Over-the-Air Rekeying (OTAR)
Over-the-Air Rekeying (OTAR) is a security function that allows encryptionEncryption protects two-way radio communications by converting voice or data into a secure form that can only be understood by authorised radios with the correct encryption capability and keys. keys used by compatible two-way radios to be changed or updated remotely through a radio communication networkA Network is a connected system of radios, equipment and infrastructure that allows users to communicate across a defined area. Radio networks can range from simple radio-to-radio systems to large multi-site networks..
OTAR removes the need to physically connect each radio to a programming computer when encryption keys need to be replaced. It is particularly useful for organisations operating large radio fleets or networks where maintaining secure communications is important.
What is Over-the-Air Rekeying?
Radio systems that use encryption rely on cryptographic keys to protect communications.
OTAR allows authorised encryption keys to be distributed to compatible radios through the communication network.
A simplified process is:
Key Management System → Radio Network → Radio
The radio receives the authorised key information and securely updates its encryption configuration.
Why is OTAR used?
Encryption keys may need to be changed for security or operational reasons.
OTAR can make this process easier when radios are:
- Distributed across multiple locations
- Used by mobile workers
- Deployed across large sites
- Part of a large radio fleet
- Difficult to access physically
Instead of collecting every radio, authorised key changes can be managed remotely.
OTAR and encryption
OTAR is closely associated with Encryption.
Encryption protects the content of radio communications, while OTAR provides a method for managing the cryptographic keys used by the encryption system.
These are separate functions:
Encryption = protects the communication
OTAR = manages encryption keys remotely
OTAR and encryption keys
An encryption key is a piece of cryptographic information used by compatible radios to encrypt and decrypt communications.
The radios communicating securely must have the appropriate key or keys.
Changing the keys can help maintain the security of the radio systemA Radio System is a complete communication solution comprising two-way radios and, where required, equipment such as repeaters, antennas, base stations, mobile radios and network infrastructure..
OTAR and Key Management Systems
OTAR normally forms part of a wider Key Management System (KMS) or radio-security infrastructureRadio infrastructure is the equipment and supporting systems behind a professional two-way radio network, including repeaters, antennas, base stations, network connections, power systems and dispatch equipment..
A key-management system can help authorised administrators control:
- Encryption keys
- Key distribution
- Key changes
- Radio access
- Security policies
- Key lifecycles
The exact architecture varies between radio technologies and manufacturers.
OTAR and radio networks
OTAR requires a suitable communication path between the key-management system and the radio.
This can involve:
- Radio networks
- Repeaters
- Digital radio infrastructure
- IP networks
- Other supported communication paths
The available method depends on the radio system.
OTAR and DMR
Some professional DMR (Digital Mobile RadioA Mobile Radio is a two-way radio designed to be installed in a vehicle. It normally uses the vehicle's power supply and an external antenna to provide reliable communication while travelling or working in the field.) systems can support encryption and associated key-management functions.
However, OTAR is not automatically available on every DMR radio.
The capability depends on the particular manufacturer, radio model, system architecture and security solution.
OTAR and MOTOTRBO™
Compatible MOTOTRBO™MOTOTRBO™ is Motorola Solutions' professional digital two-way radio platform, based on the DMR standard. It supports business communication ranging from simple radio systems to multi-site networks. systems can support advanced security and encryption-management capabilities through supported solutions.
The exact OTAR functionality depends on the radio model, system infrastructure and security software being used.
Organisations should verify compatibility before selecting equipment for an OTAR deployment.
OTAR and radio programming
OTAR is different from Over-the-Air Programming (OTAP)Over-the-Air Programming (OTAP) allows compatible two-way radios to be configured or updated remotely through a radio network, reducing the need to physically connect each radio to a programming computer..
OTAP is primarily concerned with remotely changing radio configuration.
OTAR is specifically concerned with remotely managing encryption keys.
For example:
OTAP → Channels, Talkgroups, Configuration
OTAR → Encryption Keys
Both functions can form part of a centrally managed professional radio system.
OTAR and codeplugs
A radio’s CodeplugA Codeplug is the configuration data programmed into a two-way radio that defines its channels, frequencies, talkgroups, radio ID and other operating features. contains its operational configuration.
Encryption settings can form part of a radio’s configuration, but OTAR specifically addresses the secure management and distribution of cryptographic keys.
Changing an encryption key should therefore not be confused with simply changing a channelA two-way radio channel is a programmed set of communication settings, typically including frequency and signalling, that allows compatible radios to communicate with one another. or other codeplug setting.
OTAR and radio fleets
OTAR can provide significant benefits for large radio fleets.
For example, an organisation with hundreds of radios across several locations may need to replace an encryption key.
Without remote key management, radios may need to be physically collected or connected individually.
With compatible OTAR infrastructure:
New Key → Secure Network Distribution → Multiple Radios
OTAR and multi-site networks
OTAR can be particularly useful where radios operate across multiple sites.
For example:
Head Office → Radio Network → Site A / Site B / Site C
An authorised key-management system can distribute changes across the connected network where the equipment supports the required functionality.
OTAR and radio security
Because OTAR controls sensitive cryptographic information, security around the key-management infrastructure is extremely important.
Access should be restricted to authorised personnel.
Appropriate controls can include:
- Authentication
- Access permissions
- Audit records
- Secure key storage
- Controlled key distribution
- Key lifecycle management
OTAR and key rotation
Key Rotation is the process of replacing encryption keys with new keys.
Regular or event-driven key rotation can reduce the period during which a particular key remains in use.
OTAR can make key rotation more practical across a large fleet when supported by the radio system.
OTAR after a radio is lost
If an encrypted radio is lost or stolen, security administrators may need to take action to prevent unauthorised use of the radio or its keys.
Depending on the system, remote security functions may be available.
OTAR can form part of a broader security process for managing encryption keys when equipment is lost or compromised.
The specific capabilities depend on the radio system.
OTAR and radio replacement
When a radio is replaced, its encryption credentials may need to be provisioned securely.
A compatible key-management system can help manage the process without relying solely on manual programming.
OTAR and emergency communication
Secure radio systems may be used for operational and emergency communications.
OTAR can help maintain the security of those systems by allowing authorised encryption keys to be changed without physically accessing every radio.
However, key-management procedures should be designed carefully so that essential communication is not accidentally disrupted.
OTAR and radio coverage
OTAR depends on a suitable communication path to the radio.
If a radio is outside the required network coverageRadio Coverage is the geographical area in which a two-way radio system can provide reliable communication. Coverage depends on the radios, antennas, frequency, terrain, buildings and system infrastructure., an over-the-air key update may not be received until connectivity is restored.
For this reason, reliable network coverage remains important even when a radio system supports OTAR.
OTAR and repeaters
A RepeaterA Repeater receives a two-way radio transmission and retransmits it, usually from an elevated location, to extend the coverage and reliability of a radio communication system. can form part of the communication path used by compatible radio systems.
Where OTAR traffic is supported across the network, the repeater and associated infrastructure can help deliver the required information to radios operating within its coverage.
OTAR and cloud systems
Some modern radio-management and security platforms can incorporate cloud-based infrastructure.
Where supported, a cloud-based system may provide centralised management of encryption keys across connected radio networks.
The security architecture and capabilities depend on the specific platform.
OTAR and dispatch
OTAR is separate from Dispatch, although both can exist within the same professional radio system.
A dispatch platform manages communication and operational coordination, while the key-management system manages cryptographic security.
OTAR and interoperability
When different radio systems need to communicate securely, encryption compatibility becomes an important consideration.
Different manufacturers and technologies may use different encryption methods and key-management approaches.
InteroperabilityInteroperability is the ability of different communication systems, devices or organisations to work together and exchange information. In two-way radio, it can connect different radio networks, technologies or users through compatible systems or gateways. therefore requires careful technical planning.
OTAR and end-to-end encryption
End-to-End EncryptionEnd-to-End Encryption protects radio communications between authorised endpoints, keeping voice or data encrypted through the network until it reaches the intended receiving device. (E2EE) is a security architecture in which communications are encrypted so that only authorised endpoints can decrypt them.
OTAR can be used to manage keys in systems that support appropriate end-to-end encryption architectures.
However, OTAR and E2EE are not the same thing.
OTAR describes how encryption keys are managed and distributed; E2EE describes how communications are protected between endpoints.
OTAR and licensed radio
OTAR does not change the licensing requirements for operating a radio system.
A radio using encryption must still operate on frequencies and under conditions authorised by the applicable radio licence.
In the UK, professional radio systems must comply with the conditions of the relevant Ofcom Business Radio LicenceAn Ofcom Business Radio Licence authorises businesses and organisations in the UK to use specified radio frequencies for professional two-way radio communication, subject to the licence conditions. where a licence is required.
OTAR and radio hire
OTAR can be useful for specialist Radio HireRadio Hire is the temporary rental of two-way radios and related communication equipment for events, projects and operational requirements, providing professional communication without purchasing the equipment. operations involving secure communications.
Where compatible equipment and infrastructure are available, encryption keys can be managed remotely between deployments or during a hire period.
Not all hired radio systems support OTAR.
OTAR limitations
OTAR is not available on every two-way radio.
Limitations can include:
- Radio model compatibility
- Encryption capability
- Key-management infrastructure
- Network coverage
- Security architecture
- Software requirements
- System configuration
- Manufacturer-specific implementation
OTAR should therefore be considered as part of the overall system design rather than as a standard feature of every digital radio.
OTAR vs manual rekeying
Traditional manual key management may require a technician to connect directly to each radio.
For example:
Computer → Programming Interface → Radio
OTAR can allow the equivalent key-management process to occur remotely:
Key Management System → Radio Network → Radio
This can save time and reduce the logistical burden of managing large fleets.
OTAR and compliance
Encryption key management should be controlled through appropriate organisational procedures.
Administrators should maintain control over:
- Who can access keys
- Which radios receive keys
- When keys are changed
- Which keys are currently active
- What happens when equipment is lost
- How retired keys are handled
OTAR and DCS
DCS can advise on professional radio systems where secure communications and remote encryption-key management are required.
OTAR is most useful for organisations operating compatible encrypted radio systems across large fleets or multiple locations, where physically rekeying every radio would be impractical.
The availability and functionality of OTAR depend on the radio equipment, encryption system, network infrastructure and key-management solution.

