignment. Note: the Tag field in all three AVPs is set to the same value (see RFC-2868 ).
  1. Tunnel-Type is set to the value "VLAN". Note: the AVP encodes this enumeration as an integer set to the value of 13 (see RFC-3580).
  2. Tunnel-Medium-Type is set to the string value of "802"
  3. Tunnel-Private-Group-Id is set to the value "<VLAN ID>". VLAN ID has a value between 1 and 4094 and is encoded as a string (see RFC-3580).
5 Ruckus-User-Groups Ruckus-User-Groups Optional Ruckus-User-Groups is used as Role of UE, It is the same as "Group Attributes " in ZD WebUI Configuration "Roles and Policies ".
6 Authorization reason Reply-message Optional Included if AAA server sends an Access-Accept in the workflow for DPSK passphrase renewal. When included, the ZD shall copy the contents of this AVP to the relevant syslog message (event ID 206 clientAuthorization).