
The Concept of iKey Authentication
Access to sensitive data on a ASA 310-FIPS is protected by a combination of hardware tokens
(called iKeys), passwords, and encryption procedures.
The iKey is a cryptographic token that is used as part of the authentication process for certain
operations involving the HSM cards. Whenever you perform an operation on the ASA 310-
FIPS calling for iKey authentication, you are prompted by the Command Line Interface to insert
the requested iKey into the USB port on the appropriate HSM card. (When prompted for a
particular iKey, a flashing LED always directs you to the correct HSM card.)
Types of iKeys
For each HSM card there are two unique iKeys used for identity-based authentication: the
HSM-SO iKey, and the HSM-USER iKey. Each of these iKeys define the two user roles
available: Security Officer and User. A password must be defined for each user role, and the
passwords are directly associated with the corresponding iKey. The ASA 310-FIPS is equipped
with two HSM cards, and you therefore need to maintain two pairs of HSM-SO and HSM-USER
iKeys with their associated passwords for each single ASA 310-FIPS ASA 310-FIPS device.
After an HSM card has been initialized, that card will only accept the HSM-SO and HSM-USER
iKeys that were used when initializing that particular card. You cannot create backup copies
of the associated HSM-SO iKey and HSM-USER iKey, and a lost HSM-SO or HSM-USER
password cannot be retrieved. It is therefore extremely important that you establish routines
for how the iKeys are handled.
Wrap Keys for ASA 310-FIPS Clusters
In addition to the HSM-SO and HSM-USER iKeys specific for each HSM card, one pair of iKeys
(the black HSM-CODE iKeys) need also be maintained for each cluster of ASA 310-FIPS
units.
Note:
You are strongly recommended to label two of the black HSM-CODE iKeys "CODE-SO" and
"CODE-USER" respectively; these iKeys will be referred to as such both in the
documentation and in the Command Line Interface.
During the initialization of the first ASA 310-FIPS in a cluster, a
wrap key
is automatically
generated. The wrap key is a secret shared among all ASA 310-FIPS in the cluster. It encrypts
and decrypts sensitive information that is sent over the PCI bus within an ASA 310-FIPS, and
over the network among the ASA 310-FIPS devices in the cluster. By inserting the CODE-SO
iKey and the CODE-USER iKey in turns when requested by the Setup utility, the wrap key is
The Concept of iKey Authentication
User Guide
April 2013 33
Содержание 3050-VM
Страница 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Страница 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Страница 12: ...12 User Guide April 2013 ...
Страница 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Страница 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Страница 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Страница 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Страница 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Страница 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Страница 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Страница 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Страница 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Страница 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Страница 265: ...This will print current statistics every 3 seconds Monitoring the Port Forwarder User Guide April 2013 265 ...
Страница 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Страница 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...