Aps Layer Security - Digi XBee-PRO S2C Zigbee User Manual

Rf module
Hide thumbs Also See for XBee-PRO S2C Zigbee:
Table of Contents

Advertisement

Zigbee security
Frame counter
The network header of encrypted packets includes a 32-bit frame counter. Each device in the network
maintains a 32-bit frame counter that increments for every transmission. In addition, devices track
the last known 32-bit frame counter for each of its neighbors. If a device receives a packet from a
neighbor with a smaller frame counter than previously seen, it discards the packet. The device uses
the frame counter to protect against replay attacks.
If the frame counter reaches a maximum value of 0xFFFFFFFF, it does not wrap to 0 and cannot send
any more transmissions. Due to the size of the frame counters, reaching the maximum value is
uncommon for most applications. The following table shows the required time for the frame counter
to reach its maximum value.
Average Transmission Rate
1 / second
10 / second
To clear the frame counters without compromising security, you can change the network key in the
network. When the network key is updated, the frame counters on all devices reset to 0. See
key updates
for details.
Message integrity code
The network header, APS header, and application data are all authenticated with 128-bit AES. The
device performs a hash on these fields and is appended as a 4-byte message integrity code (MIC) to
the end of the packet. The MIC allows receiving devices to ensure the message has not been changed.
The MIC provides message integrity in the Zigbee security model. If a device receives a packet and the
MIC does not match the device's own hash of the data, it drops the packet.
Network layer encryption and decryption
Packets with network layer encryption are encrypted and decrypted by each hop in a route. When a
device receives a packet with network encryption, it decrypts the packet and authenticates the
packet. If the device is not the destination, it then encrypts and authenticates the packet, using its
own frame counter and source address in the network header section.
Since the device performs network encryption at each hop, packet latency is slightly longer in an
encrypted network than in a non-encrypted network. Also, security requires 18 bytes of overhead to
include a 32-bit frame counter, an 8-byte source address, 4-byte MIC, and 2 other bytes. This reduces
the number of payload bytes that can be sent in a data packet.
Network key updates
Zigbee supports a mechanism for changing the network key in a network. When the network key is
changed, the frame counters in all devices reset to 0.

APS layer security

APS layer security can be used to encrypt application data using a key that is shared between source
and destination devices. Where network layer security is applied to all data transmissions and is
decrypted and reencrypted on a hop-by-hop basis, APS security is optional and provides end-to-end
security using an APS link key known by only the source and destination device. APS security cannot
be applied to broadcast transmissions.
XBee/XBee-PRO® S2C Zigbee® RF Module
Time until 32-bit frame counter expires
136 years
13.6 years
Zigbee security model
Network
103

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the XBee-PRO S2C Zigbee and is the answer not in the manual?

This manual is also suitable for:

Xbee s2c zigbee

Table of Contents