• To anyone looking to acquire commercial radio programming software:

    Please do not make requests for copies of radio programming software which is sold (or was sold) by the manufacturer for any monetary value. All requests will be deleted and a forum infraction issued. Making a request such as this is attempting to engage in software piracy and this forum cannot be involved or associated with this activity. The same goes for any private transaction via Private Message. Even if you attempt to engage in this activity in PM's we will still enforce the forum rules. Your PM's are not private and the administration has the right to read them if there's a hint to criminal activity.

    If you are having trouble legally obtaining software please state so. We do not want any hurt feelings when your vague post is mistaken for a free request. It is YOUR responsibility to properly word your request.

    To obtain Motorola software see the Sticky in the Motorola forum.

    The various other vendors often permit their dealers to sell the software online (i.e., Kenwood). Please use Google or some other search engine to find a dealer that sells the software. Typically each series or individual radio requires its own software package. Often the Kenwood software is less than $100 so don't be a cheapskate; just purchase it.

    For M/A Com/Harris/GE, etc: there are two software packages that program all current and past radios. One package is for conventional programming and the other for trunked programming. The trunked package is in upwards of $2,500. The conventional package is more reasonable though is still several hundred dollars. The benefit is you do not need multiple versions for each radio (unlike Motorola).

    This is a large and very visible forum. We cannot jeopardize the ability to provide the RadioReference services by allowing this activity to occur. Please respect this.

Decryting Emcrypted IMBE

Status
Not open for further replies.

opus

Member
Joined
Jan 19, 2003
Messages
155
Reaction score
0
Location
Sydney, NSW, Australia
I have just been pondering encryption and decrypting of such. These are just ponderings on my limited knowledge of such.

Basically encryption is running an algorithm on some data to get encrypted data. With IMBE this is done on the 144 bit voice frame I guess.

A scanner or radio without decryption capability will still decode the voice frame to some kind of audio.

I propose that some audio algorithm/transformation could be applied to the resulting audio to recover the original unencrypted audio.

It could be tricky, but a different method of decryption of IMBE.

Any thoughts on my ponderings.....

Opus
 

mr_hankey

Member
Joined
Dec 19, 2002
Messages
711
Reaction score
1
Location
Helotes, TX
...confused.

you mean DECODING, right?

and yes, a scanner does render IMBE into some kind of audio - some UGLY kind of audio!
 

SCPD

QRT
Joined
Feb 24, 2001
Messages
0
Reaction score
115
Location
Virginia
No, I think he means decrypting an encrypted IMBE encoded audio stream.

Interesting idea Opus but I can't begin to imagine how to go about accomplishing this. As long as the encrypting party is disciplined enough to frequently changes keys - the most you can hope for is listening to something many months old.

-rick
 

zgafford

Member
Joined
May 16, 2004
Messages
44
Reaction score
0
After it has been rendered to the crappy audio by the scanner any chance of decrypting it would be destroyed I would guess. You would need the unfiltered audio. Kinda like you need the unfiltered audio for a discriminator to work.

The information needed to decrypt it would be imbedded in the signal but any changed to the signal with render the imbedded information useless

Just my thoughts
 

ianw

Member
Joined
May 28, 2002
Messages
41
Reaction score
0
Location
England
As RFmobile pointed out this might not be as straight forward as it initially looks. Even if a single unchanging encryption key is used that key is very unlikely to be used to say XOR against the datastream from the vocoder or as the key to DES encrypt the vocoder datastream. Far more likely the key will be used initialise a pseudo random number generator of some form. So unless you know say the frame number then you aren't going to make much progress.

Don't get me wrong I'm not saying this is impossible just very very difficult. Even so its something that advanced hobbyists are going to be thinking about quite a lot in the years to come.

Ian
 

opus

Member
Joined
Jan 19, 2003
Messages
155
Reaction score
0
Location
Sydney, NSW, Australia
No confusion here. I do mean decrypting. But another fun project would be to decode APCO-25 to get RIDs etc. But that is another topic.

Thanks all for your thoughts. I think it would be quite difficult too, but not impossible. I was talking to someone who said that encrypted IMBE would never be decrypted. I am not one to say never. I agree it is a bit difficult thing to do but give it a few years.....

I like to get minds thinking.

Opus
 
N

N_Jay

Guest
opus said:
No confusion here. I do mean decrypting. But another fun project would be to decode APCO-25 to get RIDs etc. But that is another topic.

Thanks all for your thoughts. I think it would be quite difficult too, but not impossible. I was talking to someone who said that encrypted IMBE would never be decrypted. I am not one to say never. I agree it is a bit difficult thing to do but give it a few years.....

I like to get minds thinking.

Opus

The problem is not decypting the IMBE, it is breaking the DES3 or AES in less time than the agency changes codes given the little pieces of fairly random data that you have to work with.

Maybe some don't grasp the sophistication of modern encryption systems, but you are not going to stumble into the answer with out many years of post-graduate level mathmatics.

I would guess that the encryption is not just done on the IMBE stream, but on the entire payload. Since the IMBE is a non-linear transform, there would be no way to decrype the audio post the incorrect IMBE conversion.
 

ianw

Member
Joined
May 28, 2002
Messages
41
Reaction score
0
Location
England
This is an interesting thread. Out of interest has anyone ever monitored
a fully encrypted APCO25 system (i.e where all the users are encrypted).
If so is only the actual voice data encrypted ? Is the signalling encrypted ? and are radio identities encrypted ?

Tetra/Tetrapol make a big play of encrypting the the entire control channel and in some cases encrypting radio identities to prevent any kind of traffic analysis.

Regards

Ian
 
N

N_Jay

Guest
ianw said:
This is an interesting thread. Out of interest has anyone ever monitored
a fully encrypted APCO25 system (i.e where all the users are encrypted).
If so is only the actual voice data encrypted ? Is the signalling encrypted ? and are radio identities encrypted ?

Tetra/Tetrapol make a big play of encrypting the the entire control channel and in some cases encrypting radio identities to prevent any kind of traffic analysis.

Regards

Ian

This stuff was designed from the ground up with the US Gov encryptions needs in mind.

What do you think?
 

ianw

Member
Joined
May 28, 2002
Messages
41
Reaction score
0
Location
England
N_Jay said:
This stuff was designed from the ground up with the US Gov encryptions needs in mind.
What do you think?

I don't know since I have never seen any trade advert mentioning any APCO25 system with these capabilities. Since APCO25 was never designed never appears to have been designed for military or para-military use it may not have them. Also since APCO25 seems to have encryption almost as an "bolt on" afterthought makes me wonder.

Regards

Ian
 

mr_hankey

Member
Joined
Dec 19, 2002
Messages
711
Reaction score
1
Location
Helotes, TX
This stuff was designed from the ground up with the US Gov encryptions needs in mind.

never assume anything.

about 7 years ago, i was in Laredo, TX, which is infamous for having DES encrypted their entire PD channel set when i noticed PERIODICALLY i would get an officer in the clear...

a little poking around hinted that early in the deployment of the system, there was a concern about the Mobiles not being able to sync properly if DES was used all the way around, so i BELIEVE the mobiles were in the clear...the encryption seemed to be taking place at the repeaters...

i couldn't find any other way to explain this phenomenon at the time...

now, on a recent trip, i heard nothing but DES on every channel regardless of how close i was to the mobiles...

perhaps i was right?

either way, it shows that the human factor still plays a major role in system deployment (and communication encryption capabilities)
 
N

N_Jay

Guest
ianw said:
N_Jay said:
This stuff was designed from the ground up with the US Gov encryptions needs in mind.
What do you think?

I don't know since I have never seen any trade advert mentioning any APCO25 system with these capabilities. Since APCO25 was never designed never appears to have been designed for military or para-military use it may not have them. Also since APCO25 seems to have encryption almost as an "bolt on" afterthought makes me wonder.

Regards

Ian

Take a look at the TIA Standards that make up P25.
Take a look at the organizations and agencies involved in P25 from teh start.
 
N

N_Jay

Guest
mr_hankey said:
This stuff was designed from the ground up with the US Gov encryptions needs in mind.

never assume anything.

Nope, don't assume, but make logical extensions to your knowlege and test for errors.

In other words, "Assuming and ASSUMPTION is wrong, is no better than an untested assumption."

mr_hankey said:
This stuff was designed from the ground up with the US Gov encryptions needs in mind.

about 7 years ago, i was in Laredo, TX, which is infamous for having DES encrypted their entire PD channel set when i noticed PERIODICALLY i would get an officer in the clear...

a little poking around hinted that early in the deployment of the system, there was a concern about the Mobiles not being able to sync properly if DES was used all the way around, so i BELIEVE the mobiles were in the clear...the encryption seemed to be taking place at the repeaters...

i couldn't find any other way to explain this phenomenon at the time...

Either that or some foeld equipment was incorectly programmed or used.
(MUCH more likely)

mr_hankey said:
This stuff was designed from the ground up with the US Gov encryptions needs in mind.

now, on a recent trip, i heard nothing but DES on every channel regardless of how close i was to the mobiles...

perhaps i was right?

either way, it shows that the human factor still plays a major role in system deployment (and communication encryption capabilities)

The older DES/DVP systems were signififcantly different than P25 ystems.

In either case, I do not know of any system that would be designed with clear comms in and DES out.

(For security reasons most repeaters are set up as "transparent" and do not have the hardware nor keys to encrypt or decrypt.)
 

SCPD

QRT
Joined
Feb 24, 2001
Messages
0
Reaction score
115
Location
Virginia
ianw said:
Out of interest has anyone ever monitored a fully encrypted APCO25 system (i.e where all the users are encrypted). If so is only the actual voice data encrypted ? Is the signalling encrypted ? and are radio identities encrypted?

On P25, both voice and control channel information *can* be encrypted - it's up to the system manager to take advantage of these features. Also, encryption - on P25 systems at least - should not impact sound quality.

-rick
 

ianw

Member
Joined
May 28, 2002
Messages
41
Reaction score
0
Location
England
rfmobile said:
On P25, both voice and control channel information *can* be encrypted - it's up to the system manager to take advantage of these features. Also, encryption - on P25 systems at least - should not impact sound quality.
-rick

Thanks Rick. Has anyone come across an encrypted control channel in the mainland US yet ?

Regards

Ian
 

INDY72

Monitoring since 1982, using radios since 1991.
Premium Subscriber
Joined
Dec 18, 2002
Messages
15,187
Reaction score
2,022
Location
Indianapolis, IN
Umm one word, three letters.. ESK.. thus CC on EDACS is encrypted,... on the EDACS Provoice format.. which is a IMBE with modifications if I understand it right.. thus a sorta P-25 system.. add the ESK,.. and you have an Encrypted CC on a P-25 system. ?????
 

N4DES

Retired 0598 Czar ÆS Ø
Joined
Dec 19, 2002
Messages
2,627
Reaction score
617
Location
South FL
milf said:
Umm one word, three letters.. ESK.. thus CC on EDACS is encrypted,... on the EDACS Provoice format.. which is a IMBE with modifications if I understand it right.. thus a sorta P-25 system.. add the ESK,.. and you have an Encrypted CC on a P-25 system. ?????

State of Florida is doing just this with their new system currently in operation in the north areas of the state.
 

INDY72

Monitoring since 1982, using radios since 1991.
Premium Subscriber
Joined
Dec 18, 2002
Messages
15,187
Reaction score
2,022
Location
Indianapolis, IN
The State of Florida's System is even worse than that... EDACS Provoice in all digital mode with ESK, and most State Agencies full time Encrypted.... I guess thier being extra paranoid of both drug dealers (the big timers) and homeland security issues. Any way, this makes this the most unmonitorable system in the USA.
 
N

N_Jay

Guest
milf said:
Umm one word, three letters.. ESK.. thus CC on EDACS is encrypted,... on the EDACS Provoice format.. which is a IMBE with modifications if I understand it right.. thus a sorta P-25 system.. add the ESK,.. and you have an Encrypted CC on a P-25 system. ?????

You don't get it do you?

Sorry, for the attitude, but we have been round this topic many times.

Lets, at least, TRY not to confuse the people on this board.

P-25 is a set of standards.
The minimum set for compliance is called the CAI (Common Air Interface).
It includes;
a SPECIFIC MODULATION (Not just one related or close)
a SPECIFIC VOCODER (Not just one from the same family)
SPECIFIC CHANNEL CODING (Not just any 9600 bps rate)
It also includes encryption and trunking control standards, although they are not mandatory.

Yes IMBE was selected for the vocoder, but that does NOT make any other system using IMBE "sorta P-25"!

PROVOICE is NOT P25!
EDACS is not P-25 Trunking.
 
Status
Not open for further replies.
Top