You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: input/wlanclient.xml
+14-14Lines changed: 14 additions & 14 deletions
Original file line number
Diff line number
Diff line change
@@ -824,7 +824,7 @@
824
824
<selectable>PRF-704</selectable>
825
825
<selectableexclusive="yes">no other algorithm</selectable>
826
826
</selectables>
827
-
(as defined in IEEE 802.11-2012)</h:i>] and specified cryptographic key sizes [<h:i>256 bits</h:i>]
827
+
(as defined in IEEE 802.11-2020)</h:i>] and specified cryptographic key sizes [<h:i>256 bits</h:i>]
828
828
829
829
<!--
830
830
[<h:i><h:b>256 bits and
@@ -838,10 +838,10 @@
838
838
</title>
839
839
<noterole="application">
840
840
<h:p>
841
-
The cryptographic key derivation algorithm required by IEEE 802.11-2012
841
+
The cryptographic key derivation algorithm required by IEEE 802.11-2020
842
842
(Section 11.6.1.2) and verified in WPA2 certification is PRF-384, which uses the HMAC-SHA-1
843
843
function and outputs 384 bits. The use of GCMP was first defined in IEEE 802.11ac-2014 (Section
844
-
11.4.5) but subsequently integrated into 802.11-2012. This protocol requires a key derivation function (KDF)
844
+
11.4.5) but subsequently integrated into 802.11-2020. This protocol requires a key derivation function (KDF)
845
845
KDF based on HMAC-SHA-256 (for 128-bit symmetric keys) or HMAC-SHA384 (for 256-bit symmetric keys). This KDF outputs 704 bits.
846
846
</h:p><h:p>
847
847
This requirement applies only to the keys that are generated/derived for the communications
@@ -887,7 +887,7 @@ The cryptographic key derivation algorithm required by IEEE 802.11-2012
887
887
of the TOE and/or access point.
888
888
<h:br/>
889
889
Step 2: The evaluator shall configure the TOE to communicate with a WLAN access
890
-
point using IEEE 802.11-2012 and a 256-bit (64 hex values 0-f) pre-shared key. The
890
+
point using IEEE 802.11-2020 and a 256-bit (64 hex values 0-f) pre-shared key. The
891
891
pre-shared key is only used for testing.
892
892
<h:br/>
893
893
Step 3: The evaluator shall start the sniffing tool, initiate a connection between the
@@ -898,13 +898,13 @@ The cryptographic key derivation algorithm required by IEEE 802.11-2012
898
898
shall disconnect the TOE from the wireless network and stop the sniffer.
899
899
<h:br/>
900
900
Step 5: The evaluator shall identify the 4-way handshake frames (denoted EAPOL-key
901
-
in Wireshark captures) and derive the PTK from the 4-way handshake frames and pre-shared key as specified in IEEE 802.11-2012.
901
+
in Wireshark captures) and derive the PTK from the 4-way handshake frames and pre-shared key as specified in IEEE 802.11-2020.
902
902
<h:br/>
903
903
Step 6: The evaluator shall select the first data frame from the captured packets that
904
904
was sent between the TOE and access point after the 4-way handshake successfully
905
905
completed, and without the frame control value 0x4208 (the first 2 bytes are 08 42).
906
906
The evaluator shall use the PTK to decrypt the data portion of the packet as specified
907
-
in IEEE 802.11-2012, and shall verify that the decrypted data contains ASCII-readable
907
+
in IEEE 802.11-2020, and shall verify that the decrypted data contains ASCII-readable
908
908
text.
909
909
<h:br/>
910
910
Step 7: The evaluator shall repeat Step 6 for the next 2 data frames between the TOE
@@ -923,11 +923,11 @@ The cryptographic key derivation algorithm required by IEEE 802.11-2012
923
923
<consistency-rationale/>
924
924
<f-element>
925
925
<title>The TSF shall <h:b>decrypt Group Temporal Key</h:b> in accordance with a specified cryptographic key distribution method
926
-
[<h:i>AES Key Wrap (as defined in RFC 3394) in an EAPOL-Key frame (as defined in IEEE 802.11-2012 for the packet format and timing considerations</h:i>] <h:b>and does not expose the cryptographic keys</h:b>.
926
+
[<h:i>AES Key Wrap (as defined in RFC 3394) in an EAPOL-Key frame (as defined in IEEE 802.11-2020 for the packet format and timing considerations</h:i>] <h:b>and does not expose the cryptographic keys</h:b>.
927
927
</title>
928
928
<noterole="application">This requirement applies to the Group Temporal Key (GTK) that is received by
929
929
the TOE for use in decrypting broadcast and multicast messages from the access point to which
930
-
it's connected. 802.11-2012 specifies the format for the transfer as well as the fact that it must be wrapped by the AES Key Wrap method specified in RFC 3394; the TOE must be capable of
930
+
it's connected. 802.11-2020 specifies the format for the transfer as well as the fact that it must be wrapped by the AES Key Wrap method specified in RFC 3394; the TOE must be capable of
931
931
unwrapping such keys.
932
932
</note>
933
933
@@ -949,7 +949,7 @@ The cryptographic key derivation algorithm required by IEEE 802.11-2012
949
949
sniffer should also be configured to filter on the MAC address of the TOE and/or access point.
950
950
<h:br/><h:br/>
951
951
Step 2: The evaluator shall configure the TOE to communicate with the access point using IEEE
952
-
802.11-2012 and a 256-bit (64 hex values 0-f) pre-shared key, setting up the connections as
952
+
802.11-2020 and a 256-bit (64 hex values 0-f) pre-shared key, setting up the connections as
953
953
described in the operational guidance. The pre-shared key is only used for testing.
954
954
<h:br/><h:br/>
955
955
Step 3: The evaluator shall start the sniffing tool, initiate a connection between the TOE and
@@ -960,12 +960,12 @@ The cryptographic key derivation algorithm required by IEEE 802.11-2012
960
960
disconnect the TOE from the access point and stop the sniffer.
961
961
<h:br/><h:br/>
962
962
Step 5: The evaluator shall identify the 4-way handshake frames (denoted EAPOL-key in
963
-
Wireshark captures) and derive the PTK and GTK from the 4-way handshake frames and pre-shared key as specified in IEEE 802.11-2012.
963
+
Wireshark captures) and derive the PTK and GTK from the 4-way handshake frames and pre-shared key as specified in IEEE 802.11-2020.
964
964
<h:br/><h:br/>
965
965
Step 6: The evaluator shall select the first data frame from the captured packets that was sent
966
966
between the TOE and access point after the 4-way handshake successfully completed, and with
967
967
the frame control value 0x4208 (the first 2 bytes are 08 42). The evaluator shall use the GTK to
968
-
decrypt the data portion of the selected packet as specified in IEEE 802.11-2012, and shall verify
968
+
decrypt the data portion of the selected packet as specified in IEEE 802.11-2020, and shall verify
969
969
that the decrypted data contains ASCII-readable text.
970
970
<h:br/><h:br/>
971
971
Step 7: The evaluator shall repeat Step 6 for the next 2 data frames with frame control value
@@ -1877,7 +1877,7 @@ The cryptographic key derivation algorithm required by IEEE 802.11-2012
1877
1877
<f-componentid="fco-trusted-comms-wlan"cc-id="ftp_itc.1"name="Trusted Channel Communication (Wireless LAN)"iteration="WLAN">
1878
1878
<consistency-rationale/>
1879
1879
<f-element>
1880
-
<title>The TSF shall <h:b>use 802.11-2012, 802.1X, and EAP-TLS</h:b> to provide a
1880
+
<title>The TSF shall <h:b>use 802.11-2020, 802.1X, and EAP-TLS</h:b> to provide a
1881
1881
<h:b>trusted</h:b> communication channel between itself and <h:b>a wireless access point</h:b> that is logically
1882
1882
distinct from other communication channels and provides assured identification of its end points
1883
1883
and protection of the channel data from modification or disclosure.
@@ -2255,9 +2255,9 @@ The cryptographic key derivation algorithm required by IEEE 802.11-2012
2255
2255
Profile for Mobile Device Fundamentals, Version 4.0</h:a>, September 12, 2022 <comment>Adjust date when published.</comment></description>
2256
2256
</entry>
2257
2257
<entryid="bib80211">
2258
-
<tag>802.11-2012</tag>
2258
+
<tag>802.11-2020</tag>
2259
2259
<description><h:a
2260
-
href="https://ieeexplore.ieee.org/document/9363693">802.11-2012 - IEEE Standard for Information technology—Telecommunications and information exchange between systems Local and metropolitan area networks—Specific requirements -
2260
+
href="https://ieeexplore.ieee.org/document/9363693">802.11-2020 - IEEE Standard for Information technology—Telecommunications and information exchange between systems Local and metropolitan area networks—Specific requirements -
2261
2261
Part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications</h:a></description>
0 commit comments