Chapter 5: Radio Configuration
Configuring AES-256 Payload Encryption
phn-3963_004v000
Page 5-16
Configuring AES-256 Payload Encryption
Note
This feature is not supported with MIMO links.
This feature requires:
Requires an activation key. If no valid AES activation key has been applied to the unit, AES will
not operate on the unit. See
Configuring the Activation Key.
For PTP 820S and PTP 820C, any
radio manufactured after July 1, 2015, is AES hardware-ready. An easy way to validate this is
to check the radio’s S/N number. S/N’s starting F265xxx and above are AES hardware-ready.
Note
In order for the AES activation key to become active, you must reset the unit after
configuring a valid AES activation key. Until the unit is reset, an alarm will be present if
you enable AES. This is not the case for other activation keys.
PTP 820C and PTP 820S support AES-256 payload encryption. AES is enabled and configured
separately for each radio carrier.
PTP 820 uses a dual-key encryption mechanism for AES:
The user provides a master key. The master key can also be generated by the system upon
user command. The master key is a 32-byte symmetric encryption key. The same master key
must be manually configured on both ends of the encrypted link.
The session key is a 32-byte symmetric encryption key used to encrypt the actual data. Each
link uses two session keys, one for each direction. For each direction, the session key is
generated by the transmit side unit and propagated automatically, via a Key Exchange
Protocol, to the other side of the link. The Key Exchange Protocol exchanges session keys by
encrypting them with the master key, using the AES-256 encryption algorithm. Session keys
are regenerated at user-configured intervals.
AES key generation is completely hitless, and has no effect on ACM operation.
To configure payload encryption:
1
Select Radio > Payload Encryption. The Payload Encryption page opens.
Interface Configuration page opens.
o
For PTP 820C units, the Payload Encryption page initially displays a table as shown in
o
For PTP 820S units, a page appears, similar to
(which shows in PTP 820C
page).