![General DataComm 060A027-001 Скачать руководство пользователя страница 54](http://html1.mh-extra.com/html/general-datacomm/060a027-001/060a027-001_installation-and-operation-manual_2210285054.webp)
Operation
Security Overview
3-20
SpectraComm Dual V.34 Modem
060R122-000
Installation and Operation
Issue 15
Message Flow
The Secure Access Modem is connected to a PSTN by voice-band modems. The Authentication
Server is connected to the PSTN via a modem bank, allowing access to the server by multiple users.
A secondary Authentication Server minimizes delay and avoids downtime. The message flow
between components in a Secure Access Controller system is detailed below.
Figure 3-1
SAM Authentication Sequence
Background Communication
1. The Secure Access Modem (SAM) obtains a new private key from the Authentication Server
(AS) via a secure tunnel at every power-up, key time-out or session end.
First Call
2. Remote user's client software calls the Authentication Server (AS) and is identified via
encrypted communication over a secure tunnel. In the event of a hacker attempt, a secure
tunnel is never established. When the caller is authenticated, the Authentication Server sends
the client the SAM phone number and its public key over the secure tunnel. AS then
disconnects the call.
Second Call
3. Client calls the SAM and performs a public key exchange over a secure tunnel.
Authenticated Out-of-Band Management Access
4. User manages protected network equipment via the secure tunnel and AES data encryption:
•
Client sends AES encrypted data to SAM;
•
SAM decrypts data and sends it to the
protected network equipment;
•
The protected equipment sends data to SAM;
•
SAM encrypts data and sends data to client;
•
Client decrypts data and displays it to user;
Note
When the user terminates the management session, that public key is no longer valid.
MODEM
CICSO 2611
to SWITCH
SECONDARY
AUTHENTICATION
SERVER
MODEM BANK
REMOTE USER
CLIENT
Secondary Authentication Server Site
PRIMARY
AUTHENTICATION
SERVER
MODEM BANK
Primary Authentication Server Site
PSTN
REMOTE
MANAGEMENT
of SAM
Modem
connects
secure call
to Switch
4
Secure
connection
to Server
2
SAM
MODEM
Modem calls
Server for
New Key
1
3
3
Remote User Modem
calls SAM Modem
MODEM
SAM
MODEM
Protected
Equipment
Remote
User
Decrypted
Data
Encrypted
Data
Decrypted
Data
Encrypted
Data
Содержание 060A027-001
Страница 6: ...iv SpectraComm Dual V 34 Modem 060R122 000 Installation and Operation Issue 15 Table of Contents...
Страница 80: ...Operation Modem Main Menu 3 46 SpectraComm Dual V 34 Modem 060R122 000 Installation and Operation Issue 15...
Страница 137: ......
Страница 138: ...The Best Connections in the Business...