13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

OverviewCritical security parameters and private keysTable 15 describes <strong>the</strong> CSPs (Critical Security Parameters) defined in <strong>the</strong> module.Table 15: Critical security parameters 1 <strong>of</strong> 3Key Description/Usage StorageIKE Pre-shared KeysHASH_I, HASH_RIKE Pre-Shared Session Key(SKEYID)IKE Ephemeral DH sharedsecret (g^ab)IKE Ephemeral DH private key(a)IKE Ephemeral DH private key(a)IKE Session Phase 1 Secret(SKEYID_d)IKE Session Phase 1 HMACKey (SKEYID_a)IKE Session Phase 1Encrypted Key (SKEYID_e)IKE Session Phase 1 TDESkey (SKEYID_e)This key generates IKE SKEYID_dduring pre-sharedkey au<strong>the</strong>ntication.The first-time key must be enteredmanually (via RS232 connected to <strong>the</strong>PC acting as terminal emulation). O<strong>the</strong>rkeys can be defined remotely overencrypted and au<strong>the</strong>nticated IPSECtunnel.Used for generation <strong>of</strong> SKEYID,SKEYID_d, SKEYID_a, SKEYID_e.Generated for VPN IKE Phase 1 keyestablishment.Generated for VPN IKE Phase 1 byhashing pre-shared keys with responder/receiver nonceGenerated for VPN IKE Phase 1 keyestablishmentThe private exponent used in DHexchange. Generated for VPN IKEPhase 1 key establishment.The private exponent used in DHexchange. Generated for VPN IKEPhase 1 key establishment.Phase 1 key used to derive keyingmaterial for IPSec SAsKey used for integrity and au<strong>the</strong>ntication<strong>of</strong> <strong>the</strong> ISAKMP SAShared key used for extraction <strong>of</strong>encryption keys protecting <strong>the</strong> ISAKMPSAKey used for TDES data encryption <strong>of</strong>ISAKMP SADRAM (plaintext)DRAM (plaintext)DRAM (plaintext)1 <strong>of</strong> 3Issue 3 January 2005 297

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!