background image

Chapter 1. Description and Requirements

The PCI Cryptographic Coprocessor uses dedicated hardware to process cryptographic
keys, certificates, and bulk data. These cryptographic functions are performed within a
tamper-resistant module that is designed to meet the FIPS PUB 140-1 specification for
detecting attacks through temperature, radiation, voltage, and physical penetration.

You can install the PCI Cryptographic Coprocessor in a PCI card slot.

Contents of the Coprocessor Package

Your package includes the following items:

v

The PCI Cryptographic Coprocessor

v

The

Installation and Using Guide

(this manual)

If any item is missing or damaged, contact your sales representative.

Special Considerations for Handling and Storage

Each PCI Cryptographic Coprocessor is shipped from the factory with a

certified device

key

. This electronic key is digitally stored in the coprocessor’s battery-powered

protected memory. The information from this key signs status messages to confirm that
the coprocessor is genuine and that no tampering has occurred.

Note:

If any of the secure module’s tamper sensors are triggered by tampering or
accident, the coprocessor erases all data in the protected memory, including the
certified device key. The coprocessor cannot operate without the certified device
key.

To protect the certified device key, follow these guidelines:

Temperature

Do not expose the coprocessor to temperatures below
-15 degrees C (+5 degrees F) or temperatures above 60 degrees C
(+140 degrees F).

Observe the high and low temperature limits. Exceeding the limits
triggers a Tamper Event. Any Tamper Event renders the coprocessor
permanently inoperable, there is no recovery procedure.

Batteries

Do not remove the coprocessor’s batteries. Data in the protected
memory is lost when battery power is removed. For information about
replacing the batteries without erasing the protected memory, see
Chapter 5, “Replacing Coprocessor Batteries” on page 17.

1

Summary of Contents for PCI Cryptographic Coprocessor

Page 1: ...PCI Cryptographic Coprocessor Installation and Using Guide SA23 1235 01...

Page 2: ...Business Machines Corporation 2000 2002 All rights reserved Note to U S Government Users Restricted Rights Use duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp Note Befo...

Page 3: ...on the SP Nodes 11 Chapter 4 Installing the PCI Cryptographic Coprocessor 13 Installing the Coprocessor 13 Verifying Coprocessor Hardware Installation 14 Verifying AIX Software Installation 15 Runnin...

Page 4: ...iv PCI Cryptographic Coprocessor Installation and Using Guide...

Page 5: ...xisting system before you add a device Use one hand when possible to connect or disconnect signal cables to prevent a possible shock from touching two surfaces with different electrical potentials Dur...

Page 6: ...handle and possibly damage the device v While the device is still in its anti static package touch it to an unpainted metal part of the system unit for at least two seconds This drains static electric...

Page 7: ...ications contain related information v System unit documentation for information specific to your hardware configuration v Operating system documentation for information specific to your software conf...

Page 8: ...viii PCI Cryptographic Coprocessor Installation and Using Guide...

Page 9: ...rocessor s battery powered protected memory The information from this key signs status messages to confirm that the coprocessor is genuine and that no tampering has occurred Note If any of the secure...

Page 10: ...renders the coprocessor inoperable v Any short on the battery power distribution circuits causes a voltage drop and a Tamper Event While handling the coprocessor observe the following precautions v Do...

Page 11: ...required See Chapter 2 Installing the Device Driver Software on page 5 or Chapter 3 Installing the Device Driver on the RS 6000 SP System on page 7 for device driver installation instructions For addi...

Page 12: ...4 PCI Cryptographic Coprocessor Installation and Using Guide...

Page 13: ...rocessor before you install the AIX operating system See Chapter 4 Installing the PCI Cryptographic Coprocessor on page 13 If the AIX operating system is installed on your system install the PCI Crypt...

Page 14: ...ware 12 Press Enter 13 The INSTALL ADDITIONAL DEVICE SOFTWARE screen displays The entry fields are automatically updated Press Enter to accept the information 14 The ARE YOU SURE window displays Press...

Page 15: ...lowing Parallel System Support Program PSSP publications v Parallel System Support Program for AIX Administration Guide v Parallel System Support Program for AIX Command and Technical Reference If you...

Page 16: ...operating system prompt dsh oslevel OR dsh w host1 host2 oslevel Press Enter host1 host2 is a list of the host names for the nodes on which the adapter will be installed The required AIX level is 4 3...

Page 17: ...ve the cursor down until the SPOT resource is highlighted The SPOT resource should look similar to spot_AIX421 resources spot The format of the spot name is spot_ lppsource_name lppsource_name was the...

Page 18: ...M for the operating system as follows v AIX 4 3 x Additional Device Software __ 3 Insert the installation media into the drive of the Control Workstation __ 4 Transfer the files to the Control Worksta...

Page 19: ...display the list of install images and select the appropriate lppsource f Move the cursor until the appropriate lppsource is displayed For example lppsource_AIX421 resources lpp_source Press Enter g M...

Page 20: ...lled on the nodes by typing the following at the system prompt dsh installp p acqXd mnt device driver 2 1 more device driver is the fileset that must be installed for the adapter The list includes v d...

Page 21: ...entation and install your coprocessor hardware then install the AIX operating system b If the coprocessor device driver is installed on your system go to step 3 Otherwise go to Chapter 2 Installing th...

Page 22: ...our system go to step 9 v If the coprocessor is not hot pluggable on your system go to step 10 9 If the coprocessor is hot pluggable on your system do the following a If you use the pkcsslotd daemon s...

Page 23: ...vel 2 2 0 0 or higher If this information displays but you continue to experience problems go to Installing the Coprocessor on page 13 v If no data displays the coprocessor device driver did not insta...

Page 24: ...16 PCI Cryptographic Coprocessor Installation and Using Guide...

Page 25: ...ry tray needed to provide backup power while you replace the batteries You need two battery kits to replace all four of the batteries To order the kits contact your sales representative Each Replaceme...

Page 26: ...ries provide power to the coprocessor while you perform this step 9 Remove the battery tray from the J3 connector and discard it 10 Reinstall the coprocessor into the PCI bus slot be sure the card is...

Page 27: ...one or more of the following measures v Reorient or relocate the receiving antenna v Increase the separation between the equipment and receiver v Connect the equipment into an outlet on a circuit diff...

Page 28: ...ications Safety Requirements This equipment is manufactured to the International Safety Standard EN60950 and as such is approved in the UK under the General Approval Number NS G 1234 J 100003 for indi...

Page 29: ...ct is aimed to be used in a domestic environment When used near a radio or TV receiver it may become the cause of radio interference Read the instructions for correct handling Radio Protection for Ger...

Page 30: ...22 PCI Cryptographic Coprocessor Installation and Using Guide...

Page 31: ...untry where such provisions are inconsistent with local law THIS MANUAL IS PROVIDED AS IS WITHOUT WARRANTY OF ANY KIND EITHER EXPRESSED OR IMPLIED INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES O...

Page 32: ...24 PCI Cryptographic Coprocessor Installation and Using Guide...

Page 33: ......

Page 34: ...Part Number 00P4106 Printed in U S A October 2002 SA23 1235 01 1P P N 00P4106...

Reviews: