background image

USER GUIDE |

USB BACKUP HSM

Page

10

of 31

[5] SECURITY SETTINGS

[5.1] SELF-DESTRUCT PIN

The USB Backup HSM’s Self-Destruct PIN defends against physically compromising situations by erasing the
device’s contents and leaving it to look as if it never had any data written to it.

USE WITH CAUTION! When this mode is activated and the device is unlocked with the Self-Destruct PIN, it will
effectively perform a crypto-erase on the device, deleting all of its data. Additionally, the encryption device
will be deleted and a new encryption device will be created to take its place. When this Self-Destruct PIN is
entered, the device will unlock and the

green

LED will glow solidly as if the device is being normally unlocked.

The device, however, will need to be partitioned and reformatted before it can be used again. Additionally,
The previous Admin and User codes will be deleted in the crypto-erase process and the Self-Destruct PIN will
then become the new Admin PIN to unlock the device.

The Self-Destruct feature can only be enabled or disabled by the Admin. However, the Self-Destruct PIN can be
generated by either the Admin or the User. If the Admin generates the Self-Destruct PIN, only the Admin can
change that PIN. If the User generates the Self- Destruct PIN, both the User and the Admin can change the PIN.

NOTE: The Self-Destruct PIN must be different from the Admin PIN, User PIN, and Recovery PINs.

1. By default, the Self-Destruct feature is disabled. To allow the USB Backup HSM to be set with a Self-

Destruct PIN, Enter the Admin mode. (Hold

+ 0 for five seconds; while the

red

LED is blinking, enter

the Admin PIN and press the

button.) The

blue

LED will glow solidly.

2. Press the 7 and 4 buttons simultaneously. The

green

LED will blink three times, and at this point, the Self

Destruct PIN can now be set by the Admin while the device is in the Admin mode. If the intent is for the
Self-Destruct PIN to be set up at another time by the User, press the

 button and refer to the User

Setting Self Destruct PIN instructions below. Otherwise, continue to step 3.

3. Press

+ 3 until the

red

and

blue

LEDs blink alternately.

4. Enter the Self-Destruct PIN and press

. The

green

LED will blink three times and then will return to

red

and

blue

LEDs blinking alternately.

5. Re-enter the Self-Destruct PIN and press

. The

green

LED will glow solidly for a few seconds and then

will return to either the Admin mode (indicated by the

blue

LED glowing solidly) or the unlocked state if

created by User.

6. To enable or disable the Self-Destruct PIN, enter the Admin mode and press the 7 + 4 buttons

simultaneously for a second or two; successful enablement will be indicated by three

green

LED blinks.

successful disablement of Self Destruct mode (press and hold the 7 + 4 buttons again) is indicated by
three

red

LED blinks.

Self-Destruct PIN Set by the User

If the device is enabled for Self-Destruct Mode by the Admin, unlock the device with the User PIN and follow
steps 3 through 5. Additionally, the user can change their Self-Destruct PIN by following these same steps.
Note that the mode can’t be enabled or disabled in the User mode.

Содержание USB Backup HSM

Страница 1: ...Vectera Plus Guardian Series 3 KMES Series 3 RKMS Series 3 THIS DOCUMENT CONTAINS CONFIDENTIAL INFORMATION PROPRIETARY TO FUTUREX LP ANY UNAUTHORIZED USE DISCLOSURE OR DUPLICATION OF THIS DOCUMENT OR...

Страница 2: ...NG FORCED ENROLLMENT STATE ALLOWING USER TO GENERATE USER PIN 8 4 3 CHANGING THE USER PIN 8 4 4 DELETING THE USER PIN 9 5 SECURITY SETTINGS 10 5 1 SELF DESTRUCT PIN 10 5 2 BRUTE FORCE PROTECTION 11 5...

Страница 3: ...hole nor any part of the information contained in this document may be adapted or reproduced in any material or electronic form without the prior written consent of the copyright holder Information in...

Страница 4: ...battery l Interface Super Speed USB 3 1 Backwards compatible with USB 3 0 2 0 and 1 1 l Dimensions 81mm x 18 4mm x 9 5mm 22 g l Approvals FIPS 140 2 Level 3 IP 67 FCC CE VCCI WEE C TICK l ECCN HTS Ca...

Страница 5: ...ss to start the device The blue and green LEDs will turn on indicating no Admin PIN has been established 2 Press and 9 simultaneously The blue LED will illuminate and the green LED will blink 3 Enter...

Страница 6: ...her an Admin PIN or User PIN and press the button l If the PIN is accepted the green LED will quickly blink four times then continue to blink slowly until it is plugged into a USB port After being plu...

Страница 7: ...ormatted and can now be used Mac OS X The USB Backup HSM comes preformatted in FAT32 for complete cross platform compatibility and is ready for use For a strictly Mac OS environment the user must firs...

Страница 8: ...R TO GENERATE USER PIN NOTE This can only be done if there isn t already a User PIN established on the HSM using the method above 1 Enter the Admin Mode by holding and 0 for five seconds causing the r...

Страница 9: ...ond or two then will return to the User mode indicated by the green LED blinking 4 4 DELETING THE USER PIN Delete the User PIN by doing the following 1 Enter the Admin mode by holding 0 for five secon...

Страница 10: ...o allow the USB Backup HSM to be set with a Self Destruct PIN Enter the Admin mode Hold 0 for five seconds while the red LED is blinking enter the Admin PIN and press the button The blue LED will glow...

Страница 11: ...together until the red and green LEDs blink alternately 4 Enter the code LastTry 5278879 and press the button The red LED will glow steadily You will now have the remaining 50 of PIN attempts 5 When t...

Страница 12: ...inking enter the Admin PIN and press the button The blue LED will glow solidly 2 Once in the Admin mode press 6 The red and blue LEDs will blink alternately 3 Press one of the numbers below that corre...

Страница 13: ...overy PIN and pressing the button again If PIN is accepted for the final time the green LED will blink three times and the USB Backup HSM will then return to the Admin mode indicated by a solid blue L...

Страница 14: ...nged the device can only be read To return the USB to Read Write 1 Enter the Admin mode Hold 0 for five seconds with the red LED blinking enter the Admin PIN and press the button The blue LED will glo...

Страница 15: ...s type of usage Lock Override Mode will allow the device to remain unlocked through USB port re enumeration and will not lock again until USB power is interrupted NOTE When in this mode the device is...

Страница 16: ...sed will be expressed by the red LED blinking For example l 1 Button 1 blink l 2 Button 2 blinks l 3 Button 3 blinks l 0 Button 10 blinks l Button 11 blinks l Button 12 blinks 4 To exit the Diagnostic...

Страница 17: ...USER GUIDE USB BACKUPHSM Page 17 of 31 cannot recover it must be replaced...

Страница 18: ...the following 1 Press and hold 2 together for ten seconds The red and blue LEDs will blink alternately 2 The green and red LEDs will glow solidly for several seconds followed by the green LED glowing...

Страница 19: ...the left toolbar 3 Under the Backup and Restore heading click Backup Config to save the configuration data 4 The Backup device to file window will open FIGURE BACKUP DEVICE TO FILE WINDOW l The window...

Страница 20: ...sh to exit the window 5 Once the operation is completed disconnect the USB Backup HSM from the computer Backing Up Keys NOTE As with the MFK the loading of the backup key may be performed through M of...

Страница 21: ...inue through the process of loading the key through the key wizard or M of N fragments l If a key has already been loaded the Replace Backup Key button can be clicked if desired allowing you to use an...

Страница 22: ...m a backup the current users must be members of a user group with the Database Backup and Update System Configuration permissions enabled The Admin Group has this permission enabled by default 1 Unloc...

Страница 23: ...ore 1 Unlock the USB Backup HSM and insert it into one of the USB ports on the rear of the unit 2 Select Configuration from the left toolbar 3 In the Configuration window right click Restore then clic...

Страница 24: ...KSN l Use the second drop down menu to select whether the filter should find logs that simply contain the defined input or if it should only find logs that have an exact match for the defined input l...

Страница 25: ...k the Configure button at the bottom of the screen or right click on the device and select Configure Group from the drop down menu The Encryption Device Group Management window will appear 4 From the...

Страница 26: ...ing blue Key unlocked in Lock Override Mode Solid green slow blinking red Key unlocked in Read Only Mode Alternating red blue Indicates a mode has been entered that can result in the deletion of a use...

Страница 27: ...from forced enrollment state 3 Set self destruct PIN Admin Mode Keys Mode 0 Enter Admin Mode 1 Create User PIN 2 not used 3 Set self destruct PIN Admin or User setup 4 Set minimum PIN length 5 Set bru...

Страница 28: ...Page 28 of 31 Keys Mode 7 9 Read only off 7 8 Erase user and self destruct PINs 0 1 Set forced enrollment for user 0 3 Turn on LED flicker when entering PIN from standby 0 4 Turn off LED flicker when...

Страница 29: ...t of the USB Backup HSM where all PINs and data will be erased and you will need to reconfigure reformat the USB Backup HSM creating a new Admin PIN which will allow you to reload the previously backe...

Страница 30: ...upport l Extremely knowledgeable subject matter experts At Futurex we strive to supply you with the latest data encryption innovations as well as our best in class support services Our Xceptional Supp...

Страница 31: ...Boerne Road Bulverde Texas USA 78163 Phone 1 830 980 9782 1 830 438 8782 E mail info futurex com XCEPTIONAL SUPPORT 24x7x365 Toll Free 1 800 251 5112 E mail support futurex com SOLUTIONS ARCHITECT E...

Отзывы: