Code CR2500 Code FIPS Instrukcja Użytkownika Strona 2

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 8
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 1
C005590_01_CR2500_CR3500_User Manual_Appendix H
1
The FIPS versions of the Code Reader 2500 FIPS (CR2500 FIPS), Code Reader 3500 FIPS (CR3500 FIPS) and CodeXML® FIPS
Bluetooth® Modem (hereaer referred to as the modules) are bar code reading devices that have passed the rigorous
tesng of the FIPS 140-2 standard. The modules use FIPS approved AES-256 algorithms to encrypt data transmied
wirelessly between the reader and modem.
The versions of the FIPS modules are as follows:
Code Reader 2500 – 2512FIPS_01 using rmware 4641
Code Reader 3500 – 3512FIPS_01 using rmware 4641
CODE FIPS Bluetooth Modem – BTHDFIPS-M2_01 using rmware 0187
The FIPS modules are based on the standard CR2500, CR3500, and CodeXML® Bluetooth® Modem. Therefore most
operaon quesons can be answered in the User Manual for those devices. This document will call out the dierences
in behavior and operaon of the FIPS modules.
Chapter 1 – What you need to know about FIPS Mode
The FIPS modules must be used in a CR2500 FIPS /CodeXML® FIPS Bluetooth® Modem or CR3500 FIPS/CodeXML® FIPS
Bluetooth® Modem pair while in FIPS mode. FIPS mode is dened as a reader and modem paired together;
transming data encrypted with FIPS approved AES algorithms. In order to achieve FIPS mode the reader and modem
must be inialized with passwords for two dierent roles – Cryptographic Ocer (CO) and Reader – plus a Key
Encrypon Key (KEK) that is used to encrypt transmissions of passwords and keys between the reader and modem. The
readers and modem come with a default password installed for the CO role. The default password cannot be used to
transmit encrypted data and must be updated through the Inializaon process. The CO and Reader roles can’t be
inialized to the same password. Once inialized you may authencate the CO role or the Reader role by expressly
reading a bar code containing the corresponding password. The roles have dierent purposes and a dierent set of
services that are available to them in the FIPS process, as explained below.
Roles
Cryptographic Ocer (CO) – this role can request the following FIPS services:
1. Authencate to the modules
2. Inialize the modules with new CO and Reader passwords and a new Key Encrypon Key (KEK)
3. Zeroizaon of non-default passwords and KEK
Reader – this role can request the following FIPS services:
1. Authencate to the modules
2. Transmit encrypted data between the reader and the modem
3. Zeroizaon of a non-default passwords and KEK
Services
Authencaon – This is the service where a role can prove it is authorized to access the modules. Only the CO role can
authencate to the modules using the default password. Either role can authencate to either module as long as the CO
has inialized the modules with new passwords and KEK. Acvaon of this service is accomplished through reading a
Data Matrix bar code that contains the Authencaon command plus the password of the role wishing to authencate.
Code FIPS Overview
Przeglądanie stron 1
1 2 3 4 5 6 7 8

Komentarze do niniejszej Instrukcji

Brak uwag