Skip to main content

ISO/IEC/IEEE 8802-1AE:2020

Current Date published:

Telecommunications and exchange between information technology systems — Requirements for local and metropolitan area networks — Part 1AE: Media access control (MAC) security

This document specifies provision of connectionless user data confidentiality, frame data integrity, and data origin authenticity by media access independent protocols and entities that operate transparently to MAC Clients.

NOTE—The MAC Clients are as specified in IEEE Std 802®, IEEE Std 802.1Q?, and IEEE Std 802.1X.2

To this end, it

a) Specifies the requirements to be satisfied by equipment claiming conformance to this standard.

b) Specifies the requirements for MACsec in terms of provision of the MAC Service and the

preservation of the semantics and parameters of service requests and indications.

c) Describes the threats, both intentional and accidental, to correct provision of the service.

d) Specifies security services that prevent, or restrict, the effect of attacks that exploit these threats.

e) Examines the potential impact of both the threats and the use of MACsec on the Quality of Service

(QoS), specifying constraints on the design and operation of MAC Security entities and protocols.

f) Models support of the secure MAC Service in terms of the operation of media access control method

independent MAC Security Entities (SecYs) within the MAC Sublayer.

g) Specifies the format of the MACsec Protocol Data Unit (MPDUs) used to provide secure service.

h) Identifies the functions to be performed by each SecY, and provides an architectural model of its

internal operation in terms of Processes and Entities that provide those functions.

i) Specifies each SecY's use of an associated and collocated Port Access Entity (PAE,

IEEE Std 802.1X) to discover and authenticate MACsec protocol peers and its use of that PAE's

Key Agreement Entity (KaY) to agree and update cryptographic keys.

j) Specifies performance requirements and recommends default values and applicable ranges for the

operational parameters of a SecY.

k) Specifies how SecYs are incorporated within the architecture of end stations, bridges, and two-port

Ethernet Data Encryption devices (EDEs).

l) Establishes the requirements for management of MAC Security, identifying the managed objects

and defining the management operations for SecYs.

m) Specifies the Management Information Base (MIB) module for managing the operation of MAC

Security in TCP/IP networks.

n) Specifies requirements, criteria, and choices of Cipher Suites for use with this standard.

Get this standard Prices exclude GST
PDF ( Single user document)
$311.47 NZD
HardCopy
$311.47 NZD
Networkable PDF
Price varies
Preview only close
Prev {{ page }}/ {{ numPages }} Next
Preview only close
Prev {{ page }}/ {{ numPages }} Next

Keep me up-to-date

Sign up to receive updates when there are changes to this standard

Related Information

Similar Standards

  • BS EN 50173-3:2018

    Information technology. Generic cabling systems, Industrial spaces

  • BS EN 50173-3:2018 - TC

    Tracked Changes. Information technology. Generic cabling systems, Industrial spaces

  • BS EN 50173-6:2018

    Information technology. Generic cabling systems, Distributed building services

  • BS EN 50173-6:2018 - TC

    Tracked Changes. Information technology. Generic cabling systems, Distributed building services

Preview only close
Prev {{ page }}/ {{ numPages }} Next
Preview only close
Prev {{ page }}/ {{ numPages }} Next

ISO/IEC/IEEE 8802-1AE:2020

Get this standard Prices exclude GST
PDF ( Single user document)
$311.47 NZD
HardCopy
$311.47 NZD
Networkable PDF
Price varies

Request to add this standard to your subscription

ISO/IEC/IEEE 8802-1AE:2020

Price varies
Online library subscription

Click "Send request for subscription" to request for your Account Administrator to add this standard to your subscripiton.

Comment

Cancel