Cisco Systems SPA3102, SPA2102, WRP400, SPA8000, PAP2T manual Using a Mini-Certificate

Models: PAP2T SPA8000 SPA3102 WRP400 SPA2102

1 250
Download 250 pages 30.56 Kb
Page 76
Image 76

Configuring Voice Services

4

 

Secure Call Implementation

 

 

 

 

 

STEP 2 The caller sends the “Caller Final” message to the called party with the following information:

Message ID (4B)

Encrypted Master Key (16B or 128b)

Encrypted Master Salt (16B or 128b)

Using a Mini-Certificate

The Master Key and Master Salt are encrypted with the public key from the called party mini-certificate. The Master Key and Master Salt are used by both ends for deriving session keys to encrypt subsequent RTP packets. The called party then responds with a Callee Final message (which is an empty message).

The Mini-Certificate (MC) contains the following information:

User Name (32B)

User ID or Phone Number (16B)

Expiration Date (12B)

Public Key (512b or 64B)

Signature (1024b or 512B)

The MC has a 512-bit public key used for establishing secure calls. The administrator must provision each subscriber of the secure call service with an MC and the corresponding 512-bit private key. The MC is signed with a 1024-bit private key of the service provider, which acts as the CA of the MC. The 1024-bit public key of the CA signing the MC must also be provisioned for each subscriber.

The CA public key is used to verify the MC received from the other end. If the MC is invalid, the call will not switch to secure mode. The MC and the 1024-bit CA public key are concatenated and base64 encoded into the single parameter Mini Certificate. The 512-bit private key is base64 encoded into the SRTP Private Key parameter, which should be kept secret, like a password. (Mini Certificate and SRTP Private Key are configured in the Line tabs.)

Because the secure call establishment relies on exchange of information embedded in message bodies of SIP INFO requests/responses, the service provider must ensure that the network infrastructure allows the SIP INFO messages to pass through with the message body unmodified.

ATA Administration Guide

74

Page 76
Image 76
Cisco Systems SPA3102, SPA2102, WRP400, SPA8000, PAP2T manual Using a Mini-Certificate

PAP2T, SPA8000, SPA3102, WRP400, SPA2102 specifications

The Cisco Systems SPA2102 is a versatile Voice over Internet Protocol (VoIP) adapter that serves as a bridge between traditional telephony systems and modern IP networks. Designed primarily for small to medium businesses, the SPA2102 is highly regarded for its reliability, ease of use, and rich feature set. This device allows users to make and receive phone calls over the internet while maintaining the ability to connect traditional analog phones.

One of the standout features of the SPA2102 is its dual-port capability. The device includes two FXS ports, allowing users to connect two separate analog telephones. This makes it an ideal choice for businesses that want to retain their existing telephony infrastructure while transitioning to a VoIP system. The ability to utilize two telephone lines simultaneously provides flexibility and convenience, especially for users in a busy office environment.

The SPA2102 leverages Session Initiation Protocol (SIP) technology, which is widely recognized for its robustness and interoperability. The support for SIP ensures that the SPA2102 can work seamlessly with various VoIP service providers, offering users a broad range of options for their telecommunication needs. In addition to SIP, the device supports various codecs, including G.711, G.726, and G.729, allowing for flexible audio quality settings and bandwidth management.

Security is also a critical aspect of the SPA2102. It incorporates advanced encryption methods, such as Secure Real-time Transport Protocol (SRTP) and Transport Layer Security (TLS), to protect voice communications from potential eavesdropping. This focus on security makes the SPA2102 a reliable choice for businesses concerned about the confidentiality of their conversations.

The device is easy to configure and manage, thanks to its web-based interface. This allows administrators to quickly set up the adapter, manage network settings, and troubleshoot any issues that may arise. Furthermore, the SPA2102 supports Quality of Service (QoS) features, ensuring that voice traffic is prioritized over other types of network traffic, which enhances call quality and reliability.

Overall, the Cisco SPA2102 is a powerful, user-friendly VoIP adapter that combines traditional telephony with modern IP technology. Its dual-port capability, support for SIP, extensive security features, and ease of configuration make it a solid choice for businesses looking to innovate their communication systems while minimizing disruption. Whether used in a small office or a larger organizational setting, the SPA2102 continues to be a reliable component of VoIP solutions.