Advanced Encryption Standard (AES) is a widely used specification for data encryption. The AES standards describe a symmetric key algorithm. AES has a fixed block size of 128 bits and a key size of 128, 192, or 256 bits. Avaya Aura® Release 6.3 Feature Pack 4 supports AES-256 as part of TLS support over control channels. From Release 7.0, the AES-256 support extends to secure media streams.
To enable Media encryption feature, two more encryption choices are available for the Media encryption field on the ip-codec-set SAT screen. The choices are as follows:
-
srtp-aescm256-hmac80
-
srtp-aescm256-hmac32
Before Release 7.0, the Media Encryption field supported only three profiles. Release 7.0 onwards, the field supports five profiles.
You can add the following profiles to Media Encryption:
-
10-srtp-aescm256-hmac80
-
11-srtp-aescm256-hmac32
-
1-srtp-aescm128-hmac80
-
2-srtp-aescm128-hmac32
-
None
The AES-256 feature is supported on G450 Branch Gateway, G430 Branch Gateway, and Avaya Aura® Media Server (MS).
When you enable the AES-256 feature, Communication Manager determines the capability exchange with G450 Branch Gateway, G430 Branch Gateway, or Avaya Aura® Media Server (MS) and the 96x1 SIP phone. To establish call connections for media services encrypted with AES-256, an SDP media descriptor exchange occurs. During this exchange, Communication Manager functions as a back-to-back user agent. In this role, Communication Manager supports policy management over the SIP endpoints when the endpoints exercise capability negotiation.