Power Management And Tamper Detect; Fastmap Processor; Flash; Sram - Avaya VPN Gateway User Manual

Vpn gateway
Table of Contents

Advertisement

7.2 Power Management and Tamper Detect

This component monitors battery voltage and the security envelope to detect conditions that
will result in the zeroization of critical security parameters. Battery voltage is also monitored to
determine when it is necessary to replace the battery.

7.3 FastMap Processor

This component contains a processor and internal SRAM. The processor executes the
software that initially resides in Flash memory and is eventually loaded into the external SRAM
(external to the FastMap Processor yet still within the cryptographic boundary). The FastMap
Processor also contains large accumulators and a random number generator. The
accumulators are necessary for the acceleration of public key cryptographic operations. The
random number generator generates truly random numbers through a stochastic process. The
output of this random number generator is used only for seeding the FIPS-approved ANSI
X9.17 Appendix C pseudo-random number generator (PRNG). The output of the PRNG is
used for generating 3DES and RSA keys, as well as outputting random numbers requested
through the Generate Random Number service.

7.4 Flash

This component is non-volatile memory. The contents of Flash will maintain its state after PCI
power and Battery power have been removed. The Flash contains the firmware that controls
processing within the HSM. It also contains public keys and other information that are not
considered dangerous if exposed (certificates, public keys, encrypted data, encrypted keys
and hash values used for authentication).

7.5 SRAM

SRAM is Static Random Access Memory. This memory will be used to store plaintext data,
ciphertext data, symmetric keys, asymmetric keys, intermediate values, and firmware after it
has been loaded from Flash.

7.6 Real Time Clock/Battery Powered RAM (RTC/BBRAM)

This component is used to store values that are to be retained when PCI power is removed.
This includes the master key (MK) that can be used to decrypt encrypted private keys and
symmetric keys stored in Flash. The RTC is used to provide input to the key generation process
so that it is consistent with FIPS 140-1 key generation requirements.
User Guide
7.1 Components
April 2013
225

Advertisement

Table of Contents
loading

This manual is also suitable for:

3050-vmAvg 3050-vm3070-vmAvg 3070-vm3090-vmAvg 3090-vm

Table of Contents