Code CR2500 Code FIPS Manual do Utilizador Página 4

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 8
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 3
C005590_01_CR2500_CR3500_User Manual_Appendix H
3
not accessible by users.
Chapter 2 – Seng up your FIPS hardware
Out of the box the reader/modem pair will behave as any standard non-FIPS pair. You can use them in non-FIPS mode
but be aware that any data you transmit will not be protected by the FIPS approved AES-256 encrypon algorithms. In
order to use FIPS mode the modules must be inialized by the CO. Inializaon cannot be performed by the Reader
role. You must authencate the CO role using the default password before Inializaon and you must create an
Inializaon bar code before you can perform Inializaon on the FIPS readers.
The reader module provides the interface to the modem module. Therefore, if you wish to Authencate or Inialize
both the reader and the modem you must have the reader paired with the modem while performing these tasks. To
connect the reader and modem, read the QuickConnect code printed on the modem with the reader. Refer to the User
Manual for the reader and modem for more informaon on pairing.
Default CO Authencaon
The bar code below contains the Authencaon command and the default CO password. Using this Authencaon the
CO can only Inialize or Zeroize the modules.
Figure 1 - Default Cryptographic Ocer Authencaon Bar Code
Creang an Inializaon Bar Code
Create the Inializaon bar code by wring a .crb le containing the Inializaon commands and data. Convert the .crb
le to a Data Matrix bar code by passing it through the CodeXML CRB to Code Ulity found at hp://codecorp.com/
EULACodeXMLCRBtoCodeUlity.php. The Inializaon command must be encoded in a Data Matrix bar code in order to
funcon.
The inializaon bar code contains six items.
1. The Inializaon command (H2; H indicates the FIPS command set, 2 is the Inializaon command)
2. A new Cryptographic Ocer password (Eight characters in the set 20
hex
through FF
hex
)
3. A group separator (1D
hex
)
4. A new Reader password (Eight characters in the set 20
hex
through FF
hex
)
5. A group separator (1D
hex
)
6. A new Key Encrypon Key (32 characters in the set 20
hex
through FF
hex
)
The code below shows example values for the new CO password, Reader password and KEK in a .crb le. You should
not use these values when creang an Inializaon bar code and the CO and Reader passwords must not be equal. You
must substute your own eight character passwords and 32 character KEK when you inialize. The lines starng with ‘;’
are comments. Some comment lines wrap to the next line in this example. Please see your FIPS documentaon kit for
the actual demo .crb le. The last line that starts with % is the Inializaon command. You may omit all comment lines
if you wish.
An ASCII to hex converter can be found at hp://www.idea2ic.com/PlayWithJavascript/hexToAscii.html. Use the ‘De-
limit with %’ to create hex strings of ASCII characters you can paste into .crb les.
;8/6/2010 16:43
Vista de página 3
1 2 3 4 5 6 7 8

Comentários a estes Manuais

Sem comentários