background image

USER GUIDE |

USB BACKUP HSM

Page

11

of 31

[5.2] BRUTE-FORCE PROTECTION

A Brute-Force Attack is a means of breaching a cryptographic data defense scheme by systematically running
an astronomical number of decryption possibilities. With AES 256 having never been cracked, the data stored
on a USB Backup HSM is going to be more than well-protected against brute-force. But brute-force attacks
aren’t necessarily aimed at the bulk of the data itself, but rather, at the drive’s access PINs. After all, PINs are
usually the weakest links of any data protection plan, and as such, PINs are essentially all that a brute-force
attack needs to decrypt.

The default number of maximum incorrect PIN entries allowed is 20, but can be programmed to be as few as
four.

1. After three unsuccessful drive authentication attempts, the USB Backup HSM will automatically add

additional time delays to each subsequent try thereafter. The

red

LED will blink the number of failed

attempts after three, all the way up to the halfway point of total allowed attempts, e.g. 10 total
programmed attempts; halfway point is 5.

2. Once that halfway point of the number of unsuccessful authentication attempts is reached, the keypad

will lock up and the

red

LED will blink at a rate of three flashes per second. No additional PIN attempts

will be recognized.

3. To unlock the keypad and regain the ability to enter a PIN, press and hold the 5 button and the

 button

together until the

red

and

green

LEDs blink alternately.

4. Enter the code “LastTry” (5278879) and press the button. The

red

LED will glow steadily. You will now

have the remaining 50% of PIN attempts.

5. When the device is successfully unlocked, the Brute-Force counter will return to zero.

The number of attempts possible, both before and after the LastTry (5278879) code is entered, can be set (in
Admin Mode) between 2 and 10 attempts.

Setting the before/after attempts to the minimum of two would allow for a total of four attempts (two before
entering the LastTry code and two after). To program the number of Brute-Force attempts allowed:

1. Enter the Admin mode. (Hold

+ 0 for five seconds; with the

red

LED blinking, enter the Admin PIN

and press the

 button.) The

blue

LED will glow solidly.

2. Press and hold the

 + 5 button for three seconds. The

red

LED will double-blink.

3. Press the number of before/after attempts desired on the numeric keypad (2-9). The

green

LED will

blink the same number of times to correspond to the number you have entered.

l

For example: the 8 button will result in eight blinks, and yield eight attempts before the LastTry
code and another eight attempts after, yielding a total of 16.

4. To return the device to its default setting, press the 1 key, followed by the 0 key, to change the number

back to ten attempts.

NOTE: The number of before and after attempts are the same, i.e., 4 before / 4 after, 8 before / 8 after, etc.

[5.3] UNATTENDED AUTO-LOCK

To protect against unauthorized access if the device is unlocked and unattended, the USB Backup HSM can be
set to automatically lock after a predetermined period of inactivity.

Содержание USB Backup HSM

Страница 1: ...Vectera Plus Guardian Series 3 KMES Series 3 RKMS Series 3 THIS DOCUMENT CONTAINS CONFIDENTIAL INFORMATION PROPRIETARY TO FUTUREX LP ANY UNAUTHORIZED USE DISCLOSURE OR DUPLICATION OF THIS DOCUMENT OR...

Страница 2: ...NG FORCED ENROLLMENT STATE ALLOWING USER TO GENERATE USER PIN 8 4 3 CHANGING THE USER PIN 8 4 4 DELETING THE USER PIN 9 5 SECURITY SETTINGS 10 5 1 SELF DESTRUCT PIN 10 5 2 BRUTE FORCE PROTECTION 11 5...

Страница 3: ...hole nor any part of the information contained in this document may be adapted or reproduced in any material or electronic form without the prior written consent of the copyright holder Information in...

Страница 4: ...battery l Interface Super Speed USB 3 1 Backwards compatible with USB 3 0 2 0 and 1 1 l Dimensions 81mm x 18 4mm x 9 5mm 22 g l Approvals FIPS 140 2 Level 3 IP 67 FCC CE VCCI WEE C TICK l ECCN HTS Ca...

Страница 5: ...ss to start the device The blue and green LEDs will turn on indicating no Admin PIN has been established 2 Press and 9 simultaneously The blue LED will illuminate and the green LED will blink 3 Enter...

Страница 6: ...her an Admin PIN or User PIN and press the button l If the PIN is accepted the green LED will quickly blink four times then continue to blink slowly until it is plugged into a USB port After being plu...

Страница 7: ...ormatted and can now be used Mac OS X The USB Backup HSM comes preformatted in FAT32 for complete cross platform compatibility and is ready for use For a strictly Mac OS environment the user must firs...

Страница 8: ...R TO GENERATE USER PIN NOTE This can only be done if there isn t already a User PIN established on the HSM using the method above 1 Enter the Admin Mode by holding and 0 for five seconds causing the r...

Страница 9: ...ond or two then will return to the User mode indicated by the green LED blinking 4 4 DELETING THE USER PIN Delete the User PIN by doing the following 1 Enter the Admin mode by holding 0 for five secon...

Страница 10: ...o allow the USB Backup HSM to be set with a Self Destruct PIN Enter the Admin mode Hold 0 for five seconds while the red LED is blinking enter the Admin PIN and press the button The blue LED will glow...

Страница 11: ...together until the red and green LEDs blink alternately 4 Enter the code LastTry 5278879 and press the button The red LED will glow steadily You will now have the remaining 50 of PIN attempts 5 When t...

Страница 12: ...inking enter the Admin PIN and press the button The blue LED will glow solidly 2 Once in the Admin mode press 6 The red and blue LEDs will blink alternately 3 Press one of the numbers below that corre...

Страница 13: ...overy PIN and pressing the button again If PIN is accepted for the final time the green LED will blink three times and the USB Backup HSM will then return to the Admin mode indicated by a solid blue L...

Страница 14: ...nged the device can only be read To return the USB to Read Write 1 Enter the Admin mode Hold 0 for five seconds with the red LED blinking enter the Admin PIN and press the button The blue LED will glo...

Страница 15: ...s type of usage Lock Override Mode will allow the device to remain unlocked through USB port re enumeration and will not lock again until USB power is interrupted NOTE When in this mode the device is...

Страница 16: ...sed will be expressed by the red LED blinking For example l 1 Button 1 blink l 2 Button 2 blinks l 3 Button 3 blinks l 0 Button 10 blinks l Button 11 blinks l Button 12 blinks 4 To exit the Diagnostic...

Страница 17: ...USER GUIDE USB BACKUPHSM Page 17 of 31 cannot recover it must be replaced...

Страница 18: ...the following 1 Press and hold 2 together for ten seconds The red and blue LEDs will blink alternately 2 The green and red LEDs will glow solidly for several seconds followed by the green LED glowing...

Страница 19: ...the left toolbar 3 Under the Backup and Restore heading click Backup Config to save the configuration data 4 The Backup device to file window will open FIGURE BACKUP DEVICE TO FILE WINDOW l The window...

Страница 20: ...sh to exit the window 5 Once the operation is completed disconnect the USB Backup HSM from the computer Backing Up Keys NOTE As with the MFK the loading of the backup key may be performed through M of...

Страница 21: ...inue through the process of loading the key through the key wizard or M of N fragments l If a key has already been loaded the Replace Backup Key button can be clicked if desired allowing you to use an...

Страница 22: ...m a backup the current users must be members of a user group with the Database Backup and Update System Configuration permissions enabled The Admin Group has this permission enabled by default 1 Unloc...

Страница 23: ...ore 1 Unlock the USB Backup HSM and insert it into one of the USB ports on the rear of the unit 2 Select Configuration from the left toolbar 3 In the Configuration window right click Restore then clic...

Страница 24: ...KSN l Use the second drop down menu to select whether the filter should find logs that simply contain the defined input or if it should only find logs that have an exact match for the defined input l...

Страница 25: ...k the Configure button at the bottom of the screen or right click on the device and select Configure Group from the drop down menu The Encryption Device Group Management window will appear 4 From the...

Страница 26: ...ing blue Key unlocked in Lock Override Mode Solid green slow blinking red Key unlocked in Read Only Mode Alternating red blue Indicates a mode has been entered that can result in the deletion of a use...

Страница 27: ...from forced enrollment state 3 Set self destruct PIN Admin Mode Keys Mode 0 Enter Admin Mode 1 Create User PIN 2 not used 3 Set self destruct PIN Admin or User setup 4 Set minimum PIN length 5 Set bru...

Страница 28: ...Page 28 of 31 Keys Mode 7 9 Read only off 7 8 Erase user and self destruct PINs 0 1 Set forced enrollment for user 0 3 Turn on LED flicker when entering PIN from standby 0 4 Turn off LED flicker when...

Страница 29: ...t of the USB Backup HSM where all PINs and data will be erased and you will need to reconfigure reformat the USB Backup HSM creating a new Admin PIN which will allow you to reload the previously backe...

Страница 30: ...upport l Extremely knowledgeable subject matter experts At Futurex we strive to supply you with the latest data encryption innovations as well as our best in class support services Our Xceptional Supp...

Страница 31: ...Boerne Road Bulverde Texas USA 78163 Phone 1 830 980 9782 1 830 438 8782 E mail info futurex com XCEPTIONAL SUPPORT 24x7x365 Toll Free 1 800 251 5112 E mail support futurex com SOLUTIONS ARCHITECT E...

Отзывы: