76   Algorithms indication mismatch on Update Key Change methods

Created: 06 Nov 2024

Status: Approval (Editoral)

Part: Part 5 (2013, Edition 2, TS)

Links:

Page: 47, 94

Clause: 7.2.9.2, 8.2.5.9

Paragraph: Table 35

Issue

Issue 1:

The following statement in IEC 62351-5, Subclause 8.2.5.9:

“All devices that permit remote changing of Update Keys shall implement Key Change Method <4>, the symmetric method employing AES-128 for encryption and HMAC-SHA-256 for authentication. All other Update Key Change Methods shall be optional”

does not correspond to Table 35, where option <4> indicates AES-256 (AES-128 is not present in the table).

Issue 2:

In Subclause 7.2.9.2 the Key Change Methods <3> and <67> are not present in Subclause 8.2.5.9, Table 35.

IEC 62351-5, 7.2.9.2
– <3> := Symmetric AES-128 / HMAC-SHA-1
– <67> := Asymmetric RSA-2048 / DSA SHA-1 / HMAC-SHA-1

IEC 62351-5, 8.2.5.9 Table 35
– <3> := reserved
– <67> := reserved

Proposal

1) Change AES-128 to AES-256 in the above statement at Subclause 8.2.5.9.

2) Remove options <3> and <67> from the list in Subclause 7.2.9.2

Discussion Created Status
Resolution for Issue 1.

In subclause 8.2.5.9 the statement in the fourth paragraph shall be corrected to the following text:

"All devices that permit remote changing of Update Keys shall implement Key Change Method
<4>, the symmetric method employing AES-256 for key wrapping and HMAC-SHA-256 for
authentication. All other Update Key Change Methods shall be optional."

Resolution for Issue 2.

In subclause 7.2.9.2, in the list of Key Change Methods values (KCM), the text of KCM 3 and 67 shall be removed and replaced with the word "reserved". See attached file.

10 Jan 25 Approval (Editoral)
For issue 1: I believe it would be more correct to say "AES-256 key wrapping" instead of using "AES-256 for encryption". key wrapping is more than just encrypting something.

For issue 2: We could also decide to add them to table 35 in subclause 8.2.5.9
07 Nov 24 Triage

 

Privacy | Contact | Disclaimer

Tissue DB v. 25.7.7.1