C H A P T E R
4-1
Cisco uBR7200 Series Universal Broadband Router Software Configuration Guide
OL-2239-03
4
Configuring DOCSIS Baseline Privacy Interface
on the Cisco uBR7200 Series
This chapter describes the DOCSIS 1.0 Baseline Privacy Interface (BPI), guidelines for configuring
DOCSIS BPI on the Cisco uBR7200 series, and features of DOCSIS 1.1 Baseline Privacy Interface Plus
(BPI+). This chapter contains the following sections:
Baseline Privacy Interface Overview
Baseline Privacy Interface (BPI) is defined as a set of extended services within the DOCSIS MAC sublayer. BPI
gives subscribers data privacy across the RF network, encrypting traffic flows between the CMTS and CM.
Note
Encryption/decryption is subject to export licensing controls.
The level of data privacy is roughly equivalent to that provided by dedicated line network access services
such as analog modems or digital subscriber lines (DSL). BPI provides basic protection of service,
ensuring that a CM, uniquely identified by its MAC address, can obtain keying material for services only
it is authorized to access.
Note
Because DOCSIS 1.0 BPI does not authenticate CMs, it does not protect against users employing cloned
CMs masquerading as authorized CMs. Specific Cisco IOS releases provide protection against spoofing,
and provide supporting commands that can be used to configure source IP filtering on RF subnets to
prevent a user from using a source IP address that is not valid for the connected IP subnet.
BPI extends the definition of the MAC sublayer’s SID. The
DOCSIS RF Interface Specification
(viewable at
http://www.cablemodem.com/specifications/
) defines a SID as a mapping between CMTS
and CM to allocate upstream bandwidth and class of service management. When BPI is activated, the
SID also identifies a particular security association and has upstream and downstream significance.
Section
Description
“Baseline Privacy Interface Overview”
section on page 4-1
Provides a description of DOCSIS 1.0 BPI, BPI key
management, CM cummunication with the BPI, and
illustrations.
“Enabling DOCSIS BPI” section on
page 4-3
Provides guidelines for enabling DOCSIS 1.0 BPI on the
Cisco uBR7200 series.
“DOCSIS 1.1 Baseline Privacy Interface
Plus Overview” section on page 4-4
Provides an overview of the features in DOCSIS 1.1 BPI+.