Configuring Headend Broadband Access Router Features

Configuring and Activating Baseline Privacy

A KEK is assigned to a cable modem based on the cable modem SID and permits the cable modem to connect to the Cisco uBR7200 series when baseline privacy is activated. The TEK is assigned to a cable modem when its KEK has been established. The TEK is used to encrypt data traffic between the cable modem and the Cisco uBR7200 series.

KEKs and TEKs can be set to expire based on a grace-time or a life-time value. A grace-time key is used to assign a temporary key to a cable modem to access the network. A life-time key is used to assign a more permanent key to a cable modem. Each cable modem that has a life-time key assigned will request a new life-time key from the Cisco uBR7200 series before the current one expires.

Note Baseline privacy is only supported in Cisco IOS software containing “-k1” in the filename. If you do not already have a baseline privacy software image, you must download the software from Cisco Connection Online (CCO).

Note Baseline privacy will not operate unless the cable modem configuration file specifies that privacy is on.

The configuration and activation of baseline privacy depends on each cable operator physical plant.

To configure and activate baseline privacy, perform the following tasks:

Configuring KEK Privacy

Configuring TEK Privacy

Activating Baseline Privacy

Configuring KEK Privacy

A grace-time KEK can be set from 300 to 1800 seconds. A life-time KEK can be set from 86,400 to 6,048,000 seconds. If you do not set a KEK value, the default values are used.

To configure KEK data privacy on the HFC network, use the following commands in cable interface configuration mode:

Command

Purpose

 

 

CMTS01(config-if)#cable privacy kek grace-time

Sets the cable privacy KEK grace time in seconds. Valid

seconds

values are from 300 to 1800 seconds. Default = 600.

or

or

 

CMTS01(config-if)#cable privacy kek life-time seconds

Sets the cable privacy KEK life time in seconds. Valid

 

 

values are from 86400 to 6048000 seconds.

 

Default = 604800.

 

 

Cisco IOS Multiservice Applications Configuration Guide

MC-562

Page 44
Image 44
Cisco Systems uBR7200 manual Configuring KEK Privacy, MC-562, CMTS01config-if#cable privacy kek grace-time