Telecommunications and exchange between information technology systems — Requirements for local and metropolitan area networks — Part 1AR: Secure device identity

This standard specifies unique per-device identifiers (DevID) and the management and cryptographic binding of a device to its identifiers, the relationship between an initially installed identity and subsequent locally significant identities, and interfaces and methods for use of DevIDs with existing and new provisioning and authentication protocols.

Télécommunications et échange entre systèmes informatiques — Exigences pour les réseaux locaux et métropolitains — Partie 1AR: Identité de dispositif sécurisé

General Information

Publication Date
Current Stage
6060 - International Standard published
Start Date
Due Date
Completion Date
Ref Project


Standards Content (Sample)

Second edition
Telecommunications and exchange
between information technology
systems — Requirements for local and
metropolitan area networks —
Part 1AR:
Secure device identity
Télécommunications et échange entre systèmes informatiques —
Exigences pour les réseaux locaux et métropolitains —
Partie 1AR: Identité de dispositif sécurisé
Reference number
ISO/IEC/IEEE 8802-1AR:2020(E)
 IEEE 2018

ISO/IEC/IEEE 8802-1AR:2020(E)

IEEE Std 802.1AR-2018
(Revision of
(Revision of
IEEE Standard for
IEEE Standard for
Secure Device Identity
ISO/IEC/IEEE 8802-1AR:2020(E)
ISO/IEC/IEEE 8802-1AR:2020(E)
This introduction is not part of IEEE Std 802.1AR-2018, IEEE Standard for Local and Metropolitan Area
Networks—Secure Device Identity.
This standard specifies Secure Device Identifiers (DevIDs) for use with IEEE Std 802.1X [B1] and other
industry standards and protocols that authenticate, provision, and authorize communicating devices.
Each DevID comprises an RFC 5280 conformant X.509 certificate that identifies the subject device and can
include authorization information signed by the certificate’s issuer, a secret private key that corresponds to
the certificate’s subject public key, and any certificate chain required to facilitate the certificate’s use. A
device’s DevID module stores each of its DevID secrets securely and supports signing operations that prove
possession of the secret (and thus that the device is the subject of the associated DevID certificate), while
ensuring that the secret remains confidential so the device cannot be impersonated by others.
An Initial Device Identifier (IDevID) provided by a device’s supplier can be supplemented by one or more
Local Device Identifiers (LDevIDs), each using an existing or a freshly generated secret, facilitating
enrollment (provisioning of authentication and authorization credentials to authenticated devices) by a local
network administrator.
The first edition of IEEE Std 802.1AR was published in 2009. This revision added the ECDSA
P-384/SHA-384 signature suite option; removed the RSA-2048/OPAQUE option (that permitted the use of
an undisclosed hash function); restructured the document to enable future signature suite changes, for clarity
(particularly in conformance statements and the PICS), and revised the MIB. A DevID module can now
implement more than one signature suite (facilitating interoperability and the use of a device in different
authentication environments) and additional service operations (that do not conflict with mandatory
requirements) as long as these are disclosed (facilitating backwards compatibility and support of DevID
functionality by other modules, e.g., TPM).
Numbers in brackets correspond to entries in the Bibliography in Annex C.
ISO/IEC/IEEE 8802-1AR:2020(E)
1. Overview. 13
1.1 Scope. 14
1.2 Purpose. 14
1.3 Relationship to other standards. 14
2. Normative references. 15
3. Definitions . 17
4. Acronyms and abbreviations . 20
5. Conformance. 22
5.1 Requirements terminology. 22
5.2 Protocol Implementation Conformance Statement. 22
5.3 Required capabilities. 22
5.4 Optional capabilities . 23
5.5 Supplier information . 23
6. Secure Device Identifiers (DevIDs) and their use . 25
6.1 DevID secrets. 26
6.2 DevID certificates . 26
6.3 DevID certificate chains . 28
6.4 DevID Trust Model. 28
6.5 Privacy considerations . 30
7. DevID Modules. 31
7.1 DevID module functionality .31
7.2 DevID Service Interface . 33
7.3 DevID Management Interface . 37
8. DevID certificate fields and extensions . 38
8.1 version. 39
8.2 serialNumber. 39
8.3 signature. 39
8.4 issuer . 39
8.5 validity . 39
8.6 subject . 40
8.7 subjectPublicKeyInfo. 40
8.8 signatureAlgorithm . 40
8.9 signatureValue . 40
8.10 extensions. 40
9. DevID signature suites. 42
9.1 RSA-2048/SHA-256. 43
9.2 ECDSA P-256/SHA-256 . 44
9.3 ECDSA P-384/SHA-384 . 45
10. DevID MIB . 46
10.1 Internet-Standard Management Framework . 46
10.2 Relationship to other MIB modules. 46
10.3 Structure of the MIB module . 46
10.4 Security considerations . 47
ISO/IEC/IEEE 8802-1AR:2020(E)
10.5 Definitions for Secure Device Identifier MIB . 48
Annex A (normative) PICS proforma. 60
A.1 Introduction. 60
A.2 Abbreviations and special symbols. 60
A.3 Instructions for completing the PICS proforma. 61
A.4 PICS proforma for IEEE 802.1AR .

