KVL4000KeyVariableLoaderASTRO25UserGuide
1.2.4UsingtheKVL4000
Securecommunicationssystemsaredesignedtoprovidecoded(encrypted)voiceanddatasignalsbetweensomeor
alllinksinthesystem(includingRFlinksandnetworklinks).Inordertodothis,eachdevice,suchasaradioor
xedencryptionunit,isloadedwithamulti-digitencryptionvariable(akey).Thiskeyisusedbytheencryption
algorithm,suchasAES-256orDES-XL,builtintothedevicetomathematicallyencryptalltransmittedvoiceand
datasignals,anddecodeallencryptedreceivedvoiceanddatasignals.
Onlydevicesinthesystemwiththesamealgorithmandencryptionkeycandecodetheencryptedsignaland
carryoncommunicationswitheachother.Talkgroupscanthereforebecreatedbycontrollingtheassignmentof
encryptionkeystospecicgroupsofradios.
1.2.4.1TypesofEncryptionKeys
TheKVLstorestwobasictypesofencryptionkeys:
•TrafcEncryptionKeys(TEK)–Usedbysubscriberunitstoencrypt/decryptvoiceanddata
communications.
•KeyEncryptionKeys(KEK)–UsedbytheKVLtoprovideanadditionallevelofencryptiontothe
encryptionkeyswhentransferringkeysdirectlytotheKMForovertheairtosecuresubscriberdevices.
BothtypesofkeysarestoredintheKVLmemoryinanencryptedformatandareprotectedfromtampering.
1.2.4.2EnteringandLoadingKeys–Overview
EncryptionkeysareenteredintotheKVLmemorylocations(slots).Thekeysmaythenbetransferred(loaded)
toatargetdevice,suchasasecureradio.
Atwo-stepprocessisrequiredformostencryptionkeys:
•Create(enter)themulti-digitencryptionkeyintotheKVLmemory.See3.1EnteringEncryptionKeys,
page3-1.
•ConnecttheKVLtoatargetdevice,suchasaradio,andtransferthekeytothetargetdevice.See1.4.4
ConnectingtheKVLtoTargetDevices,page1-13andChapter4KVL4000–LoadingEncryptionKeysinto
TargetDevices.
1.3KVL4000UserInterface
YounavigatethroughtheKVLUserInterfaceandperformoperationsby:
•Selectinglistitems,buttons,andtabs
•Enteringdata
•Draggingsliders
•Scrollingthroughlists
YoucannavigatethroughtheKVLUIusingyournger.Alternatively,youcanusethestylusattachedtothe
sideofthePDA,orpresshardcontrolsonthePDA.
1-8
6871018P37-F-January2013