data:image/s3,"s3://crabby-images/6d542/6d5422d27ea58de33a282a48002c9c3a1dceba86" alt="Infomir MAG-200 Operator'S Manual Download Page 20"
MAG-200 Operator Guide Rev 1.05.
Operation with keys
Protecting system prohibiting the start of any programs unauthorized by the
operator is realized in the device. For this purpose the algorithm DSA (digital signature)
with the key length equal to 2048 bits is used, as well as manufacturer keys, operator
key and the key for controlling the device.
•
Manufacturer key
This key is used for checking the digital signature of the operator key. The
secret part of this key is kept by the manufacturer.
•
Operator key
This key is owned by the operator. The secret part of this key is preserved by
the operator and used for signing the program started by the Bootstrap. This can
be the core of bootstrap.
•
This key is also used for signing the image broadcast in a multicast group and it
is used by bootstrap to update the file system located in the device. The public
part of the key is installed in the device through the bootstrap menu or by
assigning “oppubKEY” to the variable of the bootloader. The public part of the
key must be signed using the manufacturer key. This digital signature is subject
to checking before using the operator key.
•
Key for controlling the device
This key is owned by the operator. The key is used for signing commands sent
to the device. Operator must place the public part of this key in the device.
Operator commands for controlling the device on the server are signed with the
secret part of this key and are sent to the device. The digital signature is
checked on the device using the public part of the key. If the digital signature is
correct, the command shall be performed. Other variants of using this key are
available on the discretion of the operator. This key is not used in the process of
loading the basic program. Utilities
dsign
,
mcsend
and
mcrec
, are supplied with
the device basic program and allow realizing this algorithm and adapt other
algorithms if necessary.
Operator key preparation
In the process of the operator key preparation proceed as follows:
1. Create the key
Start:
gpg --gen-key
20