Wi-Fi CERTIFIED WPA3 Test Plan Version 3.2
评分(0)
- 分类:无线资料 - 工程安装测试
- 浏览:30 次
- 下载:1 次
- 大小:3.8 MB
- 下载消耗: 10 金币
- 时间:2026-07-29
详细内容
Table of contents
1 OVERVIEW 12
1.1 Scope and purpose 12
1.2 Definition of devices under test 12
1.3 References 16
1.4 Acronyms and definitions 17
1.4.1 Acronyms and abbreviations. 17
1.4.2 Definitions 19
2 TEST TOOLS, METHODOLOGY AND APPROACH 21
2.1 Sniffer 21
2.2 Wi-Fi Test Suite software 21
2.3 QuickTrack Test Tool software 21
2.4 Basic system test configuration 21
2.5 Test bed capability requirements 23
2.5.1 CTT/Test bed AP requirements 23
2.5.2 CTT/Test bed STA requirements 25
2.6 AAA server 27
3 REQUIREMENTS FOR WI-FI ALLIANCE CERTIFICATION 28
3.1 General requirements. 28
3.1.1 Prerequisite certification requirements 28
3.1.2 Wi-Fi CERTIFIED WPA3 testing requirements. 28
3.1.2.1 WPA3-Personal testing requirements 28
3.1.2.2 WPA3-Enterprise testing requirements 29
3.2 Applicability of tests 29
3.2.1 APUT test applicability 30
3.2.2 STAUT test applicability 37
3.3 Configuration requirements 49
3.3.1 APUT configuration requirements 50
3.3.2 STAUT configuration requirements. 51
3.4 Testing rules. 52
4 WPA3-PERSONAL APUT TESTS. 53
4.1 APUT configuration requirements validation test 53
4.2 APUT SAE tests 54
4.2.1 APUT initial connectivity test 54
4.2.2 APUT connectivity and PMK caching test. 57
4.2.3 APUT Anti-clogging test 59
4.2.4 APUT WPA3-Personal transition test 62
4.2.5 APUT support for additional finite cyclic groups test. 64
4.2.6 APUT negative test 66
4.2.7 APUT WPA3-Personal transition negative test 69
4.2.8 APUT correct handling of PMKID during initial SAE association test
4.3 APUT rejecting unsuitable Diffie-Hellman groups for SAE tests 73
4.4 APUT H2E tests 75
4.4.1 APUT support H2E only mode test 75
4.4.2 APUT accepts SAE Commit message with Rejected Groups element test 77
4.4.3 APUT rejects SAE Commit message with Rejected Groups element test 80
4.4.4 APUT aborts 4-way handshake with RSNXE mismatch test 82
4.5 Reserved for future use 84
4.6 APUT SAE Transition Disable tests 84
4.6.1 APUT SAE Transition Disable test 84
4.7 APUT SAE-PK tests 86
4.7.1 APUT SAE-PK connectivity and PMK caching test 86
5 WPA3-PERSONAL STAUT TESTS 91
5.1 STAUT configuration requirements validation test. 91
5.2 STAUT SAE tests. 92
5.2.1 STAUT SAE connectivity and PMK caching test 92
5.2.2 STAUT Anti-clogging test 95
5.2.3 STAUT reflection attack test 97
5.2.4 STAUT WPA2-Personal compatibility test 99
5.2.5 STAUT support for additional finite cyclic groups test 101
5.2.6 STAUT negative test 103
5.2.7 STAUT SAE confirmation exchange variation test 106
5.3 STAUT does not request unsuitable Diffie-Hellman groups for SAE test 109
5.4 STAUT H2E tests 110
5.4.1 STAUT Rejected Groups element test 110
5.4.2 STAUT aborts 4-way handshake with RSNXE mismatch test 112
5.5 Reserved for future Use 115
5.6 STAUT SAE Transition Disable tests. 115
5.6.1 STAUT SAE Transition Disable test 115
5.7 STAUT SAE-PK tests. 117
5.7.1 STAUT SAE-PK connectivity and PMK caching test 117
5.7.2 STAUT SAE-PK validation failure test 121
5.7.3 STAUT SAE-PK downgrade mitigation test 124
5.7.4 STAUT SAE-PK password not in correct form or incorrect Sec encoding test 127
6 RESERVED FOR FUTURE USE 131
7 RESERVED FOR FUTURE USE 132
8 WPA3 FAST BSS TRANSITION APUT TESTS 133
8.1 CTT STA Roam from APUT to AP1 and back 133
8.2 CTT STA Roam from AP1 to APUT and back 141
8.3 APUT Interop with CTT STA that has H2E disabled 148
9 WPA3 FAST BSS TRANSITION STAUT TESTS 157
9.1 STAUT Roam from CTT AP1 to AP2 and back 157
9.2 STAUT Interop with CTT AP that has H2E disabled.
9.3 STAUT with CTT AP that sends mismatched RSNXE contents 170
10 RESERVED FOR FUTURE USE 176
11 WPA3-ENTERPRISE SERVER CERTIFICATE VALIDATION STAUT TEST CASES. 177
11.1 STAUT server certificate validation test 177
11.2 STAUT server certificate configuration requirements test 185
12 WPA3-PERSONAL BEACON PROTECTION APUT TESTS 188
12.1 APUT Capability Advertisement test 188
12.2 APUT BIGTK Distribution in 4-way test 189
12.3 APUT MMIC IE in Beacon frames with BIP-CMAC-128 test 191
12.4 APUT BIGTK rotation test 193
13 WPA3-PERSONAL BEACON PROTECTION STAUT TESTS 196
13.1 STAUT MMIC IE in Beacon Validation test 196
13.2 STAUT BIPN replay checking test 198
13.3 STAUT key rotation test 201
14 WPA3-PERSONAL OPERATING CHANNEL VALIDATION APUT TESTS 204
14.1 APUT OCVC advertisement in RSNE in Beacon frames and interop with non-OCVC STAs test. 204
14.2 APUT OCI KDE in 4-way handshake test 206
14.3 APUT OCI KDE validation in group key handshake test 208
14.4 APUT inclusion of OCI in SA Query request and validation of SA Query Response test 211
14.5 APUT OCI STA validation on channel switch test 214
14.6 APUT FTE OCI subelement validation in association request and inclusion in association response test and compatibility with non-OCVC STA 217
15 WPA3-PERSONAL OPERATING CHANNEL VALIDATION STAUT TESTS 221
15.1 STAUT OCI KDE in 4-way handshake, inclusion in M2 and Validation of M3 test 221
15.2 STAUT OCI KDE validation in M1 of the group key handshake test 224
15.3 STAUT inclusion of OCI in SA Query request and validation of SA Query response test 226
15.4 STAUT OCI STA SA Query on channel switch test 229
15.5 STAUT OCVC in RSNE, FTE OCI subelement in association request and validation in association response test and compatibility with non-OCVC AP test 231
16 RESERVED FOR FUTURE USE 236
17 WPA3-PERSONAL PRIVACY EXTENSIONS STAUT TESTS 237
17.1 STAUT construction of a uniquely randomized source MAC address per SSID test 237
17.2 STAUT construction of a randomized source MAC address per Active Scan test 239
17.3 STAUT construction of a randomized source MAC address for each ANQP exchange test 240
18 WPA3-ENTERPRISE 192-BIT SECURITY APUT TESTS 243
18.1 APUT 192-bit configuration requirements validation tests 243
18.1.1 APUT configuration requirements validation for 192-bit security on a BSSID with IPv4 test 243
18.1.2 APUT configuration requirements validation for 192-bit security on a BSSID with IPv6 test 244
18.2 APUT 192-bit security initial configuration tests. 245
18.2.1 APUT correct IE advertisement for 192-bit security test
18.3 APUT 192-bit security ECC p384 tests 246
18.3.1 APUT IPv4 connectivity using 192-bit security ECC p384 test 246
18.3.2 APUT IPv6 connectivity using 192-bit security ECC p384 test 248
18.4 APUT 192-bit security RSA 3K and TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 cipher tests 250
18.4.1 APUT IPv4 connectivity using 192-bit security RSA 3K and TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 cipher test 250
18.4.2 APUT IPv6 connectivity using 192-bit security RSA 3K and TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 cipher test 252
18.5 APUT 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 tests 254
18.5.1 APUT IPv4 connectivity using 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test. 254
18.5.2 APUT IPv6 connectivity using 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test. 256
18.6 APUT 192-bit security conformance tests 259
18.6.1 APUT response to an incorrect RSNE received from the STA test 259
18.6.2 APUT response to STA incorrect TLS authentication parameters test 261
18.7 APUT 192-bit security PMK caching 264
18.7.1 APUT 192-bit security PMK caching test 264
19 WPA3-ENTERPRISE 192-BIT SECURITY STAUT TESTS 267
19.1 STAUT 192-bit security configuration requirements validation test 267
19.1.1 STAUT configuration requirements validation for 192-bit security on a BSSID test 267
19.2 STAUT 192-bit security ECC p384 tests 268
19.2.1 STAUT IPv4 connectivity using 192-bit security ECC p384 test 268
19.2.2 STAUT IPv6 connectivity using 192-bit security ECC p384 test 270
19.3 STAUT 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test 272
19.3.1 STAUT IPv4 connectivity test using 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test 272
19.3.2 STAUT IPv6 connectivity using 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test 274
19.4 STAUT 192-bit security RSA 3K and TLS_DHE_RSA_AES_256_GCM_SHA384 cipher tests 277
19.4.1 STAUT IPv4 connectivity using 192-bit security RSA 3K and TLS_DHE_RSA_AES_256_GCM_SHA384 cipher test 277
19.4.2 STAUT IPv6 connectivity using 192-bit security RSA 3K and TLS_DHE_RSA_AES_256_GCM_SHA384 cipher test 279
19.5 STAUT 192-bit security conformance tests 281
19.5.1 STAUT response to incorrect RSNE received from AP test 281
19.5.2 STAUT response to AAA server TLS authentication parameters test 284
19.6 STAUT 192-bit security PMK caching tests 288
19.6.1 STAUT 192-bit security PMK caching test 288
APPENDIX A TEST BED PRODUCTS. 292
A.1 Approved test bed vendors 292
A.2 Approved test bed equipment 292
APPENDIX B CTT STA VALIDATION 297
B.1 CTT STA Validation for BIP MIC /Replay Error counter test 297
APPENDIX C (INFORMATIVE) DOCUMENT REVISION HISTORY
1 OVERVIEW 12
1.1 Scope and purpose 12
1.2 Definition of devices under test 12
1.3 References 16
1.4 Acronyms and definitions 17
1.4.1 Acronyms and abbreviations. 17
1.4.2 Definitions 19
2 TEST TOOLS, METHODOLOGY AND APPROACH 21
2.1 Sniffer 21
2.2 Wi-Fi Test Suite software 21
2.3 QuickTrack Test Tool software 21
2.4 Basic system test configuration 21
2.5 Test bed capability requirements 23
2.5.1 CTT/Test bed AP requirements 23
2.5.2 CTT/Test bed STA requirements 25
2.6 AAA server 27
3 REQUIREMENTS FOR WI-FI ALLIANCE CERTIFICATION 28
3.1 General requirements. 28
3.1.1 Prerequisite certification requirements 28
3.1.2 Wi-Fi CERTIFIED WPA3 testing requirements. 28
3.1.2.1 WPA3-Personal testing requirements 28
3.1.2.2 WPA3-Enterprise testing requirements 29
3.2 Applicability of tests 29
3.2.1 APUT test applicability 30
3.2.2 STAUT test applicability 37
3.3 Configuration requirements 49
3.3.1 APUT configuration requirements 50
3.3.2 STAUT configuration requirements. 51
3.4 Testing rules. 52
4 WPA3-PERSONAL APUT TESTS. 53
4.1 APUT configuration requirements validation test 53
4.2 APUT SAE tests 54
4.2.1 APUT initial connectivity test 54
4.2.2 APUT connectivity and PMK caching test. 57
4.2.3 APUT Anti-clogging test 59
4.2.4 APUT WPA3-Personal transition test 62
4.2.5 APUT support for additional finite cyclic groups test. 64
4.2.6 APUT negative test 66
4.2.7 APUT WPA3-Personal transition negative test 69
4.2.8 APUT correct handling of PMKID during initial SAE association test
4.3 APUT rejecting unsuitable Diffie-Hellman groups for SAE tests 73
4.4 APUT H2E tests 75
4.4.1 APUT support H2E only mode test 75
4.4.2 APUT accepts SAE Commit message with Rejected Groups element test 77
4.4.3 APUT rejects SAE Commit message with Rejected Groups element test 80
4.4.4 APUT aborts 4-way handshake with RSNXE mismatch test 82
4.5 Reserved for future use 84
4.6 APUT SAE Transition Disable tests 84
4.6.1 APUT SAE Transition Disable test 84
4.7 APUT SAE-PK tests 86
4.7.1 APUT SAE-PK connectivity and PMK caching test 86
5 WPA3-PERSONAL STAUT TESTS 91
5.1 STAUT configuration requirements validation test. 91
5.2 STAUT SAE tests. 92
5.2.1 STAUT SAE connectivity and PMK caching test 92
5.2.2 STAUT Anti-clogging test 95
5.2.3 STAUT reflection attack test 97
5.2.4 STAUT WPA2-Personal compatibility test 99
5.2.5 STAUT support for additional finite cyclic groups test 101
5.2.6 STAUT negative test 103
5.2.7 STAUT SAE confirmation exchange variation test 106
5.3 STAUT does not request unsuitable Diffie-Hellman groups for SAE test 109
5.4 STAUT H2E tests 110
5.4.1 STAUT Rejected Groups element test 110
5.4.2 STAUT aborts 4-way handshake with RSNXE mismatch test 112
5.5 Reserved for future Use 115
5.6 STAUT SAE Transition Disable tests. 115
5.6.1 STAUT SAE Transition Disable test 115
5.7 STAUT SAE-PK tests. 117
5.7.1 STAUT SAE-PK connectivity and PMK caching test 117
5.7.2 STAUT SAE-PK validation failure test 121
5.7.3 STAUT SAE-PK downgrade mitigation test 124
5.7.4 STAUT SAE-PK password not in correct form or incorrect Sec encoding test 127
6 RESERVED FOR FUTURE USE 131
7 RESERVED FOR FUTURE USE 132
8 WPA3 FAST BSS TRANSITION APUT TESTS 133
8.1 CTT STA Roam from APUT to AP1 and back 133
8.2 CTT STA Roam from AP1 to APUT and back 141
8.3 APUT Interop with CTT STA that has H2E disabled 148
9 WPA3 FAST BSS TRANSITION STAUT TESTS 157
9.1 STAUT Roam from CTT AP1 to AP2 and back 157
9.2 STAUT Interop with CTT AP that has H2E disabled.
9.3 STAUT with CTT AP that sends mismatched RSNXE contents 170
10 RESERVED FOR FUTURE USE 176
11 WPA3-ENTERPRISE SERVER CERTIFICATE VALIDATION STAUT TEST CASES. 177
11.1 STAUT server certificate validation test 177
11.2 STAUT server certificate configuration requirements test 185
12 WPA3-PERSONAL BEACON PROTECTION APUT TESTS 188
12.1 APUT Capability Advertisement test 188
12.2 APUT BIGTK Distribution in 4-way test 189
12.3 APUT MMIC IE in Beacon frames with BIP-CMAC-128 test 191
12.4 APUT BIGTK rotation test 193
13 WPA3-PERSONAL BEACON PROTECTION STAUT TESTS 196
13.1 STAUT MMIC IE in Beacon Validation test 196
13.2 STAUT BIPN replay checking test 198
13.3 STAUT key rotation test 201
14 WPA3-PERSONAL OPERATING CHANNEL VALIDATION APUT TESTS 204
14.1 APUT OCVC advertisement in RSNE in Beacon frames and interop with non-OCVC STAs test. 204
14.2 APUT OCI KDE in 4-way handshake test 206
14.3 APUT OCI KDE validation in group key handshake test 208
14.4 APUT inclusion of OCI in SA Query request and validation of SA Query Response test 211
14.5 APUT OCI STA validation on channel switch test 214
14.6 APUT FTE OCI subelement validation in association request and inclusion in association response test and compatibility with non-OCVC STA 217
15 WPA3-PERSONAL OPERATING CHANNEL VALIDATION STAUT TESTS 221
15.1 STAUT OCI KDE in 4-way handshake, inclusion in M2 and Validation of M3 test 221
15.2 STAUT OCI KDE validation in M1 of the group key handshake test 224
15.3 STAUT inclusion of OCI in SA Query request and validation of SA Query response test 226
15.4 STAUT OCI STA SA Query on channel switch test 229
15.5 STAUT OCVC in RSNE, FTE OCI subelement in association request and validation in association response test and compatibility with non-OCVC AP test 231
16 RESERVED FOR FUTURE USE 236
17 WPA3-PERSONAL PRIVACY EXTENSIONS STAUT TESTS 237
17.1 STAUT construction of a uniquely randomized source MAC address per SSID test 237
17.2 STAUT construction of a randomized source MAC address per Active Scan test 239
17.3 STAUT construction of a randomized source MAC address for each ANQP exchange test 240
18 WPA3-ENTERPRISE 192-BIT SECURITY APUT TESTS 243
18.1 APUT 192-bit configuration requirements validation tests 243
18.1.1 APUT configuration requirements validation for 192-bit security on a BSSID with IPv4 test 243
18.1.2 APUT configuration requirements validation for 192-bit security on a BSSID with IPv6 test 244
18.2 APUT 192-bit security initial configuration tests. 245
18.2.1 APUT correct IE advertisement for 192-bit security test
18.3 APUT 192-bit security ECC p384 tests 246
18.3.1 APUT IPv4 connectivity using 192-bit security ECC p384 test 246
18.3.2 APUT IPv6 connectivity using 192-bit security ECC p384 test 248
18.4 APUT 192-bit security RSA 3K and TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 cipher tests 250
18.4.1 APUT IPv4 connectivity using 192-bit security RSA 3K and TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 cipher test 250
18.4.2 APUT IPv6 connectivity using 192-bit security RSA 3K and TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 cipher test 252
18.5 APUT 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 tests 254
18.5.1 APUT IPv4 connectivity using 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test. 254
18.5.2 APUT IPv6 connectivity using 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test. 256
18.6 APUT 192-bit security conformance tests 259
18.6.1 APUT response to an incorrect RSNE received from the STA test 259
18.6.2 APUT response to STA incorrect TLS authentication parameters test 261
18.7 APUT 192-bit security PMK caching 264
18.7.1 APUT 192-bit security PMK caching test 264
19 WPA3-ENTERPRISE 192-BIT SECURITY STAUT TESTS 267
19.1 STAUT 192-bit security configuration requirements validation test 267
19.1.1 STAUT configuration requirements validation for 192-bit security on a BSSID test 267
19.2 STAUT 192-bit security ECC p384 tests 268
19.2.1 STAUT IPv4 connectivity using 192-bit security ECC p384 test 268
19.2.2 STAUT IPv6 connectivity using 192-bit security ECC p384 test 270
19.3 STAUT 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test 272
19.3.1 STAUT IPv4 connectivity test using 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test 272
19.3.2 STAUT IPv6 connectivity using 192-bit security RSA 3K and TLS_ECDHE_RSA_AES_256_GCM_SHA384 cipher test 274
19.4 STAUT 192-bit security RSA 3K and TLS_DHE_RSA_AES_256_GCM_SHA384 cipher tests 277
19.4.1 STAUT IPv4 connectivity using 192-bit security RSA 3K and TLS_DHE_RSA_AES_256_GCM_SHA384 cipher test 277
19.4.2 STAUT IPv6 connectivity using 192-bit security RSA 3K and TLS_DHE_RSA_AES_256_GCM_SHA384 cipher test 279
19.5 STAUT 192-bit security conformance tests 281
19.5.1 STAUT response to incorrect RSNE received from AP test 281
19.5.2 STAUT response to AAA server TLS authentication parameters test 284
19.6 STAUT 192-bit security PMK caching tests 288
19.6.1 STAUT 192-bit security PMK caching test 288
APPENDIX A TEST BED PRODUCTS. 292
A.1 Approved test bed vendors 292
A.2 Approved test bed equipment 292
APPENDIX B CTT STA VALIDATION 297
B.1 CTT STA Validation for BIP MIC /Replay Error counter test 297
APPENDIX C (INFORMATIVE) DOCUMENT REVISION HISTORY
标签:
Wi-Fi
相关截图添加图片
暂无截图
帮助说明
点评
推荐下载more
-
windows2008搭建radius测试指导
工程安装测试浏览:1776 次下载:9 次 -
WLAN工程AP施工技术规范书
工程安装测试浏览:2270 次下载:8 次 -
优科Rcukus ZoneFlex AP操作指导
工程安装测试浏览:4348 次下载:84 次 -
Anywlan 无线网络测试方案模板
工程安装测试浏览:4755 次下载:165 次 -
无线验收与优化指导
工程安装测试浏览:2746 次下载:28 次 -
无线局域网产品强制性认证实施规则(无线局域网产品)
工程安装测试浏览:1309 次下载:8 次 -
无线AP系统验收报告 模板
工程安装测试浏览:3754 次下载:36 次
热门下载more
-
NetiQ 打流测试指导书
21浏览:3406 次下载:180 次 -
Anywlan 无线网络测试方案模板
21浏览:4755 次下载:165 次 -
优科Rcukus ZoneFlex AP操作指导
21浏览:4348 次下载:84 次 -
Anywlan模板 网络设备维护巡检报告.xls
21浏览:2804 次下载:61 次 -
优科ruckus 常用配置方法
21浏览:9048 次下载:57 次 -
Ruckus无线认证配置指导手册
21浏览:3428 次下载:45 次 -
信锐瘦AP升级为胖AP操作指南
21浏览:4465 次下载:44 次 -
无线AP系统验收报告 模板
21浏览:3754 次下载:36 次
专题more
-
Aruba控制器固件
Aruba 6xx/7xxxx控制器固件下载 -
Asuswrt-Merlin梅林固件专题汇集
加拿大人Eric Sauvageau在华硕开源的Asuswrt代码基础之上,个人进行二次开发以后,对外发布的第三方固件。最早是针对ASUS RT-N66U路由器进行开发,后来也移植到了华硕其他路由器机型。 Merlin原作者官网:https://www.asuswrt-merlin.net 国内所提供的梅林固件均源上述。
