The Zigbee coordinator/combined interface device with address
0x0000 acts as a trust center, and the device with address
0x0401 acts as a Zigbee router (see
the following figure). For details on the centralized security mechanism, refer to Network Security Models.
As per Figure 6-1, MAC association packets were unencrypted. After completion of the
association process:
The trust center sends the
Transport Key (coordinator with address
0x0000) from which the joining device receives the link key
(router-0x0401) (see packet #14). The
APS frame carrying the transport key is encrypted with Link
Key A.
The joined device (router)
performs the device announcement (see packets #16 and
#17).
Node descriptor exchange happens
between coordinator and router as part of the initialization procedure (see
packets #18 to #22).
Packet #23 shows
the router sending the request key to the trust center as a request for link
Key B. Link Key A secures the APS frame
carrying this request key.
The trust center transports
(packet #25) the requested key via Transport
Key with APS encryption by Link
Key A.
Packet #27 shows
Verify Key, which ensures that the trust center and joined
device agree on the same key.
Packet #29 shows
the Confirm Key, which permits the trust center to confirm a
previous request to verify a link key.
Figure 6-12. Trust Center Key Exchange
Centralized Network
The following figure illustrates the Transport Key, where Link
Key A (5a 69 67 42 65 65 41 6c 6c 69 61 6e 63 65 30 39) is
highlighted, which encrypts the APS layer. By default, the network key
is used for cluster commands. The following figure highlights the network key,
Key: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc.
Figure 6-13. APS Tunnel Transport Key
The following figure illustrates the Request Key, where Link
Key A (5a 69 67 42 65 65 41 6c 6c 69 61 6e 63 65 30 39) is
highlighted, that encrypts the APS layer.Figure 6-14. Request Key
The following figure illustrates the Transport Key, where Link
Key A (5a 69 67 42 65 65 41 6c 6c 69 61 6e 63 65 30 39) is
highlighted, that encrypts the APS layer. The following figure illustrates the Link
Key B (fb 40 45 17 7a 0a bc 68 e3 35 ce 4b 93 12 63 0a), which is
being transported from the trust center to the router.Figure 6-15. Transport Key
The online versions of the documents are provided as a courtesy. Verify all content and data in the device’s PDF documentation found on the device product page.