Code CR2500 Code FIPS Manual do Utilizador Página 3

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 8
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 2
C005590_01_CR2500_CR3500_User Manual_Appendix H 2
An Authencaon is iniated on the reader. If the Authencaon completes successfully on the reader, and the reader
is aached to a modem, the Authencaon informaon is transferred to the modem aer being encrypted with the KEK.
If the Authencaon is completed successfully on the modem it returns an acknowledgement to the reader.
Inializaon – This is the service that can update the passwords for the roles plus update the KEK on the modules.
Only the CO role has access to the Inializaon service. Acvaon of this service is accomplished through reading a
Data Matrix bar code that contains the Inializaon command plus the new passwords for both roles and a new KEK.
An Inializaon is iniated on the reader. If the Inializaon completes successfully on the reader, and the reader is
aached to a modem, the Inializaon informaon is transferred to the modem aer being encrypted with the old
KEK. If the Inializaon is completed successfully on the modem, it returns an acknowledgement to the reader. All
subsequent non-data communicaons between the reader and the modem are encrypted with the new KEK.
Transming Encrypted Data – This is the service that transmits data from the reader to the modem using the FIPS
approved AES-256 encrypon scheme. Only the Reader role has access to this service. Acvaon of this service is
accomplished through compleng authencaon in the Reader role and reading a bar code containing data. If the
transmission is successful the reader will indicate by ashing an LED light amber.
Zeroizaon – This is the service that removes any customized passwords and KEK from the modules. Either role can
access this service at any me. Aer Zeroizaon the modules will not return to FIPS mode unl the Inializaon service
has been invoked. Acvaon of this service is accomplished through reading a Data Matrix bar code that contains the
Zeroizaon command. A Zeroizaon is iniated on the reader. If the Zeroizaon completes successfully on the reader,
and the reader is aached to a modem, the Zeroizaon informaon is transferred to the modem. If the Zeroizaon is
completed successfully on the modem it returns and acknowledgement to the reader.
Crical Security Parameters (CSPs)
The modules ulize four CSPs. They consist of the CO role password, the Reader role password, the KEK and the Trac
Encrypon Key (TEK). The passwords and KEK are updated through the Inializaon process and the TEK is internally
generated by the reader module.
Passwords and keys are made up of hexidecimal characters represenng ASCII characters. Hexidecimal values are
represented in text by a subscript ‘hex’ as in 1D
hex
. In programming, the passwords and KEK are represented by a leading
‘%’ - %1D.
CO role password – this 64 bit password is used to authencate the CO role. The modules are shipped with a default
CO password of the word ‘password’ that can only be used to inialize the modules with new CO and Reader role
passwords and a new KEK. The modules will not transfer encrypted data using the default password. A 64 bit password
is constructed out of eight ASCII characters that can be represented by the hexadecimal digits 20
hex
through FF
hex
.
Construcng a password to use in the Inializaon process is covered below.
Reader role password – this 64 bit password is used to authencate the Reader role. A 64 bit password is constructed
out of eight ASCII characters that can be represented by the hexadecimal digits 20
hex
through FF
hex
. Construcng a
password to use in the Inializaon process is covered below.
Key Encrypon Key (KEK) – this 265 bit key is used by an AES algorithm to encrypt transmissions of passwords and keys
between the reader and modem modules. A 256 bit password is constructed out of 32 ASCII characters that can be
represented by the hexadecimal digits 20
hex
through FF
hex
. Construcng a password to use in the Inializaon process is
covered below.
Trac Encrypon Key (TEK) – this 256 bit key is used by an AES algorithm to encrypt transmissions of data from the
reader to the modem. The modem ulizes the same TEK to decrypt the data. The TEK is generated by the reader and is
Vista de página 2
1 2 3 4 5 6 7 8

Comentários a estes Manuais

Sem comentários