The type of link key in use. This will determine the security policies associated with sending and receiving APS messages.
Default: 0x00
Identifies the address of the entity with which this key-pair is shared.
A set of feature flags pertaining to this security material or denoting the peer’s support for specific APS security features:
0x00-0x01, default: 0x00
Incoming frame counter value corresponding to DeviceAddress. uint32_t
Default: 0x00
If set to TRUE, the device identified by DeviceAddress is a Zigbee Direct Virtual Device (ZVD). A Trust Center SHALL NOT send network keys to this device.
default: false
This indicates attributes about the key.
The value of the selected TLV sent to the device. 0x00-0x08, default: 0x00 (APS Request Key
method)
default: 0x00
The actual value of the link key.
Outgoing frame counter for use with this link key. uint32_t
Optional
passphraseA value that is used by both sides during dynamic key negotiation. An unset value means this key-pair entry was not dynamically negotiated. Any other value indicates the entry was dynamically negotiated.
This indicates whether the particular KeyPair passphrase MAY be updated for the device. A passphrase update is normally only allowed shortly after joining. See section 4.7.2.1.
default: true
This indicates what Link Key update method was used after the device joined the network.
The timeout, in seconds, for the specified key. When this timeout expires, the key SHALL be marked EXPIRED_KEY in the KeyAttributes and the LinkKey value SHALL not be used for encryption of messages. A value of 0xFFFF for the Timeout mean the key never expires.
default: 0xffff
Optional
trustThe key used to indicate a Trust Center Swap-out has occurred. This key SHALL always be set to a hash of the LinkKey element. If the LinkKey is updated, then this value MUST be updated as well. See section 4.7.4.1.2.4. If the entry in the apsDeviceKeyPairSet is an application link key (where local device and the partner are not Trust Centers), implementations MAY elide this element for that entry.
Indicates whether the incoming frame counter value has been verified through a challenge response.
default: false
see 05-3474-23 Table 4-35 A set of key-pair descriptors containing link keys shared with other devices.