Secure Rekeying Protocol for APCO P25 Radio Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In secure communication systems, particularly those employing the APCO Project 25 protocol, the lack of outer-layer encryption for the Warm Start Command during rekeying operations increases exposure to attacks, and obtaining a Key Encryption Key (KEK) before visiting a foreign network can be inefficient or impossible, leading to non-secure rekeying.
Innovation Solution
The method involves using a Key Encryption Key (KEK) to wrap Traffic Encryption Keys (TEKs) when available, and if not, using public key encryption with the recipient device's public key for secure transmission, allowing devices to unwrap the TEKs using their private keys, ensuring secure and efficient rekeying on foreign networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the Warm Start Command is transmitted without outer-layer encryption, then the rekeying process can be initiated, but the security of the transmission is compromised and exposure to attacks increases
Solution Approach 1:
The system performs preliminary key establishment through the Warm Start Command before actual communication begins. The command initiates the rekeying process by establishing initial encryption parameters, allowing secure communication to start without requiring pre-existing outer-layer encryption keys.
Solution Approach 2:
The patent introduces an intermediary encryption layer using the KEK (Key Encryption Key) that acts as a mediator between the unencrypted Warm Start Command and the actual communication data. This intermediary layer provides security for the rekeying process without compromising the initiation capability.
2Reliability
If a KEK is obtained before visiting a foreign network, then secure rekeying can be performed, but the process becomes inefficient or impossible in many scenarios
Solution Approach 1:
The system dynamically adapts its encryption approach based on the operational context. When a KEK is unavailable (such as when visiting foreign networks), the system automatically switches to public key encryption mechanisms, allowing secure rekeying to proceed without requiring pre-obtained KEKs.
Solution Approach 2:
The patent changes the encryption parameter from requiring a shared KEK to accepting public key pairs. This parameter change enables the system to maintain secure rekeying capability across different network environments, including foreign networks where pre-establishing KEKs is impractical.
3Productivity
If symmetric-key key wrapping is used, then efficient rekeying can be achieved, but the system becomes vulnerable when the radio lacks a pre-distributed KEK
Solution Approach 1:
The system implements multi-functionality by supporting both symmetric-key wrapping (when KEK is available) and public key encryption (when KEK is unavailable). This universal approach ensures that efficient symmetric rekeying can be used when possible, while maintaining security capability through public keys when the KEK is not pre-distributed.
Solution Approach 2:
The patent applies partial action by using symmetric-key wrapping only when the KEK is available, rather than requiring it in all cases. When the KEK is not available, the system partially switches to public key encryption, maintaining sufficient security without the efficiency penalty of always using asymmetric encryption.
Data Source
AI summary
A method and apparatus for transmitting encryption keys in a secure communication system is provided herein. During rekeying of a device, a key encryption key (KEK) is utilized to wrap (encrypt) the traffic encryption key (TEK) when the KEK is available to the device. If unavailable, the TEK will be wrapped using public key encryption with the recipient device's public key. The receiving device will then be able to unwrap the TEK using public key decryption with its own private key. Because TEKs are always transmitted in a secure manner, secure and efficient rekeying of devices on foreign networks can occur.


