background image















14













Video display (EDID) information

The Display Data Channel (or DDC) communication scheme was introduced to 
allow video displays to provide details (using the information format of EDID 
- Extended Display Identification Data) about themselves and their capabilities 

to the computer’s graphic adapter circuitry. In most applications this is a useful 
and positive feature. However, in a highly secure environment this presents two 
potential problems:

•  Most video displays provide manufacturer, model and serial number 

information as part of their EDID transfer. This unique information could 
possibly be used as a marker by anyone attempting to compromise security 
within one or more of the connected computers/networks.

•  The operation of the DDC scheme could theoretically provide a means to 

transfer a small packet of EDID information to the computers at each power 
on cycle of the AdderView Secure. 

If your organisation wishes to protect against such scenarios then it is 
recommended that the DDC lines are disconnected in the cable between the 
AdderView Secure and the monitor. Alternatively, Adder would be happy 
to discuss configuring the AdderView Secure with a DDC policy to suit your 
organisation.

AdderView Secure EDID policy

The AdderView Secure maintains individual EDID memories for each connected 
computer port. During manufacture, these memories are each loaded with a 
default EDID packet. 
When the AdderView Secure is powered on, its response will be determined by 
the condition of the DDC signalling pins of the video monitor connector:

• 

If the DDC pins are connected as standard

: The AdderView Secure reads 

the EDID information from the attached video monitor and loads a copy 
into each port memory, which can then be made available to the connected 
computers.

• 

If no video monitor is connected or the monitor’s DDC signalling pins 

are disconnected

: The AdderView Secure will maintain the existing data 

held in the EDID memories and make them available to the computers. 

• 

If the video monitor’s DDC signalling pins have been connected to 

ground

: The AdderView Secure will load a set of default data to the EDID 

memories and no data will be made available to the computers. This provides 
a means of clearing information about previously attached monitors.

Note: Most analog video cards will output a video signal without EDID 
information. In such installations it may be acceptable to disconnect the DDC 
connections from the AdderView Secure so that no EDID information is made 
available to the computers. However, some graphics cards will not output a 
video signal unless they can read the EDID information.

To determine how EDID information is used

Note: The information given here is provided purely as an overview. It is beyond 
the scope of this document to provide detailed instructions on how to modify 
video display cables, which should only be attempted by a qualified engineer.

If the transfer of EDID information is unsuitable for your installation, you can 
take steps to bypass or disable its use. EDID information is sent from the video 
display on the following pins of the connector:

•  VGA (15-pin D-type) connector:   pins 12 and 15

As mentioned earlier, the AdderView Secure unit responds in the different ways, 
depending upon how the DDC data lines within the video display cable have 
been wired:

DDC pin conditions 

AdderView Secure unit response

Connected 

EDID information is harvested from the connected 
video display during unit power on and written to all 
computer port memories.  

Not connected 

Unit retains the EDID information that is already held 
in the port memories and continues to present them to 
the attached computers. No new EDID information can 
be sought from the currently connected video display.

Grounded 

Unit overwrites all EDID information held in memory 
with default information but does not present anything 
to the attached computers.

In situations where no EDID information is being supplied, it may be necessary to 
use a special driver on the connected computers to inform their graphic adapters 
on the appropriate signals to send. 
Alternatively, a ‘surrogate’ video display of the appropriate type could be 
temporarily connected to the AdderView Secure unit in order to harvest the 
necessary EDID information. The surrogate video display could then be replaced 

by the real one, which has its DDC pins disconnected (not grounded). 

Содержание AdderView Secure AVSC1102

Страница 1: ...AVSV1002 2 port AVSV1004 4 port AVSC1102 2 port AVSC1104 4 port AdderView Secure User Guide www adder com SECURE ADDERVIEW ...

Страница 2: ...dations 10 Tamper evident seals 10 Links overview 10 Mounting 11 Making connections 12 Connections to computer systems 12 Connections to user console peripherals 12 Video display EDID information 14 Connection to power supply 15 Operation Important security features 16 Tamper evident seals 16 The security indicators 16 Anti subversion monitoring enhanced models only 16 Authentication checking enha...

Страница 3: ...erational procedures must e g re staff vetting and training ensure that as far as is reasonably possible the product is received installed and managed in accordance with the manufacturer s directions This should also ensure that users are not malicious or hostile The product should be installed in an environment that is physically secure Additionally the security office in the organisation purchas...

Страница 4: ...ccess Shielding extends also to the internal circuitry with strong levels of electrical crosstalk isolation between ports to protect against signals from one computer becoming detectable on another AdderView Secure units are available in two port and four port sizes Each size can be ordered in standard and enhanced versions The enhanced versions allow you to attach a smart card reader that can be ...

Страница 5: ...04 XX Uni directional keyboard mouse data paths ü ü ü ü High port to port crosstalk isolation ü ü ü ü Heavy shielding for low emissions ü ü ü ü Single key per port for selection ü ü ü ü USB or PS 2 computer connections ü ü ü ü Tamper protection ü ü ü ü Secure DDC EDID strategy ü ü ü ü Smartcard reader support ü ü Combined keyboard smartcard reader support ü ü Advanced tamper protection reporting ü...

Страница 6: ...er An optional smart card reader can be connected and used in conjunction with user authentication schemes Secure and shielded casing The casing is shielded to reduce electromagnetic emissions to an absolute minimum access apertures are minimized and vital access screws have tamper evident seals Clear and simple connections All connections are clearly marked to avoid any ambiguity Specially design...

Страница 7: ...keyboard port The keyboard is powered down and reset at every switchover to clear stored states Mouse devices Although pointing devices don t generally process confidential data and are therefore considered to pose a lower risk you should ensure that the mouse used with the switch is approved against the security policy of your organization and plugged directly into the switch s USB mouse port wit...

Страница 8: ...er hardware device As an additional precaution against theoretical leakage threats the circuitry associated with providing the generic card reader function is powered down and its memory is actively cleared at every channel switchover The switch does not decode or store the smartcard data flowing between the computer and the smartcard itself CO NS OL E IND OO R US E ON LY 5V 2 5 A CONSOLE When usi...

Страница 9: ...yboard smartcard reader remains directly connected into the switch s USB smartcard port The combined keyboard smartcard reader is powered down and reset at every switchover to clear stored states The keyboard data and smartcard data are separated from each other as soon as they enter the switch The keyboard data is then sent uni directionally through the switch in the same way that data from a sim...

Страница 10: ...k brackets Including four screws Shielded link cable VGA PS 2 keyboard PS 2 mouse Part code VSCD5 length 1 8m 6ft Shielded link cable VGA USB keyboard mouse USB card reader Part code VSCD6 length 1 8m 6ft Shielded link cable VGA USB keyboard mouse Part code VSCD7 length 1 8m 6ft Shielded link cable VGA only Part code VSCD9 length 1 8m 6ft Four self adhesive rubber feet ...

Страница 11: ...ly seals could be added between each connection and the unit to highlight any connections that have been altered IMPORTANT Do not use the unit if the tamper evident seals are damaged Do not use if there are any signs of damage to the unit or its power supply Links overview The rear panel of the unit is well marked however the diagram below offers additional clarity on how best to arrange your conn...

Страница 12: ... 11 Mounting The AdderView Secure unit offers two main mounting methods Supplied four self adhesive rubber feet Optional rack brackets CONS INDOOR USE ONLY 3 ...

Страница 13: ...e appropriate link cable to the 26 way connector of the appropriate channel Connections to user console peripherals To connect a keyboard and mouse IMPORTANT To reduce the risk of radiated snooping do not use wireless keyboard or mouse devices See also Devices used with the AdderView Secure for advice about linking devices to the AdderView Secure unit 1 Wherever possible ensure that power is disco...

Страница 14: ...e rear panel Ensure that the securing screws are used to maintain reliable links Note We strongly recommend that you use a video cable that has been correctly screened against signal emissions such as the VSCD9 cable CONSOLE Note The use of EDID information automatically provided by the video display could cause issues in certain high security installations please see the Video display EDID inform...

Страница 15: ...oad a set of default data to the EDID memories and no data will be made available to the computers This provides a means of clearing information about previously attached monitors Note Most analog video cards will output a video signal without EDID information In such installations it may be acceptable to disconnect the DDC connections from the AdderView Secure so that no EDID information is made ...

Страница 16: ...lar do not use an unearthed power socket or extension cable To connect the power supply 1 Attach the output connector of the power supply country specific power supplies are available to the socket located in the centre of the rear panel 2 When all other connections have been made connect the main body of the power supply to a nearby earthed mains socket NSOLE 5V 2 5A ...

Страница 17: ...lock down state where the following will take place The computer channels become isolated and will not respond to the front panel buttons The green authentication channel indicator will illuminate The four red security will continually show the following flashing alert sequence Anti subversion monitoring enhanced models only The enhanced models AVSC1102 XX and AVSC1104 XX continually monitor their...

Страница 18: ...deo display is not used during this process take care to enter characters correctly The first of the four red indicators will begin to flash 3 Enter the 8 digit Unit ID code and press Enter If the code is correct the first red indicator will illuminate and the second will begin to flash 4 Enter the 16 digit Query Code code from the Authentication Certificate do not enter the dashes and press Enter...

Страница 19: ...uter network whereas channel 4 or channel 2 on two port versions has a red indicator and is generally configured to link with the highest security computer network Note If a keyboard key is held down during a channel change then the key will be sent to the selected computer upon release of the channel change button Do not hold down keys during a channel change Smart card reader Your AdderView Secu...

Страница 20: ...or malfunction or unanticipated software bugs causing data to flow between ports Unidirectional data flow is enforced by hardware data diodes so data isolation doesn t rely on software integrity Subversive snooping by means of detecting electromagnetic radiation emitted from the equipment Carefully shielded metal case with dual shielding in critical areas Detection of signals on one computer by mo...

Страница 21: ...rity computers should be arranged to look visibly different in general appearance Threat Solution Forced malfunctions due to overloaded signalling It is potentially possible to create forced malfunctions by constantly and quickly sending a stream of valid requests such as the request to update the keyboard lights A well known example of an undesirable KVM malfunction is a crazy mouse which was qui...

Страница 22: ...eshooting section then we provide a number of other solutions Adder Technology website www adder com Check the Support section of our website for the latest solutions and driver files Email support adder com Fax in the UK 01954 780081 in the US 1 888 275 1117 Phone in the UK 01954 780044 in the US 1 888 932 3337 ...

Страница 23: ...t exceed the cable s ampere rating Also make sure that the total ampere rating of all the devices plugged into the wall outlet does not exceed the wall outlet s ampere rating The power adapter can get warm in operation do not situate it in an enclosed space without any ventilation Warranty Adder Technology Ltd warrants that this product shall be free from defects in workmanship and materials for a...

Страница 24: ... is connected d Consult the supplier or an experienced radio TV technician for help FCC Compliance Statement United States This equipment generates uses and can radiate radio frequency energy and if not installed and used properly that is in strict accordance with the manufacturer s instructions may cause interference to radio communication It has been tested and found to comply with the limits fo...

Страница 25: ...Way Bar Hill Cambridge CB23 8SQ United Kingdom Tel 44 0 1954 780044 Fax 44 0 1954 780081 Adder Corporation 350R Merrimac Street Newburyport MA 01950 United States of America Tel 1 888 932 3337 Fax 1 888 275 1117 www ctxd com Documentation by Adder Asia Pacific 6 New Industrial Road Hoe Huat Industrial Building 07 01 Singapore 536199 Tel 65 6288 5767 Fax 65 6284 1150 ...

Отзывы: