Ipsec For Lte/Sae Networks; Encryption Algorithms; Hmac Functions; Diffie-Hellman Groups - Cisco ASR 5000 Series 3G Home NodeB Administration Manual

3g home nodeb gateway
Table of Contents

Advertisement

▀ IPSec for LTE/SAE Networks

IPSec for LTE/SAE Networks
The Cisco MME (Mobility Management Entity), S-GW (Serving Gateway), and P-GW (Packet Data Network Gateway)
support IPSec and IKEv2 encryption using IPv4 and IPv6 addressing in LTE/SAE (Long Term Evolution/System
Architecture Evolution) networks. IPSec and IKEv2 encryption enables network domain security for all IP packet-
switched networks, providing confidentiality, integrity, authentication, and anti-replay protection via secure IPSec
tunnels.

Encryption Algorithms

IPSec for LTE/SAE supports the following control and data path encryption algorithms:
 AES-CBC-128 (Advanced Encryption Standard-Cipher Block Chaining-128)
 AES-CBC-256 (Advanced Encryption Standard-Cipher Block Chaining-256)
 DES-CBC (Data Encryption Standard-Cipher Block Chaining)
 3DES-CBC (Triple Data Encryption Standard-Cipher Bock Chaining)

HMAC Functions

IPSec for LTE/SAE supports the following data path HMAC (Hash-based Message Authentication Code) functions:
 AES-XCBC-MAC-96 (Advanced Encryption Standard-X Cipher Block Chaining-Message Authentication Code-
96)
 MD5-96 (Message Digest 5-96)
 SHA1-96 (Secure Hash Algorithm 1-96)
IPSec for LTE/SAE supports the following control path HMAC (Hash-based Message Authentication Code) functions:
 AES-XCBC-MAC-96 (Advanced Encryption Standard-X Cipher Block Chaining-Message Authentication Code-
96)
 MD5-96 (Message Digest 5-96)
 SHA1-96 (Secure Hash Algorithm 1-96)
 SHA2-256-128 (Secure Hash Algorithm 2-256-128)
 SHA2-384-192 (Secure Hash Algorithm 2-384-192)
 SHA2-512-256 (Secure Hash Algorithm 2-512-256)

Diffie-Hellman Groups

IPSec for LTE/SAE supports the following Diffie-Hellman groups for IKE and Child SAs (Security Associations):
 Diffie-Hellman Group 1: 768-bit MODP (Modular Exponential) Group
 Diffie-Hellman Group 2: 1024-bit MODP Group
▄ Cisco ASR 5000 Series 3G Home NodeB Gateway Administration Guide
184
IP Security
OL-25069-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asr 5000 series

Table of Contents