Specifications

DOCSIS 1.1 for Cisco uBR905 and Cisco uBR925 Cable Access Routers and Cisco CVA122 Cable Voice Adapters
Information About DOCSIS 1.1 Support
15
Cisco IOS Release 12.2(15)CZ
Ability to provide separate downstream rates for any given cable modem, based on the
IP-precedence value in the packet. This helps separate voice signaling and data traffic that goes to
the same ITCM to address rate shaping purposes.
Concatenation allows a cable modem to send several packets in one large burst, instead of having to
make a separate grant request for each.
Caution All DOCSIS 1.0 extensions are available only when using a cable modem (such as the Cisco uBR924
cable access router) and CMTS (such as the Cisco uBR7200 series universal broadband router) that
supports these extensions. The cable modem activates the use of the extensions by sending a dynamic
MAC message. DOCSIS 1.0 cable modems continue to receive DOCSIS 1.0 treatment from the CMTS.
SNMPv3 Support
DOCSIS 1.1 also requires support of v3 of the Simple Network Management Protocol (SNMPv3).
SNMPv3 offers a number of significant improvements over SNMPv1 and SNMPv2:
DES 56-bit encryption that encrypts each packet to prevent interception or alteration intransit.
SNMP attributes can be set and retrieved without exposing confidential information on a public
network.
Authentication based on the HMAC-MD5 or HMAC-SHA algorithms that ensures that each packet
is from a valid source.
An improved security model that provides for a larger number of security levels, with a greater
granularity in determining per-user access. Each SNMPv3 user belongs to a group, which defines
the security model and security level for its users. This includes the level of access to SNMP objects
and the list of notifications that users can receive.
SNMPv3 Diffie-Hellman Kickstart
To ensure SNMPv3 security, the Multi-Service Operator (MSO) must perform an initialization
procedure the first time the cable modem comes online. This procedure, which the DOCSIS 1.1
specification refers to as the SNMPv3 Diffie-Hellman Kickstart, sends a public key to the cable modem
as part of the DOCSIS configuration file. The cable modem creates a secret number and encrypts it using
the public key it received in the configuration file.
The cable modem then publishes the encrypted number to the CMTS, which uses its private key to
decrypt it so as to produce the cable modem’s secret number. This secret number becomes a shared secret
value that the CMTS and CM can use to exchange SNMPv3 encryption keys.
For information on the SNMPv3 Diffie-Hellman Kickstart configuration, see the “Configuring the
SNMPv3 Diffie-Hellman Kickstart Public Key” section on page 22.
MIB Enhancements
DOCSIS 1.1 also expands the MIB support for SNMP management, including the following changes and
additions to the DOCSIS 1.0 MIB structure:
DOCS-BPI-PLUS-MIB—Describes the Baseline Privacy Interface Plus (BPI+) attributes and
replaces the DOCS-BPI-MIB, which was used in DOCSIS 1.0. This is revision 05 of the MIB.
DOCS-QOS-MIB—Describes the quality-of-service (QoS) attributes. This is revision 04 of the
MIB.