Over-the-Air Rekeying (OTAR)

Over-the-Air Rekeying (OTAR) is a security function that allows encryption keys used by compatible two-way radios to be changed or updated remotely through a radio communication network.

OTAR removes the need to physically connect each radio to a programming computer when encryption keys need to be replaced. It is particularly useful for organisations operating large radio fleets or networks where maintaining secure communications is important.

What is Over-the-Air Rekeying?

Radio systems that use encryption rely on cryptographic keys to protect communications.

OTAR allows authorised encryption keys to be distributed to compatible radios through the communication network.

A simplified process is:

Key Management System → Radio Network → Radio

The radio receives the authorised key information and securely updates its encryption configuration.

Why is OTAR used?

Encryption keys may need to be changed for security or operational reasons.

OTAR can make this process easier when radios are:

  • Distributed across multiple locations
  • Used by mobile workers
  • Deployed across large sites
  • Part of a large radio fleet
  • Difficult to access physically

Instead of collecting every radio, authorised key changes can be managed remotely.

OTAR and encryption

OTAR is closely associated with Encryption.

Encryption protects the content of radio communications, while OTAR provides a method for managing the cryptographic keys used by the encryption system.

These are separate functions:

Encryption = protects the communication

OTAR = manages encryption keys remotely

OTAR and encryption keys

An encryption key is a piece of cryptographic information used by compatible radios to encrypt and decrypt communications.

The radios communicating securely must have the appropriate key or keys.

Changing the keys can help maintain the security of the radio system.

OTAR and Key Management Systems

OTAR normally forms part of a wider Key Management System (KMS) or radio-security infrastructure.

A key-management system can help authorised administrators control:

  • Encryption keys
  • Key distribution
  • Key changes
  • Radio access
  • Security policies
  • Key lifecycles

The exact architecture varies between radio technologies and manufacturers.

OTAR and radio networks

OTAR requires a suitable communication path between the key-management system and the radio.

This can involve:

  • Radio networks
  • Repeaters
  • Digital radio infrastructure
  • IP networks
  • Other supported communication paths

The available method depends on the radio system.

OTAR and DMR

Some professional DMR (Digital Mobile Radio) systems can support encryption and associated key-management functions.

However, OTAR is not automatically available on every DMR radio.

The capability depends on the particular manufacturer, radio model, system architecture and security solution.

OTAR and MOTOTRBO™

Compatible MOTOTRBO™ systems can support advanced security and encryption-management capabilities through supported solutions.

The exact OTAR functionality depends on the radio model, system infrastructure and security software being used.

Organisations should verify compatibility before selecting equipment for an OTAR deployment.

OTAR and radio programming

OTAR is different from Over-the-Air Programming (OTAP).

OTAP is primarily concerned with remotely changing radio configuration.

OTAR is specifically concerned with remotely managing encryption keys.

For example:

OTAP → Channels, Talkgroups, Configuration

OTAR → Encryption Keys

Both functions can form part of a centrally managed professional radio system.

OTAR and codeplugs

A radio’s Codeplug contains its operational configuration.

Encryption settings can form part of a radio’s configuration, but OTAR specifically addresses the secure management and distribution of cryptographic keys.

Changing an encryption key should therefore not be confused with simply changing a channel or other codeplug setting.

OTAR and radio fleets

OTAR can provide significant benefits for large radio fleets.

For example, an organisation with hundreds of radios across several locations may need to replace an encryption key.

Without remote key management, radios may need to be physically collected or connected individually.

With compatible OTAR infrastructure:

New Key → Secure Network Distribution → Multiple Radios

OTAR and multi-site networks

OTAR can be particularly useful where radios operate across multiple sites.

For example:

Head Office → Radio Network → Site A / Site B / Site C

An authorised key-management system can distribute changes across the connected network where the equipment supports the required functionality.

OTAR and radio security

Because OTAR controls sensitive cryptographic information, security around the key-management infrastructure is extremely important.

Access should be restricted to authorised personnel.

Appropriate controls can include:

  • Authentication
  • Access permissions
  • Audit records
  • Secure key storage
  • Controlled key distribution
  • Key lifecycle management

OTAR and key rotation

Key Rotation is the process of replacing encryption keys with new keys.

Regular or event-driven key rotation can reduce the period during which a particular key remains in use.

OTAR can make key rotation more practical across a large fleet when supported by the radio system.

OTAR after a radio is lost

If an encrypted radio is lost or stolen, security administrators may need to take action to prevent unauthorised use of the radio or its keys.

Depending on the system, remote security functions may be available.

OTAR can form part of a broader security process for managing encryption keys when equipment is lost or compromised.

The specific capabilities depend on the radio system.

OTAR and radio replacement

When a radio is replaced, its encryption credentials may need to be provisioned securely.

A compatible key-management system can help manage the process without relying solely on manual programming.

OTAR and emergency communication

Secure radio systems may be used for operational and emergency communications.

OTAR can help maintain the security of those systems by allowing authorised encryption keys to be changed without physically accessing every radio.

However, key-management procedures should be designed carefully so that essential communication is not accidentally disrupted.

OTAR and radio coverage

OTAR depends on a suitable communication path to the radio.

If a radio is outside the required network coverage, an over-the-air key update may not be received until connectivity is restored.

For this reason, reliable network coverage remains important even when a radio system supports OTAR.

OTAR and repeaters

A Repeater can form part of the communication path used by compatible radio systems.

Where OTAR traffic is supported across the network, the repeater and associated infrastructure can help deliver the required information to radios operating within its coverage.

OTAR and cloud systems

Some modern radio-management and security platforms can incorporate cloud-based infrastructure.

Where supported, a cloud-based system may provide centralised management of encryption keys across connected radio networks.

The security architecture and capabilities depend on the specific platform.

OTAR and dispatch

OTAR is separate from Dispatch, although both can exist within the same professional radio system.

A dispatch platform manages communication and operational coordination, while the key-management system manages cryptographic security.

OTAR and interoperability

When different radio systems need to communicate securely, encryption compatibility becomes an important consideration.

Different manufacturers and technologies may use different encryption methods and key-management approaches.

Interoperability therefore requires careful technical planning.

OTAR and end-to-end encryption

End-to-End Encryption (E2EE) is a security architecture in which communications are encrypted so that only authorised endpoints can decrypt them.

OTAR can be used to manage keys in systems that support appropriate end-to-end encryption architectures.

However, OTAR and E2EE are not the same thing.

OTAR describes how encryption keys are managed and distributed; E2EE describes how communications are protected between endpoints.

OTAR and licensed radio

OTAR does not change the licensing requirements for operating a radio system.

A radio using encryption must still operate on frequencies and under conditions authorised by the applicable radio licence.

In the UK, professional radio systems must comply with the conditions of the relevant Ofcom Business Radio Licence where a licence is required.

OTAR and radio hire

OTAR can be useful for specialist Radio Hire operations involving secure communications.

Where compatible equipment and infrastructure are available, encryption keys can be managed remotely between deployments or during a hire period.

Not all hired radio systems support OTAR.

OTAR limitations

OTAR is not available on every two-way radio.

Limitations can include:

  • Radio model compatibility
  • Encryption capability
  • Key-management infrastructure
  • Network coverage
  • Security architecture
  • Software requirements
  • System configuration
  • Manufacturer-specific implementation

OTAR should therefore be considered as part of the overall system design rather than as a standard feature of every digital radio.

OTAR vs manual rekeying

Traditional manual key management may require a technician to connect directly to each radio.

For example:

Computer → Programming Interface → Radio

OTAR can allow the equivalent key-management process to occur remotely:

Key Management System → Radio Network → Radio

This can save time and reduce the logistical burden of managing large fleets.

OTAR and compliance

Encryption key management should be controlled through appropriate organisational procedures.

Administrators should maintain control over:

  • Who can access keys
  • Which radios receive keys
  • When keys are changed
  • Which keys are currently active
  • What happens when equipment is lost
  • How retired keys are handled

OTAR and DCS

DCS can advise on professional radio systems where secure communications and remote encryption-key management are required.

OTAR is most useful for organisations operating compatible encrypted radio systems across large fleets or multiple locations, where physically rekeying every radio would be impractical.

The availability and functionality of OTAR depend on the radio equipment, encryption system, network infrastructure and key-management solution.