|
|
Training Provider Index
Abreviation
Training Provider, Contact Information, and Funding Specifics
AMA
American Medical Association
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
APRI
American Prosecutors Research Institute
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
ARC
American Red Cross
CDC
Center Disease Control and Prevention
Information available online: http://www.bt.cdc.gov/radiation/training.asp
CDC Funded courses.
CDP
Center for Domestic Preparedness
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
CEPIN-TDHH
Community Emergency Preparedness Information Network-TeleComms for the Deaf and Hard of H
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
CJI-UA
Criminal Justice Institute-University of Askansas System
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
DHHS-FDA
Department of Health and Human Services-Food anf Drug Adminstration Online
Online training website for Radiological course delivery
DHS-OI&A
DHS Office of Intelligence and Analysis
Edward McCarroll, Branch Chief
State and Local Management Office
Phone: (703) 235-0352
Email: Edward.McCarroll@dhs.gov
Kristen Peerman, I&A Training Registrar
Phone: (202) 282-9892
Email: kristen.peerman@hq.dhs.gov
Interested applicants must submit an approved SF-182 via their Training Coordinator to the I&A
Training Registrar and I&A Training Customer Advocate (Kris Peerman & Marlys Rayford,
respectively).
DHS-TA
DHS-Technical Assistance Program
Online PDF for technical assistance request found at:
Funded by grant set aside and other sources.
DHS-Federal Emergency Management Agency
Friday, August 21,
Page 1 of 6
Training Provider Index
Abreviation
Training Provider, Contact Information, and Funding Specifics
DNDO
Domestic Nuclear Detection Office
Lonnie Swindell Chief, Training Branch
Operations Support Directorate, DNDO
Office: 202-254-4117
Mobile: 202-494-9676
Email: Robert.Swindell@dhs.gov
Funded by DNDO
DoD-ARC
Department of Defense-American Red Cross
Tim Jones
Manager, WMD/Terrorism Training Program, ARC
2025 E Street NW, Washington, DC 20006
Phone: 202-303-7271
DoD-TSWG
Department of Defense-Training Support Working Group
DoD funded. Refer to website for more information.
DOE-EM
Department of Energy-Environmental Management
DOE Funded
DOE-EOTA
Department of Energy-Emergency Operations Training Academy
Various free computer based training modules. Funded by the Department of Energy. For more
information, refer to the contact website.
DOE-ORAU
Department of Energy-Oak Ridge Associated Universities
Various REAC/TS and other course posted online at: http://www.orau.org/radiation-emergency-
medicine/default.aspx POC: Mark Hart: mark.hart@orise.orau.gov
Funded by DOE
DOT-FMCSA
Department of Transportation-Federal Motor Carrier Safety Administration
diap@dot.gov
Funded by DOT. Host to provide facilities,
DPETAP
Domestic Preparedness Equipment Training Assistance Program
dperapoutreach@gpworldwide.com or call 800-232-5741
Part of the DHS Training Assistance programs through the U.S. Army's Pine Bluff Arsenal and run
by General Physics Corporation
Dugway
Dugway Proving Ground
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
EMI
Emergency Management Institute
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
Free training to those who qualify. For more information go to:
DHS-Federal Emergency Management Agency
Friday, August 21,
Page 2 of 6
Training Provider Index
Abreviation
Training Provider, Contact Information, and Funding Specifics
EMI-IS
Emergency Management Institute-Independent Study
Free online training.
EMRTC
Energetic Material Research and Training Center at New Mexico Tech
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
EPA
Environmental Protection Agency
Mixed funding with many free online courses.
EPIC
Federal Motor Carrier Safety Administration/El Paso Intelligence Center
Mobile-Call EPIC State & Local Liaison Unit at (800) 927-0468
FBI
Federal Bureau of Investigations
Funded by the Department of Justice.
FEMA NCP
FEMA National Continuity Program
Willie York: willie.york@dhs.gov or 202-646-4163
Offered for free by FEMA
FHWA-NHI
Federal Highway Administration / National Highway Institute
NHI Scheduler (703) 235-0534
$320 per participant FY ’09, $350 FY’10
FLETC
Federal Law Enforcement Training Center
information.html/
The Office of State and Local Training (OSL) exports training across America. These programs are
tuition-free and are usually hosted by a local department or academy. Refer to online registration
page for access.
FRMAC
Colleen O’Laughlin, FRMAC Program Manager (olaughlin@nv.doe.gov)
Colleen O’Laughlin, FRMAC Program Manager (olaughlin@nv.doe.gov)
FTA
Federal Transit Authority
GWU
George Washington University
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC). Online training
available at: http://zerohour.nemspi.org/
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
HSP-WVU
Homeland Security Programs at West Virginia University
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
IAAM
Internation Association of Assembly Managers
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
DHS-Federal Emergency Management Agency
Friday, August 21,
Page 3 of 6
Training Provider Index
Abreviation
Training Provider, Contact Information, and Funding Specifics
IAFF
International Association of Fire Fighters
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
IPS
Institute for Preventative Strategies
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
LLNL
Lawrence Livermore National Labs
Brenda Pobanz [pobanz2@llnl.gov]
Funded by LLNL
MSU
Michigan State University
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
MTMI
Medical Technology Management Institute
Online resourse for medical imaging and radiation therapy professionals.
NCBRT-LSU
National Center for Biomedical Research and Training-Louisiana State University
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC). Online training
avaliable at: http://www.ncbrt.lsu.edu/eLearn/Courses.aspx
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
NERRTC-TEEX
National Emergency Response and Rescure Training Center-Texas Engineering Extension Service
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC). Online training can
be found at:
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
NFA
National Fire Academy
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
Training is free to those who qualify. For more go to: http://www.usfa.dhs.gov/nfa/index.shtm
NICI
National Interagency Civil-Military Institute
NORAD-USNORTHCOM
NORAD-USNORTHCOM
Website Registration required beginning 01Sep09: https:\\lms.noradnorthcom.mil.
Funded by DoD
NSA
National Sheriffs Association
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
NTS-CTOS
Nevada Test Site-Counter Terrorism Operations Support
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC). Website for CTOS
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
DHS-Federal Emergency Management Agency
Friday, August 21,
Page 4 of 6
Training Provider Index
Abreviation
Training Provider, Contact Information, and Funding Specifics
NW3C
National White Collar Crime Center
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
NWACC
North West Arkansas Community College
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC). For online courses,
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
OBP
Office of Bombing Prevention
ODNI
Office of the Director of National Intelligence
Online PDF form available at: http://www.dni.gov/ssc/support/DNI_SSC_TRNG_Registration.pdf
Funded directly by ODNI
RDPC
Rural Domestic Preparedness Consortium
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
Refer TWG
Refer to the Training Working Group
This request will be fielded by the Training Working Group because the course is offered by
multiple training providers. The needs of the requester will be coordinated by the TWG.
The host will be required to provide facilites in most cases, otherwise the training is delivery for
free.
REFER TWG
Training Working Group Co-Chairs
Emails can be found in the Training Request section of this Manual (SRooney, MCandee, and
TKaselionis). This means this course has multiple providers and we will work with your
agency/department to provide the delivery.
RSA
Radiation Safety Academy
For profit. Contact your SAA-TPOC for grant guidance.
SCSD
Sacramento County Sheriff's Department
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
TSI
Transportation Safety Institute
Contact: www.tsi.dot.gov
The FTA sponsors all training activities provided by the Transit Safety and Security Division. All
costs, other than a materials fee, are waived for all transit system employees, Federal agencies, or
state transportation agencies that are direct recipients or sub-recipients of FTA funds. Courses
offered on a cost-recovery basis are an exception to this waiver. Non-FTA grantees may be required
to pay additional fees in above to the materials fee.
UCD-WIFSS
UC Davis-Western Institute for Food Safety & Security
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
DHS-Federal Emergency Management Agency
Friday, August 21,
Page 5 of 6
Training Provider Index
Abreviation
Training Provider, Contact Information, and Funding Specifics
UM-CHHS
University of Maryland Center for Health and Homeland Security
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
UM-CIA
University of Memphis-Center for Information Assurance
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC). Online training
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
UNLV
University of Nevada Las Vegas
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
US-AMRICD
Unites States Army Medical research Institute of Chemical Defense
USAMRICD
3100 Ricketts Point Road
Aberdeen Proving Ground, MD 21010-5400 For questions about our in-house courses, products,
distance learning and other general questions: usamricdcccmail@amedd.army.mil
Charges vary based on course. Grant funding may be used. To know more contact your SAA-
TPOC for information.
USM-C3SM
University of Southern Mississippi-Center for Spectator Sports Security Management
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
USUHS
Uniformed Servces University of the Health Sciences-Armed Forces Radiobiology Research Institut
Information available online at: http://www.afrri.usuhs.mil/outreach/meir/meirschd.htm#Fees
◦U.S. and allied military personnel and DoD civilian personnel-Tuition waived. ◦All other personnel
(including defense contractors)-$200 each for MEIR Standard Course; $400 each for MEIR Field
Course or Scientific MEIR Course
WOU
Western Oregon University
Contact State Administraive Agency-Training Point of Contact (SAA-TPOC)
FEMA Funded and Grant approved training. https://www.firstrespondertraining.gov/TEI/cost.jsp
DHS-Federal Emergency Management Agency
Friday, August 21,
Page 6 of 6
UNCLASSIFIED//FOR OFFICIAL USE ONLY
(U) Cable Installation at NSA Facilities
Version 1.4
Date: 09/25/2008
Derived From: NSA/CSS Manual 1-52
Dated: 08 January 2007
Declassify on: 20320108
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
(U) Approval Signature Block
Printed Name
Organization
Signature
Date
John Egolf
X312
Patricia Jones
X31
Elizabeth Hobbins
X32
Carlos Acaron
X3
Greg Witschey
X3
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 2 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
(U) Version Control
(U//FOUO) All authorized changes to this document are to be recorded below at the time the
changes are received and inserted. This sheet is to be retained in the front of each document, thus
enabling ready determination of the configuration status of documents.
Version/Change History
Version #
Document Date
Description of Change
Author (Name)
1.0
12/21/2006
Initial Version
Charles Nace X312 Planning &
Instruction 2-06
Management
1.1
04/20/07
Updated Format
Charles Nace X312 Planning &
Management
1.2
3/21/2008
Expanded Grounding and
Charles Nace, T3212
added additional Appendix
1.3
9/08/2008
Added para regarding SCIF
Charles Nace, T3212
accreditation
1.4
09/25/2008
Added UFC information to
Charles Nace, T3212
Section 2.
DOCUMENT OWNER
(U//FOUO) Chief, T3212.
DOCUMENT STORAGE
(U//FOUO) T3212, Workflow, Standards and Support, maintains this document. Please submit
corrections, updates and recommendations to the document owner, for inclusion in future
versions. All changes will be approved by T3212 prior to the release of a new version.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 3 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
(U) Table of Contents
1
(U) Introduction
6
2
(U) Approved Infrastructure and Applications
6
2.1
(U) Fiber
7
2.2
(U) Copper
7
3
(U) Classification Separation
8
4
(U) Transport Vehicle
9
4.1
(U) Ground Source
11
4.2
(U) Wire-Way Installation Procedures
11
4.2.1
(U) Securing Sections
11
4.2.2
(U) Grounding
11
4.2.3
(U) Wire-Way Support
11
4.3
(U) Transport Vehicle Identification
12
4.3.1
(U//FOUO) Wire-Way
12
4.3.2
(U) Cabinets and Main Distribution Frames (MDF)
12
4.4
(U) Distribution of Services Within an Office
12
4.4.1
(U) Overhead Implementations
12
4.4.2
(U) Station Drop Construction
12
4.4.3
(U) Station Outlet Patch Cord Connections
13
4.5
(U) Distribution of Services Within a Machine Room
13
4.5.1
(U) Vertical Wire Management Systems
13
4.5.2
(U) Horizontal Wire Management Systems
13
5
(U) Cable Fabrication
13
6
(U) Cable Administration
16
7
(U) Cable Labeling
16
7.1
(U) Campus Backbone Cabling Identifier
16
7.2
(U) Building Backbone Cabling Identifier
16
7.3
(U) Equipment Room (ER) or Telecommunications Space (TS) Infrastructure Cable
Identifier
17
8
(U) Enclosure Power Panel and Caution Tag
17
9
(U) Communications Closet Terminations
18
10
(U) NSTS Instrument Identification
18
11
(U) Infrastructure Audits
18
Appendix A (U) Cable Color-Codes and Separation Requirements
19
Appendix B (U) Backbone Installation Tracking Database Sample
1
Appendix C (U) Label Types
1
Appendix D (U) Acronyms
2
Appendix E (U) References
3
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 4 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
(U) List of Figures
Figure 4 (U) Square D NEMA Type 1 Wire Way
10
Figure 5 (U) TIA/EIA 568B Terminating Instructions
15
(U) List of Tables
Table 2.2 (U) Approved Cable Applications
8
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 5 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
1
(U) Introduction
(U//FOUO) This document provides detailed instructions for the implementation and installation
of premise wire infrastructure in support of unclassified and classified networks within NSAW,
Build-out Facilities, domestic facilities where NSA controls the plenum1, domestic facilities
where NSA does not control the plenum and all OCONUS field sites. This document provides
instructions for implementations and installations of premise wiring in communications facilities,
office spaces and machine rooms by ITD Internal Service Providers (ISP), External Service
providers (ESP), field personnel stationed at the respective facilities or authorized NSA agents.
(U//FOUO) This document applies to all new voice, video, and data cabling including TS/SCI,
Secret and Unclassified networks for all NSA facilities identified in the previous paragraph. This
includes any construction, restoration, and modernization projects. This document is not intended
to justify wholesale replacement and upgrade of existing premise wiring or cable infrastructure
unless security violations are found.
(U//FOUO) It is presumed that any facility in which these instructions pertain is protected by
approved means of anti-terrorist force protection (ATFP), owned or leased by the NSA/CSS and
perimeters monitored by security cameras, intrusion alarms or other means approved and
implemented by the Office of Physical Security, Countermeasures/Headquarters Security and
Program Protection or Field Security. Where these do not apply, additional Security and
TEMPEST counter measures are required. Details are provided in the respective sections of this
document.
(U//FOUO) Prior to the installation of any Red communications or network infrastructure, all
facilities will have Sensitive Compartmented Information Facility (SCIF) accreditation in
accordance with NSA/CSS Manual 130-1, Annex P and NSA/CSS Policy 6-3, Operational
Information Systems Security Policy. All installation personnel must be legal U.S. citizens in
accordance with NSA/CSS Policy 5-23, Physical Security Requirements for Controlled Areas.
(U//FOUO) Failure to adhere to the Standards outlined in this document will result in delays in
activation and possibly denial of services until the facility is certified to be in compliance.
Additional site surveys will be conducted by the Office of Technical Security Countermeasures
as part of the automated Annex P process detailing appropriate Countermeasures for the
respective facility.
2
(U) Approved Infrastructure and Applications
(U//FOUO) Per NSA/CSS Policy 6-18, Secure Network Cabling2, fiber optic cable of total
dielectric construction remains the standard methodology for premise wiring implementations.
Copper shielded twisted pair (STP) cable is approved where specific applications demand it. At
no time will copper unshielded twisted pair (UTP) be permitted for use in transporting classified
1 Controlled plenum is defined as being a space where telecommunications networks infrastructure is installed. Only
NSA/CSS personnel or their authorized agents are permitted to install, remove or modify the infrastructure in any
way.
2 Policy is effective upon signature of DC31.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 6 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
or unclassified information. All fiber optic and STP cables will meet DOD Unified Facilities
Criteria (UFC), Document UFC 3-600-01, Fire Protection Engineering For Facilities. Paragraph
6-8.1.3 Power and Communication Cabling, under Electronic Equipment Installations. "Power
and communication (data) cabling installed in spaces above ceilings or below raised floors must
be plenum rated or installed in metallic conduit." See Table 2.2.
2.1
(U) Fiber
•
(U//FOUO) Single-Mode (SM) and Multi-Mode (MM) fiber optic - Telephone, Data,
Video
2.2
(U) Copper
•
(U) CAT3 STP - w/drain wire - Telephone only
•
(U) CAT5/5E STP - Telephone and DATA w/appropriate countermeasures
•
(U) CAT6 STP - Telephone and DATA w/appropriate countermeasures
•
(U) CAT7 STP - TBD. Waiting for test results and is currently not approved for use
•
(U) Coaxial - Video and News Magazine
•
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 7 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
FIBER OPTIC CABLE
SPECS
APPROVED APPLICATIONS
Single-Mode
8.5um/125um
Backbone Infrastructure
Desktop Data 1G/10G NIC
Equipment - Equipment Jumpers
Multi-Mode
62.5um/125um
Backbone Infrastructure
Desktop Data 10/100/GigE
Telephony
Equipment - Equipment Jumpers
50um/125um
Desktop Data 10/100 E/GigE
10GigE @ 850 NM wavelength, limited distance
Telephony
Equipment - Equipment Jumpers
COPPER STP
CAT3
STP w/drain
Telephony
CAT5/CAT5E
STP w/drain
Desktop (Classified) w/countermeasures
Network Printers and Servers w/countermeasures
Digital Telephony w/countermeasures
Analog Telephony w/countermeasures
Unclassified Telephony
Network Equiment - Equipment connections w/countermeasures
Unclassified Desktop
CAT6
STP w/drain
Desktop (Classified) w/countermeasures
Network Printers and Servers w/countermeasures
Analog Telephony w/countermeasures
Digital Telephony w/countermeasures
Unclassified Telephony
Network Equipment - Equipment connections w/countermeasures
Unclassified Desktop
CAT6E
TBD
CAT6A
TBD
CAT7
STP w/drain
TBD (currently being tested)
COAXIAL
Video
News Magazine
Mission Applications
(controlled use)
Test equipment
(controlled use)
TWINAX
Mission Applications
(controlled use)
Test equipment
(controlled use)
Table 2.2 (U) Approved Cable Applications
3
(U) Classification Separation
(U//FOUO) All cables transporting Red classified data may be installed within the same vehicles.
However, the end terminations will be in separate patch panels and outlet boxes based on
classification of information being transported. At no time will classified and unclassified cable
systems traverse the same vehicle or outlet boxes. Classification is determined based on whether
it is Special Compartmented Information (SCI) and Non-SCI.
(U//FOUO) When installing parallel cable systems, a minimum of 6 inches of clearance must
separate the Red conveyance from any unclassified and power wire/cabling distribution.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 8 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
Intersections of cable systems must be made at a 90° angle and provide a minimum of two (2)
inches vertical separation.
4
(U) Transport Vehicle
(U//FOUO) Premise wire cable management systems are strongly recommended for all classified
and unclassified services but are not required for raised floor controlled plenum applications.
However, when an overhead infrastructure is designed, all classified and unclassified copper and
fiber optic communications premise wiring will be installed in a dedicated approved wire
management system. Cable management systems mitigate the risk of damage to the critical
infrastructure and the possible compromise of sensitive classified data due to improper “after-
the-fact” installations.
(U//FOUO) In all other facilities, whether an overhead or under floor infrastructure is designed,
all classified and unclassified copper and fiber optic communications premise wiring will be
installed in a dedicated approved wire management system.
(U//FOUO) Approved vehicles are Electrical Metallic Tubing (EMT) and anodized or standard
painted metallic wire ways (SQUARE-D general purpose NEMA Type-1 w/knockouts in Figure
4) with secured covers, flex and telepoles. Ladder racks with no more than six (6) inches of
separation between rungs and cable trays are approved only for installations within
telecommunications closets and transport rooms. The designer will scope the size of wire-way to
accommodate the total number of cables plus 40% growth.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 9 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
GENERAL PURPOSE - NEMA TYPE 1 PAINTED WIREWAY
Concentric knockout (1-1¼)
Concentric knockout (½-¾)
sizes
sizes
12.00 in
5.97 in
3.0 in
3.0 in
1.5 in
3.0 in
1.5 in
12.00 in
Figure 4 (U) Square D NEMA Type 1 Wire Way
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 10 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
4.1
(U) Ground Source
(U//FOUO) A dedicated signal ground plate must be provided in each Communications
Closet providing NSA services. Approved grounding methods are Signal Reference Ground
(SRG) also known as Common Bonding Network (CBN) and Isolated low impedance
ground known as Isolated Bonding Network (IBN). The method chosen will be implemented
in accordance with TIA/EIA-607-A Commercial Building Grounding and Bonding
Requirements for Telecommunications. These grounding networks ultimately terminate to
the same Telecommunication Main Ground Bar (TMGB). However, the primary conductors
must traverse diverse paths to the TMGB.
(U) (U//FOUO) The SRG/CBN is used as the National Electric Code (NEC)/NFPA70
compliant system for grounding electrical noise generating equipment such as High Volume
Air Conditioning (HVAC) systems, transformers and alarm systems. The SRG/CBN
provides an independent path to the Telecommunications Main Ground Bar (TMGB). The
TMGB is typically installed in a primary electrical switch gear room or service entrance.
While NFPA-70 requires a ground of 25 ohms or less, the SRG/CBN when installed in a
telecommunications facility provides the same potential to earth ground as the IBN.
(U) Most Original Equipment Manufacturers (OEM) bond the Signal and Safety grounds
internal to the devices. However, there are instances where sensitive electronic equipment
requires a separate ground source be supplied to an isolated grounding lug. This requires the
implementation of an IBN. IEEE-142-1999 requires IBN supporting sensitive electronic
equipment to have a measured impedance of 1 ohm or less to the earth ground. The IBN
provides a means to properly ground equipment with no risk of stray electrical currents or
Radio Frequency Interference (RFI) which may degrade the performance of the associated
network, operational missions and in extreme cases damage sensitive electronic equipment.
(U) Approved methods of bonding to the ground plate are cad/exothermic welds and double
through bolted using approved grounding connectors, pressure crimps and star lock washers.
4.2
(U) Wire-Way Installation Procedures
4.2.1 (U) Securing Sections
(U) Sections of wire-way will be joined using vendor specified unions/straps and
secured using machine screws, 2 each outside locking star washers and nut.
4.2.2 (U) Grounding
(U) The vehicle will be grounded in accordance with the NFPA-70/National Electric
Code (NEC) and TIA/EIA-607-A, Commercial Building Grounding and Bonding
Requirements for Telecommunications.
4.2.3 (U) Wire-Way Support
(U) Suspend wire-way from building structure using approved methods. The wire-way
will be secured to supporting device-using vendor recommended hardware and weight
loading specifications.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 11 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
4.3
(U) Transport Vehicle Identification
4.3.1 (U//FOUO) Wire-Way
(U//FOUO) Vehicles containing NSA services will be distinctly marked. Identification
will consist of three (3) bands of tape in a pattern of Red-Blue-Red, ¾ inch - 1.5 inch -
¾ inch respectively, to identify the presence of classified data. Only a high quality pipe
banding tape such as SETON (seton.com), Red ¾ inch style M4293, Part # 26019; Blue
1.5 inch, style M4294, Part # 26023 or equivalent will be used. The use of existing
NSTS marking tape (Red-Grey-Red) is permitted until current inventory is depleted.
Standard color-coded electrical tape will not be used. This sequence will be repeated
every five (5) feet, two and one half (2.5) feet from each end of a ten (10) foot section
of wire-way.
4.3.2 (U) Cabinets and Main Distribution Frames (MDF)
(U//FOUO) These will be marked in accordance with the ITD Premise Wire Standards.
4.4
(U) Distribution of Services Within an Office
4.4.1 (U) Overhead Implementations
(U//FOUO) The approved vehicle will be installed from the respective communications
distribution closet. When there is an existing primary vehicle, determine a point of
intersection and install the new vehicle, to the office area in which the connections are
terminated. It is required to install overhead vehicles in areas where raised flooring
systems are not available. Installation, labeling and grounding will be in accordance
with TIA/EIA-569A, Commercial Building Standard for Pathways and Spaces;
TIA/EIA-606A, Administration Standard for Commercial Telecommunications
Infrastructure; NFPA-70/NEC and TIA/EIA-607-A, Commercial Building Grounding
and Bonding Requirements for Telecommunications respectively.
4.4.2 (U) Station Drop Construction
(U//FOUO) Approved methods of cable distribution to the desktop from overhead
transport vehicles include ferrous metallic telepoles, ferrous metallic flex and EMT
conduit.
4.4.2.1
(U) Overhead Applications
(U//FOUO) Will be constructed of a minimum of ¾ inch EMT, Flex or telepoles
and will be joined to the wire-way using standard couplings and connectors
designed for their intended purpose. The station drop will be grounded in
accordance with NFPA-70 and TIA/EIA-607A.
4.4.2.2
(U) Under Floor Applications
(U//FOUO) The last ten (10) feet will be constructed of a minimum of ¾ inch EMT
or flex conduit. The conduit will be terminated in the LISKEY box or other
approved ITD device with appropriate couplings and connectors. The station drop
will be grounded in accordance with NFPA-70 and TIA/EIA-607A.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 12 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
(U//FOUO) When installing parallel cable systems, a minimum of 6 inches of
clearance must separate the Red conveyance from any unclassified and power
wire/cabling distribution. Intersections of cable systems must be made at a 90°
angle and provide a minimum of two (2) inches vertical separation.
4.4.3 (U) Station Outlet Patch Cord Connections
(U//FOUO) Due to customer requirements for rapid reconfigurations and placement of
distribution boxes, it is permissible to extend the desktop access cabling through the
flooring system via a protective sleeve.
(U//FOUO) Patch cords connecting premise wiring to desktop device will be no longer
than three (3) meters in length, will be STP and terminated with RFI, metallic jacketed
connectors and are to be routed so as to maintain a minimum of six (6) inches of
separation between power, classified and unclassified services.
4.5
(U) Distribution of Services Within a Machine Room
4.5.1 (U) Vertical Wire Management Systems
(U//FOUO) Equipment rack enclosures hosting Local Area Network (LAN) and Wide
Area Network (WAN) telecommunications equipment will include vertical wire
management systems in the front and rear sections. Approved systems such as the
square PANDUIT wire management with covers will be used. The vertical management
systems will interface with the horizontal management systems providing a seamless
transition and required radius bend for both fiber and copper infrastructures.
Installation, labeling and grounding will be in accordance with TIA/EIA-569A,
Commercial Building Standard for Pathways and Spaces; TIA/EIA-606A,
Administration Standard for Commercial Telecommunications Infrastructure;
NFPA70/NEC and TIA/EIA-607A, Commercial Building Grounding and Bonding
Requirements for Telecommunications respectively.
4.5.2 (U) Horizontal Wire Management Systems
(U//FOUO) Horizontal cable management systems will be installed in all machine
rooms and will not be dependent on overhead or under floor implementations.
Installation, labeling and grounding will be in accordance with TIA/EIA-569A,
Commercial Building Standard for Pathways and Spaces; TIA/EIA-606A,
Administration Standard for Commercial Telecommunications Infrastructure; NEC,
NFPA70 and TIA/EIA-607A, Commercial Building Grounding and Bonding
Requirements for Telecommunications respectively.
5
(U) Cable Fabrication
(U//FOUO) All cable will be Plenum rated. When installing CAT5 STP, CAT5E STP or CAT6
STP, it will be terminated with metallic jacketed connectors and in accordance with EIA/TIA-
568B (Figure 5). All cables will be contiguous and splice free from Communications closet to
the station drop outlet box.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 13 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
(U//FOUO) All copper STP cable jackets will be color-coded respective to the classification of
data being transported. Black will denote unclassified data. Purple will denote Red Non-SCI and
Red will denote TS/SCI. In the event OEM system cables and/or jumpers are not available in the
specified color code, the installer will place a band of ¾ inch industrial grade tape, SETON style
M4293, Red (#26019), Black (#26011) or Purple (#26018) or equivalent, three (3) inches from
the end of the jacket at the points of origin and destination and at increments of five (5) feet
between. All communications cables will be tested for compliance with their intended purposes.
(U//FOUO) Fiber optic jumper jackets will be color coded respective to Single Mode (SM) or
Multi Mode (MM). SM will be identified by using a Yellow jacket and Orange will denote MM.
The data classification will be identified using colored tape as described in the preceding
paragraph.
(U//FOUO) See Appendix C for application and separation criteria relevant to implementations
of copper and fiber optic infrastructures.
(U//FOUO) All tests will be documented and made available upon request by ITD personnel or
their authorized agents.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 14 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
How to Assemble CAT 5e Shielded
Solid or Stranded RJ 45 Plugs
Step 1. Carefully strip the outer sheath
Step 4. Insert the plug into a crimp tool.
insulation back1". Roll back
Firmly squeeze the handles to set
the foil shield insulation and
the contacts and secure the cable.
wrap the drain wire around the
foil. Do not remove and
insulation from the
conductors.
Step 2. Untwist the pairs to within1/8" of
Step 5. Test the cable using a cable tester
the jacket. Arrange the wires
for shorts, opens or miswires.
according to TIA/EIA 568A &
Wiring Diagram
568B standards. Flatten and align
OrangePair 2
the wires. Make one straight cut
GreenPair 3
Blue
Brown
Pair 1
Pair 4
across all the conductors, removing
approximately ½” to ensure the
ends are of equal length.
1
2
3
4
5
6
7
8
Step 3. Hold the connector in front of you
with the locking tab down. Orient
RJ-45 JACKTIA/EIA 568A STANDARD
the wires so connector Pin 1 aligns
GreenPair 3
OrangePair 2
Blue
Brown
with cable Pin 1, etc. Pin 1 is on
Pair 1
Pair 4
the far left. Slide the wires into the
CAT5e connector. The cable
jacket should extend into the
connector about ¼” for strain relief.
1
2
3
4
5
6
7
8
RJ-45 JACK
TIA/EIA 568B STANDARD
W iring Diagram
OrangePair 2
Green
Blue
Brown
Pair 3
Pair 1
Pair 4
1
2
3
4
5
6
7
8
RJ-45 JACK
TIA/EIA
568A STANDARD
Green
Pair 3
OrangePair 2
Blue
Brown
Pair 1
Pair 4
1
2
3
4
5
6
7
8
TIA/EIA
RJ-45 JACK
568B STANDARD
Figure 5 (U) TIA/EIA 568B Terminating Instructions
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 15 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
6
(U) Cable Administration
(U//FOUO) All cables, wire-ways and station drops will be documented in accordance with
EIA/TIA-606-A, Administration Standard for Commercial Telecommunications Infrastructure,
dated 2002. See Appendix B for data base example.
7
(U) Cable Labeling
(U//FOUO) Connections and service loops, at the distribution shelves, will be in accordance with
the cable manufacturer’s recommendation and the field site-specific installation requirements.
All jumpers3 will be labeled at each end with the minimum of origination/destination
information. All cables will be identified with cable markers in accordance with NSA Standard
DS-61E. The cable markers will be black printing on a white backg1round. The printing must be
legible and not hand-written. All cables will include a unique alphanumeric identifier as
described in Sections 7.1, 7.2, and 7.3. Appendix C shows examples of labeling types.
7.1
(U) Campus Backbone Cabling Identifier
(U//FOUO) A unique campus backbone cable identifier shall be assigned to each backbone
cable connecting Telecommunications Space (TS)4 in different buildings and it shall have
the format [b1fs1]/[b2fs2]-n as stated in TIA/EIA-606-A, P20, Section 7.1.2. The format is:
•
(U) b1fs1 = building identifier and TS identifier for the TS in which one end of the
backbone cable is terminated
•
(U) b2fs2 = building identifier and TS identifier for the TS in which the other end of
the backbone cable is terminated
•
(U) n = one or two alpha-numeric characters identifying a single cable with one end
terminated in the TS designated b1fs1 and the other end terminated in the TS
designated as b2fs2
(e.g.: R&E TS1 (R1C052) to OPS2A TS1 (Penthouse OP2AP5) Backbone cable 3 = RE-
R1C052/OPS2A-OP2AP5-3)
(U//FOUO) All campus backbone cables shall follow the same format and the label shall be
placed within 300mm (12 in.) of the end of the cable jacket.
7.2
(U) Building Backbone Cabling Identifier
(U//FOUO) A backbone cable between TS in a single building shall have a unique identifier
having the format fs1/fs2 - n where:
•
(U) fs1 = TS identifier for the space containing the termination of one end of the
backbone cable
•
(U) fs2 = TS identifier for the space containing the termination of the other end of the
backbone cable
3 Jumpers are pre-terminated STP copper or fiber optic cables providing a connection between two
telecommunications or network devices.
4 TS is an area used for housing the installation and termination of telecommunications equipment and cable.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 16 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
•
(U) n = One or two alphanumeric characters identifying a single cable terminated
between fs1 and fs2
(e.g.: OPS2A TS1 (OP2AP5) to OPS2A TS4 (2AB060) cable number 1 = OPS2A-
OP2AP5/OPS2A-2AB060 - 1)
(U//FOUO) All building backbone cables shall follow the same format and the label shall be
placed within 300mm (12 in.) of the end of the cable jacket.
7.3
(U) Equipment Room (ER) or Telecommunications Space (TS)
Infrastructure Cable Identifier
(U//FOUO) A unique cable identifier will be placed on infrastructure cabling connecting a
central distribution point to a specified row of equipment racks. The cable identifier will
have the format op1/tp1 - n where:
•
(U) op1 = The rack location and elevation of copper terminal block or optical fiber
Light Guide Exchange (LGX)
•
(U) tp1 = The rack location and elevation in which the opposite end of the cable is
terminated in the associated copper terminal block or optical fiber LGX
•
(U) n = A one or two character numeric designator assigned to the physical cable (e.g.:
Distribution rack RBE04 Front Elevation 29 to RBC15 Front Elevation 39 cable
number 1 = RBE04-F-29/RBC15-F-39 - 1)
(U//FOUO) ER5 or TS Copper Shielded Twisted Pair (STP) and Optical Fiber Jumper
Identifier shall be labeled with a unique identifier having the format op1/tp1 where:
•
(U) op1 = The enclosure location and elevation of copper terminal block, optical fiber
LGX originating termination, patch panel detail or equipment port
•
(U) tp1 = The enclosure location and elevation in which the opposite end of the cable
is terminated in the respective copper terminal block, optical fiber LGX originating
termination, patch panel detail or equipment port. (e.g.: RBC10 front elevation 35 port
2 to RBC20 rear elevation 40 port 3 = RBC10-F-35 p2/RBC20-R-40 p3)
(U//FOUO) All infrastructure cables shall follow the same format and the label shall be
placed within 300mm (12 in.) of the end of the cable jacket.
8
(U) Enclosure Power Panel and Caution Tag
(U//FOUO) The rack power panel tag identifies the power disconnect point, including power
panel and circuit breaker numbers. The rack power panel tag is required on the front and back of
each rack. For those racks equipped with solid doors, the labels will be placed on the inside of
each door. Those racks with mesh or vented doors, the labels will be placed on the mounting
rails. See Appendix C for example.
5 ER is an enclosed space for housing telecommunications equipment, cable terminations, and cross-connect cabling
that is the recognized location of the horizontal cross-connect
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 17 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
(U//FOUO) Caution tags are required on the rear of racks containing equipment powered by
other than 120 VAC. The caution tag identifies any power usage other than the normal 120 VAC.
See Appendix C for example.
(U//FOUO) A unique cable identifier will be placed on cables from rectifiers to the batteries and
main distribution panels to the equipment fused distribution panel (BDFP). The label will follow
the same format as detailed in Section 5.3 (e.g.: Distribution rack RBE04 Rear Elevation 29 to
RBC15 Rear Elevation 39 cable number 1 = RBE04-R-29/RBC15-R-39-1). The tags will be
black printing on a yellow backg1round.
9
(U) Communications Closet Terminations
(U//FOUO) Approved methods of terminations within the closet are: BIX blocks, LUCENT 110
blocks and KRONE for CAT3 STP Implementation. RJ45/11 patch panels with metallic jacketed
female connectors will be used for CAT5 STP, 5E STP and Cat 6 STP.
(U//FOUO) Each equipment rack installed within Red communications closets will be grounded
individually to the Red Signal Ground Plate using American Wiring Guide (AWG) #6 stranded
or solid core wire.
(U//FOUO) All “wall mounted” cable termination devices will have an “intermediate” ground
bus bar and must be installed in close proximity to allow proper termination of cable drain wires.
This bus bar will be grounded to the Red Signal Ground Plate using #6AWG stranded or solid
core wire.
10 (U) NSTS Instrument Identification
(U//FOUO) All telephone instruments connected to the NSTS will be properly labeled with NSA
provided “NSTS” stickers. Stickers will be applied to the top of each telephone instrument’s
handset.
11 (U) Infrastructure Audits
(U//FOUO) The entire distribution system will be inspectable. All cables will be clearly marked
and documented in accordance with section seven (7) of this document.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 18 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
Appendix A (U) Cable Color-Codes and Separation Requirements
CABLE
APPLICATION
COLOR
COMMENTS
COPPER
12-900 pr
Campus PDS
Grey or Black
Red and Black transport cables
will be installed in separate
conduits and termination frames
12-900 pr
Building Vertical
Grey or Black
Must be installed in separate
Backbone
conduits, frames. Physical
separation in frame rooms or
transport closets. Ex.-Opposite
sides of rooms or separate rooms.
12-900 pr
Horizontal Transport
Grey or Black
Must be installed in separate
conduits, frames management
systems. Physical separation in
frame rooms or transport closets.
Ex.-Opposite sides of rooms or
different rooms.
12-50 pr
Inter-machine
Neutral orGrey
Color-coded with industrial grade
Connections
tape. Red=SCI
Purple=Non-SCI
Black=Unclassified
CAT5E STP
InterRow/Rack/
Red
SCI
IntraRow/Rack/
Purple
Non-SCI
Telephony/Desktop
Black
Unclassified
CAT6E/A
TBD
TBD
TBD
CAT7
TBD
TBD
TBD
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 19 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
CABLE
APPLICATION
COLOR
COMMENTS
FIBER
48-144
PDS
Black
Hybrid cable customer specifies
strands
number if SM and MM
Red/Black separation using
separate conduits and
incompatible terminations.
48-144
Vertical Backbone
Orange
MM
strands
Yellow
SM
Red/Black separation using
separate conduits and
incompatible terminations.
12-144
Horizontal Distribution
Orange
MM
strands
Yellow
SM
Red/Black separation using
separate conduits and
incompatible terminations.
PDS/Interstate
Green
TRUEWAVE
Trans-Oceanic
1 strand
InterRow/Rack/
Yellow
SM
Simplex
w/appropriate color
IntraRow/Rack/
Red/Black separation using
marking tape
separate cable management
Desktop
systems and incompatible
terminations.
2 strands
InterRow/Rack/
Orange
MM
Duplex
w/appropriate color
IntraRow/Rack/
Red/Black separation using
marking tape
separate cable management
Desktop
systems and incompatible
terminations.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 20 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Appendix B (U) Backbone Installation Tracking Database Sample
STO#
STO Name
Leg Name
Color
Status
SM Counts
MM Counts
Truwave Counts
Comments
STO 015
MAR
Cooper Ave (Bldg
Black
Ctd
“AY” 1-144
-----
-----
Complete
3904) to NBP140 - 144
Fiber
STO 048
NBP318
NBP140 to NBP318 -
Red
Ctd
“EC” 265-552
-----
-----
Complete
288 Fiber
STO 064
NBP322
OPS1 to NBP322
Red
Not
“RSR” 265-522
-----
-----
Waiting to start
Customer Fiber - 288
Started
NBP322; Crew
Fiber
will terminate
STO 077
FGGM Fiber
Fort Meade DCO Fiber
Black
Hold
“DI” 1-36
-----
-----
On hold. Waiting
Upgrade
Upgrade
for additional
funding
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Appendix C (U) Label Types
Type
Description
Example
Campus Backbone
Cables connecting
R&E TS1 to OPS2A TS2
Telecommunications
Backbone cable 3.
Spaces (TS) in different
RE-R1C052/OPS2A-OP2AP5-3
buildings.
Building Backbone
Cable connecting TS’ in a
OPS2A TS1 to OPS2A TS4 cable
single building.
1.
OPS2A-OP2AP5/OPS2A-
2AB060-1
Equipment Room (ER) or TS
Central distribution point to a
Distribution rack RBE04 Front
Infrastructure
specific row of Equipment
Elevation 29 to RBC15 Front
enclosures.
Elevation 39 cable 1.
RBE04-F-29/RBC15-F-39-1
Equipment-to-Equipment Jumper
Cable connecting two (2)
RBC04-R-20 port 4 to RBC07-R-
pieces of Telecommunications
35 port 10.
or Networking equipment.
RBC04-R-20 p4/RBC07-R-35
p10
Light Guide Exchange (LGX) or
Optical or Copper Jumper
LGX or Patch RDC01-F-33 detail
RJ Patch Panel to
ALL Red copper jumpers must
13 to Equipment RDC12-R-14
Telecommunications or Network
be Shielded Twisted Pair
port 3.
Equipment Jumper
(STP).
RDC01-F-33-13/RDC12-R-14
p3
Power Distribution
Connection from Source to
48VDC Rectifier RDC10-R-33
Equipment.
connector 5 to Battery
Distribution Fuse Board (BDFB)
RDC11-R-24 input A.
48VDC RDC10-R-33 p5/
RDC11-R-24 IN A
Enclosure Power Panel and
Identifies power disconnect
120VAC from RDC01 Circuit
Caution Tag
point (panel and circuit
Breaker 13.
breaker) and Voltage.
120VAC
RDC01-13
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
Appendix D (U) Acronyms
Acronym
Definition
ATFP
Anti-Terrorist Force Protection
AWG
American Wire Gauge Standard
CAT3
Category 3 - reliably carry data up to 10 Mbits; possible bandwidth of 16
Mbits
CAT5
Category 5 - 100MHz
CAT5E
Category 5 Enhanced - 100MHz
CAT6
Category 6 - 250 MHz
CAT7
Category 7 - 600 MHz
CBN
Common Bonding Network
EMT
Electrical Metallic Tubing
IBN
Isolated Bonding Network
LAN
Local Area Network
MM
Multi mode
OEM
Original Equipment Manufacturer
SM
Single mode
RF
Radio Frequency
SRG
Signal Reference Ground
STP
Shielded Twisted Pair
TMGB
Telecommunications Main Ground Bar
UTP
Unshielded Twisted Pair
WAN
Wide Area Network
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 2 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
Appendix E (U) References
Reference Number
Reference Name
DCID 6-3
Protecting Sensitive Compartmented Information Within Information
Policy Home Page
Systems, dated 11 December 2003
X3224 Web
ITD Premise Wire Standard
(See Jeffrey Parr for hard copy)
LF13 Web
LF13 Facility Electrical Engineering Standard (FEES)
Mil-Hndbk-419A
Grounding, Bonding and Shielding for Electronic Equipment and Facilities,
dated 29 Dec. 1987
NFPA-70
National Electric Code (NEC)
NSA/CSS DS-61E
Standards for Preparation of Engineering Documentation, dated 22 Oct.
1999
NSTISSAM 2-95
Red/Black Installation Guidance, dated 03 Feb. 2000
TELECORDIA GR-
Generic Requirements for Single mode Optical Connectors and Jumper
326-CORE
Assemblies, dated 03 Sept 1999
TELCORDIA-409-
Generic Requirements for Premise Fiber Optic Cable, dated 01 May 1994
CORE
TIA/EIA-568-B.1
Commercial Building Telecommunications Cabling Standard, dated 2001
TIA/EIA-569-B
Commercial Building Standard for Telecommunications Pathways And
Spaces, dated 1990
TIA/EIA-606-A
Administration Standard for Commercial Telecommunications
Infrastructure, dated 2002
TIA/EIA 607-A
Commercial Building Grounding (EARTHING) And Bonding
Requirements for Telecommunications
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 3 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Document Number: X312-061-1006
Name: Cable Installation at NSAW Facilities
T3212 Public Folder
Installation Guidelines, Ford Aerospace And Communications Corp, dated
Jan 1986
UFC 3-600-01
Fire Protection Engineering for Facilities, dated 26 Sept 2006
NSA/CSS 130-1
NSA/CSS Access to NSA/CSS Information Systems and Services, dated 02
April 2004
NSA/CSS Policy 6-3
NSA/CSS Operational Information System Security Policy, dated 08 Aug
2006
NSA/CSS Policy
NSA/CSS Physical Security Requirements for Controlled Spaces Policy,
5-23
dated 24 Aug 2007
NSA/CSS Manual
NSA/CSS Physical Security Requirements for Controlled Spaces Manual,
5-23
dated 24 Aug 2007
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 4 of 25
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NATIONAL SECURITY AGENCY
NAG-16F
(U) FIELD GENERATION AND
OVER-THE-AIR DISTRIBUTION
OF COMSEC KEY IN SUPPORT OF
TACTICAL
OPERATIONS AND EXERCISES
(U) HANDLING INSTRUCTIONS
1. (U) This document is effective upon receipt and supersedes NAG-16E,
dated January 1999, which should be destroyed.
2. (U) Changes to this document will be promulgated by printed or message
amendments that are to be entered upon receipt. Persons entering such
amendments are expected to record entry on the Record of Amendments
page.
3. (U) This document in not accountable in the COMSEC Material Control
System. It may be reproduced without report, and extracts from it that are
marked “UNCLASSIFIED//FOR OFFICIAL USE ONLY” may be made for
official purposes.
4. (U) This document and its extracts may be used in aircraft.
5. (U) Foreign release of this document must be approved by the Director,
National Security Agency.
MAY 2001
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED
NAG-16F
RECORD OF AMENDMENTS
DATE
AMEND NO.
BY WHOM ENTERED
ENTERED
UNCLASSIFIED
ORIGINAL
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
(U) FOREWORD
1. (U//FOUO) Where Are We Heading? - A major evolution in communications security
(COMSEC) keying technology has begun. Under the Electronic Key Management System (EKMS)
program, standards, hardware, and applications are being developed to apply state of the art
automation to generate, distribute, load, control, and account for COMSEC key. The program
incorporates sufficient backward compatibility to assure that both future, automated key and existing,
common electronic key can be handled. EKMS hardware is being fielded, but full development of
tailored tactical key generation and distribution programs may take several more years.
2. (U//FOUO) Where Are We Now? - Until EKMS Key Processors (KPs) and local
management devices (LMDs) are fully implemented throughout the tactical forces, military
commanders must be able to establish secure communications, without needless and/or redundant
prepositioning of key or last minute key tape distribution. This document prescribes pre-EKMS
techniques to satisfy that requirement, but emphasizes use of available EKMS terminals and other
key variable generators (KVGs) to generate tactical key.
3. (U//FOUO) Interoperability - Effective and timely creation of secure tactical nets and
circuits requires that communications planners and operators have a common base of understanding
regarding applicable COMSEC procedures and equipment operating instructions. This document
fulfills that requirement for Joint commands and their Service components. It also has limited
applicability in multi-national operations and exercises, when the Allied participants use COMSEC
equipment that is capable of over-the-air key distribution (OTAD).
NOTE: (U//FOUO) ACP-132A, Field Generation and Over-the-Air Distribution of Key
in Support of Tactical Operations and Exercises, is the equivalent of NAG-16F for use by
the military forces of Australia, Canada, New Zealand, and the United Kingdom. U.S. tactical
forces do not hold ACP-132A, because its provisions are similar to those of NAG-16F.
NOTE: (U//FOUO) NAG-22A, Over-the-Air Rekeying of Combined Tactical Nets and
Circuits, is a partial equivalent of NAG-16F intended to explain over-the-air rekeying (OTAR)
to Allied users of “S” nomenclatured (special purpose) COMSEC equipment. When
Combined nets/circuits include terminals equipped with “S” equipment, a U.S. station
equipped with “K” nomenclatured equipment must serve as the net control station (NCS).
U.S. tactical forces do not hold nor need NAG-22A.
NOTE: (U//FOUO) SDIP-14, Operational Doctrine for TSEC/KW-46 Fleet Broadcast,
includes doctrine for Over-The-Air Transfer (OTAT) of tactical key via the single-channel
North Atlantic Treaty Organization (NATO) fleet broadcasts. U.S. Navy (USN) tactical forces
having NATO missions should hold SDIP-14.
4. (U//FOUO) Implementation - The principal advantage of the key management procedures
presented here is flexibility to create a continuing supply of tactical key for a variety of commonly
held COMSEC equipment and to distribute it electronically to potential users. The key generation
and distribution routines given are particularly suitable for support of Joint operations and exercises
involving forces that do not routinely train together. However, they cannot be relied upon to
contribute to joint mission accomplishment, unless required levels of user competency are
maintained through incorporation into intra-Service operations and exercises.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
i
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
5. (U) Assumption - The keying routines presented herein assume that operators are familiar
with the capabilities, operation, and safeguarding of the COMSEC equipment used and that secure
communications capable of transmitting tactical key exist or can be established.
6. (U) Relationship to National Directives - NAG-16F incorporates innovative key
distribution concepts that may not be reflected in national-level information systems security
directives. Until the National Security Agency (NSA) can resolve and such conflicts, the provisions
of NAG-16F constitute approved operational exceptions to the affected national directives.
7. (U) Changes Reflected in NAG-16F - The principal differences between NAG-16F and its
predecessor, NAG-16E, involve:
a. (U) KW-46 - A corrected OTAD routine for the KW-46 equipment used to secure U.S.
Navy (USN) and U.S. Coast Guard (USCG) broadcasts, which was provided by Fleet Training
Center Norfolk, VA, is reflected in Annex H.
b. (U//FOUO) SINCGARS OTAD & ERF - Because the user application software that has
been developed for the data transfer device (DTD) has become so specialized, it is no longer feasible
to publish a standard procedure for performing OTAD and electronic remote fill (ERF) for the various
Single Channel Ground and Airborne Radio System (SINCGARS) securable radios. On the basis of
an Army suggestion, the SINCGARS and ERF procedures that had been included as Annex F in
NAG-16E have been omitted from NAG-16F. Users who find the previous SINCGARS OTAD and
ERF procedures useful may clip them out of NAG-16E and retain them, before NAG-16E is
destroyed.
c. (U) Users of 128-bit TEK - On the basis of another Army suggestion, the listing of
contemporary U.S. COMSEC equipment that accepts 128-bit traffic encryption key (TEK), which
had been included in NAG-16E as Annex K, has been omitted from NAG-16F. Here again, users
who find that listing useful may clip it out from NAG-16E and retain it, before NAG-16E is
destroyed.
d. (U) OTAT via AUTODIN - Because the Automatic Digital Information Network
(AUTODIN) is being replaced by the Defense Message System (DMS), the paragraph in NAG-16E
that had addressed the conduct of OTAT on AUTODIN has been omitted from NAG-16F.
e. (U//FOUO) AN/CYZ-10 - Revised procedures for performing OTAD with
AN/CYZ-10s, including provisions for transferring all types and classifications of COMSEC key
between DTDs via Secure Telephone Unit (STU) - III, STU-IIIA, STU-IIB, and Secure Terminal
Equipment (STE) secured telephone circuits, and OTAT of DTD transfer key encryption key
(TrKEK) on EKMS-to-DTD circuits have been reflected in Annex I.
f. (U//FOUO) ANDVT and KY-57/58/67 Cold Starting - New mandatory cold starting
procedures for KY-57/58/67 (See paragraphs 3.a. step 2 and 3.b. step 3 of Annex E.) and for KYV-5
and KY-99/99A/100 (See paragraphs 3.a. step 2 and 3.b. step 3.) of Annex F.)
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
ii
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
g. (U//FOUO) US-Only Key to Allies - Authorization and criteria by which controlling
authorities (CAs) of US-Only key may release it to Allies have been included in paragraph 3.h.(3)(a)
on page 11 of the main section of NAG-16F.
h. (U//FOUO) JTIDS Key and Data Transfers Via Secure Telephone Circuits -
Procedures for OTAT of Joint Tactical Information Distribution System (JTIDS) key and data
between DTDs connected by secure telephone circuits that were developed by SPAWARSYSCEN
San Diego are stated in Annex I.
8. (U) Comments - Holders of this document are encouraged to review it critically and to
submit comments for its improvement, through command channels, to Director, National Security
Agency, ATTN: I41T, Fort George G. Meade, MD 20755-6000.
9. (U//FOUO) Action Officer - The NSA NAG-16F action officer, Mr. Maguire, may be
reached by phone at Defense Switched Network (DSN) 244-6804 or commercial (COML) (410)
854-6804.
MICHAEL J. JACOBS
Information Assurance
Director
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
iii
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
THIS PAGE IS INTENTIONALLY BLANK
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
iv
UNCLASSIFIED
NAG-16F
TABLE OF CONTENTS
(Also Serves as Index)
SUBJECT
PAGE
(U) RECORD OF CORRECTIONS
Reverse of Front Cover
(U) FOREWORD
i
1. Where Are We Heading?
i
2. Where Are We Now?
i
3. Interoperability
i
4. Implementation
i
5. Assumption
ii
6. Relationship to National Directives
ii
7. Changes Reflected in NAG-16F
ii
8. Comments
iii
9. Action Officer
iii
(U) TABLE OF CONTENTS
iv
(U//FOUO) FIELD GENERATION AND OVER-THE-AIR DISTRIBUTION OF
1
COMSEC KEY IN SUPPORT OF TACTICAL OPERATIONS AND EXERCISES
1. INTRODUCTION
1
a. Perspective
1
b. Purpose
1
c. Definitions & Acronyms
1
d. Activation
1
e. Application to TRI-TAC & MSE
1
(1) Using KVGs & Fill Devices
2
(2) Certifying KT -83s & KVGs
2
(3) Storing KT -83s & KVGs
2
(a) Physical Safeguards
2
(b) Tamper Detection Labels
2
(c) KVG Locking Bars
2
(d) KVG Inspections
3
f. KY-68 OTAT
3
2. OTAD-CAPABLE EQUIPMENT
3
3. OTAD KEYING DOCTRINE
4
a. Key Requirements
4
b. Communications Paths
4
c. Types of Key
4
(1) TEK
4
(2) Key Encryption Key (KEK)
5
(3) Start-up KEK
5
(4) KW-46 Keys
5
(a) Broadcast Area Variable (BAV)
5
(b) Community Variable (CV)
5
(c) TEK5
5
(d) KEK
5
(e) Unique Variable (UV)
6
(5) Transmission Security Key (TSK)
6
UNCLASSIFIED
ORIGINAL
v
UNCLASSIFIED
NAG-16F
SUBJECT
PAGE
d. KEK Doctrine
6
(1) KEK Generation & Distribution
6
(a) Routine Procedures
6
(b) Emergency Procedures
6
(c) TRI-TAC/MSE KEK Generation & Distribution
6
(2) Cold Start
6
(3) KEK Classification
7
(4) KEK Allocation
7
(a) Multi-Station Nets
7
(b) P-T-P Circuits
7
(5) KEK Cryptonet Size
7
(6) KEK Cryptoperiods
8
(7) KEK Supersession
8
(a) Tape KEK
8
(b) Field-generated KEK
8
e. Start-up KEK Doctrine
8
(1) Start-up KEK Production & Distribution
8
(2) Start-up KEK CA Responsibilities
8
(3) Start-up KEK Holders and Cryptonet Size
8
(4) Start-up KEK Segment Count, Cryptoperiod and Supersession 8
(5) Start-up KEK Use
9
(6) ICP Start-up KEK Use
9
f. TEK Doctrine
9
(1) Sources of TEK
9
(a) TEK Generation with Certified KVGs
9
(b) Key Generation with LMD/KP
10
(b) TEK Generation with KY-57/58/67 and KYV-5/
10
KY-99/99A/100
(2) TEK Distribution
10
(a) Methods
10
(b) TEK Implementation
10
“1” GENSER TEK
10
“2” SCI/SI TEK
10
(3) TEK Classification
10
(4) TEK Allocation
10
(5) TEK Cryptoperiods
10
(a) Cryptoperiod Norms
10
“1” Tactical Secure Voice TEK
11
“2” Data TEK
11
“3” TEK Cryptoperiod Extensions
11
(b) Special Situations
11
g. KW-46 OTAD
11
(1) Limiting Distribution
11
(2) OTAT on GENSER Broadcasts
11
(3) OTAT on SI Broadcasts
11
(4) CV OTAT/OTAR
11
(5) KEK OTAT/OTAR
11
h. OTAR on Combined Nets and Circuits
12
(1) Background
12
(2) Feasibility
12
UNCLASSIFIED
ORIGINAL
vi
UNCLASSIFIED
NAG-16F
SUBJECT
PAGE
(3) Keying
12
(a) “K” Equipment Key
12
(b) “S” Equipment KEK
12
(c) “S” Equipment TEK
12
(d) Release of Start-up KEK
12
4. OTAD IMPLEMENTATION
12
a. Identifying Electronic Key
12
(1) Identifying Field-generated Key
13
(2) Identifying Converted Key
13
b. OTAD with ICP Key
13
(1) Using ICP Start-up KEK
13
(2) Using ICP Generic Key
13
(a) Using ICP Generic Key as KEK
13
(b) Using ICP Generic Key as TEK
14
c. Key Transfer Between DTDs via STU-III/STU-IIIA/STU-IIB/STE
14
d. Key Transfer Between EKMS Terminals & DTDs
14
e. Key Transfer via TRI-TAC and MSE
14
(1) Inter-switch Key Transfer
14
(2) Key Transfer via KY-68
14
f. Problems & Special Situations
15
(1) Unsuccessful OTAR
15
(a) Plain Text Override Fall-back
15
(b) Secure Voice Fall-Back
15
(2) Late Joiners & Rejoiners
15
(a) OS Holds Net Start-up KEK
15
(b) OS Holds Net KEK
15
(c) NCS & OS Hold Other Key in Common
.16
g. Establishing Additional Nets/Circuits
16
h. Alerting Receivers
16
i. Record Keeping
16
j. Reporting and Evaluating COMSEC Incidents
16
k. Operating Procedures
16
l. Safeguarding Exposed Key
16
(1) Redundant Segment Key Tape Formats
16
(2) Start-up KEK
17
(3) TRI-TAC Switch Interconnect Keys
17
(4) Tamper-Evident Bags
18
ANNEX A - TERMS, DEFINITIONS & ACRONYMS
A-1
ANNEX B - KEY TAPE ORDERING GUIDE
B-1
1. GENERAL GUIDANCE
B-1
2. PURPOSE
B-1
3. LONG TITLE
B-1
4. ORDERING TAPE TEK
B-1
a. Uses
B-1
b. Format
B-1
c. Copy Count
B-1
d. Supersession
B-1
(1) Irregular
B-1
(2) Regular
B-2
UNCLASSIFIED
ORIGINAL
vii
UNCLASSIFIED
NAG-16F
SUBJECT
PAGE
5. ORDERING TAPE START -UP KEK
B-2
a. Use
B-2
b. Format
B-2
c. Copy Count
B-2
d. Supersession
B-2
6. ORDERING TAPE KEK
B-2
a. Use
B-2
b. Format
B-2
c. Copy Count
B-2
d. Supersession
B-3
7. ORDERING KW-46 OTAT TAPE KEY
B-3
a. Use
B-3
b. Format
B-3
c. Copy Count
B-3
d. Supersession
B-3
8. FUTURE EDITION PROVISIONING
B-3
9. TAPE KEY ORDERING CHART
B-3
ANNEX C - LOGGING ELECTRONIC KEY TRANSFERS
C-1
1. Controlling Authority (CA) RESPONSIBILITIES
C-1
2. RECORD KEEPING
C-1
ANNEX D - KG-84A/C AND KIV-7/7HS OTAD PROCEDURES
D-1
1. INTRODUCTION
D-1
2. PURPOSE AND SCOPE
D-1
3. KG-84 AND KIV-7 COLD START
D-1
a. Cold Starting Point-to-point Circuits
D-1
b. Cold Starting Multi-station Nets with Start-up KEK or
Common KEK
D-2
c. Cold Starting Multi-station Nets with OS-unique KEK
D-2
4. KG-84 AND KIV-7 POINT -TO-POINT OTAR (MK)
D-2
a. Regular KG-84 and KIV-7 MK OTAR
D-3
b. KIV-7 Front Panel MK OTAR
D-4
5. KG-84 AND KIV-7 NET AK OTAR
D-6
a. Allocating Net KEKs
D-6
b. KG-84 and KIV-7 AK OTAR
D-6
6. KG-84 AND KIV-7 OTAT
D-8
a. OTAT with Common KEK or Start-up KEK (MK/RV)
D-8
b. OTAT with Multiple KEKs (MK/RV)
D-8
ANNEX E - KY-57/58/67 OTAD PROCEDURES
E-1
1. INTRODUCTION
E-1
2. PURPOSE AND SCOPE
E-1
3. KY-57/58/67 COLD START
E-1
a. Using Start-up KEK or Common KEK
E-1
b. Using Multiple KEKs
E-1
4. KY-57/58/67 KEY GENERATION
E-2
5. KY-57/58/67 AK OTAR
E-3
6. KY-57/58/67 MK OTAR
E-4
7. KY-57/58/67 OTAT
E-7
UNCLASSIFIED
ORIGINAL
viii
UNCLASSIFIED
NAG-16F
SUBJECT
PAGE
ANNEX F - KYV-5, KY-99, KY-99A, AND KY-100 OTAD PROCEDURES
F-1
1. INTRODUCTION
F-1
a. TACTERM
F-1
b. MINTERM
F-1
c. AIRTERM
F-1
2. PURPOSE AND SCOPE
F-1
3. ANDVT COLD START
F-2
a. Using Start-up KEK or Common KEK
F-2
b. Using Multiple KEKs
F-2
4. ANDVT KEY GENERATION
F-3
5. ANDVT NON-COOPERATIVE AK OTAR
F-3
6. ANDVT COOPERATIVE AK OTAR
F-5
7. ANDVT OTAT
F-7
ANNEX G - KY-68 OTAD PROCEDURES
G-1
1. INTRODUCTION
G-1
2. PURPOSE AND SCOPE
G-1
3. SOLE-USER KY-68 OTAR
G-1
4. KY-68 OTAT
G-2
ANNEX H - KW-46 OTAD PROCEDURES
H-1
1. PURPOSE
H-1
2. LOADING KEY
H-1
3. OTAT/OTAR PROCEDURES
H-1
ANNEX I - OTAR AND OTAT USING AN/CYZ-10
I-1
1. INTRODUCTION
I-1
a. Capabilities
I-1
b. Purpose
I-1
2. EMULATING COMMON FILL DEVICES
I-1
3. LOADING DTD FROM KOI-18
I-1
4. LOADING DTD FROM ANOTHER DTD
I-2
a. Data Standard
I-2
b. Sending CYZ-10
I-2
c. Receiving CYZ-10
I-2
5. LOADING COMSEC EQUIPMENT FROM DTD
I-2
6. PERFORMING MK OTAR
I-3
7. PERFORMING AK OTAR
I-3
8. PERFORMING OTAT
I-3
a. NCS
I-4
b. OSs
I-4
9. TRANSFERRING KEY AND TAG FROM ONE DTD TO ANOTHER
I-4
VIA STU-III/STU-IIIA/STU-IIB/STE TELEPHONE CKTS
a. Sending Operator
I-4
b. Receiving Operator
I-5
UNCLASSIFIED
ORIGINAL
ix
UNCLASSIFIED
NAG-16F
SUBJECT
PAGE
10. TRANSFERRING JOINT TACTICAL INFORMATION
I-5
DISTRIBUTION SYSTEM (JTIDS) KEY AND TAG FROM ONE
DTD TO ANOTHER VIA STU-III/STU-IIIA/STU-IIB/STE
TELEPHONE CIRCUITS USING THE “FILL” THREAD OF JFILL
USER APPLICATION SOFTWARE (UAS)
a. Sending Operator
I-6
b. Receiving Operator
I-6
11. TRANSFERRING JTIDS KEY AND TAG FROM ONE DTD TOI-7
I-7
ANOTHER VIA STU-III/STU-IIIA/STU-IIB/STE TELEPHONE
CIRCUITS USING JFILL (FILL) - JFILL (FILL) UAS
a. Sending Operator
I-7
b. Receiving Operator
I-8
12. TRANSFERRING JTIDS KEY AND TAG FROM ONE DTD TO
I-9
ANOTHER VIA STU-III/STU-IIIA/STU-IIB/STE TELEPHONE
CIRCUITS TRANSFERRING FROM JFILL AND RECEIVING ON
CT-3 UAS
a. Sending Operator
I-9
b. Receiving Operator
I-10
13. TRANSFERRING JTIDS KEY AND TAG FROM ONE DTD TO
I-11
ANOTHER VIA STU-III/STU-IIIA/STU-IIB/STE TELEPHONE
CIRCUITS USING CT3 - CT3 UAS
a. Sending Operator
I-11
b. Receiving Operator
I-12
14. TRANSFERRING JTIDS DATA BASES FROM ONE DTD TO
I-12
ANOTHER VIA STU-III/STU-IIIA/STUIIB/STE TELEPHONE
CIRCUIT USING CT3 TO CT3 UAS
a. Sending Operator
I-13
b. Receiving Operator
I-13
15. TRANSFERRING JTIDS KEY AND TAG FROM ONE DTD TO
I-14
ANOTHER VIA STU-III/STU-IIIA/STU-IIB/STE TELEPHONE
CIRCUIT USING FILL UAS
a. Sending Operator
I-14
b. Receiving Operator
I-15
UNCLASSIFIED
ORIGINAL
x
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
(U) FIELD GENERATION AND OVER-THE-AIR DISTRIBUTION
OF COMSEC KEY IN SUPPORT OF
TACTICAL OPERATIONS AND EXERCISES
1. (U) INTRODUCTION
a. (U//FOUO) Perspective - Field generation and Over-The-Air-Distribution (OTAD) of the
COMSEC key needed to support tactical communications offers distinct operational advantages over
dependence on centrally produced, physically distributed tape key. Communications efficiency and
flexibility can be materially enhanced, if secure tactical nets and circuits are established and rekeyed
with field-generated TEK that is distributed via Over-The-Air Rekeying (OTAR). Pending full
implementation of the Electronic Key Management System (EKMS), operational flexibility can also
be enhanced if TEK for other tactical applications is distributed via Over-the-Air Transfer (OTAT),
between Data Transfer Device (DTDs), using STU-III, STU-IIIA, STU-IIB, STE, or KY-68 secured
telephone circuits, KW-46 secured broadcasts, or nets/circuits secured by KG-84A/C and KIV-7/7HS
equipment. Commanders who generate and electronically distribute needed key have maximum
latitude to structure their communications to support mission requirements and to react quickly to
fluid tactical situations and potentially serious key compromises.
b. (U) Purpose - This document is intended as the standard U.S. user's manual for planning
and conducting field key generation and OTAD in support of tactical activities. It is targeted
primarily at Joint and Intra-Service Operations and Exercises, particularly those involving forces that
do not routinely train or operate together. It also has limited application to Combined operations and
exercises involving Allied forces that hold OTAR- and OTAT-capable COMSEC equipment.
c. (U) Definitions & Acronyms - Many of the specialized terms used in this document are
defined in Annex A. Acronyms that appear in the document are also expanded in Annex A.
d. (U//FOUO) Activation - U.S. commanders at all echelons are authorized and encouraged to
direct field generation and OTAD of keys needed to support tactical operations and exercises for
which they are responsible.
NOTE: (U//FOUO) The procedures addressed herein are presented as routine communications
practices for tactical forces, but exceptions to certain specified COMSEC procedural
constraints are authorized during COMSEC emergencies, in which the only viable alternative
available to the responsible commander is plain text communications. The distinction between
routine communications and COMSEC emergencies must be recognized, so that the emergency
easements do not become standard operating practices, when the risks they entail should not be
accepted. It is also important to note that the security easements permitted by this manual apply
only in tactical applications and may not be extended to fixed-facility or strategic
communications.
e. (U//FOUO) Application to TRI-TAC & MSE - The TRI-TAC and Mobile Subscriber
Equipment (MSE) tactical communications systems have internal procedures for generating and
distributing the keys they use; the provisions of this manual do not apply to those keys. However, due
to the vital function they can perform in the production of keys intended for other applications,
TRI-TAC/MSE KG-83 and KGX-93/93A KVGs and the KT-83 test equipment used to certify them
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
1
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
require special safeguards that do not apply to the other TRI-TAC/MSE COMSEC equipment. These
are stated in the following subparagraphs.
(1) (U//FOUO) Using KVGs & Fill Devices - Any certified KVG having all of its tamper
detection labels intact may generate 128-bit key at any classification level for any purpose, but fill
devices into which KVGs load key must be safeguarded at the level of the most highly classified key
they contain.
(2) (U//FOUO) Certifying KT-83s & KVGs - All KT-83s, KG-83s, and KGX-93/93As
must be certified to the SECRET level at least every 24 months; none of these equipment need be
certified to the TOP SECRET level. Each certification must be accomplished with a certified KT-83
and NSA-approved procedures and may be done by one qualified person who must be cleared at least
SECRET. Any certified KT-83 with its tamper detection labels intact may be used to certify any
other KT-83 or any KG-83 or KGX-93/93A. One result of this authorization is that any command
that holds two or more KT-83s may stagger their certification dates and use one to certify the other,
indefinitely. In COMSEC emergencies, responsible commanders are authorized to use KVGs with
expired certifications, provided field certification is not feasible and certified replacements have been
requisitioned.
(3) (U//FOUO) Storing KT-83s & KVGs - Tamper detection labels are required on all
operational KVGs and KT-83s. After tamper detection labels have been applied to them, certified but
uninstalled KG-83s, KGX-93/93As, and KT-83s may be stored and handled without Two-Person
Integrity (TPI) controls. Installed KVGs may be stored in unmanned TRI-TAC and MSE shelters, if
the following conditions are met:
(a) (U//FOUO) Physical Safeguards - Responsible commanders must ensure that
adequate physical safeguards are provided for non-operational TRI-TAC/MSE shelters to minimize
the risk of theft, tampering, or sabotage to all of the COMSEC equipment stored therein.
(b) (U//FOUO) Tamper Detection Labels - At the time of its last certification,
NSA-furnished, coyote logo tamper detection labels must have been applied to each KT-83, KG-83,
and KGX-93/93A, in accordance with NSA instructions. Certifying activities must record the serial
numbers of the labels they apply to each KT-83 or KVG, so that this information may be made
available to investigating elements, if tampering with a certified KVG is suspected. Recorded label
serial numbers must also be compared with those removed from each KVG that is recertified at the
same facility two or more consecutive times. Any unexplained serial number anomalies must be
reported as COMSEC incidents.
NOTE: (U//FOUO) To increase the security of the coyote logo tamper detection labels, NSA
has classified them SECRET prior to application; upon application, they are declassified. Any
UNCLASSIFIED coyote logo labels on hand at using locations must be brought under
SECRET protection. Pertinent questions may be referred to the NSA Protective Technologies
Division at (301) 688-6816 of DSN 644-6816.
(c) (U//FOUO) KVG Locking Bars - Each KVG must be secured in its mounting by
means of a hinged locking bar that is locked in place, on a TPI basis, by two combination locks.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
2
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
(d) (U//FOUO) KVG Inspections - All KVG tamper detection labels must be visually
inspected (by partially withdrawing the KVG from its mount) immediately before each KG-83 or
KGX-93/93A activation. If the locking bar or any of the tamper detection labels is found to be
damaged, the affected KVG loses its certification, and the circumstances must be reported as a
COMSEC incident. However, use of a decertified KVG may begin or continue while the incident
report is being evaluated.
f. (U//FOUO) KY-68 OTAT - OTAT procedures for TRI-TAC/MSE and sole-user
(unswitched) KY-68 secured tactical voice circuits are stated in Annex G.
2. (U//FOUO) OTAD-CAPABLE EQUIPMENT - U.S. COMSEC equipment capable of generating
key and/or of transmitting it via OTAD is identified in the following table:
EQUIPMENT
OTAR
OTAT
GENERATION
KY-57/58/67
X
X
X (1)
AN/CSZ-1A (2)
X
KYV-5/KYX-99/99A/100
X
X
X (3)
KT-1523/1523A (4)
X
X
X (1)
AN/PRC-117C(C) (5)
X
RT-1672C(C) (6)
X
KG-84A/C
X
X (7)
KIV-7/7HS (8)
X
X (7)
AN/USC-61(C)(9)
X
X
MIDS LVT(10)
X
KW-46
X (11)
X
KY-68
X
DTD via STU-III/IIIA/IIB/STE (12)
X
KGX-93/93A
X (13)
X
KG-83
X
1 -
(U) Routine use authorized only for nets/circuits secured by KY-57/58/67, RT-1523/1523A, AN/PRC-117C(C)
RT-1672C(C), AN/USC-61(C), and AN/CSZ-1A.
2 -
(U//FOUO) SUNBURST processor. Compatible with KY-57/58/67, KYV-5 and KY-99/99A/100. May not
serve as OTAR net control station (NCS). Capable of Automatic Rekeying (AK) OTAR, but not of Manual
Rekeying (MK) OTAR or OTAT.
3 -
(U) Routine use authorized only for nets/circuits secured by KYV-5/KY-99/99A/100, and AN/CSZ-1A.
4 -
(U//FOUO) Single Channel, Ground/Air Radio System (SINCGARS) is compatible with KY-57/58/67.
Provides Transmission Security (TRANSEC).
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
3
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
5 -
(U//FOUO) SINCGARS. Compatible with KY-57/58/67. TRANSEC not compatible with RT-1523/1523A and
not approved by NSA.
6 -
(U) SHADOWFIRE interoperates with SINCGARS.
7 -
(U) Outstations (OSs) extract key with KYX-15 or AN/CYZ-10.
8 -
(U//FOUO) Modular equivalent of KG-84A/C. KIV-7HS is the high speed equivalent of the KIV-7.
9 -
(U//FOUO) Navy Digital Modular Radio (DMR) is compatible with SINCGARS, KY-57/58/67, KG-84/KIV-7,
KYV-5/KY-99/99A,100 (ANDVT), HAVE QUICK transceiver and AN/ARC-210 transceiver, and UHF
SATCOM Demand Assigned Multiple Access terminal.
10 - (U//FOUO) Multifunctional Information Distribution System (MIDS) Low Volume Terminal (LVT) is capable
of OTAR, but MIDS F-15 Fighter Data Link is not.
11 - (U//FOUO) KW-46 can OTAR only Community Variables (CVs).
12 - (U) Requires special connector cable (NSN 5810-01-391-4212) at sending and receiving
terminals; see NOTE on page I-4 under paragraph 9.a. step 1.
13 - (U//FOUO) Capable of OTAT to other KGX-93s, using KG-82 and/or KG-112.
3. (U) OTAD KEYING DOCTRINE
a. (U//FOUO) Key Requirements - As a basis for employing the field key generation and
OTAD schemes presented herein, commanders must identify lateral and subordinate commands that
require common key for specific purposes and must direct generation and distribution of the needed
key. Each commander who directs the generation of a COMSEC key becomes its Controlling
Authority (CA).
b. (U) Communications Paths - When existing communications needed to accomplish OTAD
are inadequate or unavailable, communications planners may be called upon to establish temporary
nets or circuits to effect timely distribution of COMSEC key.
c. (U) Types of Key
(1)
(U//FOUO) TEK is used to protect traffic passed on Point-To-Point (P-T-P) circuits and
multi-station nets that are secured by KG-84A/C, KIV-7/7HS, KY-57/58/67, RT-1523/A, KYV-5/
KY-99/99/100 and KY-68 equipment.
NOTE: (U//FOUO) TEK used by STU-IIIs, STU-IIIAs, and STEs is cooperatively generated,
on a per-call basis, by the conversing terminals.
NOTE: (U) When it is appropriate to make the distinction, TEK that is distributed via OTAR
should be referred to as “OTAR TEK”, and TEK that is distributed physically, should be
referred to as “non-OTAR TEK”.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
4
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
NOTE: (U) Since EKMS terminals are not programmed to generate “KG-84 OTAR TEKs”,
operators must direct them to generate “KG-84 TEKs” for support of OTAD.
(2) (U//FOUO) Key Encryption Key (KEK) is used to protect TEK during OTAD on
KG-84A/C, KIV-7/7HS, KY-57/58/67, RT-1523/A, KYV-5/KY-99/99A/100, and KY-68 secured
nets and circuits and on KW-46 secured broadcasts. In tactical applications, KEKs (rather than start-
up KEKs) should be used on communications nets and circuits that have stable compositions and that
exist on a continuing basis.
(3) (U//FOUO) Start-up KEK is functionally similar to KEK, but is not dedicated to
particular nets or circuits. Use of start-up KEK is appropriate when it is necessary to create
temporary nets/circuits on short notice from, a predetermined group of tactical force terminals. With
start-up KEK, any group of holders can create any number of nets or circuits secured by KY-57/58/
67, KG-84A/C, KIV-7/7HS, KYV-5/KY-99/99A/100, RT-1523/A, and/or KY-68 equipment, with
minimum pre-arrangement.
NOTE: (U) Using start-up KEK enhances flexibility and reduces the volume of tape key
that must be held by tactical units.
(4) (U) KW-46 Keys - KW-46 secured broadcasts use the following keys:
(a) (U//FOUO) Broadcast Area Variable (BAV) - The USN uses separate BAVs for
its broadcasts covering the Western Pacific/Indian Ocean area, the Eastern Pacific area, the Atlantic
area, and the Mediterranean area. The USCG West Coast and East Coast/Gulf broadcasts use
separate BAVs, and the NATO KW-46 secured broadcasts use separate BAVs for the Western
Atlantic/Eastern Atlantic/Iberian area, the North Atlantic/Baltic Approaches area, and the
Mediterranean/Black Sea area.
(b) (U//FOUO) Community Variable (CV) - A separate CV must be used for each
channel of each USN surface ship and submarine general service (GENSER) fleet broadcast, for each
USN special intelligence (SI) broadcast, for each USCG broadcast, and for each NATO broadcast.
The same punched tape GENSER and SI CVs are used by Naval Computer and Telecommunications
Area Master Stations (NCTAMSs) Pacific (Honolulu), Atlantic (Norfolk), and Central Europe
(Naples). Under conditions when many carrier battle groups and amphibious ready groups are
concentrated in a single fleet broadcast area, operational requirements for CVs may exceed the
number of punched tape CVs available to a particular NCTAMS. When this occurs, the affected
NCTAMS may generate additional CVs, using EKMS terminals or certified KVGs, and may allocate
and distribute them electronically via OTAD.
NOTE: (U) EKMS terminals are not programmed to generate “KW-46 CVs”, but can
generate “KG-84 TEKs”, which can serve effectively as KW-46 CVs.
(c) (U//FOUO) TEK - A “working” variable for each KW-46 secured broadcast
channel and single-channel broadcast is formed by combining the appropriate BAV with the assigned
CV.
(d) (U//FOUO) KEK - Cryptographically, KW-46 KEKs function like CVs. USN
Pacific/Indian Ocean and USCG Pacific broadcasts use the same KEK for OTAT. USN Atlantic/
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
5
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
Mediterranean and USCG Atlantic/Gulf area broadcasts use another KEK in common, and all USN
SI broadcasts use a single KEK. The NATO KW-46 broadcast OTAT KEK is AMST-4042.
(e) (U//FOUO) Unique Variable (UV) - Unique variables are used to decrypt KW-46
BAVs as they are loaded into each using equipment. A separate UV is assigned to each USN and
USCG ship or activity that copies any USN KW-46 secured broadcast, and a separate NATO UV is
assigned to each ship/station that copies any of the NATO broadcasts. Additionally, all USCG units
that copy the Coast Guard East Coast/Gulf broadcast use a common UV, and all USCG units that
copy the West Coast broadcast use a different, common UV.
(5) (U//FOUO) Transmission Security Key (TSK) is used to deny adversaries
opportunities to exploit radio signals, thus protecting them from intercept and jamming. In the
SINCGARS equipment, TSK is used to “wrap” other TRANSEC information (time of day, and either
hopsets or frequency lockouts), by a process known as ERF, which may be used with radios not
possessing COMSEC capabilities.
d. (U) KEK Doctrine
(1) (U) KEK Generation & Distribution
(a) (U//FOUO) Routine Procedures - Most KEK is NSA-produced and distributed
physically, in punched tape form. Except in COMSEC emergencies, KEKs may not be distributed via
OTAT over the nets/circuits on which they are used. However, when all users are located close
enough to the producer so that distribution may be effected physically, KEK may be field-generated
and delivered to users in keyed fill devices. Additionally, where it is necessary to do so, KEK may
also be sent between DTDs that are connected by STU-III or STE secured secure voice circuits.
EKMS terminals and certified KVGs may generate KEK for any of the OTAR-capable COMSEC
equipment, but KY-57/58/67s and RT-1523/As may only generate KEK for use with those systems,
and KYV-5/ KY-99/99A/100s may only generate KEK for use with those systems.
(b) (U) Emergency Procedures - In COMSEC emergencies, KY-57/58, KY-67,
KYV-5, and KY-99/99A/100 equipment may generate KEK for use by any COMSEC equipment that
requires it, and both centrally-produced and field-generated KEK may be distributed via OTAT on
nets and circuits secured by any OTAT-capable COMSEC equipment.
(c) (U//FOUO) TRI-TAC/MSE KEK Generation & Distribution - Certified KVGs
associated with TRI-TAC and MSE switches may generate KEKs classified SECRET and below for
use in non-TRI-TAC/MSE applications. Such KEK may be routinely distributed via OTAT on TRI-
TAC/MSE circuits, but key identification or “tagging” information must be passed separately on
secure TRI-TAC/MSE orderwires.
NOTE:(U//FOUO) NCSs using this method should distribute the next-up KEK one
cryptoperiod in advance, so it will be available to support unscheduled cold starts on the
using nets or circuits.
(2) (U//FOUO) Cold Start - A cold start is required each time a KG-84A/C, KIV-7/7HS,
KY-57/58/67, KYV-5/KY-99/99A/100, RT-1523/A, or sole-user KY-68 secured net or circuit that
rekeys via OTAR is initially activated and when a keyed COMSEC equipment fails or must be
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
6
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
replaced for any other reason at either terminal of a P-T-P circuit. If fresh fill hold batteries are used
to hold key in COMSEC equipment, cold starts should not be required because of power failures or
circuit path interruptions, or when OTAR is initiated on an operational net/circuit. Cold start routines
for KG-84A/C and KIV-7/7HS, KY-57/58/67, KYV-5, KY-99/99A/100, and KY-68 equipment are
shown in Annexes D thru G, respectively.
NOTE: (U//FOUO) There is no relationship between the replacement of KEK and TEK.
When it is necessary to replace the KEK on a net or circuit that distributes TEK via OTAR,
it is not necessary to zeroize the TEK in use and to perform a cold start. Shortly before the
time scheduled for each KEK replacement, the NCS should remind the OSs that a KEK
replacement is about to occur. The NCS should also direct the OS(s) not to zeroize their
effective TEK.
(3) (U//FOUO) KEK Classification - Each KEK is classified at the level of the highest
classified TEK it secures. In COMSEC emergencies, any uncompromised classified, 128-bit key that
is held in common by the affected commands and that is not used for any other purpose, may serve
temporarily as KG-84A/C, KIV-7/7HS, KY-57/58/67, KYV-5/KY-99/99A/100 or KY-68 KEK, until
properly classified KEK can be provided.
(4) (U) KEK Allocation
(a) (U//FOUO) Multi-Station Nets - OTAR on KY-57/58/67, KYV-5/KY-99/99A/100,
KG-84A/C, and KIV-7/7HS secured multi-station nets may be accomplished either sequentially, one
OS at a time, or simultaneously for all net OSs. The simultaneous approach is attractive in large or
slow-speed nets, where the time required to complete a sequential OTAR cycle would be
operationally unacceptable. However, the sequential approach is less prone to operator error. If a
NCS selects the sequential method, multiple KEKs are used, and each OS or group of OSs is
assigned a unique KEK. When the simultaneous approach is used, all net OSs must hold common
KEK (or start-up KEK). When it is operationally advantageous to do so, as might be the case when
some OSs are particularly vulnerable to capture, the two schemes may be combined. The NCS may
then allocate KEK so that each vulnerable OS holds a unique KEK, while the other OSs hold a
common KEK. The NCS of each tactical net that rekeys with OTAR should consider carefully the
method by which net KEK will be allocated.
NOTE: (U//FOUO) Creation of a net with start-up KEK automatically provides common
KEK for all net OSs and mandates simultaneous OTAR.
(b) P-T-P Circuits - Each KG-84A/C, KIV-7/7HS, KY-57/58/67, KY-68, or KYV-5/
KY-99/99A/100 secured P-T-P circuit that distributes TEK or TSK via OTAD must use a unique
KEK. In COMSEC emergencies, common KEK may be used for all P-T-P circuits controlled by a
NCS, until separate, two-copy KEK can be provided for use with each OS.
(5) (U//FOUO) KEK Cryptonet Size - The number of holders of each centrally-produced
and field-generated KEK should be kept as small as possible. Where tape KEKs are used, CAs may
order a reasonable number of extra copies to accommodate future net expansion, but NSA may
challenge tape copy counts of over 50.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
7
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
NOTE: (U//FOUO) Some COMSEC account other than the U.S. National Distribution
Authority (NDA) holds uncommitted, extra copies of distributed KEK or other types of
key. Normally the CA’s account performs this function.
(6) U//FOUO) KEK Cryptoperiods - The maximum cryptoperiod for each OTAD KEK is
three months. CAs may extend KEK cryptoperiods for up to 7 additional days without report, but
longer extensions must have prior NSA approval or be reported as COMSEC incidents.
NOTE: (U//FOUO) The cryptoperiod for each segment of KEK is unaffected by the
subsequent supersession of the canister from which it was drawn. Example: If a segment
of KEK tap becomes effective on 1 February and the canister from which it was taken
supersedes on 1 April, the KEK segment cryptoperiod runs through 30 April.
(7) (U) KEK Supersession
(a) (U//FOUO) Tape KEK - Each edition of tape KEK that supports a continuing net/
circuit is superseded annually; resupply is automatic, without further action by the CA. Tape KEK
intended for use with nets and circuits that operate intermittently may be requisitioned on an
irregularly superseded basis. However, irregular supersession places the burden of ensuring
continuing re-supply on the CA, who should allow at least four months for central production and
physical distribution of requisitioned follow-on editions.
(b) (U//FOUO) Field-generated KEK is superseded at three month intervals or at the
conclusion of the tactical operation or exercise in which it is used, whichever is shorter.
e. (U) Start-up KEK Doctrine - Start-up KEK is the basis for activating tactical nets and
circuits that distribute TEK via OTAR, but that do not have a designated KEK. Except as amended or
amplified below, the procedures expressed in paragraph 3.d. apply to start-up KEK
(1) (U//FOUO) Start-up KEK Production & Distribution - U.S. military commanders at
all echelons may requisition start-up KEK. Such key must be prepositioned in tape form or converted
from tape to electronic form and delivered physically in fill devices. In COMSEC emergencies,
individual segments of start-up KEK may be distributed via OTAT.
(2) (U//FOUO) Start-up KEK CA Responsibilities - The CA for each start-up KEK must
designate and maintain accurate records of its holders, must designate its potential NCSs, and must
ensure that each potential NCS holds a KYX-15 (or a DTD) and a source of TEK (either a single
copy tape TEK or access to an EKMS terminal or a certified KVG).
(3) U//FOUO) Start-up KEK Holders & Cryptonet Size - Holders of each start-up KEK
must be U.S. or Allied military commands that have potential need to participate in
KY-57/58/67, KYV-5/KY-99/99A/100, KG-84A/C, or KIV-7/7HS secured nets and circuits, that is,
they must constitute a pre-determined community of interest. Cryptonet sizes should be kept as small
as possible, and NSA may challenge requests for production of start-up KEKs having copy counts
higher than 250.
(4) (U//FOUO) Start-up KEK Segment Count, Cryptoperiod and Supersession - Each
edition of start-up KEK is produced in the “VA” format (62 segments - daily cryptoperiod) and is
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
8
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
effective for two months. Segment use is based on a predictable day/date relationship. Segments 1A
thru 31A are available for establishing nets and circuits during the first month an edition is effective,
and segments 1B thru 31B are available for establishing nets and circuits during the second month.
For example, segment 5B may be used only on the fifth day of the second month an edition is
effective.
(5) (U//FOUO) Start-up KEK Use - Where all stations that need to communicate hold
more than one start-up KEK of the required classification, the NCS should use the start-up KEK
having the smallest number of holders. On its effective date, a segment of start-up KEK may be used
by any of its designated NCSs to activate any number of KY-57/58/67, KYV-5, KY-99/99A/100,
KG-84A/C, or KIV-7/7HS secured nets or circuits, without specific authorization from the CA. The
NCS must notify the prospective OSs via secure communications of the date and time the net/circuit
will begin operation, the short title and segment of start-up KEK to be used, the COMSEC equipment
affected, and communications path involved. In COMSEC emergencies, unsecured communications
may be used for such notification. Segments of start-up KEK must not be extracted from their
protective canisters until shortly before they are required to create authorized tactical nets or circuits.
At that time, lower-numbered tape segments and their electronic equivalents must be destroyed
within 12 hours.
(6) (U//FOUO) ICP Start-up KEK Use - The Joint Intertheater COMSEC Package (ICP)
includes SECRET USKAT B13333 and TOP SECRET USKAT B13334 start-up KEKs. These keys
may be used to establish tactical nets/circuits that will distribute TEK via OTAR, only when no other
start-up KEK (or KEK) is held in common by prospective net/circuit members.
f. (U) TEK Doctrine
(1) (U//FOUO) Sources of TEK - To the maximum feasible extent, commanders should
field-generate the TEK needed to support their operations and exercises. Field generation of TEK is
accomplished by EKMS terminals, by certified KG-83s/KGX-93s, by KY-57/58/67s, or by KYV-5/
KY-99/99A/100s. One-copy, centrally-produced tape key may also be used as TEK. In COMSEC
emergencies, any uncompromised, tape key that is controlled by the using NCS and that is not used
for any other purpose may be used as TEK.
(a) (U//FOUO) TEK Generation with Certified KVGs - TEK intended for use with
any COMSEC equipment that uses 128-bit key may be generated by certified KG-83/KGX-93s. KG-
83s and KGX-93s must be certified before initial use and recertified every two years. In COMSEC
emergencies, KG-83s/KGX-93s with expired certifications may be used, pending recertification or
replacement with a certified equipment.
NOTE: ((U//FOUO) KVGs certified to SECRET level may be used to generate key at any
classification and for any purpose, provided prescribed security procedures are applied to keyed
fill devices into which such key is loaded. When TOP SECRET or sensitive compartmented
information (SCI) key is generated and stored in an HGX-83 or KGX-93/93A, all personnel
allowed access to the stored key must be appropriately cleared. Where NSA waivers are in
place to accommodate certain exceptions to this procedure, compliance with the requirements
of those waivers is mandatory.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
9
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
(b) (U) Key Generation with LMD/KP - EKMS Local LMD and KP equipped
terminals are being introduced throughout the Department of Defense. Like certified KVGs, LMD/
KPs are capable of generating unlimited quantities of 128-bit key, but the LMD/KP offers an
important operational advantage over KG-83 and KGX-93/93A key generation, in that it is capable
of loading up to 1,000 OTAR TEKs into a DTD using one series of commands, rather than one key at
a time. Users of OTAR TEK are encouraged to use LMD/KP key generation whenever possible.
NOTE: (U//FOUO) Simple sequential numbering (e.g., 1 - 1,000) may be used to tag
OTAR TEKs generated by an LMD/KP. No record keeping, other than that which takes
place automatically through the LMD/KP and DTD audit trails, is required for such keys.
(c) (U) TEK Generation with KY-57/58/67 and KYV-5/KY-99/99A/
100 - KY-57/58/67s and KYV-5/KY-99/99A/100s are only authorized to generate TEK for use by
their respective COMSEC equipment families. In COMSEC emergencies, KY-57/58/67 and KYV-5/
KY-99/99A/100 equipment may be used to generate TEK for any COMSEC equipment used to
support tactical operations.
(2) (U) TEK Distribution
(a) (U//FOUO) Methods - To the maximum feasible extent, commanders should
distribute TEK via OTAD, e.g., each carrier battle group should generate and distribute intra-battle
group TEK, rather than requesting that it be sent on a fleet broadcast. TEK may also be distributed
physically, in tape form or in loaded fill devices.
(b) (U) TEK Implementation
“1” (U//FOUO) GENSER TEK - If OTAT is accomplished on a net/circuit that
uses KEK of the proper classification, any TEK intended for tactical, GENSER use may be
distributed via OTAT.
“2” (U//FOUO) SCI/SI TEK - TEK intended for use on tactical, SCI or SI nets,
circuits, or broadcasts may only be distributed on SCI/SI nets/circuits or broadcasts that use KEK of
the proper classification.
(3) (U//FOUO) TEK Classification - TEK is classified at the level of the most highly
classified information normally transmitted on the net, circuit, or broadcast with which it is
associated. Although field-generated TEK cannot be marked with a classification, fill devices must
be protected at the level of the most highly classified key or information they contain that can be
accessed.
(4) (U//FOUO) TEK Allocation - A unique segment of TEK tape or a unique field-
generated TEK must be used on each tactical net or circuit.
(5) (U) TEK Cryptoperiods
(a) (U) Cryptoperiod Norms
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
10
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
“1” (U) Tactical Secure Voice TEK - One month is the normal cryptoperiod for
full-time, tactical KY-57/58/67 and KYV-5/KY-99/99A/100 TEKs.
“2” (U//FOUO) Data TEK - Either one week (for OTAR applications) or one
month with daily update (for non-OTAR applications) are the normal crypto- periods for full-time,
tactical KG-84A/C and KIV-7/7HS TEKs.
“3” (U//FOUO) TEK Cryptoperiod Extensions - Using commanders may
authorize temporary, local extensions of voice and data circuit/net TEK cryptoperiods to complete
ongoing operational activity, such as recovering tactical aircraft that are airborne at key change time.
Tactical commanders who authorize such extensions assume the responsibility to notify other
commanders whose forces may be affected. Notification of the CA is required only for extensions
that are longer than one day.
(b) (U//FOUO) Special Situations - NCSs may specify mission length TEK
cryptoperiods up to one month, that do not coincide with calendar months, for nets/circuits secured
by KY-57/58/67, KYV-5/KY-99/99A/100, KG-84A/C, and KIV-7/7HS crypto- equipment. Also,
where highly sensitive traffic is being transmitted, NCSs may specify TEK periods that are shorter
than the stated tactical norms.
g. (U//FOUO) KW-46 OTAD - KW-46 secured broadcasts are particularly well suited to
distributing COMSEC key to widely dispersed surface forces afloat. In addition to transferring U.S.
Navy, Coast Guard, and Marine Corps-controlled key to forces afloat, U.S. broadcasts may be used
to transfer Allied key, joint key, and key controlled by U.S. Army and U.S. Air Force commanders.
NATO has adopted OTAT as a means of distributing key to its forces afloat using KW-46 secured,
NATO broadcasts. U.S. and NATO KW-46 secured broadcasts may also be used to transmit KW-46
CVs via OTAR or OTAT. Guidance for implementing broadcast OTAD is expressed below:
(1)
(U//FOUO) Limiting Distribution - In U.S. multi-channel, KW-46 secured broadcasts,
OTAD must be conducted on channels that serve the intended recipients but that have the narrowest
distribution. For example, key intended for a carrier battle group should be sent on a dedicated
channel, rather than the “common” channel.
(2) (U//FOUO) OTAT on GENSER Broadcasts - USN and USCG GENSER broadcasts
may transfer, via OTAT, GENSER TEK that is classified up to the level of the BAV/CV used on the
transmitting broadcast or broadcast channel.
(3) (U//FOUO) OTAT on SI Broadcasts - U.S. Navy SI broadcasts may transfer any key
intended for tactical use. However, SCI and SI key may only be transferred via OTAT on SI
broadcasts, nets, and circuits.
(4) (U//FOUO) CV OTAT/OTAR - KW-46 CVs that are field-generated or converted
from tape may be distributed on KW-46 secured broadcasts via OTAT, for extraction into a fill
device, or via OTAR, for use in the receiving KWR-46.
(5) (U//FOUO) KEK OTAT/OTAR - KW-46 KEKs and other KEKs and start-up KEKs
must be distributed physically, normally in tape form. In COMSEC emergencies, keys of these types
may be distributed via OTAT on KW-46 secured broadcasts.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
11
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
h. (U) OTAR on Combined Nets & Circuits
(1) (U//FOUO) Background - Some Allied nations intercommunicate securely with U.S.
forces using standard (“K” nomenclatured) COMSEC equipment they purchase from the United
States or produce. with U.S. authorization. Others inter-communicate using special-purpose (“S”
nomenclatured) equipment they lease from the United States, and still others intercommunicate using
cryptographically compatible, national COMSEC equipment that may or may not be capable of
OTAR. Some Allied nations have adopted OTAR as a routine means for rekeying tactical nets and
circuits, but others have not done so and do not hold DTDs or KYX-15 fill devices needed to perform
NCS functions. For these reasons, OTAR during Combined operations and exercises must be planned
and implemented on a case-by-case basis.
(2)
(U//FOUO) Feasibility - Allied OSs in Combined nets and circuits secured by KG-84A/
C or KIV-7/7HS and/or SG-84A/C, KY-57/58 and/or SY-57/58, and KYV-5/
KY-99/99A/100 and/or SYV-5/99 equipment may be rekeyed via OTAR, if they hold properly
configured KEK in common with a U.S. NCS. OTAR may not be technically feasible on Combined
nets/circuits secured by other types of COMSEC equipment.
(3) (U) Keying
(a) (U//FOUO) “K” Equipment Key - KEK and TEK used on Combined nets and
circuits that involve only “K” nomenclatured COMSEC equipment are normally nomenclatured
“AKAT”. When operationally necessary, CAs are authorized to release US-Only keys they control to
specified Allied users for specified periods. When this is done, all U.S. holders must be notified and
no releases of U.S. COMSEC equipment may be involved.
(b) (U//FOUO) “S” Equipment KEK - On Combined nets or circuits that include any
“S” nomenclatured equipment, the KEK used by OSs having such equipment is nomenclatured
“ASAT”. KEK used by the NCS and all U.S. or Allied OSs using “K” nomenclatured equipment
bears the same number, but is nomenclatured “AKAT”, for example,
ASAT-1234/AKAT-1234.
(c) (U//FOUO) “S” Equipment TEK - On Combined nets or circuits that include any
“S” nomenclatured equipment, U.S. produced tape TEK nomenclatured “AKAT”, as well as field-
generated TEK may be transmitted to U.S. and Allied OSs via OTAR. In COMSEC emergencies,
tape TEK nomenclatured “USKAT” may also be transmitted, on a case-by-case basis, with
permission of the CA.
(d) (U) Release of Start-up KEK - Foreign release or OTAD of start-up KEK
nomenclatured “USKAT” must be specifically authorized by the CA. Start-up KEK nomenclatured
“AKAT” may be furnished to authorized Allied holders.
4. (U) OTAD IMPLEMENTATION
a. (U) Identifying Electronic Key - Field-generated TEK that is distributed via OTAR is not
labeled, since it is delivered directly into NCS and OS COMSEC equipment. However, identification
must be assigned to each key that is distributed via OTAT to support written record keeping at the
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
12
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
stations that send, receive, and relay such key. Of the COMSEC equipment capable of OTAT, only
the DTD can transmit the electronic identification or “key tag” associated with each key it transfers.
For this reason, identification must be included in all DTD key transfers. When key is transferred via
OTAT on a KW-46 secured broadcast or a net or circuit secured by KY-57/58/67, KYV-5/KY-99/
99A/100, KG-84A/C, KIV-7/7HS, or KY-68, equipment, key identification must be sent by separate
transmissions. Annex C presents sample log formats for OTAT activity.
(1) (U//FOUO) Identifying Field-generated Key - The commander who orders field
generation of a key must ensure that it is assigned an appropriate identification. One identification
scheme is “##LLLLL###”, where “##” is the sequential number among keys generated on a
particular day, “LLLLL” identifies the controlling authority, and “###” is the Julian date of
generation. “0852ID180” would identify the eighth key generated for the 52nd Infantry Division on
the 180th day of the calendar year. Key tags should not exceed ten characters, and the “LLLLL”
portion may include letters and numerals, and may have fewer than five characters.
(2) U//FOUO) Identifying Converted Key - Identification of electronic key that originated
as key tape is derived from the short title, edition, and segment number of the tape used. A
recommended approach is “L#####LL##”, where “L” shows either “U” for U.S-only key or “A” for
allied key, “#####” shows the four or five digits of the short title, “LL” represents the one or two
letters of the edition number, and “##” is the one or two digits identifying the tape segment number.
“U634D05” would be the identification of the fifth segment of USKAT-634D.
b. (U//FOUO) OTAD with ICP Key - OTAD using ICP keys is limited to holders and users
who have been validated by the Joint COMSEC Manager, a Unified Commander-in-chief (USCINC),
or, if the USCINC so requests, a Joint Task Force Commander. Exceptions may be requested via
message addressed for action to the theater headquarters, and for information to the Joint COMSEC
Manager and appropriate Service Component Commanders. Emergency exceptions may be requested
via secure telephone from the Joint COMSEC Manager (DSN/STU-III 968-2461) or via facsimile at
DSN/STU-III 968-6502.
(1) (U//FOUO) Using ICP Start-up KEK - The Joint ICP includes SECRET USKAT
B133333 and TOP SECRET B13334 start-up KEKs. When no other KEK or start-up KEK is held in
common by U.S. commands that must transfer key via OTAD on nets/circuits secured by KG-84A/
Cs, KIV-7/7HS, KY-57/58/67s, KYV-5, KY-99/99A/100s, or KY-68s, the responsible commander
may direct use of the appropriate ICP start-up KEK to establish such nets and circuits. Specific
authorization to do so need not be requested from the Joint COMSEC Manager, and no report of use
need be made.
(2) (U//FOUO) Using ICP Generic Key - The Joint ICP also includes a generic key,
USKAT-5360, that is assigned on a segment-by-segment basis to fulfill unplanned 128-bit key
requirements. When a designated segment of USKAT-5360 is assigned for use by a particular set of
holders, it normally becomes necessary for them to extract unwanted, lower-numbered segments
from the effective canister. To ensure that these by-passed segments are securely stored and available
if the holding unit is directed to join nets that use them, they must be sealed in opaque, tamper-
evident, plastic bags; see paragraph 4.l.(4) on page 12.
(a) (U//FOUO) Using ICP Generic Key as KEK - When neither USKAT-B13333/
B13334 nor any other KEK or start-up KEK is held in common by commands that must
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
13
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
communicate via nets/circuits secured by KG-84A/C, KIV-7/7HS, KY-57/58/67, or KYV-5/KY-99/
99A/100 equipment, the responsible commander may request that the Joint COMSEC Manager
authorize use of a designated segment of USKAT-5360, the ICP generic key, as the start-up KEK on
such nets/circuits. Address message requests to do this for action to the JOINT COMSEC
MANAGER MACDILL AFB FL and information to affected USCINCs. Use of USKAT-5360 may
also be requested by secure telephone or facsimile.
(b) (U//FOUO) Using ICP Generic Key as TEK - When a NCS that must establish a
net/circuit secured by KG-84A/C, KIV-7/7HS, KY-57/58/67, KYV-5, KY-99/99A/100, or KY-68
equipment has no other source of TEK, the responsible commander may request that the Joint
COMSEC Manager authorize use of designated segments of USKAT-5360 for that purpose.
c. (U//FOUO) Key Transfer Between DTDs via STU-III/STU-IIIA/STU-IIB/STE - Key of
any classification for any purpose may be transferred between DTDs via STU-III, STU-IIIA,
STU-IIB, or STE secure voice circuits, provided the affected terminals are authorized to handle
information classified at the level of the transmitted key. In COMSEC emergencies, key that is
classified higher than that level may be transferred.
CAUTION: (U) DTDs must be connected to STU-III/STU-IIIA/STU-IIB/STEs by a
special connector cable (NSN 5810-01-391-4212) that is not furnished with the DTD, but
that may be ordered from USACSLA Ft. Huachuca, AZ (Code SELCL-IA) at a cost of
about $35 each.
d. (U//FOUO) Key Transfer Between EKMS Terminals & DTDs - Key of any classification
for any purpose may be transferred from EKMS terminals to local or distant DTDs, provided the
TrKEKs used are classified at least at the level of the transferred key. In COMSEC emergencies, key
that is classified higher than the level of the TrKEK being used may be transferred.
NOTE: (U//FOUO) Provided the protocol “E-FILL 410" has been implemented on the
affected EKMS terminal, and a distant using activity has at least two DTDs that hold
different TrKEKs, new TrKEK for one DTD may be transferred via OTAT to the other
DTD and vice versa. This practice may continue indefinitely and obviates the
inconvenience and physical risks associated with returning DTDs to their host EKMS
terminal for replacement of TrKEK.
e. (U) Key Transfer via TRI-TAC and MSE
(1) (U//FOUO) Inter-switch Key Transfer - Key intended for use outside TRI-TAC and
MSE applications may be transferred between MSE node center switches and large extension nodes,
between AN/TTC-42 switches (using “command 11" procedures), and between TRI-TAC AN/TTC-
39D switches. However, AN/TTC-39A switches do not have that capability. When key is transferred
between MSE and AN/TTC-39D switches and extracted into KYK-13s or KYX-15s, associated key
identification must be transmitted separately. Key generated by AN/TTC-39A switches can only be
extracted into fill devices at the generating sites.
(2) (U//FOUO) Key Transfer via KY-68 - When under control of a KYX-15 or DTD, the
KY-68 can perform OTAT, using manual cooperative variable transfer procedures,
as stated in Annex G.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
14
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
NOTE: (U//FOUO) When the DTD is used, the KY-68 also transfers the tags associated
with the transferred keys. However, key tags must be passed separately, by use of the
orderwire or some other means, when the KYX-15 is used to input or extract the transferred
key.
f. (U) Problems & Special Situations - NCSs responsible for conducting OTAD on
KG-84A/C, KIV-7/7HS, KY-57/58/67, KYV-5/KY-99/99A/100 or KY-68 secured nets and circuits
must plan ahead to deal with unforeseen problems, such as equipment or communications path
failures and operator mistakes, as well as predictable problems, such as late joiners.
(1) (U) Unsuccessful OTAR - NCS and OS COMSEC equipment operators must know, in
advance, the fallback arrangements to be used if an unsuccessful OTAR disrupts secure
communications.
(a) (U//FOUO) Plain Text Override Fall-back - One means of accommodating the
fall-back requirement for KY-57/58/67 and KYV-5/KY-99/99A/100 secured nets and circuits is to
take advantage of the plain text override capability of these equipment. In COMSEC emergencies,
OSs experiencing OTAD difficulties may call their NCSs in-the-clear and advise of their specific
problems. Another technique involves the NCS keeping a separate KY-57/58/67 or KYV-5/KY-99
keyed with the net or circuit KEK in a TEK fill position, so that an OS experiencing difficulty may
securely communicate with the NCS to explain the problem.
(b) (U//FOUO) Secure Voice Fall-back - When STU-III, STU-IIIA, STU-IIB, or STE
terminals and interconnecting communications are available to the NCS and an OS of a KY-57/58/
67, KYV-5/KY-99/99A/100, KG-84A/C, KIV-7/7HS, or KY-68 secured net/circuit, they may be
used to report and recover from OTAD problems. DTDs connected to STU-III/STE terminals may
also be used to transfer key to afloat commands that missed its transmission on a secure broadcast.
(2) U//FOUO) Late Joiners & Rejoiners - When an authorized OS is unable to join a
KG-84A/C, KIV-7/7HS, KY-57/57/67, or KYV-5/ KY-99/99A/100 secured net on the day it was
established or must leave and rejoin such a net after one or more key changes have taken place, the
NCS must provide it with the effective TEK via secure means.
(a) (U//FOUO) OS Holds Net Start-up KEK - If the late joiner or rejoiner holds the
net start-up KEK the NCS can provide it with the effective TEK, via OTAR, using the start-up KEK
that is effective for the date on which the late joiner or rejoiner enters the net.
(b) (U//FOUO) OS Holds Net KEK - If the late joiner or rejoiner holds the net KEK
but is unaware of the current KEK update count, the NCS must advise the OS, by secure means, of
the KEK update in effect. In COMSEC emergencies, that information may be transmitted via
unsecured means. The NCS can also cold start the net, with the additional OS included.
NOTE: (U) To prepare for possible late joiners and rejoiners entering a net, the NCS
operator must keep accurate records of the number of times the KEK of his COMSEC
equipment has been updated.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
15
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
(c) (U//FOUO) NCS & OS Hold Other Key in Common - If a NCS can confirm that
it holds any uncompromised, U.S. classified key in common with a late joiner or rejoiner, it may use
such key to OTAT needed TEK to the OS.
g. (U//FOUO) Establishing Additional Nets/Circuits - Once an OTAD-capable KG-84A/C &
KIV-7/7HS or KYV-5/KY-99/99A/100 secured net or circuit is established with a late joiner or
rejoiner, the NCS can transfer TEK and TSK for other nets and circuits to the joining OS via OTAT.
In COMSEC emergencies, KY-57/58/67 secured nets or circuits may also be used for that purpose.
h. (U) Alerting Receivers - Before distributing key via OTAT or MK OTAR, the sender
should advise intended recipients of his intentions.
i. (U) Record Keeping - Stations that transmit, relay, or receive key via OTAT must maintain
local records, to verify that intended delivery has been accomplished. Local records should be
retained at least for the duration of the effective cryptoperiod of the key. Suggested log formats are
presented in Annex C.
j. (U//FOUO) Reporting and Evaluating COMSEC Incidents - It is essential that each
incident that jeopardizes key be reported expeditiously, in accordance with applicable Service
instructions. In most cases, such reports are sent by messages addressed for action to the CA, who
then becomes responsible for evaluating the reported incident and for directing measures to minimize
its security impact. For field generated key, priority should be given to directing replacement of
jeopardized key.
k. (U//FOUO) Operating Procedures - Concise operating procedures for cold starting nets and
circuits secured by KG-84A/C, KIV-7/7HS, KY-57/58/67, KYV-5, KY-99/99A/100, and KY-68
equipment, for keying such nets and circuits, and for conducting OTAR and OTAT on them are
stated in Annexes D - G. Operating procedures for performing OTAT (and CV OTAR) on KW-46
secured broadcasts are expressed in Annex H, and operating procedures for using DTDs to emulate
KYX-15 and KYK-13 common fill devices and for transferring key and data tags between DTDs
over P-T-P circuits that are secured by STU-III/STU-IIIA, STU-IIB, and STE are stated in Annex I.
l. (U//FOUO) Safeguarding Exposed Key - COMSEC key tape segments that have been
removed from their protective canisters for use or for any other authorized purpose are highly
vulnerable to human intelligence exploitation, e.g., copying for sale to a hostile interest. Several
means for reducing that vulnerability are discussed below.
(1) (U//FOUO) Redundant Segment Key Tape Formats - CAs should deter- mine
whether the holders of each of the TEKs they control are normally expected to enter, leave, and
reenter the using net during individual cryptoperiods, e.g., where a Coast Guard aircraft or small
surface craft joins and leaves a drug interdiction net several times in the same month. Where this is
the case, the CA should request a format change that provides an appropriate number of redundant
copies of each unique key tape segment. Use of the redundant segment approach allows holders to
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
16
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
destroy most segments shortly after they are loaded for use and obviates most segment retention.
Redundant Segment key tape formats available to CAs are listed in the following table:
Production Digraph Unique Key Copies Per Total Segments
First Letter
Segments
Segment
Per Edition
B
5
3
15
C
1
5
5
D
6
5
30
F
1
10
10
H
1
31
15
K
6
12
72
R
4
5
20
W
1
65
65
Y
26
2
52
Z
15
5
75
NOTE: (U//FOUO) To ensure that effective key will always be available for use, the final
segment of a redundant segment TEK (and/or its electronic equivalent stored in a fill
device) may be retained, in secure storage, through-out the remainder of its cryptoperiod.
This easement does not apply to single-copy format keys, such as “V format” (1 copy each
of 62 unique segments) TEKs and “G format” (1 copy each of 16 unique segments) KEKs.
With some important exceptions noted below, effective segments of single-copy keys must
be securely destroyed within 12 hours after they are loaded for use.
(2) (U//FOUO) Start-Up KEK - The Joint ICP includes SECRET USKAT B13333 and
TOP SECRET B13334 start-up KEKs. Segments of these and all other start-up KEKs must not be
extracted from their protective canisters until shortly before they are required to create authorized
tactical nets or circuits. At that time, lower-numbered tape segments must be destroyed within 12
hours. Since each segment of start-up KEK may be implemented at any time during its effective day,
it and/or its electronic equivalent should be retained, in secure storage, throughout the remainder of
its one-day cryptoperiod. Following supersession, start-up KEKs in tape form or its electronic
equivalent stored in a fill device must be securely destroyed within 12 hours.
NOTE: (U//FOUO) Effective segments of start-up KEKs may be stored in tamper-evident
plastic bags, but this is not mandatory.
(3) (U//FOUO) TRI-TAC Switch Interconnect Keys - Another major grouping of ICP
keys (USKAT 60501 - 60580) are the TOP SECRET TEKs used to interconnect operational TRI-
TAC switches. Each edition of these keys is effective for three months. Because TRI-TAC switches
are normally fielded on an ad hoc basis, most users of these keys must by-pass unused segments to
access those that provide required connectivity. Such exposed segments must then be sealed in
opaque, tamper-evident, plastic bags; see paragraph (4) below.
NOTE: (U//FOUO) Each edition of USKAT 60501 - 60580 contains one copy each of 80
unique TEKs.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
17
UNCLASSIFIED //FOR OFFICIAL USE ONLY
NAG-16F
(4) (U//FOUO) Tamper-Evident Bags - Based on their experience with use of tape keys
that must be retained outside their protective canisters throughout their effective cryptoperiods, each
holder should requisition an appropriate number of COMSEC-accountable, 6"x 6", opaque, plastic,
tamper-evident bags from the Marketing Group of the NSA Protective Technologies Division (Y26)
to meet their projected operational requirements. Since these bags are expensive and have a shelf-life
of only about eighteen months, requesting COMSEC custodians/managers should order only those
they expect to use within a year.
NOTE: (U//FOUO) Use of the tamper-evident bags requires that each using activity hold an
NSA pamphlet, INSPECTION AND HANDLING CRITERIA FOR TAMPER-EVIDENT
BAGS, which may be requested from the NSA Y26 Marketing Group at DSN 644-6816 or
commercial (301) 688-6816.
ANNEXES:
A - TERMS AND DEFINITIONS
B - KEY TAPE ORDERING GUIDE
C - LOGGING ELECTRONIC KEY TRANSFERS
D - KG-84A/C AND KIV-7/7HS OTAD PROCEDURES
E - KY-57/58/67 OTAD PROCEDURES
F - KYV-5/KY-99/99A/100 OTAD PROCEDURES
G - KY-68 OTAR PROCEDURES
H - KW-46 OTAD PROCEDURES
I -
OTAR AND OTAT USING AN/CYZ-10
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
18
UNCLASSIFIED
NAG-16F
ANNEX A
TERMS, DEFINITIONS, AND ACRONYMS
Specialized terms used in this document are defined below, and acronyms are expanded.
Term
Definition
automatic remote rekeying (AK)
Procedure to rekey a distant crypto-equipment electron-
ically without specific actions by the receiving terminal
operator.
BLACK key
Encrypted key.
cold start
Procedure for initially keying crypto-equipment.
COMSEC account
Administrative entity, identified by an account number,
used to maintain accountability, custody, and control of
COMSEC material.
COMSEC custodian
Person designated by proper authority to be responsible for
the receipt, transfer, accounting, safeguarding and
destruction of COMSEC material assigned to a COMSEC
account.
COMSEC emergency
Tactical operational situation, as perceived by the
responsible commander, in which the alternative to strict
compliance with procedural restrictions affecting use of a
COMSEC equipment would be plain text communications.
COMSEC equipment
Equipment designed to provide security to telecommuni-
cations by converting information to a form unintelligible to
an unauthorized intercepter and, subsequently, by
reconverting such information to its original form for
authorized recipients; also, equipment designed specific-
ally to aid in, or as an essential element of, the conversion
process. COMSEC equipment includes crypto-equipment,
crypto-ancillary equipment, crypto-production equipment,
and authentication equipment.
COMSEC incident
Occurrence that potentially jeopardizes the security of
COMSEC material or the secure electrical transmission of
national security information.
COMSEC manager
Person who manages the COMSEC resources of an
organization.
NOTE: Air Force COMSEC managers perform the duties of COMSEC custodians and also
manage the COMSEC resources of their COMSEC accounts. Air Force does not have COMSEC
custodians.
UNCLASSIFIED
ORIGINAL
A-1
UNCLASSIFIED
NAG-16F
controlling authority (CA)
Official responsible for directing the operation of a
cryptonet and for managing the operational use and control
of keying material assigned to the cryptonet.
crypto-equipment
Equipment that embodies a cryptographic logic.
cryptonet
Stations that hold a specific key for use.
cryptoperiod
Time span during which each key setting remains in effect.
frequency hopping
Repeated switching of frequencies during radio
transmission according to a specified algorithm, to
minimize unauthorized interception or jamming of
telecommunications.
key
Usually a sequence of random or pseudorandom bits used
initially to set up and periodically change the operations
performed in crypto-equipment for the purpose of
encrypting or decrypting electronic signals, for determining
electronic counter-countermeasures patterns, e.g., frequency
hopping or spread spectrum), or for producing other keys.
key encryption key (KEK)
Key that encrypts or decrypts other key for transmission or
storage.
manual remote rekeying (MK)
Procedure by which a distant crypto-equipment is rekeyed
electronically, with specific actions required by the
receiving terminal operator.
net control station (NCS)
Terminal in a secure telecommunications net responsible for
distributing key in electronic form to the members of the
net.
over-the-air key distribution
Providing electronic key via over-the-air rekeying, over-
(OTAD)
the-air key transfer, or cooperative key generation.
over-the-air key transfer (OTAT)
Electronically distributing key without changing the traffic
encryption key used on the secured communications path
over which the transfer is accomplished.
over-the-air rekeying (OTAR)
Changing traffic encryption key or transmission security
key in remote crypto-equipment by sending new key
directly to the remote crypto-equipment over the
communications path it secures.
RED key
Unencrypted key.
UNCLASSIFIED
ORIGINAL
A-2
UNCLASSIFIED
NAG-16F
spread spectrum
Telecommunications techniques in which a signal is
transmitted in a bandwidth considerably greater than the
frequency content of the original information. Frequency
hopping, direct sequence spreading, time scrambling, and
combinations of these techniques are forms of spread
spectrum.
start-up KEK
Key encryption key held in common by a group of potential
communicating entities and used to establish ad hoc tactical
networks.
supersession
Scheduled or unscheduled replacement of a COMSEC aid
with a different edition.
traffic encryption key (TEK)
Key used to encrypt plain text or to superencrypt previ-
ously encrypted text and/or to decrypt cipher text.
transmission security (TRANSEC)
Component of communications security that results from
the application of measures designed to protect transmis-
sions from interception and exploitation by means other
than cryptanalysis.
transmission security key (TSK)
Key that is used in the control of transmission security
processes, such as frequency hopping and spread spectrum.
Acronym
Expansion
AIRTERM
Air Terminal (ANDVT)
AK
Automatic Rekeying
ANDVT
Advanced Narrowband Digital Voice Terminal
BAV
Broadcast Area Variable (KW-46)
BCS
Broadcast Control Station (KW-46)
CA
Controlling Authority
CMCS
COMSEC Material Control System
COMSEC
Communications Security
CT3
Common Tier 3 (DTD)
CV
Community Variable (KW-46)
DSN
Defense Switched Network
DTD
Data Transfer Device (EKMS)
EKMS
Electronic Key Management System
ERF
Electronic Remote Fill (SINCGARS)
UNCLASSIFIED
ORIGINAL
A-3
UNCLASSIFIED
NAG-16F
GENSER
General Service
ICP
Intertheater COMSEC Package
JFILL
Joint Fill (JTIDS)
JTIDS
Joint Tactical Information Distribution System
KEK
Key Encryption Key
KP
Key Processor (EKMS)
KVG
Key Variable Generator (KG-83, KGX-93, KGX-93A)
LMD
Local Management Device (EKMS)
LVT
Low Volume Terminal (MIDS)
MIDS
Multifunctional Information Distribution System
MK
Manual Rekeying
MK/RV
Manual Rekeying/Receive Variable
MSE
Mobile Subscriber Equipment
NATO
North Atlantic Treaty Organization
NCS
Net Control Station
NCTAMS
Naval Computer and Telecommunications Master Station
NDA
National Distribution Authority
NSA
National Security Agency
OS
Outstation
OTAD
Over-the-Air Key Distribution
OTAR
Over-the-Air Rekeying
OTAT
Over-the-Air Key Transfer
P-T-P
Point-to-Point
RS
Receiving Station (KW-46)
SCI
Sensitive Compartmented Information
SI
Special Intelligence
SINCGARS
Single Channel Ground / Air Radio System
STE
Secure Terminal Equipment
STU
Secure Telephone Unit
TACTERM
Tactical Terminal (ANDVT)
UNCLASSIFIED
ORIGINAL
A-4
UNCLASSIFIED
NAG-16F
TEK
Traffic Encryption Key
TPI
Two-person Integrity
TrKEK
Transfer Key Encryption Key (DTD)
TRANSEC
Transmission Security
TSK
Transmission Security Key
USCG
United States Coast Guard
USN
United States Navy
UV
Unique Variable (KW-46)
UNCLASSIFIED
ORIGINAL
A-5
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
ANNEX B
(U) KEY TAPE ORDERING GUIDE
1. (U//FOUO) GENERAL GUIDANCE - Key Encryption Key (KEK) and start-up KEK are
normally produced in punched tape form, but TEK (including OTAR TEK) required by tactical
forces should be produced as close to the using locations and as near to the time of use as is feasible.
If a NCS has access to a KG-83/KGX-93/KGX-93A KVG or to an EKMS terminal or uses an
equipment such as the KY-57 that is authorized to produce its own TEK, needed TEK and OTAR
TEK should be field generated. TEK in tape form should only be used when field generation is not a
viable alternative.
2. (U) PURPOSE - This annex is provides guidance to assist CAs in ordering KEK, start-up KEK,
TEK, and OTAR TEK, in tape form, when field generation is not a viable alternative.
3. (U//FOUO) LONG TITLE - The CA who requisitions tape key must assign a descriptive long
title to each new tape key. Long titles may contain up to 100 characters, to identify the user
community, crypto system (where appropriate), and purpose of the key. Long titles, e.g., USPACOM
START-UP KEK, are not printed on the associated key tapes, but provide useful information when
entered into NSA and Service CMCS data bases.
4. (U) ORDERING TAPE TEK
a. (U//FOUO) Uses - For nets/circuits that distribute TEK via OTAR, tape TEK serves two
purposes. At NCSs that derive TEK from certified KG-83/KGX-93s of EKMS terminals, irregularly
superseded tape TEK serves as emergency back-up, in case of a KVG or EKMS failure. At NCSs
that do not use field-generated TEK, tape TEK is required. Tape TEK associated with OTAR is not
dedicated to any specific net, circuit, or COMSEC equipment. In that application, a short title of
appropriately classified key tape can serve as the source of OTAR TEK for any or all nets and
circuits that are controlled by a NCS.
b. (U//FOUO) Format - Tape TEK intended for use on nets/circuits that distribute TEK via
OTAR is produced in the “V_” format, indicating that each canister contains 62 segments. The
second letter of the digraph identifies the cryptoperiod, which may vary with specific uses.
c. (U//FOUO) Copy Count - Only one copy is produced of each edition of tape TEK intended
for use on nets/circuits that distribute TEK via OTAR, since the using NCS is the only holder. Each
alternate NCS should hold its own short title(s) of one-copy tape TEK.
d. (U//FOUO) Supersession - At the discretion of the CA, tape TEK may be resupplied on a
regular or irregular basis.
(1) (U//FOUO) Irregular - In most tactical applications, the consumption rate for tape
TEK is not accurately predictable. For example, a commander who has been designated as a possible
NCS for a particular start-up KEK may not serve in that capacity for long periods, or tape TEK held
as back-up for a stand-alone (non-TRI- TAC) KG-83 may never be used. In applications of this
nature, CAs should order reasonable quantities of tape OTAR TEK, each edition of.which is
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
B-1
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
superseded irregularly, and should reorder follow-on editions as needed, allowing four months for
production and delivery. The recommended procurement strategy is to requisition as many editions
of a single short title of tape OTAR TEK as may be required for each using NCS or alternate NCS.
Where tape OTAR TEK is held only as back-up, the recommended stock level is one month's worth
of expected use. That period should be long enough to requisition and obtain a replacement KVG or
to repair an EKMS terminal.
(2)
(U//FOUO) Regular - In applications where its use rate can be predicted, the number of
62-segment TEK tape canisters required to meet a NCS's requirements and the schedule on which
they are resupplied are inter-related. Continuing resupply requires that the CA adjust the number of
short titles and their supersession schedules to ensure that the required volume of tape TEK is
received. For example, if a NCS expects to use 150 segments of tape TEK per month, the CA should
order three, monthly-superseded short titles.
5. (U) ORDERING TAPE START-UP KEK
a. (U//FOUO) Use - Start-up KEK tape supports the establishment of temporary tactical nets
and circuits secured by KY-57/58/67, KYV-5/KY-99, or KG-84/KIV-7 equipment. Any military
commander may order a start-up KEK tape for use by an identified community of potential users.
Requisitioners should allow four months for production and distribution.
b. (U//FOUO) Format - Start-up KEK tape is produced in the “VA” format (62 segments -
daily crypto-period).
c. (U//FOUO) Copy Count - The copy count in which a start-up KEK tape is requisitioned
should provide for the expected number of holders and a reasonable number of spare copies to
accommodate unplanned additions to the cryptonet. The CA must designate where spare copies are to
be held. The U.S. NDA does not hold spare (uncommitted) copies of operational key.
d. (U//FOUO) Supersession - Each edition of start-up KEK tape is regularly superseded at
two-month intervals.
6. (U//FOUO) ORDERING TAPE KEK - Where physical distribution in keyed fill devices is
operationally viable, KEK should be field-generated. However, since many tactical environments
require use of tape KEK, guidance for ordering tape KEK follows.
a. (U//FOUO) Use - Tape KEK, rather than tape start-up KEK, should be used on
KG-84/KIV-7, KY-57/58/67, and KYV-5/KY-99 secured nets and circuits that exist on a continuing
basis and that distribute TEK via OTAR.
b. (U//FOUO) Format - Tape KEK (except that used with KW-46) is normally produced in the
“GF” (16 segments - three month cryptoperiod), but KEK may be ordered in the “AF” or “VF”
formats (31 and 62 segments, respectively, for use on nets/circuits that experience numerous cold
starts. At least four segments per edition are used each year, and the remaining segments are
available for cold starts.
c. (U//FOUO) Copy Count - In point-to-point applications and nets that use a unique KEK for
each OS, that is, nets that OTAR sequentially, the copy count for each edition of tape KEK is two. In
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
B-2
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
multi-station nets that OTAR simultaneously, the copy count corresponds to the number of net
members. The CA may order a few extra copies, to accommodate possible future cryptonet
expansion and must designate where such extra copies will be held. The U.S. NDA does not hold
spare (uncommitted) copies of operational key.
d. (U//FOUO) Supersession - Each edition of tape KEK associated with continuing nets and
circuits is superseded annually. Tape KEK associated with contingency applications may be
requisitioned with irregular supersession, but this places the burden of ensuring continuing resupply
on the CA. In either case, four months should be allowed for production and distribution of tape
KEK.
7. (U) ORDERING KW-46 OTAT TAPE KEK
a. (U//FOUO) Use - Navy, Coast Guard, and NATO KW-46 secured broadcasts that are used to
transfer key to forces afloat via OTAT require tape KEKs.
b. (U//FOUO) Format - KW-46 tape KEK is produced in the “DC” format (5 copies each of 6
segments - monthly cryptoperiod).
c. (U//FOUO) Copy Count - Each ship or station required to copy a Navy or Coast Guard
broadcast that transfers key via OTAT must hold at least one copy of the tape KEK used with that
broadcast.
d. (U//FOUO) Supersession - Each edition of KW-46 tape KEK is superseded semi-annually.
8. (U//FOUO) FUTURE EDITION PROVISIONING - CAs should ensure that user COMSEC
accounts hold at least one future edition of tape KEK and tape start-up KEK.
9. (U) TAPE KEY ORDERING CHART - The foregoing information relating to OTAR key, other
than KW-46 tape key, is recapitulated in chart form for the convenience of CAs.
NOTE: (U) Substantive entries in the following table are UNCLASSIFIED//FOR OFFICIAL
USE ONLY.
ORDERING GUIDE FOR OTAR KEY
COPY
EDITION
RESUPPLY
TYPE KEY
USE
FORMAT
COUNT
SUPER.
STRATEGY
OTAR TEK
Back-up for KVG or
VA, VB,
1
Irregular
1 short title per NCS - order
EKMS
or VC
editions as needed.
OTAR TEK
Primary source (not
VA, VB, or
1
Irregular
Adjust number of short titles
field generated)
VC
and supersessions.
Start-up
Temporary OTAR
VA
1/netmem.
Regular
Users hold one future
KEK
nets & circuits
& spares
every 2
edition.
months
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
B-3
UNCLASSIFIED//FOR OFFICIAL USE ONLY
NAG-16F
KEK
Continuing P-T-P
GF
2
Regular
Users hold one future
circuits
yearly
edition.
KEK
Continuing nets
GF
1/net mem.
Regular
Users hold one future
that OTAR
& spares
yearly
edition.
simultaneously
KEK
Continuing nets that
GF
2
Regular
Users hold one future
OTAR sequentially
yearly
edition.
KEK
Contingency OTAR
GF, AF or
1/net mem.
Irregular
Users hold one future
nets & circuits
VF
& spares
edition.
NOTE: First letter of format digraph expresses key tape segment count per canister. “A” = 1
copy each of 31 unique segments, “G” = 1 copy each of 16 unique segments, “V” = 1 copy
each of 62 unique segments. Second letter of format digraph expresses cryptoperiod.
“A” = Daily, “B” = Weekly, “C” = Monthly, “F” = Quarterly
UNCLASSIFIED//FOR OFFICIAL USE ONLY
ORIGINAL
B-4
|
||
|
|
|