Introducing the EHN Directory Security Architecture

Building Trust, Privacy, and Resilience into Emergency Communications

EmergencyHam.net has always been about more than just connecting radios — it’s about building a modern, resilient communications framework that bridges amateur radio and today’s digital world.

As the platform evolves, one of the most important new components is the EHN Directory — a system designed to enable identity-based communication across multiple networks, including:

  • Amateur radio (RF)
  • Internet-connected services
  • Local WiFi and edge systems
  • Message relay platforms like Winlink, APRS, and SMS gateways

But introducing identity into a distributed communications system raises an important question:

👉 How do you protect personal data while still operating legally over amateur radio?


The Challenge: Privacy vs. RF Transparency

Amateur radio operates under rules that prioritize openness. Messages transmitted over RF must remain intelligible and not intentionally obscured.

At the same time, modern systems require:

  • Identity
  • Authentication
  • Contact routing
  • Service permissions (like SMS gateways)

These two realities create a natural tension:

  • We need identity to route messages intelligently
  • But we cannot expose personal data over RF

The Solution: A Dual-Layer Architecture

The EHN Directory solves this problem with a two-layer security model:

🔒 Private Identity Layer

This is where full user records live, including:

  • Callsign and identity mapping
  • Contact methods (email, SMS, Winlink)
  • Roles and permissions
  • Service eligibility (like SMS access)

This layer is:

  • Encrypted
  • Access-controlled
  • Synchronized only over secure links (Internet or trusted networks)

📡 RF Operational Layer

This is what travels over amateur radio.

It contains only:

  • EHN_ID (a non-personal identifier)
  • Gateway association
  • Capability flags (e.g., “can send SMS locally”)
  • Coarse region (not precise location)
  • Temporary routing and roaming data

👉 No personal identity. No contact details.

This ensures:

  • Legal compliance
  • Privacy protection
  • Safe over-the-air operation

Why This Matters

This separation is not just a technical detail — it’s a foundational design decision that enables EHN to:

✅ Protect Operators

Sensitive information stays off the air and under user control.

✅ Stay Compliant

All RF transmissions remain consistent with amateur radio regulations.

✅ Operate During Outages

Gateways can continue functioning using secure cached data, even when disconnected from the Internet.

✅ Scale Across Networks

The same identity system works across RF, IP, and hybrid environments.


Gateway Roles in the System

The architecture introduces three types of gateways:

🖥️ Full Gateway

  • Holds an encrypted local copy of the directory
  • Provides services like SMS bridging
  • Continues operating offline using cached data

📡 RF Gateway

  • Relays messages over radio
  • Broadcasts only RF-safe operational data
  • Stores no sensitive user information

🔄 Sync Gateway

  • Reconciles updates when connectivity returns
  • Validates signatures and resolves conflicts
  • Maintains authoritative consistency

Roaming Without Exposure

One of the most powerful features of the EHN Directory is roaming.

When a user moves between regions, the system does not transmit their full profile. Instead, it shares a simple, temporary update:

  • EHN_ID
  • Current gateway
  • General region
  • Expiration time

This allows the network to route messages correctly — without exposing personal details.


Built for the Real World

In a real emergency or outage scenario:

  • Internet connectivity may be unavailable
  • Infrastructure may be degraded
  • Operators may be mobile

The EHN Directory is designed to handle this:

👉 Full gateways continue operating using cached data
👉 RF distributes only essential routing information
👉 Systems resynchronize when connectivity returns


Security by Design

The EHN Directory includes modern security practices:

  • Strong authentication (including key-based identity)
  • Encrypted storage and transport (off-RF)
  • Digital signatures for data integrity
  • Role-based access control
  • Full audit and logging capability

At the same time, it respects the unique requirements of amateur radio:

👉 No encryption over RF that obscures meaning
👉 Transparent, interpretable operational messages


A Foundation for the Future

The EHN Directory is more than a database — it is the foundation for identity-based routing across hybrid communications networks.

It enables:

  • Smart message delivery
  • Cross-network interoperability
  • Secure service integration (like SMS gateways)
  • Resilient, decentralized operation

And most importantly:

👉 It does all of this while protecting operators and respecting the spirit of amateur radio


What’s Next

This architecture lays the groundwork for:

  • Advanced messaging services
  • Distributed applications across RF and IP
  • Integration with existing systems like Winlink and mesh networks
  • A growing community of operators, developers, and educators

EmergencyHam.net is building a bridge between tradition and innovation — and the EHN Directory is a critical part of that vision.

Stay tuned as we continue to develop and expand this system.


EmergencyHam.net — Connected when it matters most.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *