background image

  

Encryption Key Loading Guide

9

© Tait Electronics Limited September 2006

Configuring Encryption Operation

In addition to loading secure key data into the Tait P25 equipment, you 
need to configure the way the equipment uses these keys. Configuration 
settings refer to keys by name, so before you can select a key, you must give 
it a name. 

Because the secure key data is invisible, you have to name keys by mapping 
a name to a CKR number. This is done in a Keys table. You add a row for 
each key and ensure that each row contains a suitable name and CKR.   

Once you have a set of named keys, you can choose which one to assign to 
each channel profile (mobiles and portables) or calling profile (P25 Console 
Gateway) that supports encryption.

When the equipment encrypts a call, its default operation is to look in the 
current profile for the key name, and then to read the CKR number 
corresponding to that name. The CKR number tells it where to go in the 
secure key data storage area to obtain the encryption key data it needs. 

This indirect way of referring to keys by name makes it possible to update 
keys without changing the configuration. You simply use the key fill device 
to load different secure key data using the same CKR numbers.

Secure key data loaded

from 

Configuration settings

Profile

1

2

No.

Name

Tx & Rx

Freqs

1

Ch 001

2

Ch 002

Channel table

Profiles

Key table

Name

CKR

Key 01

25

Key 02

35

Profile 3

Profile 2

Profile 1

Encryption:
Key 01

Variable

******

******

CKR

KeyID AlgID

25

3

DES

35

4

AES

Summary of Contents for P25

Page 1: ...Tait P25 products Encryption Key Loading Guide MTA 00004 02 Issue 2 September 2006 ...

Page 2: ...cal issues contact Technical Support E mail support taitworld com Website http support taitworld com Tait Electronics Limited is an environmentally responsible company which supports waste minimization and material recovery The European Union s Waste Electrical and Electronic Equipment Directive requires that this product be disposed of separately from the general waste stream when its service lif...

Page 3: ... Electronics Limited September 2006 Contents Equipment Required 4 Encryption Overview 5 Entering Encryption Keys 6 Connecting the KVL3000 to the Target Device 7 Loading Keys 8 Supported KVL3000 Tasks 8 Configuring Encryption Operation 9 ...

Page 4: ...upplements the KVL3000 documentation with information on how to use the KVL3000 with Tait equipment For instructions on how to use the KVL3000 see the KVL3000 User s Guide Equipment Required Motorola KVL3000 key fill device with the following battery charger user s guide option for ASTRO P25 mode option for ASN mode required for operation in ASTRO P25 mode option for DES DES XL DES OFB encryption ...

Page 5: ...Algorithm ID which specifies which encryption algorithm is to be used DES OFB or AES Key variable a multi digit number that the crypto module uses when encrypting and decrypting In addition the Tait TM9000 TP9000 programming software for mobiles and portables or Customer Service Software for the P25 Console Gateway gives each CKR a name Only the CKR is visible to the software Motorola KVL3000 Key ...

Page 6: ... system will need following the instructions for ASTRO 25 operation in the KVL3000 User s Guide Important Make sure that you follow your organization s security pol icy when handling keys If encryption information falls into unauthorized hands the security of voice communications could be compromised The CKR can be any number from 1 to 4095 For example if all radios will use the same keys you can ...

Page 7: ... use Connecting the KVL3000 to the Target Device 1 Connect the cable attached to the Tait adapter to the keyload port on the back of the KVL3000 This cable provides power from the KVL3000 to the adapter 2 Connect the other end of the adapter to the target device using the appropriate cabling For a TM9100 mobile connect a TPA SV 006 programming lead 9 pin to RJ12 to the programming microphone port ...

Page 8: ...ice is a P25 Console Gateway it automatically resets Supported KVL3000 Tasks The following table indicates which KVL3000 tasks can be carried out on Tait target devices These tasks must be carried out in ASTRO P25 mode The KVL3000 has two operational modes ASTRO P25 and ASN Only ASTRO P25 mode applies to Tait equipment KVL3000 Task Supported by Tait Equipment Load a key Yes Load a group of keys Ye...

Page 9: ...biles and portables or calling profile P25 Console Gateway that supports encryption When the equipment encrypts a call its default operation is to look in the current profile for the key name and then to read the CKR number corresponding to that name The CKR number tells it where to go in the secure key data storage area to obtain the encryption key data it needs This indirect way of referring to ...

Page 10: ...IFY REVERSE COMPILE OR REVERSE ASSEMBLE ANY SOFTWARE OR FIRMWARE IN WHOLE OR PART Important Notice THE SOFTWARE OR FIRMWARE MAY CONTAIN OPEN SOURCE SOFTWARE COMPONENTS OPEN SOURCE COMPONENTS OPEN SOURCE COMPONENTS ARE EXCLUDED FROM THE TERMS OF THIS AGREEMENT EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT AND ARE COVERED BY THE TERMS OF THEIR RESPECTIVE LICENCES WHICH MAY EXCLUDE OR LIMIT ANY WARRAN...

Page 11: ...S SOLE AND TOTAL LIABILITY FOR ANY SUCH CLAIM SHALL BE LIMITED AT THE OPTION OF TAIT TO THE REPAIR OR REPLACEMENT OF THE SOFTWARE OR FIRMWARE OR THE REFUND OF THE PURCHASE PRICE OF THE SOFTWARE OR FIRMWARE General THE LICENSEE CONFIRMS THAT IT SHALL COMPLY WITH THE PROVISIONS OF LAW IN RELATION TO THE SOFTWARE OR FIRMWARE Law and Jurisdiction THIS AGREEMENT SHALL BE SUBJECT TO AND CONSTRUED IN ACC...

Page 12: ...12 Encryption Key Loading Guide Tait Electronics Limited September 2006 ...

Reviews: