Skip to main content

5.7. Proof of Possession

Proof of Possession (POP) authenticates that a group member possesses the keys distributed in the GROUPKEY-PULL exchange.

Purpose​

  • Confirms successful key receipt
  • Prevents unauthorized access
  • Validates group member authentication

Signature Computation​

The POP payload is used as part of group member authorization during a GDOI exchange. It is identical in format to the ISAKMP SIG payload, but used differently.

The GCKS, its delegate, or the member signs a hash over the following values:

POP_HASH = hash("pop" | Ni | Nr)

where hash() is the hash function used with the signature.

Security Considerations​

The "pop" prefix ensures that the signature in the POP payload cannot be reused for any other purpose within the GDOI protocol.