HighSecLabs K2016E User Manual Download Page 4

 

 

 

 

 

Secure Large KVM Switches User Manual

 

Security Features 

HSL  Secure  KVM  Switch  is  the  most  advanced  and  secure 
commercially available KVM Switch available today. This product is a 
derivative of high security KVM product used in newest NATO nuclear 
submarines.  Below  is  a  summary  of  some  of  the  security  features 
incorporated into the product. 

Unidirectional Data Paths 

Optical  diodes  used  to  enforce  unidirectional  data  flow  from  the 
peripheral devices to computers preventing potential leakage paths 
between  computers  even  in  the  severe  threat  of  two  infected 
computers attacking the KVM. 

No Shared Resources 

This KVM Switch designed to securely operate even when peripheral 
devices are vulnerable to signaling attacks. This KVM Switch does not 
allow  computer  access  to any  shared  resource  and  does  not  share 
controllable power sources.  

Dedicated Processors for Emulation 

The  Switch  features  a  dedicated  processor  per  computer  port  to 
emulate  peripheral  devices.  This  keeps  each  computer  running  on 
different security levels physically separated and secure at all times, 
and prevents any unintended data leakage between computers. 

Non-Reprogrammable Firmware 

The  Switch  features  custom  firmware  that  is  not  reprogrammable, 
preventing the ability to remotely attack the KVM control logic. 

 

 

 

 

EDID Emulation and Firewall 

HSL  Secure  KVM  Switch  blocks  the  computer  access  to  the  shared 
display by using isolated EDID emulators. This arrangement together 
with the internal EDID firewall protects from KVM attacks targeting 
the external memory effect of the shared display. 

USB Ports Protection 

Console USB ports are protected from the use of storage and other 
unsafe  USB  devices  through  strong  filtering  (independent  of 
computer protection means). Unqualified devices are rejected when 
connected to the Switch. Only mouse and keyboard data are passed 
through. 

Heavy-duty Steel Enclosure 

HSL Secure KVM Switches uses thick steel components to protect the 
product  from  physical  tampering  and  to  minimize  radiated 
electromagnetic emissions that can be snooped or intercepted. 

Active Always-On Anti-Tamper 

Active  chassis  anti-tamper  system  prevents  the  KVM  electronic 
circuitry  from  being  accessed  and  tampered  with  by  permanently 
disabling the product once tampering is detected. 

Holographic Tamper-Evident Labels 

Four  serially  numbered  holographic  security  tamper-evident  labels 
are placed on the enclosure surface to provide a visual indication if 
the Switch has been opened or compromised. 

 

 

 

Summary of Contents for K2016E

Page 1: ...nual K208E Secure 8 port Single Head DVI I KVM Switch w DPP K248E Secure 8 port Dual Head DVI I KVM Switch w DPP K2016E Secure 16 port Dual Head DVI I KVM Switch w DPP Rev 2 5 Doc No HDC06193 K208E 24...

Page 2: ...Tampering System 10 Product Specifications 11 Before Installation 12 Installation 13 Operation 16 DPP Operation 17 Troubleshooting Guide 18 Copyright and Legal Notice 21 Record of Revisions Rev Date D...

Page 3: ...ity organizations such as government agencies military and financial institutions and any other organization that handles sensitive and confidential information and are fully compatible with Common Cr...

Page 4: ...rogrammable Firmware The Switch features custom firmware that is not reprogrammable preventing the ability to remotely attack the KVM control logic EDID Emulation and Firewall HSL Secure KVM Switch bl...

Page 5: ...ceptionally high isolation between computer channels to prevent analog leakages across the KVM Dedicated Peripheral Port HSL patented Dedicated Peripheral Ports enables secure use of CAC or smart card...

Page 6: ...ces including CAC smart card and biometric readers Keyboard Shortcuts Support HSL Secure KVM Switch is the only Secure KVM that supports keyboard shortcuts switching mode while providing highest level...

Page 7: ...nsole USB keyboard and mouse ports are switchable i e you can connect keyboard to mouse port and vice versa However for optimal operation it is recommended to connect USB keyboard to console USB keybo...

Page 8: ...s power supply is overheated damaged broken causes smoke or shortens the mains power socket Liquid penetrates the product s case The product is exposed to excessive moisture or water The product is no...

Page 9: ...Manual Front Panel Features Model shown K208E 1 Steel enclosure 2 DPP Dedicated Peripheral Port Status LED Freeze 3 DPP channel select LEDs 4 Channel Select push buttons and LEDs 5a 5b Holographic Tam...

Page 10: ...se 3 Audio console output 3 5 mm stereo jack 4 USB Keyboard Mouse jacks 5 PS 2 Keyboard Mouse jacks Mini DIN 6 Console 2 X DVI I video input jacks diagnostic LEDs 2 4 1 6 Computer Area 7 Computer USB...

Page 11: ...more tamper evident label is missing appears disrupted or looks different than the example shown here please call HSL Technical Support and avoid using that product HSL Holographic Tampering Evident L...

Page 12: ...6 pin female connector Console DPP Input USB Type A Console Display Port 1 DVI I dual link female connector Console Audio Out 3 5mm stereo jack CPU Keyboard Mouse Ports USB Type B jack CPU DPP Ports U...

Page 13: ...ding where to place product Product front panel must be visible to the user at all times The location of the computers in relation to the product and the length of available cables typically 1 8 m War...

Page 14: ...uch as keyboards with integrated USB hubs and other USB integrated devices may not be fully supported due to security policy If they are supported only classical keyboard HID operation will be functio...

Page 15: ...port DPP functionality such as user authentication smart card reader do the following 1 Connect USB device such as smart card reader to DPP port on product console 2 Connect DPP input port on product...

Page 16: ...15 Secure Large KVM Switches User Manual Typical system installation diagram...

Page 17: ...annel will be channel 1 This will be indicated by white color illumination of push button 1 Product Mapping to Sources Product mapping to sources is indicated by stickers labels specifying which chann...

Page 18: ...nel would illuminate steady green o When connecting a USB device that is rejected for security reasons to the product s DPP port the DPP LED will illuminate steady red and USB device will be inoperabl...

Page 19: ...upport Important Security Note If you are aware of potential security vulnerability while installing or operating this product we encourage you to contact us immediately in one of the following ways W...

Page 20: ...s keyboard Mouse Problem Mouse cursor does not switch from primary to secondary display Solutions Driver supporting multiple displays was not installed or not installed properly on computer Reinstall...

Page 21: ...channels Solutions Check that all video cables are properly connected to product computer and display Check that cables are original cables supplied by HSL With everything connected power cycle the p...

Page 22: ...ut express written permission from HSL HSL SHALL NOT BE LIABLE FOR TECHNICAL OR EDITORIAL ERRORS OR OMISSIONS CONTAINED HEREIN NOR FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES RESULTING FROM THE FURNISHING...

Reviews: