User's Manual

Table Of Contents
Viking VM600 Mobile Radio Operating Manual 8-13
Secure Communication (Encryption)
Black - Refers to information that is encrypted. The opposite is “Red” which refers to
unencrypted information.
Common Key Encryption Key (CKEK) - This is a KEK common to a group of
subscriber units which share the same encryption. These keys can be the DES or AES
type. The use of a common key allows the subscriber units to be rekeyed by the KMF
using one Key Management Message in some circumstances by addressing the KMM to a
group RSI. Refer to “KEK” for more information.
Common Key Reference (CKR) Group - Same as Storage Location Number (SLN).
Crypto Group - A group of up to 16 keysets containing the same type of keys (either
TEK or KEK). Although a crypto group can contain up to 16 keysets, only two are
normally used. Only one keyset in a crypto group is active at a time. EFJohnson
Technologies radios currently support only one crypto group: for TEKs, crypto group 0.
Cryptographic Variable - The variable used by a cryptographic algorithm to encrypt a
message. Also called a “key”.
Key - A variable used by a cryptographic algorithm to encrypt voice or data. Also called
“Cryptographic Variable”. Keys are identified by their Algorithm ID and Key ID values.
Key Encryption Key (KEK) - A key used to encrypt keys contained in Key Management
Messages (KMMs) during OTAR. These messages may themselves be encrypted by a
TEK. These keys can be the AES or DES type. There are KEKs unique to a subscriber unit
(UKEK) and common to a group (CKEK). The other type of key is the Traffic Encryption
Key (TEK) used to encrypt voice and data messages.
Key ID - This is a 16-bit (four hex digit) number identifier from 1-65535 for an encryption
key which allows the key to be identified without revealing the actual key variable. This
ID and the Algorithm ID uniquely identify a key within the KMF or subscriber unit.
Therefore, two keys can have the same ID if they have different algorithm IDs and vice
versa. The Key ID and Algorithm ID are usually transmitted with a message to identify the
key that must be used to decrypt it. Key ID 0 is not used with OTAR.
Key Management Facility (KMF) - The equipment and software which provide OTAR
and related key management services to the subscriber units.
Key Management Message (KMM) - These are the messages composed by the KMF to
send encryption information to subscriber units through the keyloader or OTAR. KMMs
are themselves encrypted using two layers of encryption: inner and outer. The inner layer
of encryption uses a KEK and the outer layer uses a TEK. Additional security measures
contained within KMMs include a Message Number (MN) and a Message Authentication
Code (MAC).
Keyset - A structure containing keys of the same type (TEK or KEK). There are two TEK
keysets, Keyset 1 and Keyset 2, and one KEK keyset, Keyset 255. Only one of the two
TEK keysets is active at a given time. This provides a way to divide the two keys
contained within each SLN into two groups, active keys and inactive keys, based on the
currently active keyset setting.
Draft 4/29/2014