MPM-1000A Operator Manual
1000-7075 Rev E
15-6
15.10 Recovery Protocol Actions at the Initiating Terminal
The initiating NM Terminal transmits a Zeroize message addressed to the compromised
node. The initiating NM transmits a Zeroize message in each successive assigned
ROW slot until acknowledged by the NC. If the node being zeroized is not itself, the NC
will perform the actions identified in 15.11.
Upon receipt of a Zeroize message, the named node will purge all keys, passphrases
and other sensitive parameters including the network-forwarding table from memory.
This purge is immediate and automatic, and takes place without the possibility of
operator intervention. Because of this purge, a node is rendered incapable of
participating in a network without manual re-keying.
If the compromised node is the NC, an unplanned handover protocol will be invoked
when the NC is zeroized. If this occurs, the NM repeats the protocol immediately
following reestablishment of the network.
Following the transmission of each Zeroize message, the initiating NM will monitor the
FOW for an acknowledgement that the Zeroize message was received by the NC
(potentially a new NC). If the FOW indicates that the NC received the message, the NM
will then discontinue transmission of Zeroize messages.
15.11 Recovery Protocol Actions at the Network Controller
Upon receipt of a Zeroize message, the NC will perform the following compromise
recovery steps.
The NC will begin transmitting a Zeroize message addressed to the compromised node.
The NC will continue to transmit the Zeroize message in each frame until the MSK
changeover process is complete.
On receipt of a Zeroize message, the compromised node will purge its memory
(Zeroize) as described above.
Using an uncompromised Terminal, Modem operators will initiate the MSK changeover
procedure to distribute a new MSK to all nodes. The currently active MEK will continue
to be used for message encryption until the changeover is complete. A new TRANSEC
Passphrase should also be distributed via a secure channel (e.g. SVOW) prior to the
changeover. This will isolate a compromised Terminal that fails to Zeroize due to
equipment failure or loss of power.
The NC will cease transmitting the Zeroize message to the compromised Terminal
when the MSK changeover procedure is completed.