Encryption Key Loading Guide
9
© Tait Electronics Limited September 2006
Configuring Encryption Operation
In addition to loading secure key data into the Tait P25 equipment, you
need to configure the way the equipment uses these keys. Configuration
settings refer to keys by name, so before you can select a key, you must give
it a name.
Because the secure key data is invisible, you have to name keys by mapping
a name to a CKR number. This is done in a Keys table. You add a row for
each key and ensure that each row contains a suitable name and CKR.
Once you have a set of named keys, you can choose which one to assign to
each channel profile (mobiles and portables) or calling profile (P25 Console
Gateway) that supports encryption.
When the equipment encrypts a call, its default operation is to look in the
current profile for the key name, and then to read the CKR number
corresponding to that name. The CKR number tells it where to go in the
secure key data storage area to obtain the encryption key data it needs.
This indirect way of referring to keys by name makes it possible to update
keys without changing the configuration. You simply use the key fill device
to load different secure key data using the same CKR numbers.
Secure key data loaded
from
Configuration settings
Profile
1
2
No.
Name
Tx & Rx
Freqs
1
Ch 001
2
Ch 002
Channel table
Profiles
Key table
Name
CKR
Key 01
25
Key 02
35
Profile 3
Profile 2
Profile 1
Encryption:
Key 01
Variable
******
******
CKR
KeyID AlgID
25
3
DES
35
4
AES