the encryption accelerators. The encryption accelerators implement the following
•
•
Cryptographic processing is performed during SSHv2, SNMPv3, IKE, IPSec, and when accessing and storing database files.
The module supports the following critical and
CSPs and non- | CSPs and non- | Generation | Storage | Use |
critical SPs | critical SPs type |
|
|
|
Key encryption | External | Encrypts master | ||
key |
|
| plaintext | encryption key |
Master encryption | Internal – using | Stored encrypted | Encrypts user data, | |
key |
| FIPS | in NVRAM of the | certificates, and |
|
| Or | Dallas DS1687 | DSA host key, and |
|
| External | real time clock | the load test HMAC |
|
|
| chip | |
DSA host key pair | Internal – using | Stored encrypted | Module | |
| private key and | FIPS | in Flash | authentication |
|
|
| during SSHv2 | |
| public key |
|
|
|
IKE RSA key pair | Internal – using | Stored encrypted | Module | |
| private/public key | FIPS | in Flash | authentication |
| pair |
|
| during IKE |
IKE User RSA | External | Stored encrypted | User authentication | |
public keys | public key |
| in Flash | during IKE |
≥ | External | Stored encrypted | User and module | |
| shared key |
| in Flash | authentication |
|
|
|
| during IKE |
IKE | Internal – using | Stored in plaintext | Key agreement | |
key pair | FIPS | in memory | during IKE | |
| private/public key |
|
|
|
| pair |
|
|
|
IKE User Diffie- | External | Stored in plaintext | Key agreement | |
Hellman public key |
| in memory | during IKE | |
| public key |
|
|
|
SSHv2 Diffie- | Internal – using | Stored in plaintext | Key agreement | |
Hellman key pair | FIPS | in memory | during SSHv2 | |
| private/public key |
|
|
|
| pair |
|
|
|
SSHv2 User Diffie- | External | Stored in plaintext | Key agreement | |
Hellman public key |
| in memory | during SSHv2 | |
| public key |
|
|
|
SSHv2 session | Established during | Stored in plaintext | Secure SSH traffic | |
keys | the SSH key | in memory |
| |
| AES keys; HMAC | exchange using |
|
|
| the |
|
| |
|
| key agreement |
|
|
© Copyright 2003 Enterasys Networks Page 17 of 25
This document may be freely reproduced and distributed whole and intact including this Copyright Notice.