Avaya G250 and G250-BRI Branch Office Media Gateways w/FIPS Non-Proprietary Security Policy
Version 1.2 Wednesday, 14 December, 2005
© 2005 Avaya Inc.
May be reproduced only in its original entirety [without revision]. Page 16 of 23
CID 106595
5.3.
Definition of Critical Security Parameters (CSPs)
The following are CSPs contained in the module:
Key
Description/Usage
IKE Pre-shared Keys
IKE Pre-Shared key is used to establish the IKE SKEYID_d during
pre-shared key authentication, as part of the commercially available
IKE key establishment process that meet the requirements specified
in FIPS PUB 140-2 Annex D.
HASH_I, HASH_R
Used for generation of SKEYID, SKEYID_d, SKEYID_a,
SKEYID_e. Generated for VPN IKE Phase 1 key establishment.
IKE Pre-shared Session Key (SKEYID)
Generated for VPN IKE Phase 1 by hashing pre-shared keys with
responder/receiver nonce.
IKE Ephemeral DH shared secret (g^ab)
Generated for VPN IKE Phase 1 key establishment.
IKE Ephemeral DH private key (a)
The private exponent used in DH exchange. Generated for VPN IKE
Phase 1 key establishment.
IKE Session Phase 1 Secret (SKEYID_d)
Phase 1 key used to derive keying material for IPSec Sas.
IKE Session Phase 1 HMAC Key
(SKEYID_a)
Key used for integrity and authentication of the ISAKMP SA.
IKE Session Phase 1 Encrypted Key
(SKEYID_e)
Shared key used for extraction of encryption keys protecting the
ISAKMP SA.
IKE Session Phase 1 TDES key
Key used for TDES data encryption of ISAKMP SA.
IKE Session Phase 1 DES key
Key used for DES data encryption of ISAKMP SA.
IKE Session Phase 1 AES key
Key used for AES data encryption of ISAKMP SA.
Noncei, Noncer
Phase 2 initiator and responder nonce.
IPSEC SA Phase-2 TDES key
Phase 2, basic quick mode
IPSEC SA Phase-2 DES key
Phase 2, basic quick mode
IPSEC SA Phase-2 AES key
Phase 2, basic quick mode
IPSEC SA Phase-2 HMAC key
Phase 2, basic quick mode
IKE Ephemeral Phase-2 DH private key
Phase 2 Diffie Hellman private keys used in PFS for key renewal.
IKE Ephemeral Phase-2 DH shared secret
Phase 2 Diffie Hellman shared secret used in PFS for key renewal.
User password
Used for password authentication of CLI users.
Root password
Used for authentication of default CLI user during first setup.