background image

USER GUIDE |

USB BACKUP HSM

Page

13

of 31

[6] SPECIAL MODES

[6.1] ONE-TIME-USE RECOVERY PINS

The Admin has the ability to set Recovery PINs that will allow a User to access data on the USB Backup HSM in
the event of a forgotten PIN by creating a new state of User Forced Enrollment in which a new User PIN can be
established without wiping any data off of the drive. The Admin can establish up to four single-use Recovery
PINs; once a Recovery PIN has been used to access the USB Backup HSM, it will no longer be available for
future recovery efforts.

NOTE: The Recovery PIN will not unlock the device, but will place the USB Backup HSM into a User Forced
Enrollment state, where the User can then establish a new User PIN which will then grant access the Key’s
data.

Setting Recovery PINs

1. Enter the Admin mode. (Hold

 + 0 for five seconds. With the

red

LED blinking, enter the Admin PIN

and press the

 button.) The

blue

LED will now glow solidly.

2. Press the

 + 8 buttons together. The

green

LED will blink three times by itself, and then will be joined

by a solid

blue

LED.

3. Enter the Recovery PIN and press the

 button. If the PIN is accepted, the

green

LED will blink three

times.

4. Repeat by entering that same Recovery PIN and pressing the

 button again. If PIN is accepted for the

final time, the

green

LED will blink three times and the USB Backup HSM will then return to the Admin

mode indicated by a solid

blue

LED.

5. To add more Recovery PINs, repeat steps 2-4. When finished, press the

 button to return device to its

standby mode.

Using a Recovery PIN

Deploying a Recovery PIN will put the USB Backup HSM into a state of User Forced Enrollment and that
recovery PIN will no longer be useable. Additionally, once in a state of User Forced Enrollment, the previous
User PIN will no longer be recognized as a valid PIN for drive authentication and a new User PIN must be
created.

1. With the USB Backup HSM in Standby mode, press and hold the

 + 7 buttons together for five seconds

and release once the

red

LED starts blinking.

2. Enter a recovery PIN (from Admin) and press the

 button. The

green

LED will blink three times by

itself, and then will be joined by a solid

blue

LED indicating the device is in User Forced Enrollment

mode.

3. Enter a new User PIN and press the

 button. The

green

LED will blink three times if accepted.

4. Re-enter that same new User PIN and press the

 button again to verify it. If accepted, the

green

LED

will blink three times and then the USB Backup HSM will return to its Standby state, indicated by the

red

LED glowing steadily. The USB Backup HSM will now be accessible using this new User PIN.

Summary of Contents for USB Backup HSM

Page 1: ...Vectera Plus Guardian Series 3 KMES Series 3 RKMS Series 3 THIS DOCUMENT CONTAINS CONFIDENTIAL INFORMATION PROPRIETARY TO FUTUREX LP ANY UNAUTHORIZED USE DISCLOSURE OR DUPLICATION OF THIS DOCUMENT OR...

Page 2: ...NG FORCED ENROLLMENT STATE ALLOWING USER TO GENERATE USER PIN 8 4 3 CHANGING THE USER PIN 8 4 4 DELETING THE USER PIN 9 5 SECURITY SETTINGS 10 5 1 SELF DESTRUCT PIN 10 5 2 BRUTE FORCE PROTECTION 11 5...

Page 3: ...hole nor any part of the information contained in this document may be adapted or reproduced in any material or electronic form without the prior written consent of the copyright holder Information in...

Page 4: ...battery l Interface Super Speed USB 3 1 Backwards compatible with USB 3 0 2 0 and 1 1 l Dimensions 81mm x 18 4mm x 9 5mm 22 g l Approvals FIPS 140 2 Level 3 IP 67 FCC CE VCCI WEE C TICK l ECCN HTS Ca...

Page 5: ...ss to start the device The blue and green LEDs will turn on indicating no Admin PIN has been established 2 Press and 9 simultaneously The blue LED will illuminate and the green LED will blink 3 Enter...

Page 6: ...her an Admin PIN or User PIN and press the button l If the PIN is accepted the green LED will quickly blink four times then continue to blink slowly until it is plugged into a USB port After being plu...

Page 7: ...ormatted and can now be used Mac OS X The USB Backup HSM comes preformatted in FAT32 for complete cross platform compatibility and is ready for use For a strictly Mac OS environment the user must firs...

Page 8: ...R TO GENERATE USER PIN NOTE This can only be done if there isn t already a User PIN established on the HSM using the method above 1 Enter the Admin Mode by holding and 0 for five seconds causing the r...

Page 9: ...ond or two then will return to the User mode indicated by the green LED blinking 4 4 DELETING THE USER PIN Delete the User PIN by doing the following 1 Enter the Admin mode by holding 0 for five secon...

Page 10: ...o allow the USB Backup HSM to be set with a Self Destruct PIN Enter the Admin mode Hold 0 for five seconds while the red LED is blinking enter the Admin PIN and press the button The blue LED will glow...

Page 11: ...together until the red and green LEDs blink alternately 4 Enter the code LastTry 5278879 and press the button The red LED will glow steadily You will now have the remaining 50 of PIN attempts 5 When t...

Page 12: ...inking enter the Admin PIN and press the button The blue LED will glow solidly 2 Once in the Admin mode press 6 The red and blue LEDs will blink alternately 3 Press one of the numbers below that corre...

Page 13: ...overy PIN and pressing the button again If PIN is accepted for the final time the green LED will blink three times and the USB Backup HSM will then return to the Admin mode indicated by a solid blue L...

Page 14: ...nged the device can only be read To return the USB to Read Write 1 Enter the Admin mode Hold 0 for five seconds with the red LED blinking enter the Admin PIN and press the button The blue LED will glo...

Page 15: ...s type of usage Lock Override Mode will allow the device to remain unlocked through USB port re enumeration and will not lock again until USB power is interrupted NOTE When in this mode the device is...

Page 16: ...sed will be expressed by the red LED blinking For example l 1 Button 1 blink l 2 Button 2 blinks l 3 Button 3 blinks l 0 Button 10 blinks l Button 11 blinks l Button 12 blinks 4 To exit the Diagnostic...

Page 17: ...USER GUIDE USB BACKUPHSM Page 17 of 31 cannot recover it must be replaced...

Page 18: ...the following 1 Press and hold 2 together for ten seconds The red and blue LEDs will blink alternately 2 The green and red LEDs will glow solidly for several seconds followed by the green LED glowing...

Page 19: ...the left toolbar 3 Under the Backup and Restore heading click Backup Config to save the configuration data 4 The Backup device to file window will open FIGURE BACKUP DEVICE TO FILE WINDOW l The window...

Page 20: ...sh to exit the window 5 Once the operation is completed disconnect the USB Backup HSM from the computer Backing Up Keys NOTE As with the MFK the loading of the backup key may be performed through M of...

Page 21: ...inue through the process of loading the key through the key wizard or M of N fragments l If a key has already been loaded the Replace Backup Key button can be clicked if desired allowing you to use an...

Page 22: ...m a backup the current users must be members of a user group with the Database Backup and Update System Configuration permissions enabled The Admin Group has this permission enabled by default 1 Unloc...

Page 23: ...ore 1 Unlock the USB Backup HSM and insert it into one of the USB ports on the rear of the unit 2 Select Configuration from the left toolbar 3 In the Configuration window right click Restore then clic...

Page 24: ...KSN l Use the second drop down menu to select whether the filter should find logs that simply contain the defined input or if it should only find logs that have an exact match for the defined input l...

Page 25: ...k the Configure button at the bottom of the screen or right click on the device and select Configure Group from the drop down menu The Encryption Device Group Management window will appear 4 From the...

Page 26: ...ing blue Key unlocked in Lock Override Mode Solid green slow blinking red Key unlocked in Read Only Mode Alternating red blue Indicates a mode has been entered that can result in the deletion of a use...

Page 27: ...from forced enrollment state 3 Set self destruct PIN Admin Mode Keys Mode 0 Enter Admin Mode 1 Create User PIN 2 not used 3 Set self destruct PIN Admin or User setup 4 Set minimum PIN length 5 Set bru...

Page 28: ...Page 28 of 31 Keys Mode 7 9 Read only off 7 8 Erase user and self destruct PINs 0 1 Set forced enrollment for user 0 3 Turn on LED flicker when entering PIN from standby 0 4 Turn off LED flicker when...

Page 29: ...t of the USB Backup HSM where all PINs and data will be erased and you will need to reconfigure reformat the USB Backup HSM creating a new Admin PIN which will allow you to reload the previously backe...

Page 30: ...upport l Extremely knowledgeable subject matter experts At Futurex we strive to supply you with the latest data encryption innovations as well as our best in class support services Our Xceptional Supp...

Page 31: ...Boerne Road Bulverde Texas USA 78163 Phone 1 830 980 9782 1 830 438 8782 E mail info futurex com XCEPTIONAL SUPPORT 24x7x365 Toll Free 1 800 251 5112 E mail support futurex com SOLUTIONS ARCHITECT E...

Reviews: