9.2.4  

Upgrade HiPath 3000 for Signalling & Payload Encryption (SPE) 
 

Overview  
The Signaling & Payload encryption feature is provided in HiPath 3000/5000 V7 R4 or higher. If a software version lower than V7 R4 is in use, it must be upgraded before the SPE feature can be used in HiPath 3000. Please refer to the published release notes.
A hardware upgrade is not required. As a result of the increased demand by SPE for resources further HG 1500 boards might be required.

9.2.4.1  

Upgrading 
If a software version lower than V7 R4 is in use, the following software upgrades must be performed before the SPE feature can be used without restriction:
 •   Upgrade of all HFA terminals to an SPE-enabled software version
    Due to the introduction of EFC, HiPath 3000 V7 and higher is no longer upwardly compatible with regard to the "Signaling & Payload Encryption" feature, except to HiPath  3000 V6.0 systems which have an EFC-enabled HG 1500 and EFC-enabled IP terminals.
 •   Upgrade of all HG 1500 gateways to V8
 •   Upgrade of the HiPath 3000/5000 to V8. The "VoIP Security" feature must be deactivated before upgrading a HiPath 3000/5000 V7 to HiPathV83000/5000  . This is necessary due to the fact that this feature is not compatible with the "Signaling & Payload Encryption (SPE) feature described here.
 •   Upgrade of administration program DLS and HiPath Manager E
 •   Configuration changes so that SIP-Q is used instead of CorNet-IP to network HiPath 3000 with HiPath 4000 V4.0 systems. The HiPath 4000 supports SPE only via the SIP-Q protocol.
   
In HiPath 3000 V8 and HiPath 4000 V5 and later systems, only SIP-Q V2 protocol is supported for IP networking of these two systems. CorNet-IP protocol is no longer supported.  
 •   Changes to the configuration of the "Always use DSP" option if HiPath 4000 networking should still be achieved using H.323-Q (CorNet-IP). In this case no SPE to the HiPath 4000 is possible.
 •   In HiPath 3000/5000 V7 and higher, the HiPath 4000 must be connected as an external H.323 gatekeeper or external SIP registrar.

9.2.4.2  

Additional System Load 

Overview  
Activation of the Signalling & Payload Encryption feature has the following consequences for the HiPath network:
 •   Higher bandwidth requirement due to continuous TLS sessions for:
   -   Connections to HFA terminals (CorNet-IP TC/TS, H.225 CS)
   -   Connections for SIP terminals (SIP including SDP)
   -   H.323 and SIP trunking connections
 •   Higher bandwidth requirement:
   -   Due to the fill and authentication algorithms used by TLS during transmission of user data
   -   Due to the proprietary encryption protocols used for IPDA and CTI connections
   -   Due to SRTP/SRTCP
 •   Higher network traffic due to periodic downloads of CRL (Certificate Revocation List) or delta CRL by each Gateway
 •   Higher network traffic due to recently introduced protocols
   -   H.235 Annex D for DMC Slave connections
   -   MIKEY messages
 •   Additional data due to protocol extensions:
   -   CorNet-TC/TS plus X messages
   -   H.225 RAS (LEGK communication)
   -   CorNet NQ
Because of the many configuration options and scenarios possible, it is difficult to accurately determine the effects of this feature on the system, that is, the additional bandwidth requirement and the increased data traffic volume. The following sections are intended as suggestions on how to calculate the additional system load.

Increased bandwidth requirement with SRTP  
The table provides an overview of the increase in bandwidth requirements caused by the SRTP. The bandwidth is assumed to rise by 70 bytes as a result of RTP, UDP, IP, 802.1Q VLAN tagging and MAC (incl. preamble, FCS). SRTP accounts for an additional increase of 10 bytes. This brings the overall increase to 80 bytes.

 Voice codec  
 Sample duration  
 Payload  
 Ethernet data packet size  
 RTP
Ethernet bandwidth incl. preamble  
 SRTP Ethernet bandwidth incl. preamble  
 SRTP  
 Increased Ethernet bandwidth  
 
 (ms)  
 (bytes)  
 (bytes)  
 (Kbps)  
 (Kbps)  
 (%)  
G.711  
 20  
 160  
 240  
 92  
 96  
 4.3  
 
 40  
 320  
 400  
 78  
 80  
 2.6  
 
 60  
 480  
 560  
 73.3  
 74.7  
 1.9  
G.723.1  
 30  
 24  
 104  
 25.1  
 27.7  
 10.4  
G.723.1A  
 60  
 48  
 128  
 15.7  
 17.1  
 8.9  
G.729A  
 20  
 20  
 100  
 36  
 40  
 11.1  
 
 40  
 40  
 120  
 22  
 24  
 9.1  
 
 60  
 60  
 140  
 17.3  
 18.7  
 8.1  
G.729A DMC Master Call  
 100  
 6  
 86  
 6.1  
 6.9  
 13.1  
G.711 DMC Master Call  
 100  
 11  
 91  
 6.5  
 7.3  
 12.3  
G.723 DMC Master Call  
 90  
 6  
 86  
 6.8  
 7.6  
 11.8  

Higher demand for resources by SPE  
The following table provides an overview of the higher demand for resources caused by the SPE (Signaling & Payload Encryption) feature. The values are automatically applied by the system. If the SPE feature is active, a reduced number of channels is reported to the system.

 Feature  
 Max. number of voice channels (per DSP)  
 Loss  
 HG 1500  
 STMI2  
 HG 1500  
 HXGS3  
 HXGR3  
Standard  
 16  
 8  
 0%  
QDC  
 16  
 8  
 6%  
SRTP  
 12  
 6  
 20%  
DMC  
 12  
 6  
 25%  
QDC+ SRTP  
 12  
 6  
 24%  
QDC+DMC  
 12  
 6  
 28%  
SRTP+DMC  
 10  
 5  
 37%  
QDC+SRTP+DMC  
 10  
 5  
 39%  

Higher data volume as a result of SPE  
This table can be used to calculate the additional system load resulting from the Signaling & Payload Encryption (SPE) feature:

Feature  
Approximate data volume  
Explanations  
TLS session:  
 
These are 1-KB certificates that do not support hierarchical certification. Precisely one certificate or precisely two certificates are therefore transferred via LAN.  
 •   Server authentication
1.5 KB  
 •   Both-way authentication
2.5 KB  
Fixed data volume for TLS encryption  
+ 20 to 30 bytes per message  
AES_128_CBC_SHA1 is assumed.  
CRL  
250 bytes to several MB  
The CRL size depends on the theoretically unlimited number of CRL entries (= revoked certificates). The entry is 40 bytes in size (ASN.1-enoded), therefore, for example:  
 •   CRL with 250 entries: ~10 KB
 •   CRL with 1000 entries: ~40 KB
CorNet-TC/TS  
+ ~70 bytes/call  
Key for DMC and display updates  
CorNet NQ  
+ ~60 bytes/call  
Security procedure and key for DMC  
H.225 RAS  
+ ~10 bytes/call  
Security  
H.235 Annex D  
+ ~10 bytes/packet  
Authentication code  
MIKEY  
~200 bytes to 2 KB per message  
In MIKEY options #0 and #1, a MIKEY message is ~200 bytes long, in #3, the length of the message increases by 2 KB on account of the certificate included.  
Proprietary encryption protocol  
50 bytes for encryption messages  
+ up to 15 bytes/message to pad the message if it is less than 16 bytes in size.  
+ 10 bytes/message if the authentication code was configured.  
SRTP  
+ 10 bytes/packet  
Authentication code (MKI not used)  
SRTCP  
+ 14 bytes/packet  
Authentication code and SRTCP index  
If the individual data volumes are added together, then the per-call data traffic increases in the LAN as follows:
 •   for a local call: 2 KB
(60 CorNet TC + 4 H.225 CS messages over TLS + 2 MIKEY#0 messages)
 •   for an external call: 700 bytes
(12 H.225 CS messages incl. CorNet NQ messages over TLS + 2 MIKEY#0 messages)
The increased data traffic volume in payload connections is mainly due to the authentication code of 10 bytes, which is added to every data packet as a result of SRTP. The additional data volume due to SRTCP is negligible.