Q A_3.pdf
PDF 99 KB Posted
- Attached to
- Land Mobile Radios Federal contract opportunity
- Solicitation number
- FA4855-16-T-0027
About this file
Q A 3
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Q A_4.pdf | ||
| Requirements.pdf | ||
| FAR_Part_6_Brand_Name_J_and_A_Redacted.pdf | ||
| Q A_2.pdf | ||
| Q A_2.pdf | ||
| Q A.pdf | ||
| Requirements.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Questions:
Q: 2.) Is the use of DES encryption authorized in the US Air Force? To my knowledge AES 256 kb encryption is the lowest encryption standard authorized.
DES is authorized to use in the US Air Force IAW DODI 4650.10:
(1) Encryption will comply with applicable security standards as set by the NIST Federal Information Processing Standards (FIPS) Publication Level 1 140-2 (Reference (l)), FIPS Publication 197 (Reference ( m)), and NIST Special Publication (SP) 800-38A (Reference (n)).
Systems will not use the Data Encryption Standard (DES) or Triple DES encryption algorithms .If equipped with encryption capability, be equipped with:
(a) A warning (audible or visual) to positively alert the user that a given transmission is not encrypted.
(b) Over-the-air-rekeying (OTAR) where security or operational requirements do not supersede this capability.
(c) Over-the-air-zeroization (OTAZ) or similar related to remote management of encryption keys where security or operational requirements do not supersede this capability.
(2) LMR trunking will comply with the P25 trunking specification, testing, and compliance assessment documents identified in Reference (i).
A: 2.) 256-DES is authorized in the DoD but it will not meet are requirements for transmitting unclassified but sensitive operations that is why we are requesting 256 AES encryption.
We discuss sensitive but unclassified operations over the radios so we are requesting 256 AES IAW DODI 4650.10
2. CYBERSECURITYa. FIPS-Validated Cryptography
(1) For unclassified but sensitive operations, all cryptographic operations will be implemented in validated module as specified in Reference (l). Symmetric encryption will use 256-bit advanced encryption standard (AES) encryption certified as compliant with Reference (m). Asymmetric cryptography will use public key infrastructure cross certified with the Federal Bridge at Medium assurance or higher.
(2) For classified operations, all LMR systems will be implemented using NSA-approved cryptography.
(3) AES implementations will support the output feedback mode for block encryption of digital communications as specified in Reference (n).
(4) If OTAR is employed, radios will authenticate key messages using AES with cipher-based message authentication code defined in NIST SP 800-38B (Reference (u)).
File details come from the government source that posted it. Updated .