English
56
Detailed description of the above-named steps is outlined in relevant chapters of this
manual.
The information about the type, version and serial number of the hard drive are located
on the back of each HS256 S3. Because the hard drive is not updatable, this information
is sufficient for determining the version of the delivered HS256 S3.
The DIGITTRADE HS256 S3 ensures the safety of the data through the following security
mechanisms:
- Encryption
- User authentication
- Administration of the cryptographic keys
1.1 Encryption
- 256 bit AES full disk hardware encryption in XTS mode
The encryption module inside the secure casing encrypts the hard drive/SSD completely.
Every saved byte and every written sector on the hard drive/SSD are encrypted according
to 256 bit AES (Advanced Encryption Standard) in XTS mode with
two 256 bit cryptographic keys.
The DIGITTRADE HS256 S3 encrypts additionally to all stored data temporary files as
well as areas that would normally be unnoticed by encryption software.
10110101010101009F75B162580DAC9F
AES key
plain text cipher text
1.2 User authentication
- 2-factor authentication using smart card and PIN
The user authentication is based on the principal “having and knowing”.
To get an access to the data the user must have the smart card and need to know the
correct 8-digit PIN.
If the 8-digit PIN was entered incorrectly 8 times, the smart card is disabled and no
longer usable. The cryptographic keys is also irreversibly deleted.