December 2006
5100 ES Model II/III Portable Radio Operating Manual 10-11
Secure Communication (Encryption)
Logical Link ID (LLID)
- An ID transmitted with a CAI data message to identify the
destination of the message.
Message Number Period (MNP)
- The maximum difference between message numbers
that can occur before a message is declared invalid (see Section 10.4.4).
Over-The-Air-Rekeying (OTAR)
- The process of sending new encryption keys over the
air using an RF interface.
Red
- Refers to information that is not encrypted. The opposite is “Black”.
Rekey
- The process of preparing, sending, and loading encryption keys into a subscriber
unit for current or future use. This may be done over-the-air (OTAR) or by directly
connecting a keyloader to the subscriber unit.
Radio Set Identifier (RSI)
- Subscriber units are programmed with one or two Radio Set
Identifier (RSI) numbers that identify the unit for OTAR purposes. The RSI can be unique
to an individual subscriber unit or unique to a group of subscriber units. An individual
(unit) RSI is always assigned and a group RSIs may be assigned. The individual RSI is
typically programmed when the subscriber unit is initially brought into service. The KMF
is also identified by an RSI (KMFRSI) to use as the destination of any KMMs a subscriber
unit originates. The KMMs (Key Management Messages) generated by the KMF (Key
Management Facility) are addressed to a specific RSI.
Storage Location Number (SLN)
- A link to a specific TEK in a given keyset. A given
SLN can contain two keys, one for the active keyset and one for the inactive keyset. SLNs
and CKRs are equivalent terms (see Section 10.2).
Traffic Encryption Key (TEK)
- A key used to encrypt voice or data. The other type of
key is the Key Encryption Key (KEK) which is used to encrypt keys contained in Key
Management Messages. TEKs can be either the AES or DES type.
Unique Key Encryption Key (UKEK)
- A KEK unique to a particular subscriber unit.
Refer to “KEK” for more information. These keys can be either the AES or DES type.
Zeroize
- The process of deleting all keys from a compromised subscriber unit to disable
it. To make the unit encryptionally functional again, the keys must be reloaded by a
keyloader.
10.5 Radio Setup For Encryption
10.5.1 General Encryption Setup
The following radio setup is required for encryption regardless of whether OTAR is used:
Summary of Contents for 5100 ES II
Page 2: ......
Page 4: ......
Page 6: ......
Page 24: ...1 4 5100 ES Model II III Portable Radio Operating Manual December 2006 Features...
Page 122: ...9 4 5100 ES Model II III Portable Radio Operating Manual December 2006 Password Description...
Page 143: ......