MM101880V1 R1A
11
6. KEY
MANAGEMENT
The M/A Com Jaguar 700P radio has a very simple key management plan. The radio only stores one type
of cryptographic key (DES). The DES keys stored by the radio are used for the protection of data
transmitted when the radio is in Private mode. The DES keys stored on the radio are the only security
relevant data items (SRDIs) stored within the radio. These cryptographic keys are accessible to both the
User and Crypto-Officer roles for use. However, DES keys can never be read or output from the radio.
The radio can store up to 56 separate and distinct DES keys.
All DES keys can be zeroized by pressing the MONITOR/CLEAR button and while still pressing this
button, press and hold the OPTION button. Continue to press both buttons for 2 seconds. A series of
beeps will begin at the start of the 2 second period and then switch to a solid tone after the keys have been
zeroized. The display will then indicate “KEY ZERO.”
7. PHYSICAL
SECURITY
The M/A Com Jaguar 700P radio was designed to meet Level 1 physical security requirements for a
multiple-chip standalone module. The radios are packaged in a polycarbonate blend exterior housing.
The radio does not have any special physical security mechanisms beyond the rugged enclosure of the
radio itself. The operator is responsible for ensuring the security and safety of the radio.
8. SECURE
OPERATION
Initialization is procedurally controlled prior to module configuration. The initialization process includes
radio personality configuration, key entry, and disabling of PIN1 on the UDC port. The following are
security requirements that have been implemented within the Jaguar radio:
•
Radio initialization is procedurally control. All radios must be received directly from M/A
Com.
•
DES encryption must be used for protection of all encrypted data transmissions
•
Radio must confirm that bypass activation has been requested by the operator and is allowed
by the radio
•
Operators may zeroize all cryptographic keys by performing the appropriate key sequence as
described in operator documentation
•
Self-test are performed at power-up and do not require operator intervention
i.
DES Power-up Known Answer Test
ii.
Bypass Power-up Self-test
iii.
Firmware Integrity Test (CRC)
•
Radio performs a continuous random number generator test to ensure that two consecutive
blocks of random values generated are not equal