https://urgentcomm.com/wp-content/themes/ucm_child/assets/images/logo/footer-new-logo.png
  • Home
  • News
  • Multimedia
    • Back
    • Multimedia
    • Video
    • Podcasts
    • Galleries
    • IWCE’s Video Showcase
    • IWCE 2022 Winter Showcase
    • IWCE 2023 Pre-event Guide
  • Commentary
    • Back
    • Commentary
    • Urgent Matters
    • View From The Top
    • All Things IWCE
    • Legal Matters
  • Resources
    • Back
    • Resources
    • Webinars
    • White Papers
    • Reprints & Reuse
  • IWCE
    • Back
    • IWCE
    • Conference
    • Special Events
    • Exhibitor Listings
    • Premier Partners
    • Floor Plan
    • Exhibiting Information
    • Register for IWCE
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Terms of Service
    • Privacy Statement
    • Cookie Policy
  • Related Sites
    • Back
    • American City & County
    • IWCE
    • Light Reading
    • IOT World Today
    • Mission Critical Technologies
    • TU-Auto
  • In the field
    • Back
    • In the field
    • Broadband Push-to-X
    • Internet of Things
    • Project 25
    • Public-Safety Broadband/FirstNet
    • Virtual/Augmented Reality
    • Land Mobile Radio
    • Long Term Evolution (LTE)
    • Applications
    • Drones/Robots
    • IoT/Smart X
    • Software
    • Subscriber Devices
    • Video
  • Call Center/Command
    • Back
    • Call Center/Command
    • Artificial Intelligence
    • NG911
    • Alerting Systems
    • Analytics
    • Dispatch/Call-taking
    • Incident Command/Situational Awareness
    • Tracking, Monitoring & Control
  • Network Tech
    • Back
    • Network Tech
    • Interoperability
    • LMR 100
    • LMR 200
    • Backhaul
    • Deployables
    • Power
    • Tower & Site
    • Wireless Networks
    • Coverage/Interference
    • Security
    • System Design
    • System Installation
    • System Operation
    • Test & Measurement
  • Operations
    • Back
    • Operations
    • Critical Infrastructure
    • Enterprise
    • Federal Government/Military
    • Public Safety
    • State & Local Government
    • Training
  • Regulations
    • Back
    • Regulations
    • Narrowbanding
    • T-Band
    • Rebanding
    • TV White Spaces
    • None
    • Funding
    • Policy
    • Regional Coordination
    • Standards
  • Organizations
    • Back
    • Organizations
    • AASHTO
    • APCO
    • DHS
    • DMR Association
    • ETA
    • EWA
    • FCC
    • IWCE
    • NASEMSO
    • NATE
    • NXDN Forum
    • NENA
    • NIST/PSCR
    • NPSTC
    • NTIA/FirstNet
    • P25 TIG
    • TETRA + CCA
    • UTC
Urgent Communications
  • NEWSLETTER
  • Home
  • News
  • Multimedia
    • Back
    • Video
    • Podcasts
    • Omdia Crit Comms Circle Podcast
    • Galleries
    • IWCE’s Video Showcase
    • IWCE 2023 Pre-event Guide
    • IWCE 2022 Winter Showcase
  • Commentary
    • Back
    • All Things IWCE
    • Urgent Matters
    • View From The Top
    • Legal Matters
  • Resources
    • Back
    • Webinars
    • White Papers
    • Reprints & Reuse
    • UC eZines
    • Sponsored content
  • IWCE
    • Back
    • Conference
    • Why Attend
    • Exhibitor Listing
    • Floor Plan
    • Exhibiting Information
    • Join the Event Mailing List
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Terms of Service
    • Privacy Statement
  • Related Sites
    • Back
    • American City & County
    • IWCE
    • Light Reading
    • IOT World Today
    • TU-Auto
  • newsletter
  • In the field
    • Back
    • Internet of Things
    • Broadband Push-to-X
    • Project 25
    • Public-Safety Broadband/FirstNet
    • Virtual/Augmented Reality
    • Land Mobile Radio
    • Long Term Evolution (LTE)
    • Applications
    • Drones/Robots
    • IoT/Smart X
    • Software
    • Subscriber Devices
    • Video
  • Call Center/Command
    • Back
    • Artificial Intelligence
    • NG911
    • Alerting Systems
    • Analytics
    • Dispatch/Call-taking
    • Incident Command/Situational Awareness
    • Tracking, Monitoring & Control
  • Network Tech
    • Back
    • Cybersecurity
    • Interoperability
    • LMR 100
    • LMR 200
    • Backhaul
    • Deployables
    • Power
    • Tower & Site
    • Wireless Networks
    • Coverage/Interference
    • Security
    • System Design
    • System Installation
    • System Operation
    • Test & Measurement
  • Operations
    • Back
    • Critical Infrastructure
    • Enterprise
    • Federal Government/Military
    • Public Safety
    • State & Local Government
    • Training
  • Regulations
    • Back
    • Narrowbanding
    • T-Band
    • Rebanding
    • TV White Spaces
    • None
    • Funding
    • Policy
    • Regional Coordination
    • Standards
  • Organizations
    • Back
    • AASHTO
    • APCO
    • DHS
    • DMR Association
    • ETA
    • EWA
    • FCC
    • IWCE
    • NASEMSO
    • NATE
    • NXDN Forum
    • NENA
    • NIST/PSCR
    • NPSTC
    • NTIA/FirstNet
    • P25 TIG
    • TETRA + CCA
    • UTC
acc.com

View From The Top


Commentary

Adding low-cost ADP encryption could be a pricy decision

Adding low-cost ADP encryption could be a pricy decision

By Scott Tschetter — A movement is afoot to add a proprietary encryption protocol called advanced digital privacy, or ADP, to Project 25 systems across the country. However, in so doing, users are at risk of losing federal grant funds.
  • Written by
  • 17th April 2012

Photo of Scott TschetterBy Scott Tschetter

A movement is afoot to add a proprietary encryption protocol called advanced digital privacy, or ADP, to Project 25 systems across the country. However, in so doing, users are at risk of losing federal grant funds.

It is easy to understand the appeal of adopting ADP. Most public-safety radio system administrators do not like the idea of their P25 radio systems being monitored by anyone with a $125 scanner (or worse, streamed live across the Internet). The P25 standards include 256-bit AES and DES encryption options, but these protocols can be expensive. In response, 40-bit ADP was introduced.

As far as security goes, ADP offers very little protection. With a laptop and a hacker program downloaded from the Internet, a 40-bit key can be broken in just a few hours. In contrast, the 256-bit encryption, as included in the P25 standard, would take more than a trillion years to hack — not even feasible. But ADP can be deployed at very little cost, which cash-strapped agencies might find attractive.

But while the up-front cost of ADP is basically nothing, it actually could end up being quite expensive. Here’s why:

The Department of Homeland Security, via its SAFECOM program, has included six federal grant requirements for 2012:

  • Include P25 standards in a statement of requirements
  • Select P25-eligible equipment
  • Obtain documented evidence of P25 compliance
  • Ensure compliance with the P25/AES encryption standard
  • Ensure additional features purchased are P25-compliant
  • Written justification required for non-P25 purchases

The adoption of ADP encryption clearly violates the fourth requirement and violates the spirit of the fifth requirement, as no P25 radio with ADP enabled can pass the P25 Compliance Assessment Program. What happens two years from now when DHS audits a 2012 grant awardee? If DHS determines that the agency violated these requirements (or worse, misled grant reviewers), the agency could be required to return funds and also could risk its eligibility for future funding.

Awareness of this issue was one reason why lawmakers in Ohio recently adopted new language that stipulates any state or federal funds spent on the statewide Multiagency Radio Communications System (MARCS) “may not limit interoperability in mission-critical communications.” Further the MARCS steering committee must “certify that the P25 system complies with P25 standards.”

One such advocate of this new requirement is Bob Glaser, a trustee of Beavercreek Township, Ohio. Glaser’s testimony on this issue before the state’s Senate finance committee last week played a key part in convincing lawmakers that these controls were necessary to ensure P25 interoperability, and also to avoid the risk of forfeiting grant funding.

But the original problem remains: Public safety wants secure (and private) communications. So what is a P25 system owner to do? Multiple manufacturers now are offering “single-key DES” as an alternative. In considering this option, it should be noted first that DES is a P25-recognized encryption standard. Though single-key DES provides radios with just one encryption key — it does so in a vendor-neutral, P25-compliant fashion and is still orders of magnitude stronger than ADP. And for now, this new feature is being offered for free. Sometimes you can have your cake and eat it too!

What should an agency do if it already has deployed ADP encryption? First, create non-ADP, P25 talkgroups for interoperability. Second, create a migration plan to single-key DES for talkgroups that need privacy, but not necessarily full-blown encryption. For tactical or other talkgroups that truly need encryption, investigate the cost of adopting multi-key DES or AES — it may be less than you think if it is only used for the small number of users that require this level of security.

Scott Tschetter is vice president of Eastern Communications, a land-mobile-radio dealer in Long Island City, N.Y., and is a member of Urgent Communications’ editorial advisory council.

Tags: Data Public Safety Security Commentary Project 25 Security Software View From The Top Commentary

Most Recent


  • Researchers uncover RaaS affiliate distributing multiple ransomware strains
    A new threat group is leveraging a relatively large network of malicious servers to distribute and manage multiple ransomware families including prolific ones such as ALPHV, Quantum, and Nokoyawa. The group has been active since at least June 2022 and appears to have links to the operators of Cl0p, Play, Royal, and Cactus ransomware families […]
  • Cisco drops $28 billion on Splunk acquisition
    Cisco plans to bring on data mining and cybersecurity company Splunk for $28 billion, according to an announcement today. This is Cisco’s largest-ever acquisition and the latest in a string of cybersecurity-related acquisitions, according to CNBC. Splunk monitors and analyzes enterprise customer data to reduce the threat of security breaches and remediate threats. Cisco said the acquisition […]
  • Generative AI's masters are coming for your network
    “Copilot” is suddenly a popular word to humanize “generative” artificial intelligence, the incarnation that has sparked new fears about job losses and murderous robots. It was almost a standard response to questions about genAI’s potential impact on the workforce at this year’s Digital Transformation World (DTW) event in Copenhagen. Microsoft’s code-writing genAI is even called […]
  • UK Home Office targets ESN system buildout finish by 2024 year end, Lot 2 award next year
    United Kingdom (UK) Home Office officials believe most of the cell sites—also known as masts—necessary for the Emergency Service Network (ESN) will be completed by the end of the next year, according to a report filed with a Parliament committee. This ESN coverage projection was noted in the system progress update provided in response to […]

Related Content

  • Adding low-cost ADP encryption could be a pricy decision
  • Adding low-cost ADP encryption could be a pricy decision
  • Adding low-cost ADP encryption could be a pricy decision
  • New Orleans-area 911 center inks multiyear APEX deal with Carbyne to replace call-handling system

Commentary


Better technology can help solve the public-safety staffing crisis

26th June 2023

Updated: How ‘sidelink’ peer-to-peer communications can enhance public-safety operations

  • 1
27th February 2023

NG911 needed to secure our communities and nation

24th February 2023
view all

Events


UC Ezines


IWCE 2019 Wrap Up

13th May 2019
view all

Twitter


Newsletter

Sign up for UrgentComm’s newsletters to receive regular news and information updates about Communications and Technology.

Expert Commentary

Learn from experts about the latest technology in automation, machine-learning, big data and cybersecurity.

Business Media

Find the latest videos and media from the market leaders.

Media Kit and Advertising

Want to reach our digital and print audiences? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • American City & County
  • IWCE
  • Light Reading
  • IOT World Today
  • Mission Critical Technologies
  • TU-Auto

WORKING WITH US

  • About Us
  • Contact Us
  • Events
  • Careers

FOLLOW Urgent Comms ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.