Encryption- CKR and keysets
Posted: Mon Sep 24, 2012 10:03 am
I am trying to understand the different ways that CKR can be used in combination with KID in A25 mode and LID in ASN mode. I have read through the topics on CKR/KID/LID/PID etc but still have a few questions.
Here's the situation:
The system is 700/800 P25 Digital trunked. Mcc7500 consoles with multikey secure cards. There is NO KMF. Keyloading will be done to each radio and console with a KVL4000. The KVL4000 has ADP, AES256 and AES-GCM. We will be using AES256 on our local talkgroups, and ADP to only use for the local county talkgroup that has ADP already in place on their radios. Radios are APX mobiles and portables and XTL5k mobiles with multikey hardware kits.
I'm trying to understand If I can use the PID mode/slots to accomplish using two keysets in the users radios. For example: For the first time period the users would use Keyset A and for the second time period the users would use Keyset B. During the second time period, the users radios would be touched for maintenance and a new set of keys for Keyset A. When they rotate back to the new Keyset A, the radios would come in for maintenance and a new set of keys for Keyset B. This would continue ad infinitum...
I'm just not clear on how to accomplish such a thing or if it's possible. I know that Console/Trunking controller systems reference to the CKR and a certain AES256 TEK for that talkgroup. Can what I am envisioning happen by using the PID slots in conjunction with a Keyset menu item? -By using the A25 mode KID that is associated with the CKR # and then referencing that KID to the associated LID that is loaded into the appropriate time period's keyset slot via ASN mode???
Yes, using the KMF and OTAR would be the solution but there is no funding for that currently. Yes, it would be easy to just stay with a single key and not rotate keys/keysets. Yes, the operations of a small town agency could be considered "not that critical to worry about encryption and all of the trouble."
Thoughts?
Thanks in advance!
JJ
Here's the situation:
The system is 700/800 P25 Digital trunked. Mcc7500 consoles with multikey secure cards. There is NO KMF. Keyloading will be done to each radio and console with a KVL4000. The KVL4000 has ADP, AES256 and AES-GCM. We will be using AES256 on our local talkgroups, and ADP to only use for the local county talkgroup that has ADP already in place on their radios. Radios are APX mobiles and portables and XTL5k mobiles with multikey hardware kits.
I'm trying to understand If I can use the PID mode/slots to accomplish using two keysets in the users radios. For example: For the first time period the users would use Keyset A and for the second time period the users would use Keyset B. During the second time period, the users radios would be touched for maintenance and a new set of keys for Keyset A. When they rotate back to the new Keyset A, the radios would come in for maintenance and a new set of keys for Keyset B. This would continue ad infinitum...
I'm just not clear on how to accomplish such a thing or if it's possible. I know that Console/Trunking controller systems reference to the CKR and a certain AES256 TEK for that talkgroup. Can what I am envisioning happen by using the PID slots in conjunction with a Keyset menu item? -By using the A25 mode KID that is associated with the CKR # and then referencing that KID to the associated LID that is loaded into the appropriate time period's keyset slot via ASN mode???
Yes, using the KMF and OTAR would be the solution but there is no funding for that currently. Yes, it would be easy to just stay with a single key and not rotate keys/keysets. Yes, the operations of a small town agency could be considered "not that critical to worry about encryption and all of the trouble."
Thoughts?
Thanks in advance!
JJ