Abstract

Incorporate engineering changes and update TS 102 639-5: Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services

Status
Published
Public Enquiry End Date
30-Jun-2011
Publication Date
10-Jan-2012
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
10-Jan-2012
Due Date
16-Mar-2012
Completion Date
11-Jan-2012

Buy Documents

Standard

en_30287805v010100c - Access, Terminals, Transmission and Multiplexing (ATTM); Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services; DOCSIS 3.0

English language (185 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

en_30287805v010100v - Access, Terminals, Transmission and Multiplexing (ATTM); Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services; DOCSIS 3.0

English language (185 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

en_30287805v010101p - Access, Terminals, Transmission and Multiplexing (ATTM); Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services; DOCSIS 3.0

English language (185 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

SIST EN 302 878-5 V1.1.1:2012

English language (185 pages)
Preview
Preview
e-Library read for
×1 day

SIST EN 302 878-5 V1.1.1:2012 is the Slovenian adoption of ETSI EN 302 878-5 for Access, Terminals, Transmission and Multiplexing (ATTM) - Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems. It specifies security services for DOCSIS 3.0 cable modem communications, including provisioning security, key management, encryption, certificate handling, and secure software download for cable modems (CM) and Cable Modem Termination Systems (CMTS).

What does SIST EN 302 878-5 V1.1.1:2012 specify?

SIST EN 302 878-5 V1.1.1:2012 specifies the security mechanisms used to protect DOCSIS communications between a CM and a CMTS. The document focuses on data privacy over the cable network and on preventing unauthorized access to RF MAC services, while also covering secure provisioning and software trust.

The structure is practical for implementation work:

  • Clause 1 introduces the scope and conventions.
  • Clause 2 lists normative and informative references.
  • Clause 3 gives definitions and abbreviations.
  • Clause 5 gives the security overview and DOCSIS 3.0 additions.
  • Clauses 6 to 14 define frame formats, key management, provisioning, certificates, and software download.
  • Annexes A, C, D, E, F, and G provide encodings, SA mapping, interoperability guidance, worked examples, an MMH implementation example, and certificate/provisioning guidelines.
AnnexWhat it covers
Annex AEncodings and parameter guidelines for Baseline Privacy settings
Annex CSA Mapping state model
Annex DBPI/BPI+ interoperability
Annex EWorked examples for authentication, key exchange, encryption, and software download
Annex FExample implementation of the MMH algorithm
Annex GCertificate authority and provisioning guidelines

What are the key requirements of SIST EN 302 878-5 V1.1.1:2012?

SIST EN 302 878-5 V1.1.1:2012 defines a layered security model: public-key cryptography creates an Authorization Key, and that key is then used to derive and protect traffic-encryption keys. In practice, this means a CM and CMTS do not rely on public-key operations for every protected exchange, which supports key refresh without heavy computation.

Provisioning and network access

Clause 5 states two main goals: user data privacy and protection against unauthorized access to RF MAC services. It also identifies protected service categories as best-effort high-speed IP data, QoS data, and IP multicast group services, which shows the standard is meant for everyday subscriber traffic, not only special security cases.

Clause 5.2.1.5 defines BPI+ Enforce. When the CMTS enforces BPI+ on a CM, it must not forward post-registration traffic until a Primary SA has been established through EAE or post-registration BPI+ provisioning. For operators, this means traffic should stay blocked until the modem has completed the required security handshake.

Clause 9 adds secure provisioning measures such as encrypted provisioning messages, TFTP proxy support, configuration file learning, and source address verification. The CMTS must be able to enable SAV by configuration and, by default, must enable it. When SAV is active, it must drop upstream packets whose IP source address has not been assigned by the operator, which helps stop spoofed traffic and misbehaving customer equipment.

Frame and message protection

Clause 6 defines the encrypted DOCSIS MAC frame formats. The document specifies how the Baseline Privacy Extended Header is used and how encryption status is signaled with the ENABLE and TOGGLE bits. For implementers, this is the part that makes CM and CMTS frame handling interoperable at the wire level.

Clause 6.5 is specific about REG-REQ-MP messages: the first 12 octets containing the Ethernet/802.3 addresses are left unencrypted, the CRC is encrypted, and the Baseline Privacy Extended Header must be the first extended header in the upstream frame. That matters because a small header mistake can break registration or authentication.

Key management and state machines

Clause 7 defines the Baseline Privacy Key Management (BPKM) protocol. The Authorization Request carries the CM identification, public key, certificate, and cryptographic capabilities; the Authorization Reply carries the Authorization Key, the Primary SAID, and the SA descriptors the CM is allowed to use. This is the core exchange that proves identity and authorizes service.

Clause 7 also requires overlapping key lifetimes. The CM and CMTS must each support at least two simultaneously active Authorization Keys, and the CMTS must maintain the keying material needed for uninterrupted TEK refresh. In practice, that avoids service drops during reauthorization.

Clause 7.1.5 defines the TEK state machine and the Key Request/Key Reply flow. The Key Reply carries the active traffic keying material for a SAID, encrypted with a KEK derived from the Authorization Key. This is the routine traffic-protection mechanism once the modem is authorized.

Cryptographic methods and suites

Clause 11 defines the cryptographic methods and key sizes. The standard supports CBC-mode 56-bit DES, optional 40-bit DES for interoperability with older DOCSIS 1.0 hardware, and CBC-mode 128-bit AES. It also defines HMAC-Digest, RSA-based authorization-key encryption, and the MMH-MIC. In practical terms, vendors need to implement the exact suite identifiers and key-handling rules the document assigns.

Clause 11.1 says the optional 40-bit DES mode is created by masking off the left-most 16 bits of a 56-bit DES key before use. That allows older equipment to participate while keeping the algorithm behavior consistent.

Clause 10 requires the CMTS to maintain two sets of active traffic encryption keys and CBC initialization vectors per SAID, with overlapping lifetimes and a defined key-sequence progression. That makes key rollover predictable and keeps encrypted traffic continuous.

Certificates, revocation, and software trust

Clause 13 defines the BPI+ X.509 certificate profile and management rules. It covers the DOCSIS Root CA, Centralized Mfg CA, Manufacturer CA, and CM certificates, along with certificate revocation lists and Online Certificate Status Protocol. For buyers and integrators, this is the part that controls who can authenticate a modem and who can revoke trust.

Clause 14 defines secure software download. The CM must verify the code file structure, reject incompatible code, and verify the configuration-file CVC before accepting upgrade settings. If the download succeeds, the CM replaces stored root and manufacturer trust material when the signed content includes it. In practice, software updates are part of the trust chain, not a separate afterthought.

What terms does SIST EN 302 878-5 V1.1.1:2012 define?

Baseline Privacy Key Management (BPKM) is the protocol used by the CM and CMTS to exchange authorization and traffic key material.

Early Authentication and Encryption (EAE) is the mechanism that starts authentication and protection during initial modem startup, before normal registration is complete.

Traffic Encryption Key (TEK) is the key used to protect traffic on a Security Association, and it is refreshed through the key-management process.

Key Encryption Key (KEK) is derived from the Authorization Key and is used to encrypt TEKs in key-management exchanges.

Security Association Identifier (SAID) identifies the Security Association a modem is allowed to use for traffic protection.

Cable Modem Termination System (CMTS) is the network-side system that authenticates the modem, controls access, and exchanges keys.

Cable Modem (CM) is the customer-side device that authenticates itself, receives keys, and encrypts or decrypts traffic.

Certificate Validation Certificate (CVC) is the certificate used in the secure software download and trust-management procedures.

Who uses SIST EN 302 878-5 V1.1.1:2012?

SIST EN 302 878-5 V1.1.1:2012 is used by cable operators, DOCSIS modem and CMTS manufacturers, provisioning-system designers, security engineers, and compliance or test laboratories. They use it to implement modem authentication, configure encrypted service access, validate certificates, set up secure provisioning, and verify secure software download behavior.

It is also relevant to quality managers and buyers who need to check whether a DOCSIS 3.0 product supports the expected security model, especially for provisioning, key rollover, multicast security, and certificate-based trust.

What changed in SIST EN 302 878-5 V1.1.1:2012 from the previous edition?

SIST EN 302 878-5 V1.1.1:2012 incorporates engineering changes and updates TS 102 639-5 for the DOCSIS 3.0 security services part. It is the updated version identified in the document as EN 302 878-5 Version 1.1.1.

Which standards are used with SIST EN 302 878-5 V1.1.1:2012?

The document names these normative references:

  • RSA Laboratories PKCS #1 (Version 2.0 - October 1999) - used for RSA cryptography and authorization-key encryption.
  • ANSI/SCTE 22-2 (2007) - the DOCSIS 1.0 Baseline Privacy Interface reference for backward compatibility.
  • ANSI/SCTE 52 (2008) - the DES-CBC packet-encryption specification used by the privacy mechanism.
  • ITU-T Recommendation X.509 (2008) - the certificate framework used for DOCSIS certificates.
  • ITU-T Recommendation X.690 / ISO/IEC 8825-1:2002 - the BER, CER, and DER encoding rules used for certificate and CVC encoding.

What does the SIST EN 302 878-5 V1.1.1:2012 document contain?

The document contains protocol definitions, frame formats, state machines, attribute encodings, and security procedures for DOCSIS 3.0. It includes the BPKM state models, message codes, TLV attributes, and the rules for encrypted MAC frames, multicast signaling, and secure provisioning.

It also includes worked examples and implementation material in the annexes. Annex E gives examples for Authentication Info, Authorization Request and Reply, Key Request and Reply, packet encryption with DES and AES, payload header suppression, fragmented packets, and secure software download code files.

Annex F gives an example implementation of the Multilinear Modular Hash (MMH) algorithm, including MMH32 and MMH64 computation examples. Annex G gives certificate authority and provisioning guidance, including X.509 field descriptions, certificate re-issuance guidance, and code-file signing policy.

Buy Documents

Standard

en_30287805v010100c - Access, Terminals, Transmission and Multiplexing (ATTM); Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services; DOCSIS 3.0

English language (185 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

en_30287805v010100v - Access, Terminals, Transmission and Multiplexing (ATTM); Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services; DOCSIS 3.0

English language (185 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

en_30287805v010101p - Access, Terminals, Transmission and Multiplexing (ATTM); Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services; DOCSIS 3.0

English language (185 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

SIST EN 302 878-5 V1.1.1:2012

English language (185 pages)
Preview
Preview
e-Library read for
×1 day

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

NYCE

Mexican standards and certification body.

EMA Mexico Verified

Sponsored listings

Frequently Asked Questions

SIST EN 302 878-5 V1.1.1:2012 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Access, Terminals, Transmission and Multiplexing (ATTM) - Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems - Part 5: Security Services - DOCSIS 3.0". This standard covers: Incorporate engineering changes and update TS 102 639-5: Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services

Incorporate engineering changes and update TS 102 639-5: Third Generation Transmission Systems for Interactive Cable Television Services - IP Cable Modems; Part 5: Security Services

SIST EN 302 878-5 V1.1.1:2012 is classified under the following ICS (International Classification for Standards) categories: 35.180 - IT Terminal and other peripheral equipment. The ICS classification helps identify the subject area and facilitates finding related standards.

SIST EN 302 878-5 V1.1.1:2012 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


Draft ETSI EN 302 878-5 V1.1.0 (2011-04)
European Standard
Access, Terminals, Transmission and Multiplexing (ATTM);
Third Generation Transmission Systems for
Interactive Cable Television Services - IP Cable Modems;
Part 5: Security Services;
DOCSIS 3.0
2 Draft ETSI EN 302 878-5 V1.1.0 (2011-04)

Reference
DEN/ATTM-003006-5
Keywords
access, broadband, cable, data, IP, IPCable,
modem
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88

Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
http://portal.etsi.org/tb/status/status.asp
If you find errors in the present document, please send your comment to one of the following services:
http://portal.etsi.org/chaircor/ETSI_support.asp
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.

© European Telecommunications Standards Institute 2011.
All rights reserved.
TM TM TM TM
DECT , PLUGTESTS , UMTS , TIPHON , the TIPHON logo and the ETSI logo are Trade Marks of ETSI registered
for the benefit of its Members.
TM
3GPP is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners.
LTE™ is a Trade Mark of ETSI currently being registered
for the benefit of its Members and of the 3GPP Organizational Partners.
GSM® and the GSM logo are Trade Marks registered and owned by the GSM Association.
ETSI
3 Draft ETSI EN 302 878-5 V1.1.0 (2011-04)
Contents
Intellectual Property Rights . 10
Foreword . 10
1 Scope . 11
1.1 Introduction and Purpose . 11
1.2 Requirements . 11
1.3 Conventions . 11
2 References . 11
2.1 Normative references . 12
2.2 Informative references . 13
3 Definitions and abbreviations . 14
3.1 Definitions . 14
3.2 Abbreviations . 14
4 Void . 16
5 Overview . . 16
5.1 New DOCSIS 3.0 Security Features. 16
5.2 Technical Overview . 17
5.2.1 BPI+ Architecture . 17
5.2.1.1 Packet Data Encryption . 17
5.2.1.2 Key Management Protocol . 17
5.2.1.3 DOCSIS Security Associations . 18
5.2.1.4 QoS SIDs and DOCSIS SAIDs . 19
5.2.1.5 BPI+ Enforce. 19
5.2.2 Secure Provisioning . 20
5.3 Operation . 20
5.3.1 Cable Modem Initialization . 20
5.3.1.1 Network Admission Control . 21
5.3.1.2 EAE and Authentication Reuse . 21
5.3.1.3 Configuration Registration Enforcement . 21
5.3.2 Cable Modem Key Update Mechanism . 22
5.3.3 Cable Modem Secure Software Download . 22
6 Encrypted DOCSIS MAC Frame Formats . 22
6.1 CM Requirements. 22
6.2 CMTS Requirements . 22
6.3 Variable-Length PDU MAC Frame Format . 23
6.3.1 Baseline Privacy Extended Header Formats . 24
6.4 Fragmentation MAC Frame Format . 25
6.5 Registration Request (REG-REQ-MP) MAC Management Messages. 26
6.6 Use of the Baseline Privacy Extended Header in the MAC Header . 28
7 Baseline Privacy Key Management (BPKM) Protocol . 28
7.1 State Models . 28
7.1.1 Introduction. 28
7.1.1.1 Authorization State Machine Overview . 28
7.1.1.2 TEK State Machine Overview . 30
7.1.2 Encrypted Multicast . 31
7.1.2.1 Signaling of Dynamic and Static Multicast Session SAs when MDF is Disabled . 32
7.1.2.2 Signaling of Dynamic and Static Multicast Session SAs when MDF is Enabled . 32
7.1.2.2.1 Requirements Specific to the Signaling of Dynamic SAs for Dynamic Multicast Sessions . 32
7.1.2.2.2 Requirements Specific to the Signaling of Dynamic SAs for Static Multicast Sessions . 33
7.1.3 Selecting Cryptographic Suites . 33
7.1.4 Authorization State Machine . 34
7.1.4.1 Brief Description of States . 35
7.1.4.1.1 [Start] . 35
ETSI
4 Draft ETSI EN 302 878-5 V1.1.0 (2011-04)
7.1.4.1.2 [Auth Wait] . 35
7.1.4.1.3 [Authorized] . 35
7.1.4.1.4 [Reauth Wait] . 35
7.1.4.1.5 [Auth Reject Wait] . 35
7.1.4.1.6 [Silent] . 36
7.1.4.2 Brief Description of Messages . 36
7.1.4.2.1 Authorization Request (Auth Request) . 36
7.1.4.2.2 Authorization Reply (Auth Reply) . 36
7.1.4.2.3 Authorization Reject (Auth Reject) . 36
7.1.4.2.4 Authorization Invalid (Auth Invalid) . 36
7.1.4.2.5 Authentication Information (Auth Info) . 36
7.1.4.3 Brief Description of Events . 37
7.1.4.3.1 {Initiate Authentication} . 37
7.1.4.3.2 {Timeout} . 37
7.1.4.3.3 {Auth Grace Timeout} . 37
7.1.4.3.4 {Reauth} . 37
7.1.4.3.5 {Auth Invalid} . 37
7.1.4.3.6 {Perm Auth Reject} . 37
7.1.4.3.7 {Auth Reject} . 37
7.1.4.3.8 {EAE Disabled Auth Reject} . 37
7.1.4.4 Events sent to TEK State Machine . 37
7.1.4.4.1 {TEK Stop} . 38
7.1.4.4.2 {TEK Authorized} . 38
7.1.4.4.3 {Auth Pend} . 38
7.1.4.4.4 {Auth Comp} . 38
7.1.4.5 Brief Description of Timing Parameters . 38
7.1.4.5.1 Authorize Wait Timeout (Auth Wait Timeout) . 38
7.1.4.5.2 Reauthorize Wait Timeout (Reauth Wait Timeout). 38
7.1.4.5.3 Authorization Grace Time (Auth Grace Timeout). 38
7.1.4.5.4 Authorize Reject Wait Timeout (Auth Reject Wait Timeout) . 38
7.1.4.6 Timers . 38
7.1.4.6.1 Authorization Request . 38
7.1.4.6.2 Authorization Reject . 38
7.1.4.6.3 Authorization Grace . 38
7.1.4.7 Actions . 39
7.1.5 TEK State Machine . 41
7.1.5.1 Brief Description of States . 42
7.1.5.1.1 [Start] . 42
7.1.5.1.2 [Op Wait] . 42
7.1.5.1.3 [Op Reauth Wait] . 42
7.1.5.1.4 [Op] . 42
7.1.5.1.5 [Rekey Wait] . 42
7.1.5.1.6 [Rekey Reauth Wait] . 42
7.1.5.2 Brief Description of Messages . 42
7.1.5.2.1 Key Request . 42
7.1.5.2.2 Key Reply . 43
7.1.5.2.3 Key Reject . 43
7.1.5.2.4 TEK Invalid . 43
7.1.5.3 Brief Description of Events . 43
7.1.5.3.1 {Stop} . 43
7.1.5.3.2 {Authorized} . 43
7.1.5.3.3 {Auth Pend} . 43
7.1.5.3.4 {Auth Comp} . 43
7.1.5.3.5 {TEK Invalid} . 43
7.1.5.3.6 {Timeout} . 43
7.1.5.3.7 {TEK Refresh Timeout} . 43
7.1.5.4 Brief Description of Timing Parameters . 43
7.1.5.4.1 Operational Wait Timeout . 44
7.1.5.4.2 Rekey Wait Timeout . 44
7.1.5.4.3 TEK Grace Time . 44
7.1.5.5 Timers . 44
7.1.5.5.1 Key Request Retry . 44
ETSI
5 Draft ETSI EN 302 878-5 V1.1.0 (2011-04)
7.1.5.5.2 TEK Refresh . 44
7.1.5.6 Actions . 44
7.2 Key Management Message Formats. 46
7.2.1 Packet Formats . 46
7.2.1.1 Authorization Request (Auth Request) . 48
7.2.1.2 Authorization Reply (Auth Reply) . 48
7.2.1.3 Authorization Reject (Auth Reject) . 49
7.2.1.4 Key Request . 49
7.2.1.5 Key Reply . 50
7.2.1.6 Key Reject . 50
7.2.1.7 Authorization Invalid . 51
7.2.1.8 TEK Invalid. 51
7.2.1.9 Authentication Information (Auth Info) . 51
7.2.1.10 SA Map Request (MAP Request) . 52
7.2.1.11 SA Map Reply (Map Reply) . 52
7.2.1.12 SA Map Reject (Map Reject) . 52
7.2.2 BPKM Attributes . 53
7.2.2.1 Serial-Number . 54
7.2.2.2 Manufacturer-ID . 54
7.2.2.3 MAC-Address . 55
7.2.2.4 RSA-Public-Key . 55
7.2.2.5 CM-Identification . 55
7.2.2.6 Display-String . 56
7.2.2.7 Auth-Key . 56
7.2.2.8 TEK . 56
7.2.2.9 Key-Lifetime . 56
7.2.2.10 Key-Sequence-Number . 57
7.2.2.11 HMAC-Digest . 57
7.2.2.12 SAID . 57
7.2.2.13 TEK-Parameters . 57
7.2.2.14 CBC-IV . 58
7.2.2.15 Error-Code . 58
7.2.2.16 Vendor-Defined . 59
7.2.2.17 CA-Certificate . 59
7.2.2.18 CM-Certificate . 60
7.2.2.19 Security-Capabilities . 60
7.2.2.20 Cryptographic-Suite . 60
7.2.2.21 Cryptographic-Suite-List . 61
7.2.2.22 BPI-Version . 61
7.2.2.23 SA-Descriptor . 61
7.2.2.24 SA-Type . 62
7.2.2.25 SA-Query . 62
7.2.2.26 SA-Query-T ype . 63
7.2.2.27 IPv4-Address . 63
7.2.2.28 Download-Parameters . 63
7.2.2.29 CVC-Root-CA-Certificate . 63
7.2.2.30 CVC-CA-Certificate . 64
8 Early Authentication and Encryption (EAE) . 64
8.1 Introduction . 64
8.2 EAE Signaling . 64
8.3 EAE Encryption . 66
8.4 EAE Enforcement. 66
8.4.1 CMTS and CM behaviours when EAE is Enabled . 66
8.4.2 EAE enforcement determination . 67
8.4.2.1 Ranging-Based EAE Enforcement . 67
8.4.2.2 Capability-Based EAE Enforcement . 67
8.4.2.3 Total EAE Enforcement . 67
8.4.3 EAE Enforcement of DHCP Traffic . 67
8.4.4 CMTS and CM Behaviour when EAE is Disabled . 67
8.4.5 EAE Exclusion List . 67
8.4.6 Interoperability issues . 68
ETSI
6 Draft ETSI EN 302 878-5 V1.1.0 (2011-04)
8.5 Authentication Reuse . 68
8.6 BPI+ Control by Configuration File . 68
8.6.1 EAE Enabled . 68
8.6.2 EAE Disabled . 69
9 Secure Provisioning . 69
9.1 Introduction . 69
9.2 Encryption of Provisioning Messages . 69
9.3 Securing DHCP . 69
9.3.1 Securing DHCP on the Cable Network Link . 69
9.3.2 DHCPv6 . 69
9.4 TFTP Configuration File Security . 70
9.4.1 Introduction. 70
9.4.2 CMTS Security Features for Configuration File Download . 70
9.4.2.1 TFTP Proxy . 70
9.4.2.2 Protecting TFTP Server Addresses . 70
9.4.2.3 Configuration File Name Authorization. 70
9.4.2.4 Configuration File Learning . 71
9.4.2.5 TFTP Options for CM's MAC and IP Address . 71
9.5 Securing REG-REQ-MP Messages . 71
9.6 Source Address Verification. 71
9.7 Address Resolution Security Considerations . 73
10 Using Cryptographic Keys . 74
10.1 CMTS . 74
10.2 Cable Modem . 76
10.3 Authentication of Dynamic Service Requests . 77
10.3.1 CM . 77
10.3.2 CMTS . 77
11 Cryptographic Methods . 77
11.1 Packet Data Encryption . 77
11.2 Encryption of the TEK . 78
11.3 HMAC-Digest Algorithm . 79
11.4 TEKs, KEKs and Message Authentication Keys . 79
11.5 Public-Key Encryption of Authorization Key . 79
11.6 Digital Signatures . 80
11.7 The MMH-MIC . 80
11.7.1 The MMH Function . 80
11.7.1.1 MMH[16, σ, 1] . 80
11.7.1.2 MMH[16, σ, n] . 82
11.7.1.3 MMH[16, σ, 4] . 82
11.7.1.4 Handling Variable-Size Data . 82
11.7.2 Definition of MMH-MAC . 82
11.7.3 Calculating the DOCSIS MMH-MAC . 83
11.7.4 MMH Key Derivation for CMTS Extended MIC . 84
11.7.5 Shared Secret Recommendations . 85
11.7.6 Key Generation Function . 85
12 Physical Protection of Keys in the CM . 85
13 BPI+ X.509 Certificate Profile and Management . 86
13.1 BPI+ Certificate Management Architecture Overview . 86
13.2 Cable Modem Certificate Storage and Management in the CM . 88
13.3 Certificate Processing and Management in the CMTS . 89
13.3.1 CMTS Certificate Management Model. 89
13.3.2 Certificate Validation . 89
13.4 Certificate Revocation . 90
13.4.1 Certificate Revocation Lists . 90
13.4.1.1 CMTS CRL Support . 91
13.4.2 Online Certificate Status Protocol . 91
14 Secure Software Download . 92
14.1 Introduction . 92
ETSI
7 Draft ETSI EN 302 878-5 V1.1.0 (2011-04)
14.2 Overview . 92
14.3 Software Code Upgrade Requirements . 94
14.3.1 Code File Processing Requirements . 94
14.3.2 Code File Access Controls . 95
14.3.2.1 Subject Organization Names . 95
14.3.2.2 Time Varying Controls . 95
14.3.3 Cable Modem Code Upgrade Initialization . 95
14.3.3.1 Manufacturer Initialization . 96
14.3.3.2 Network Initialization . 96
14.3.3.2.1 Processing the Configuration File CVC . 97
14.3.3.2.2 Processing the SNMP CVC . 97
14.3.4 Code Signing Guidelines . 98
14.3.5 Code Verification Requirements . 98
14.3.5.1 Cable Modem Code Verification Steps . 98
14.3.6 DOCSIS Interoperability . 99
14.3.7 Error Codes . 99
14.4 Security Considerations (Informative) . 100
Annex A (normative): TFTP Configuration File Extensions . 102
A.1 Encodings . 102
A.1.1 Baseline Privacy Configuration Setting . 102
A.1.1.1 Internal Baseline Privacy Encodings . 102
A.1.1.1.1 Authorize Wait Timeout . 102
A.1.1.1.2 Reauthorize Wait Timeout . 102
A.1.1.1.3 Authorization Grace Time . 103
A.1.1.1.4 Operational Wait Timeout . 103
A.1.1.1.5 Rekey Wait Timeout . 103
A.1.1.1.6 TEK Grace Time . 103
A.1.1.1.7 Authorize Reject Wait Timeout . 103
A.1.1.1.8 SA Map Wait Timeout . 103
A.1.1.1.9 SA Map Max Retries . 103
A.2 Parameter Guidelines . 104
Annex B (normative): TFTP Options . 105
Annex C (normative): DOCSIS 1.1/2.0 Dynamic Security Associations . 113
C.1 Introduction . 113
C.2 Theory of Operation . 113
C.3 SA Mapping State Model . 114
C.3.1 Brief Description of States . 115
C.3.1.1 [Start]
...


Final draft ETSI EN 302 878-5 V1.1.0 (2011-09)

European Standard
Access, Terminals, Transmission and Multiplexing (ATTM);
Third Generation Transmission Systems for
Interactive Cable Television Services - IP Cable Modems;
Part 5: Security Services;
DOCSIS 3.0
2 Final draft ETSI EN 302 878-5 V1.1.0 (2011-09)

Reference
DEN/ATTM-003006-5
Keywords
access, broadband, cable, data, IP, IPCable,
modem
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88

Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
http://portal.etsi.org/tb/status/status.asp
If you find errors in the present document, please send your comment to one of the following services:
http://portal.etsi.org/chaircor/ETSI_support.asp
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.

© European Telecommunications Standards Institute 2011.
All rights reserved.
TM TM TM
DECT , PLUGTESTS , UMTS and the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members.
TM
3GPP and LTE™ are Trade Marks of ETSI registered for the benefit of its Members and
of the 3GPP Organizational Partners.
GSM® and the GSM logo are Trade Marks registered and owned by the GSM Association.
ETSI
3 Final draft ETSI EN 302 878-5 V1.1.0 (2011-09)
Contents
Intellectual Property Rights . 10
Foreword . 10
1 Scope . 11
1.1 Introduction and Purpose . 11
1.2 Requirements . 11
1.3 Conventions . 11
2 References . 11
2.1 Normative references . 12
2.2 Informative references . 13
3 Definitions and abbreviations . 14
3.1 Definitions . 14
3.2 Abbreviations . 14
4 Void . 16
5 Overview . . 16
5.1 New DOCSIS 3.0 Security Features. 16
5.2 Technical Overview . 17
5.2.1 BPI+ Architecture . 17
5.2.1.1 Packet Data Encryption . 17
5.2.1.2 Key Management Protocol . 17
5.2.1.3 DOCSIS Security Associations . 18
5.2.1.4 QoS SIDs and DOCSIS SAIDs . 19
5.2.1.5 BPI+ Enforce. 19
5.2.2 Secure Provisioning . 20
5.3 Operation . 20
5.3.1 Cable Modem Initialization . 20
5.3.1.1 Network Admission Control . 21
5.3.1.2 EAE and Authentication Reuse . 21
5.3.1.3 Configuration Registration Enforcement . 21
5.3.2 Cable Modem Key Update Mechanism . 22
5.3.3 Cable Modem Secure Software Download . 22
6 Encrypted DOCSIS MAC Frame Formats . 22
6.1 CM Requirements. 22
6.2 CMTS Requirements . 22
6.3 Variable-Length PDU MAC Frame Format . 23
6.3.1 Baseline Privacy Extended Header Formats . 24
6.4 Fragmentation MAC Frame Format . 25
6.5 Registration Request (REG-REQ-MP) MAC Management Messages. 26
6.6 Use of the Baseline Privacy Extended Header in the MAC Header . 28
7 Baseline Privacy Key Management (BPKM) Protocol . 28
7.1 State Models . 28
7.1.1 Introduction. 28
7.1.1.1 Authorization State Machine Overview . 28
7.1.1.2 TEK State Machine Overview . 30
7.1.2 Encrypted Multicast . 31
7.1.2.1 Signaling of Dynamic and Static Multicast Session SAs when MDF is Disabled . 32
7.1.2.2 Signaling of Dynamic and Static Multicast Session SAs when MDF is Enabled . 32
7.1.2.2.1 Requirements Specific to the Signaling of Dynamic SAs for Dynamic Multicast Sessions . 32
7.1.2.2.2 Requirements Specific to the Signaling of Dynamic SAs for Static Multicast Sessions . 33
7.1.3 Selecting Cryptographic Suites . 33
7.1.4 Authorization State Machine . 34
7.1.4.1 Brief Description of States . 35
7.1.4.1.1 [Start] . 35
ETSI
4 Final draft ETSI EN 302 878-5 V1.1.0 (2011-09)
7.1.4.1.2 [Auth Wait] . 35
7.1.4.1.3 [Authorized] . 35
7.1.4.1.4 [Reauth Wait] . 35
7.1.4.1.5 [Auth Reject Wait] . 35
7.1.4.1.6 [Silent] . 36
7.1.4.2 Brief Description of Messages . 36
7.1.4.2.1 Authorization Request (Auth Request) . 36
7.1.4.2.2 Authorization Reply (Auth Reply) . 36
7.1.4.2.3 Authorization Reject (Auth Reject) . 36
7.1.4.2.4 Authorization Invalid (Auth Invalid) . 36
7.1.4.2.5 Authentication Information (Auth Info) . 36
7.1.4.3 Brief Description of Events . 37
7.1.4.3.1 {Initiate Authentication} . 37
7.1.4.3.2 {Timeout} . 37
7.1.4.3.3 {Auth Grace Timeout} . 37
7.1.4.3.4 {Reauth} . 37
7.1.4.3.5 {Auth Invalid} . 37
7.1.4.3.6 {Perm Auth Reject} . 37
7.1.4.3.7 {Auth Reject} . 37
7.1.4.3.8 {EAE Disabled Auth Reject} . 37
7.1.4.4 Events sent to TEK State Machine . 37
7.1.4.4.1 {TEK Stop} . 38
7.1.4.4.2 {TEK Authorized} . 38
7.1.4.4.3 {Auth Pend} . 38
7.1.4.4.4 {Auth Comp} . 38
7.1.4.5 Brief Description of Timing Parameters . 38
7.1.4.5.1 Authorize Wait Timeout (Auth Wait Timeout) . 38
7.1.4.5.2 Reauthorize Wait Timeout (Reauth Wait Timeout). 38
7.1.4.5.3 Authorization Grace Time (Auth Grace Timeout). 38
7.1.4.5.4 Authorize Reject Wait Timeout (Auth Reject Wait Timeout) . 38
7.1.4.6 Timers . 38
7.1.4.6.1 Authorization Request . 38
7.1.4.6.2 Authorization Reject . 38
7.1.4.6.3 Authorization Grace . 38
7.1.4.7 Actions . 39
7.1.5 TEK State Machine . 41
7.1.5.1 Brief Description of States . 42
7.1.5.1.1 [Start] . 42
7.1.5.1.2 [Op Wait] . 42
7.1.5.1.3 [Op Reauth Wait] . 42
7.1.5.1.4 [Op] . 42
7.1.5.1.5 [Rekey Wait] . 42
7.1.5.1.6 [Rekey Reauth Wait] . 42
7.1.5.2 Brief Description of Messages . 42
7.1.5.2.1 Key Request . 42
7.1.5.2.2 Key Reply . 43
7.1.5.2.3 Key Reject . 43
7.1.5.2.4 TEK Invalid . 43
7.1.5.3 Brief Description of Events . 43
7.1.5.3.1 {Stop} . 43
7.1.5.3.2 {Authorized} . 43
7.1.5.3.3 {Auth Pend} . 43
7.1.5.3.4 {Auth Comp} . 43
7.1.5.3.5 {TEK Invalid} . 43
7.1.5.3.6 {Timeout} . 43
7.1.5.3.7 {TEK Refresh Timeout} . 43
7.1.5.4 Brief Description of Timing Parameters . 43
7.1.5.4.1 Operational Wait Timeout . 44
7.1.5.4.2 Rekey Wait Timeout . 44
7.1.5.4.3 TEK Grace Time . 44
7.1.5.5 Timers . 44
7.1.5.5.1 Key Request Retry . 44
ETSI
5 Final draft ETSI EN 302 878-5 V1.1.0 (2011-09)
7.1.5.5.2 TEK Refresh . 44
7.1.5.6 Actions . 44
7.2 Key Management Message Formats. 46
7.2.1 Packet Formats . 46
7.2.1.1 Authorization Request (Auth Request) . 48
7.2.1.2 Authorization Reply (Auth Reply) . 48
7.2.1.3 Authorization Reject (Auth Reject) . 49
7.2.1.4 Key Request . 49
7.2.1.5 Key Reply . 50
7.2.1.6 Key Reject . 50
7.2.1.7 Authorization Invalid . 51
7.2.1.8 TEK Invalid. 51
7.2.1.9 Authentication Information (Auth Info) . 51
7.2.1.10 SA Map Request (MAP Request) . 52
7.2.1.11 SA Map Reply (Map Reply) . 52
7.2.1.12 SA Map Reject (Map Reject) . 52
7.2.2 BPKM Attributes . 53
7.2.2.1 Serial-Number . 54
7.2.2.2 Manufacturer-ID . 54
7.2.2.3 MAC-Address . 55
7.2.2.4 RSA-Public-Key . 55
7.2.2.5 CM-Identification . 55
7.2.2.6 Display-String . 56
7.2.2.7 Auth-Key . 56
7.2.2.8 TEK . 56
7.2.2.9 Key-Lifetime . 56
7.2.2.10 Key-Sequence-Number . 57
7.2.2.11 HMAC-Digest . 57
7.2.2.12 SAID . 57
7.2.2.13 TEK-Parameters . 57
7.2.2.14 CBC-IV . 58
7.2.2.15 Error-Code . 58
7.2.2.16 Vendor-Defined . 59
7.2.2.17 CA-Certificate . 59
7.2.2.18 CM-Certificate . 60
7.2.2.19 Security-Capabilities . 60
7.2.2.20 Cryptographic-Suite . 60
7.2.2.21 Cryptographic-Suite-List . 61
7.2.2.22 BPI-Version . 61
7.2.2.23 SA-Descriptor . 61
7.2.2.24 SA-Type . 62
7.2.2.25 SA-Query . 62
7.2.2.26 SA-Query-T ype . 63
7.2.2.27 IPv4-Address . 63
7.2.2.28 Download-Parameters . 63
7.2.2.29 CVC-Root-CA-Certificate . 63
7.2.2.30 CVC-CA-Certificate . 64
8 Early Authentication and Encryption (EAE) . 64
8.1 Introduction . 64
8.2 EAE Signaling . 64
8.3 EAE Encryption . 66
8.4 EAE Enforcement. 66
8.4.1 CMTS and CM behaviours when EAE is Enabled . 66
8.4.2 EAE enforcement determination . 67
8.4.2.1 Ranging-Based EAE Enforcement . 67
8.4.2.2 Capability-Based EAE Enforcement . 67
8.4.2.3 Total EAE Enforcement . 67
8.4.3 EAE Enforcement of DHCP Traffic . 67
8.4.4 CMTS and CM Behaviour when EAE is Disabled . 67
8.4.5 EAE Exclusion List . 67
8.4.6 Interoperability issues . 68
ETSI
6 Final draft ETSI EN 302 878-5 V1.1.0 (2011-09)
8.5 Authentication Reuse . 68
8.6 BPI+ Control by Configuration File . 68
8.6.1 EAE Enabled . 68
8.6.2 EAE Disabled . 69
9 Secure Provisioning . 69
9.1 Introduction . 69
9.2 Encryption of Provisioning Messages . 69
9.3 Securing DHCP . 69
9.3.1 Securing DHCP on the Cable Network Link . 69
9.3.2 DHCPv6 . 69
9.4 TFTP Configuration File Security . 70
9.4.1 Introduction. 70
9.4.2 CMTS Security Features for Configuration File Download . 70
9.4.2.1 TFTP Proxy . 70
9.4.2.2 Protecting TFTP Server Addresses . 70
9.4.2.3 Configuration File Name Authorization. 70
9.4.2.4 Configuration File Learning . 71
9.4.2.5 TFTP Options for CM's MAC and IP Address . 71
9.5 Securing REG-REQ-MP Messages . 71
9.6 Source Address Verification. 71
9.7 Address Resolution Security Considerations . 73
10 Using Cryptographic Keys . 74
10.1 CMTS . 74
10.2 Cable Modem . 76
10.3 Authentication of Dynamic Service Requests . 77
10.3.1 CM . 77
10.3.2 CMTS . 77
11 Cryptographic Methods . 77
11.1 Packet Data Encryption . 77
11.2 Encryption of the TEK . 78
11.3 HMAC-Digest Algorithm . 79
11.4 TEKs, KEKs and Message Authentication Keys . 79
11.5 Public-Key Encryption of Authorization Key . 79
11.6 Digital Signatures . 80
11.7 The MMH-MIC . 80
11.7.1 The MMH Function . 80
11.7.1.1 MMH[16, σ, 1] . 80
11.7.1.2 MMH[16, σ, n] . 82
11.7.1.3 MMH[16, σ, 4] . 82
11.7.1.4 Handling Variable-Size Data . 82
11.7.2 Definition of MMH-MAC . 82
11.7.3 Calculating the DOCSIS MMH-MAC . 83
11.7.4 MMH Key Derivation for CMTS Extended MIC . 84
11.7.5 Shared Secret Recommendations . 85
11.7.6 Key Generation Function . 85
12 Physical Protection of Keys in the CM . 85
13 BPI+ X.509 Certificate Profile and Management . 86
13.1 BPI+ Certificate Management Architecture Overview . 86
13.2 Cable Modem Certificate Storage and Management in the CM . 88
13.3 Certificate Processing and Management in the CMTS . 89
13.3.1 CMTS Certificate Management Model. 89
13.3.2 Certificate Validation . 89
13.4 Certificate Revocation . 90
13.4.1 Certificate Revocation Lists . 90
13.4.1.1 CMTS CRL Support . 91
13.4.2 Online Certificate Status Protocol . 91
14 Secure Software Download . 92
14.1 Introduction . 92
ETSI
7 Final draft ETSI EN 302 878-5 V1.1.0 (2011-09)
14.2 Overview . 92
14.3 Software Code Upgrade Requirements . 94
14.3.1 Code File Processing Requirements . 94
14.3.2 Code File Access Controls . 95
14.3.2.1 Subject Organization Names . 95
14.3.2.2 Time Varying Controls . 95
14.3.3 Cable Modem Code Upgrade Initialization . 95
14.3.3.1 Manufacturer Initialization . 96
14.3.3.2 Network Initialization . 96
14.3.3.2.1 Processing the Configuration File CVC . 97
14.3.3.2.2 Processing the SNMP CVC . 97
14.3.4 Code Signing Guidelines . 98
14.3.5 Code Verification Requirements . 98
14.3.5.1 Cable Modem Code Verification Steps . 98
14.3.6 DOCSIS Interoperability . 99
14.3.7 Error Codes . 99
14.4 Security Considerations (Informative) . 100
Annex A (normative): TFTP Configuration File Extensions . 102
A.1 Encodings . 102
A.1.1 Baseline Privacy Configuration Setting . 102
A.1.1.1 Internal Baseline Privacy Encodings . 102
A.1.1.1.1 Authorize Wait Timeout . 102
A.1.1.1.2 Reauthorize Wait Timeout . 102
A.1.1.1.3 Authorization Grace Time . 103
A.1.1.1.4 Operational Wait Timeout . 103
A.1.1.1.5 Rekey Wait Timeout . 103
A.1.1.1.6 TEK Grace Time . 103
A.1.1.1.7 Authorize Reject Wait Timeout . 103
A.1.1.1.8 SA Map Wait Timeout . 103
A.1.1.1.9 SA Map Max Retries . 103
A.2 Parameter Guidelines . 104
Annex B (normative): TFTP Options . 105
Annex C (normative): DOCSIS 1.1/2.0 Dynamic Security Associations . 113
C.1 Introduction . 113
C.2 Theory of Operation . 113
C.3 SA Mapping State Model . 114
C.3.1 Brief Description of States . 115
C.3.1.1 [Start] .
...


European Standard
Access, Terminals, Transmission and Multiplexing (ATTM);
Third Generation Transmission Systems for
Interactive Cable Television Services - IP Cable Modems;
Part 5: Security Services;
DOCSIS 3.0
2 ETSI EN 302 878-5 V1.1.1 (2011-11)

Reference
DEN/ATTM-003006-5
Keywords
access, broadband, cable, data, IP, IPCable,
modem
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88

Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
http://portal.etsi.org/tb/status/status.asp
If you find errors in the present document, please send your comment to one of the following services:
http://portal.etsi.org/chaircor/ETSI_support.asp
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.

© European Telecommunications Standards Institute 2011.
All rights reserved.
TM TM TM
DECT , PLUGTESTS , UMTS and the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members.
TM
3GPP and LTE™ are Trade Marks of ETSI registered for the benefit of its Members and
of the 3GPP Organizational Partners.
GSM® and the GSM logo are Trade Marks registered and owned by the GSM Association.
ETSI
3 ETSI EN 302 878-5 V1.1.1 (2011-11)
Contents
Intellectual Property Rights . 10
Foreword . 10
1 Scope . 11
1.1 Introduction and Purpose . 11
1.2 Requirements . 11
1.3 Conventions . 11
2 References . 11
2.1 Normative references . 12
2.2 Informative references . 13
3 Definitions and abbreviations . 14
3.1 Definitions . 14
3.2 Abbreviations . 14
4 Void . 16
5 Overview . . 16
5.1 New DOCSIS 3.0 Security Features. 16
5.2 Technical Overview . 17
5.2.1 BPI+ Architecture . 17
5.2.1.1 Packet Data Encryption . 17
5.2.1.2 Key Management Protocol . 17
5.2.1.3 DOCSIS Security Associations . 18
5.2.1.4 QoS SIDs and DOCSIS SAIDs . 19
5.2.1.5 BPI+ Enforce. 19
5.2.2 Secure Provisioning . 20
5.3 Operation . 20
5.3.1 Cable Modem Initialization . 20
5.3.1.1 Network Admission Control . 21
5.3.1.2 EAE and Authentication Reuse . 21
5.3.1.3 Configuration Registration Enforcement . 21
5.3.2 Cable Modem Key Update Mechanism . 22
5.3.3 Cable Modem Secure Software Download . 22
6 Encrypted DOCSIS MAC Frame Formats . 22
6.1 CM Requirements. 22
6.2 CMTS Requirements . 22
6.3 Variable-Length PDU MAC Frame Format . 23
6.3.1 Baseline Privacy Extended Header Formats . 24
6.4 Fragmentation MAC Frame Format . 25
6.5 Registration Request (REG-REQ-MP) MAC Management Messages. 26
6.6 Use of the Baseline Privacy Extended Header in the MAC Header . 28
7 Baseline Privacy Key Management (BPKM) Protocol . 28
7.1 State Models . 28
7.1.1 Introduction. 28
7.1.1.1 Authorization State Machine Overview . 28
7.1.1.2 TEK State Machine Overview . 30
7.1.2 Encrypted Multicast . 31
7.1.2.1 Signaling of Dynamic and Static Multicast Session SAs when MDF is Disabled . 32
7.1.2.2 Signaling of Dynamic and Static Multicast Session SAs when MDF is Enabled . 32
7.1.2.2.1 Requirements Specific to the Signaling of Dynamic SAs for Dynamic Multicast Sessions . 32
7.1.2.2.2 Requirements Specific to the Signaling of Dynamic SAs for Static Multicast Sessions . 33
7.1.3 Selecting Cryptographic Suites . 33
7.1.4 Authorization State Machine . 34
7.1.4.1 Brief Description of States . 35
7.1.4.1.1 [Start] . 35
ETSI
4 ETSI EN 302 878-5 V1.1.1 (2011-11)
7.1.4.1.2 [Auth Wait] . 35
7.1.4.1.3 [Authorized] . 35
7.1.4.1.4 [Reauth Wait] . 35
7.1.4.1.5 [Auth Reject Wait] . 35
7.1.4.1.6 [Silent] . 36
7.1.4.2 Brief Description of Messages . 36
7.1.4.2.1 Authorization Request (Auth Request) . 36
7.1.4.2.2 Authorization Reply (Auth Reply) . 36
7.1.4.2.3 Authorization Reject (Auth Reject) . 36
7.1.4.2.4 Authorization Invalid (Auth Invalid) . 36
7.1.4.2.5 Authentication Information (Auth Info) . 36
7.1.4.3 Brief Description of Events . 37
7.1.4.3.1 {Initiate Authentication} . 37
7.1.4.3.2 {Timeout} . 37
7.1.4.3.3 {Auth Grace Timeout} . 37
7.1.4.3.4 {Reauth} . 37
7.1.4.3.5 {Auth Invalid} . 37
7.1.4.3.6 {Perm Auth Reject} . 37
7.1.4.3.7 {Auth Reject} . 37
7.1.4.3.8 {EAE Disabled Auth Reject} . 37
7.1.4.4 Events sent to TEK State Machine . 37
7.1.4.4.1 {TEK Stop} . 38
7.1.4.4.2 {TEK Authorized} . 38
7.1.4.4.3 {Auth Pend} . 38
7.1.4.4.4 {Auth Comp} . 38
7.1.4.5 Brief Description of Timing Parameters . 38
7.1.4.5.1 Authorize Wait Timeout (Auth Wait Timeout) . 38
7.1.4.5.2 Reauthorize Wait Timeout (Reauth Wait Timeout). 38
7.1.4.5.3 Authorization Grace Time (Auth Grace Timeout). 38
7.1.4.5.4 Authorize Reject Wait Timeout (Auth Reject Wait Timeout) . 38
7.1.4.6 Timers . 38
7.1.4.6.1 Authorization Request . 38
7.1.4.6.2 Authorization Reject . 38
7.1.4.6.3 Authorization Grace . 38
7.1.4.7 Actions . 39
7.1.5 TEK State Machine . 41
7.1.5.1 Brief Description of States . 42
7.1.5.1.1 [Start] . 42
7.1.5.1.2 [Op Wait] . 42
7.1.5.1.3 [Op Reauth Wait] . 42
7.1.5.1.4 [Op] . 42
7.1.5.1.5 [Rekey Wait] . 42
7.1.5.1.6 [Rekey Reauth Wait] . 42
7.1.5.2 Brief Description of Messages . 42
7.1.5.2.1 Key Request . 42
7.1.5.2.2 Key Reply . 43
7.1.5.2.3 Key Reject . 43
7.1.5.2.4 TEK Invalid . 43
7.1.5.3 Brief Description of Events . 43
7.1.5.3.1 {Stop} . 43
7.1.5.3.2 {Authorized} . 43
7.1.5.3.3 {Auth Pend} . 43
7.1.5.3.4 {Auth Comp} . 43
7.1.5.3.5 {TEK Invalid} . 43
7.1.5.3.6 {Timeout} . 43
7.1.5.3.7 {TEK Refresh Timeout} . 43
7.1.5.4 Brief Description of Timing Parameters . 43
7.1.5.4.1 Operational Wait Timeout . 44
7.1.5.4.2 Rekey Wait Timeout . 44
7.1.5.4.3 TEK Grace Time . 44
7.1.5.5 Timers . 44
7.1.5.5.1 Key Request Retry . 44
ETSI
5 ETSI EN 302 878-5 V1.1.1 (2011-11)
7.1.5.5.2 TEK Refresh . 44
7.1.5.6 Actions . 44
7.2 Key Management Message Formats. 46
7.2.1 Packet Formats . 46
7.2.1.1 Authorization Request (Auth Request) . 48
7.2.1.2 Authorization Reply (Auth Reply) . 48
7.2.1.3 Authorization Reject (Auth Reject) . 49
7.2.1.4 Key Request . 49
7.2.1.5 Key Reply . 50
7.2.1.6 Key Reject . 50
7.2.1.7 Authorization Invalid . 51
7.2.1.8 TEK Invalid. 51
7.2.1.9 Authentication Information (Auth Info) . 51
7.2.1.10 SA Map Request (MAP Request) . 52
7.2.1.11 SA Map Reply (Map Reply) . 52
7.2.1.12 SA Map Reject (Map Reject) . 52
7.2.2 BPKM Attributes . 53
7.2.2.1 Serial-Number . 54
7.2.2.2 Manufacturer-ID . 54
7.2.2.3 MAC-Address . 55
7.2.2.4 RSA-Public-Key . 55
7.2.2.5 CM-Identification . 55
7.2.2.6 Display-String . 56
7.2.2.7 Auth-Key . 56
7.2.2.8 TEK . 56
7.2.2.9 Key-Lifetime . 56
7.2.2.10 Key-Sequence-Number . 57
7.2.2.11 HMAC-Digest . 57
7.2.2.12 SAID . 57
7.2.2.13 TEK-Parameters . 57
7.2.2.14 CBC-IV . 58
7.2.2.15 Error-Code . 58
7.2.2.16 Vendor-Defined . 59
7.2.2.17 CA-Certificate . 59
7.2.2.18 CM-Certificate . 60
7.2.2.19 Security-Capabilities . 60
7.2.2.20 Cryptographic-Suite . 60
7.2.2.21 Cryptographic-Suite-List . 61
7.2.2.22 BPI-Version . 61
7.2.2.23 SA-Descriptor . 61
7.2.2.24 SA-Type . 62
7.2.2.25 SA-Query . 62
7.2.2.26 SA-Query-T ype . 63
7.2.2.27 IPv4-Address . 63
7.2.2.28 Download-Parameters . 63
7.2.2.29 CVC-Root-CA-Certificate . 63
7.2.2.30 CVC-CA-Certificate . 64
8 Early Authentication and Encryption (EAE) . 64
8.1 Introduction . 64
8.2 EAE Signaling . 64
8.3 EAE Encryption . 66
8.4 EAE Enforcement. 66
8.4.1 CMTS and CM behaviours when EAE is Enabled . 66
8.4.2 EAE enforcement determination . 67
8.4.2.1 Ranging-Based EAE Enforcement . 67
8.4.2.2 Capability-Based EAE Enforcement . 67
8.4.2.3 Total EAE Enforcement . 67
8.4.3 EAE Enforcement of DHCP Traffic . 67
8.4.4 CMTS and CM Behaviour when EAE is Disabled . 67
8.4.5 EAE Exclusion List . 67
8.4.6 Interoperability issues . 68
ETSI
6 ETSI EN 302 878-5 V1.1.1 (2011-11)
8.5 Authentication Reuse . 68
8.6 BPI+ Control by Configuration File . 68
8.6.1 EAE Enabled . 68
8.6.2 EAE Disabled . 69
9 Secure Provisioning . 69
9.1 Introduction . 69
9.2 Encryption of Provisioning Messages . 69
9.3 Securing DHCP . 69
9.3.1 Securing DHCP on the Cable Network Link . 69
9.3.2 DHCPv6 . 69
9.4 TFTP Configuration File Security . 70
9.4.1 Introduction. 70
9.4.2 CMTS Security Features for Configuration File Download . 70
9.4.2.1 TFTP Proxy . 70
9.4.2.2 Protecting TFTP Server Addresses . 70
9.4.2.3 Configuration File Name Authorization. 70
9.4.2.4 Configuration File Learning . 71
9.4.2.5 TFTP Options for CM's MAC and IP Address . 71
9.5 Securing REG-REQ-MP Messages . 71
9.6 Source Address Verification. 71
9.7 Address Resolution Security Considerations . 73
10 Using Cryptographic Keys . 74
10.1 CMTS . 74
10.2 Cable Modem . 76
10.3 Authentication of Dynamic Service Requests . 77
10.3.1 CM . 77
10.3.2 CMTS . 77
11 Cryptographic Methods . 77
11.1 Packet Data Encryption . 77
11.2 Encryption of the TEK . 78
11.3 HMAC-Digest Algorithm . 79
11.4 TEKs, KEKs and Message Authentication Keys . 79
11.5 Public-Key Encryption of Authorization Key . 79
11.6 Digital Signatures . 80
11.7 The MMH-MIC . 80
11.7.1 The MMH Function . 80
11.7.1.1 MMH[16, σ, 1] . 80
11.7.1.2 MMH[16, σ, n] . 82
11.7.1.3 MMH[16, σ, 4] . 82
11.7.1.4 Handling Variable-Size Data . 82
11.7.2 Definition of MMH-MAC . 82
11.7.3 Calculating the DOCSIS MMH-MAC . 83
11.7.4 MMH Key Derivation for CMTS Extended MIC . 84
11.7.5 Shared Secret Recommendations . 85
11.7.6 Key Generation Function . 85
12 Physical Protection of Keys in the CM . 85
13 BPI+ X.509 Certificate Profile and Management . 86
13.1 BPI+ Certificate Management Architecture Overview . 86
13.2 Cable Modem Certificate Storage and Management in the CM . 88
13.3 Certificate Processing and Management in the CMTS . 89
13.3.1 CMTS Certificate Management Model. 89
13.3.2 Certificate Validation . 89
13.4 Certificate Revocation . 90
13.4.1 Certificate Revocation Lists . 90
13.4.1.1 CMTS CRL Support . 91
13.4.2 Online Certificate Status Protocol . 91
14 Secure Software Download . 92
14.1 Introduction . 92
ETSI
7 ETSI EN 302 878-5 V1.1.1 (2011-11)
14.2 Overview . 92
14.3 Software Code Upgrade Requirements . 94
14.3.1 Code File Processing Requirements . 94
14.3.2 Code File Access Controls . 95
14.3.2.1 Subject Organization Names . 95
14.3.2.2 Time Varying Controls . 95
14.3.3 Cable Modem Code Upgrade Initialization . 95
14.3.3.1 Manufacturer Initialization . 96
14.3.3.2 Network Initialization . 96
14.3.3.2.1 Processing the Configuration File CVC . 97
14.3.3.2.2 Processing the SNMP CVC . 97
14.3.4 Code Signing Guidelines . 98
14.3.5 Code Verification Requirements . 98
14.3.5.1 Cable Modem Code Verification Steps . 98
14.3.6 DOCSIS Interoperability . 99
14.3.7 Error Codes . 99
14.4 Security Considerations (Informative) . 100
Annex A (normative): TFTP Configuration File Extensions . 102
A.1 Encodings . 102
A.1.1 Baseline Privacy Configuration Setting . 102
A.1.1.1 Internal Baseline Privacy Encodings . 102
A.1.1.1.1 Authorize Wait Timeout . 102
A.1.1.1.2 Reauthorize Wait Timeout . 102
A.1.1.1.3 Authorization Grace Time . 103
A.1.1.1.4 Operational Wait Timeout . 103
A.1.1.1.5 Rekey Wait Timeout . 103
A.1.1.1.6 TEK Grace Time . 103
A.1.1.1.7 Authorize Reject Wait Timeout . 103
A.1.1.1.8 SA Map Wait Timeout . 103
A.1.1.1.9 SA Map Max Retries . 103
A.2 Parameter Guidelines . 104
Annex B (normative): TFTP Options . 105
Annex C (normative): DOCSIS 1.1/2.0 Dynamic Security Associations . 113
C.1 Introduction . 113
C.2 Theory of Operation . 113
C.3 SA Mapping State Model . 114
C.3.1 Brief Description of States . 115
C.3.1.1 [Start] . 115
C.3.1.2 [Map W
...


SLOVENSKI STANDARD
01-februar-2012
'RVWRSSULNOMXþNLSUHQRVLQPXOWLSOHNVLUDQMH $770 7UHWMDJHQHUDFLMDSUHQRVQLK
VLVWHPRY]DVWRULWYHLQWHUDNWLYQHNDEHOVNHWHOHYL]LMH,3NDEHOVNLPRGHPLGHO
9DUQRVWQHVWRULWYH'2&6,6
Access, Terminals, Transmission and Multiplexing (ATTM) - Third Generation
Transmission Systems for Interactive Cable Television Services - IP Cable Modems -
Part 5: Security Services - DOCSIS 3.0
Ta slovenski standard je istoveten z: EN 302 878-5 Version 1.1.1
ICS:
35.180 Terminalska in druga IT Terminal and other
periferna oprema IT peripheral equipment
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

European Standard
Access, Terminals, Transmission and Multiplexing (ATTM);
Third Generation Transmission Systems for
Interactive Cable Television Services - IP Cable Modems;
Part 5: Security Services;
DOCSIS 3.0
2 ETSI EN 302 878-5 V1.1.1 (2011-11)

Reference
DEN/ATTM-003006-5
Keywords
access, broadband, cable, data, IP, IPCable,
modem
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88

Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
http://portal.etsi.org/tb/status/status.asp
If you find errors in the present document, please send your comment to one of the following services:
http://portal.etsi.org/chaircor/ETSI_support.asp
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.

© European Telecommunications Standards Institute 2011.
All rights reserved.
TM TM TM
DECT , PLUGTESTS , UMTS and the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members.
TM
3GPP and LTE™ are Trade Marks of ETSI registered for the benefit of its Members and
of the 3GPP Organizational Partners.
GSM® and the GSM logo are Trade Marks registered and owned by the GSM Association.
ETSI
3 ETSI EN 302 878-5 V1.1.1 (2011-11)
Contents
Intellectual Property Rights . 10
Foreword . 10
1 Scope . 11
1.1 Introduction and Purpose . 11
1.2 Requirements . 11
1.3 Conventions . 11
2 References . 11
2.1 Normative references . 12
2.2 Informative references . 13
3 Definitions and abbreviations . 14
3.1 Definitions . 14
3.2 Abbreviations . 14
4 Void . 16
5 Overview . . 16
5.1 New DOCSIS 3.0 Security Features. 16
5.2 Technical Overview . 17
5.2.1 BPI+ Architecture . 17
5.2.1.1 Packet Data Encryption . 17
5.2.1.2 Key Management Protocol . 17
5.2.1.3 DOCSIS Security Associations . 18
5.2.1.4 QoS SIDs and DOCSIS SAIDs . 19
5.2.1.5 BPI+ Enforce. 19
5.2.2 Secure Provisioning . 20
5.3 Operation . 20
5.3.1 Cable Modem Initialization . 20
5.3.1.1 Network Admission Control . 21
5.3.1.2 EAE and Authentication Reuse . 21
5.3.1.3 Configuration Registration Enforcement . 21
5.3.2 Cable Modem Key Update Mechanism . 22
5.3.3 Cable Modem Secure Software Download . 22
6 Encrypted DOCSIS MAC Frame Formats . 22
6.1 CM Requirements. 22
6.2 CMTS Requirements . 22
6.3 Variable-Length PDU MAC Frame Format . 23
6.3.1 Baseline Privacy Extended Header Formats . 24
6.4 Fragmentation MAC Frame Format . 25
6.5 Registration Request (REG-REQ-MP) MAC Management Messages. 26
6.6 Use of the Baseline Privacy Extended Header in the MAC Header . 28
7 Baseline Privacy Key Management (BPKM) Protocol . 28
7.1 State Models . 28
7.1.1 Introduction. 28
7.1.1.1 Authorization State Machine Overview . 28
7.1.1.2 TEK State Machine Overview . 30
7.1.2 Encrypted Multicast . 31
7.1.2.1 Signaling of Dynamic and Static Multicast Session SAs when MDF is Disabled . 32
7.1.2.2 Signaling of Dynamic and Static Multicast Session SAs when MDF is Enabled . 32
7.1.2.2.1 Requirements Specific to the Signaling of Dynamic SAs for Dynamic Multicast Sessions . 32
7.1.2.2.2 Requirements Specific to the Signaling of Dynamic SAs for Static Multicast Sessions . 33
7.1.3 Selecting Cryptographic Suites . 33
7.1.4 Authorization State Machine . 34
7.1.4.1 Brief Description of States . 35
7.1.4.1.1 [Start] . 35
ETSI
4 ETSI EN 302 878-5 V1.1.1 (2011-11)
7.1.4.1.2 [Auth Wait] . 35
7.1.4.1.3 [Authorized] . 35
7.1.4.1.4 [Reauth Wait] . 35
7.1.4.1.5 [Auth Reject Wait] . 35
7.1.4.1.6 [Silent] . 36
7.1.4.2 Brief Description of Messages . 36
7.1.4.2.1 Authorization Request (Auth Request) . 36
7.1.4.2.2 Authorization Reply (Auth Reply) . 36
7.1.4.2.3 Authorization Reject (Auth Reject) . 36
7.1.4.2.4 Authorization Invalid (Auth Invalid) . 36
7.1.4.2.5 Authentication Information (Auth Info) . 36
7.1.4.3 Brief Description of Events . 37
7.1.4.3.1 {Initiate Authentication} . 37
7.1.4.3.2 {Timeout} . 37
7.1.4.3.3 {Auth Grace Timeout} . 37
7.1.4.3.4 {Reauth} . 37
7.1.4.3.5 {Auth Invalid} . 37
7.1.4.3.6 {Perm Auth Reject} . 37
7.1.4.3.7 {Auth Reject} . 37
7.1.4.3.8 {EAE Disabled Auth Reject} . 37
7.1.4.4 Events sent to TEK State Machine . 37
7.1.4.4.1 {TEK Stop} . 38
7.1.4.4.2 {TEK Authorized} . 38
7.1.4.4.3 {Auth Pend} . 38
7.1.4.4.4 {Auth Comp} . 38
7.1.4.5 Brief Description of Timing Parameters . 38
7.1.4.5.1 Authorize Wait Timeout (Auth Wait Timeout) . 38
7.1.4.5.2 Reauthorize Wait Timeout (Reauth Wait Timeout). 38
7.1.4.5.3 Authorization Grace Time (Auth Grace Timeout). 38
7.1.4.5.4 Authorize Reject Wait Timeout (Auth Reject Wait Timeout) . 38
7.1.4.6 Timers . 38
7.1.4.6.1 Authorization Request . 38
7.1.4.6.2 Authorization Reject . 38
7.1.4.6.3 Authorization Grace . 38
7.1.4.7 Actions . 39
7.1.5 TEK State Machine . 41
7.1.5.1 Brief Description of States . 42
7.1.5.1.1 [Start] . 42
7.1.5.1.2 [Op Wait] . 42
7.1.5.1.3 [Op Reauth Wait] . 42
7.1.5.1.4 [Op] . 42
7.1.5.1.5 [Rekey Wait] . 42
7.1.5.1.6 [Rekey Reauth Wait] . 42
7.1.5.2 Brief Description of Messages . 42
7.1.5.2.1 Key Request . 42
7.1.5.2.2 Key Reply . 43
7.1.5.2.3 Key Reject . 43
7.1.5.2.4 TEK Invalid . 43
7.1.5.3 Brief Description of Events . 43
7.1.5.3.1 {Stop} . 43
7.1.5.3.2 {Authorized} . 43
7.1.5.3.3 {Auth Pend} . 43
7.1.5.3.4 {Auth Comp} . 43
7.1.5.3.5 {TEK Invalid} . 43
7.1.5.3.6 {Timeout} . 43
7.1.5.3.7 {TEK Refresh Timeout} . 43
7.1.5.4 Brief Description of Timing Parameters . 43
7.1.5.4.1 Operational Wait Timeout . 44
7.1.5.4.2 Rekey Wait Timeout . 44
7.1.5.4.3 TEK Grace Time . 44
7.1.5.5 Timers . 44
7.1.5.5.1 Key Request Retry . 44
ETSI
5 ETSI EN 302 878-5 V1.1.1 (2011-11)
7.1.5.5.2 TEK Refresh . 44
7.1.5.6 Actions . 44
7.2 Key Management Message Formats. 46
7.2.1 Packet Formats . 46
7.2.1.1 Authorization Request (Auth Request) . 48
7.2.1.2 Authorization Reply (Auth Reply) . 48
7.2.1.3 Authorization Reject (Auth Reject) . 49
7.2.1.4 Key Request . 49
7.2.1.5 Key Reply . 50
7.2.1.6 Key Reject . 50
7.2.1.7 Authorization Invalid . 51
7.2.1.8 TEK Invalid. 51
7.2.1.9 Authentication Information (Auth Info) . 51
7.2.1.10 SA Map Request (MAP Request) . 52
7.2.1.11 SA Map Reply (Map Reply) . 52
7.2.1.12 SA Map Reject (Map Reject) . 52
7.2.2 BPKM Attributes . 53
7.2.2.1 Serial-Number . 54
7.2.2.2 Manufacturer-ID . 54
7.2.2.3 MAC-Address . 55
7.2.2.4 RSA-Public-Key . 55
7.2.2.5 CM-Identification . 55
7.2.2.6 Display-String . 56
7.2.2.7 Auth-Key . 56
7.2.2.8 TEK . 56
7.2.2.9 Key-Lifetime . 56
7.2.2.10 Key-Sequence-Number . 57
7.2.2.11 HMAC-Digest . 57
7.2.2.12 SAID . 57
7.2.2.13 TEK-Parameters . 57
7.2.2.14 CBC-IV . 58
7.2.2.15 Error-Code . 58
7.2.2.16 Vendor-Defined . 59
7.2.2.17 CA-Certificate . 59
7.2.2.18 CM-Certificate . 60
7.2.2.19 Security-Capabilities . 60
7.2.2.20 Cryptographic-Suite . 60
7.2.2.21 Cryptographic-Suite-List . 61
7.2.2.22 BPI-Version . 61
7.2.2.23 SA-Descriptor . 61
7.2.2.24 SA-Type . 62
7.2.2.25 SA-Query . 62
7.2.2.26 SA-Query-T ype . 63
7.2.2.27 IPv4-Address . 63
7.2.2.28 Download-Parameters . 63
7.2.2.29 CVC-Root-CA-Certificate . 63
7.2.2.30 CVC-CA-Certificate . 64
8 Early Authentication and Encryption (EAE) . 64
8.1 Introduction . 64
8.2 EAE Signaling . 64
8.3 EAE Encryption . 66
8.4 EAE Enforcement. 66
8.4.1 CMTS and CM behaviours when EAE is Enabled . 66
8.4.2 EAE enforcement determination . 67
8.4.2.1 Ranging-Based EAE Enforcement . 67
8.4.2.2 Capability-Based EAE Enforcement . 67
8.4.2.3 Total EAE Enforcement . 67
8.4.3 EAE Enforcement of DHCP Traffic . 67
8.4.4 CMTS and CM Behaviour when EAE is Disabled . 67
8.4.5 EAE Exclusion List . 67
8.4.6 Interoperability issues . 68
ETSI
6 ETSI EN 302 878-5 V1.1.1 (2011-11)
8.5 Authentication Reuse . 68
8.6 BPI+ Control by Configuration File . 68
8.6.1 EAE Enabled . 68
8.6.2 EAE Disabled . 69
9 Secure Provisioning . 69
9.1 Introduction . 69
9.2 Encryption of Provisioning Messages . 69
9.3 Securing DHCP . 69
9.3.1 Securing DHCP on the Cable Network Link . 69
9.3.2 DHCPv6 . 69
9.4 TFTP Configuration File Security . 70
9.4.1 Introduction. 70
9.4.2 CMTS Security Features for Configuration File Download . 70
9.4.2.1 TFTP Proxy . 70
9.4.2.2 Protecting TFTP Server Addresses . 70
9.4.2.3 Configuration File Name Authorization. 70
9.4.2.4 Configuration File Learning . 71
9.4.2.5 TFTP Options for CM's MAC and IP Address . 71
9.5 Securing REG-REQ-MP Messages . 71
9.6 Source Address Verification. 71
9.7 Address Resolution Security Considerations . 73
10 Using Cryptographic Keys . 74
10.1 CMTS . 74
10.2 Cable Modem . 76
10.3 Authentication of Dynamic Service Requests . 77
10.3.1 CM . 77
10.3.2 CMTS . 77
11 Cryptographic Methods . 77
11.1 Packet Data Encryption . 77
11.2 Encryption of the TEK . 78
11.3 HMAC-Digest Algorithm . 79
11.4 TEKs, KEKs and Message Authentication Keys . 79
11.5 Public-Key Encryption of Authorization Key . 79
11.6 Digital Signatures . 80
11.7 The MMH-MIC . 80
11.7.1 The MMH Function . 80
11.7.1.1 MMH[16, σ, 1] . 80
11.7.1.2 MMH[16, σ, n] . 82
11.7.1.3 MMH[16, σ, 4] . 82
11.7.1.4 Handling Variable-Size Data . 82
11.7.2 Definition of MMH-MAC . 82
11.7.3 Calculating the DOCSIS MMH-MAC . 83
11.7.4 MMH Key Derivation for CMTS Extended MIC . 84
11.7.5 Shared Secret Recommendations . 85
11.7.6 Key Generation Function . 85
12 Physical Protection of Keys in the CM . 85
13 BPI+ X.509 Certificate Profile and Management . 86
13.1 BPI+ Certificate Management Architecture Overview . 86
13.2 Cable Modem Certificate Storage and Management in the CM . 88
13.3 Certificate Processing and Management in the CMTS . 89
13.3.1 CMTS Certificate Management Model. 89
13.3.2 Certificate Validation . 89
13.4 Certificate Revocation . 90
13.4.1 Certificate Revocation Lists . 90
13.4.1.1 CMTS CRL Support . 91
13.4.2 Online Certificate Status Protocol . 91
14 Secure Software Download . 92
14.1 Introduction . 92
ETSI
7 ETSI EN 302 878-5 V1.1.1 (2011-11)
14.2 Overview . 92
14.3 Software Code Upgrade Requirements . 94
14.3.1 Code File Processing Requirements . 94
14.3.2 Code File Access Controls . 95
14.3.2.1 Subject Organization Names . 95
14.3.2.2 Time Varying Controls . 95
14.3.3 Cable Modem Code Upgrade Initialization . 95
14.3.3.1 Manufacturer Initialization . 96
14.3.3.2 Network Initialization . 96
14.3.3.2.1 Processing the Configuration File CVC . 97
14.3.3.2.2 Processing the SNMP CVC . 97
14.3.4 Code Signing Guidelines . 98
14.3.5 Code Verification Requirements . 98
14.3.5.1 Cable Modem Code Verification Steps . 98
14.3.6 DOCSIS Interoperability . 99
14.3.7 Error Codes . 99
14.4 Security Considerations (Informative) . 100
Annex A (normative): TFTP Configuration File Extensions . 102
A.1 Encodings . 102
A.1.1 Baseline Privacy Configuration Setting . 102
A.1.1.1 Internal Baseline Privacy Encodings . 102
A.1.1.1.1 Authorize Wait Timeout . 102
A.1.1.1.2 Reauthorize Wait Timeout . 102
A.1.1.1.3 Authorization Grace Time . 103
A.1.1.1.4 Operational Wait Timeout . 103
A.1.1.1.5 Rekey Wait Timeout . 103
A.1.1.1.6 TEK Grace Time . 103
A.1.1.1.7 Authorize Reject Wait Timeout . 103
A.1.1.1.8 SA Map Wait Timeout . 103
A.1.1.1.9 SA Map Max Retries . 103
A.2 Parameter Guidelines .
...