There
is a paragraph in 7.1.3 that states:
An
SA's keying material [e.g. Data Encrytion Standard (DES) key and CBC
Initialization Vector] has a limited lifetime. When the BS delivers SA
keying material to an SS, it also provides the SS with that material's remaining
lifetime. It is the responsibility of the SS to request new keying
material from the BS before the set of keying material that the SS currently
holds expires at the BS. Should the current keying material expire before
a new set of keying material is received, the SS shall perform network entry as
described in 6.3.9. The PKM protocol specifies how SS and BS maintain key
synchronization.
Thanks,
Steve