Q A_3.pdf

PDF 99 KB Posted

Attached to
Land Mobile Radios Federal contract opportunity
Solicitation number
FA4855-16-T-0027
Issued by
Department of the Air Force Special Operations Command

About this file

Q A 3

View the file

Other files for this federal contract opportunity

Other files attached to Land Mobile Radios, newest first.
File Type Posted
Q A_4.pdf PDF
Requirements.pdf PDF
FAR_Part_6_Brand_Name_J_and_A_Redacted.pdf PDF
Q A_2.pdf PDF
Q A_2.pdf PDF
Q A.pdf PDF
Requirements.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Questions:

Q: 2.) Is the use of DES encryption authorized in the US Air Force? To my knowledge AES 256 kb encryption is the lowest encryption standard authorized.

DES is authorized to use in the US Air Force IAW DODI 4650.10:

(1) Encryption will comply with applicable security standards as set by the NIST Federal Information Processing Standards (FIPS) Publication Level 1 140-2 (Reference (l)), FIPS Publication 197 (Reference ( m)), and NIST Special Publication (SP) 800-38A (Reference (n)).

Systems will not use the Data Encryption Standard (DES) or Triple DES encryption algorithms .If equipped with encryption capability, be equipped with:

(a) A warning (audible or visual) to positively alert the user that a given transmission is not encrypted.

(b) Over-the-air-rekeying (OTAR) where security or operational requirements do not supersede this capability.

(c) Over-the-air-zeroization (OTAZ) or similar related to remote management of encryption keys where security or operational requirements do not supersede this capability.

(2) LMR trunking will comply with the P25 trunking specification, testing, and compliance assessment documents identified in Reference (i).

A: 2.) 256-DES is authorized in the DoD but it will not meet are requirements for transmitting unclassified but sensitive operations that is why we are requesting 256 AES encryption.

We discuss sensitive but unclassified operations over the radios so we are requesting 256 AES IAW DODI 4650.10

2. CYBERSECURITYa. FIPS-Validated Cryptography

(1) For unclassified but sensitive operations, all cryptographic operations will be implemented in validated module as specified in Reference (l). Symmetric encryption will use 256-bit advanced encryption standard (AES) encryption certified as compliant with Reference (m). Asymmetric cryptography will use public key infrastructure cross certified with the Federal Bridge at Medium assurance or higher.

(2) For classified operations, all LMR systems will be implemented using NSA-approved cryptography.

(3) AES implementations will support the output feedback mode for block encryption of digital communications as specified in Reference (n).

(4) If OTAR is employed, radios will authenticate key messages using AES with cipher-based message authentication code defined in NIST SP 800-38B (Reference (u)).

File details come from the government source that posted it. Updated .