USER GUIDE |
USB BACKUP HSM
Page
13
of 31
[6] SPECIAL MODES
[6.1] ONE-TIME-USE RECOVERY PINS
The Admin has the ability to set Recovery PINs that will allow a User to access data on the USB Backup HSM in
the event of a forgotten PIN by creating a new state of User Forced Enrollment in which a new User PIN can be
established without wiping any data off of the drive. The Admin can establish up to four single-use Recovery
PINs; once a Recovery PIN has been used to access the USB Backup HSM, it will no longer be available for
future recovery efforts.
NOTE: The Recovery PIN will not unlock the device, but will place the USB Backup HSM into a User Forced
Enrollment state, where the User can then establish a new User PIN which will then grant access the Key’s
data.
Setting Recovery PINs
1. Enter the Admin mode. (Hold
+ 0 for five seconds. With the
red
LED blinking, enter the Admin PIN
and press the
button.) The
blue
LED will now glow solidly.
2. Press the
+ 8 buttons together. The
green
LED will blink three times by itself, and then will be joined
by a solid
blue
LED.
3. Enter the Recovery PIN and press the
button. If the PIN is accepted, the
green
LED will blink three
times.
4. Repeat by entering that same Recovery PIN and pressing the
button again. If PIN is accepted for the
final time, the
green
LED will blink three times and the USB Backup HSM will then return to the Admin
mode indicated by a solid
blue
LED.
5. To add more Recovery PINs, repeat steps 2-4. When finished, press the
button to return device to its
standby mode.
Using a Recovery PIN
Deploying a Recovery PIN will put the USB Backup HSM into a state of User Forced Enrollment and that
recovery PIN will no longer be useable. Additionally, once in a state of User Forced Enrollment, the previous
User PIN will no longer be recognized as a valid PIN for drive authentication and a new User PIN must be
created.
1. With the USB Backup HSM in Standby mode, press and hold the
+ 7 buttons together for five seconds
and release once the
red
LED starts blinking.
2. Enter a recovery PIN (from Admin) and press the
button. The
green
LED will blink three times by
itself, and then will be joined by a solid
blue
LED indicating the device is in User Forced Enrollment
mode.
3. Enter a new User PIN and press the
button. The
green
LED will blink three times if accepted.
4. Re-enter that same new User PIN and press the
button again to verify it. If accepted, the
green
LED
will blink three times and then the USB Backup HSM will return to its Standby state, indicated by the
red
LED glowing steadily. The USB Backup HSM will now be accessible using this new User PIN.