Your suggested change has been received. Thank you.

close

Suggest A Change

https://thales.na.market.dpondemand.io/docs/dpod/services/kmo….

back

Install Physical CipherTrust Manager Appliance

Hardware Specifications

search

Please Note:

Hardware Specifications

Available Models

  • k470 - no HSM, 4x1Gbit ports

  • k470 - no HSM, 2x1Gbit ports and 2x10Gbit ports

  • k570 - HSM, 4x1Gbit ports

  • k570 - HSM, 2x1Gbit ports and 2x10Gbit ports

  • k160 - HSM

Specifications for k470 and k570

The base chassis for k470 and k570 are the same, and so the specifications are presented together. However, the k570 includes a PCIe HSM and the k470 does not.

The CipherTrust Manager k470 and k570 Appliances are 1U high and fit into standard 19-inch equipment racks.

Appliances

Hardware Specifications for k470 and k570

Hardware SpecificationValue
Dimensions19.0"(W) x 21"(D) x 1.75"(H)
Weight12.7 kg(28lbs)
Memory16 GB
Hard Disk and Protections1 X 2TB SATA SE (Spinning Disk)
Serial Port1
CPU1 CPU with 4 cores
Ethernet / NICs4 X 1 GB
2 X 10 GB
2 X 1 GB
IMPINot Available
Power Supplies2 Power Supplies; Average Power (Watts) 0.7A @120V 84W
Maximum Power (Watts) 100-240V 50-60Hz
Voltage: 100W
Power Cord PSE Certified
Available for multiple country profiles for power consumption
Chassis Intrusion Detectionk470 and k570: Tamper seals
Operating Temperature0 to 35°C (32 to 95°F)
Non-Operating Temperature-20 to 60°C (-4 to 140°F)
Safety Agency ApprovalsCB Scheme, CSA-UL, FCC Part 15, Subpart B, Class B, EN55032:2010, EN55024:2010, EN61000-3-2:2006 +A1:2009 +A2:2009, EN61000-3-3:2008 ICES-003 Issue 4 February 2004, C-Tick, AS/NZS CISPR 22:2009, VCCI V-3/2009.04, KN22, KN24, BIS (in progress)
FIPS 140-2 CertificationsLevel 3 with HSM as root of trust
Embedded HSM AdministrationK570 (Built in HSM) , Management Console and REST API allow configuration to HSM

Firmware Specifications for k470 and k570

Firmware SpecificationValue
Administrative InterfacesManagement Console
Max Keysk470, k570, k470v: 1,000,000
k170v: 25,000
Max Domains1000
API SupportREST, NAE-XML, KMIP, PKCS#11, JCE, .NET, MCCAPI, MS CNG
Security AuthenticationUsername/Password (Local User), AD/LDAP , Certificate based authentication
Cluster SupportClustering is supported between physical and /or virtual appliances for High Availability
BackupManual and Scheduled; Option for HSM key to encrypt CM backup
Network ManagementSNMP v1, v2c, v3 , NTP, Syslog-TCP
Syslog FormatsRFC-5424, CEF, LEEF
Software Certifications and ValidationsFIPS 140-2 L3 with k570; K470 and Virtual CipherTrust Manager can use an External HSM as Root of Trust for Master Key protection

Front Panel for k470 and k570

The front panel is illustrated below, with the secure locking bezel removed:

Front Panel

ItemNameDescription
AFront ear bracketsConnect to the front of the appliance chassis with the provided screws, allowing it to be mounted in a standard 19-inch equipment rack. The extending tabs act as posts for the locking bezel.
BMounts for locking bezelThe secure locking bezel connects to the appliance faceplate here.
CFront-panel displayDisplays basic configuration and status information for the appliance.
DUSB 3.0 portsThese USB ports are not used and are disabled.
EStop/start switchPowers the appliance on or off.
FFan status LEDsThe appliance has three (3) cooling fans. If these lights are illuminated, the fans are working correctly.
GVentilation fan filter coverRemovable cover allows cleaning of air filter.
HFan bay securing screwsTorx screw secures the fan bay.

Opening to swap fan modules triggers a tamper event on the appliance.

Rear Panel for k470 and k570

The rear panel is illustrated below:

Rear panel

ItemNameDescription
ASliding rail bracketsConnect to the sliding rails mounted on the sides of the appliance chassis, allowing it to be mounted in a standard 19-inch appliance rack.
BKensington lock connectorAllows the appliance to be secured to a desk or equipment rack using Kensington lock.
CModels with HSM: HSM card with USB portWhen authenticating with a PED, the PED must be connected directly to the USB port of the HSM card. The other USB ports on the appliance will not work for PED connection.
CModels without HSM: No HSM cardNo HSM card installed - a blank plate is installed.
DUSB 3.0 portsThese USB ports are not used and are disabled.
ERJ45 serial portConnect a terminal to this port using the included RJ45 to USB cable.
FFan status LEDsThe appliance has three (3) cooling fans. If these lights are illuminated, the fans are working correctly.
GDecommission buttonThis button should only be pressed as part of decommissioning and zeroizing the appliance.
HPower supplies2 Power Supplies connect the appliance to power. For proper redundancy and best reliability, the power cables should connect to two completely independent power sources.

Network Interface for 1Gbps k470 and k570 Models

1Gbps models come with four 1 Gbit RJ45 Ethernet network ports (labeled 0, 1, 2, and 3). The network interfaces are mapped to Ethn, as detailed in the following illustration.

Rear Ports 1G

All ports are identical and equally usable and can be bonded in any combination. By default port Eth0 is configured for DHCP but this can be configured.

Refer to Network Configuration Tutorial for more information.

Network Interface Mapping for 1Gbps/10Gbps k470 and k570 Models

10 Gbps models provide two 10Gbps SFP optical Ethernet network ports (labeled 0 and 1) and two 1Gbps copper RJ45 network ports (labeled 2 and 3). The network interfaces are mapped to Ethn, as detailed in the following illustration.

Rear Ports 10G

You can optionally bond the network interfaces Eth0 with Eth1 or Eth2 with Eth3 to form a logical interface, providing a redundant active/standby virtual interface. By default port Eth0 is configured for DHCP but this can be configured.

Refer to Network Configuration Tutorial for more information.

Front Panel LCD for k470 and k570 Models

The Front Panel displays the product name (CipherTrust), the firmware version, and the IP address of any configured network interface.

LCD display

HSM Emergency Decommission Button for k570 models

The CipherTrust Manager k570 Appliance includes a way to decommission the HSM, or permanently deny access to all objects on it, without need for either a serial console or a remote (SSH) connection.

To directly decommission the HSM inside the appliance, press and release the small red button on the rear panel.

  • The appliance does not need to be powered on.

  • The appliance does not need to have power cables connected.

Zeroize button

You will need a small screw-driver or other tool to reach the Emergency Decommission button. This is intentional, to prevent accidental pressing of that button.

What the Emergency Decommission Button Does

When you press the Decommission button, all partitions and their contents are deleted, as well as the audit role, and the audit configuration. The HSM policy settings are retained.

For k570 models, pressing the Decommission button makes all data and keys created on the CipherTrust Manager become permanently unusable, including keys in backups associated to the HSM.

To bring the HSM back into service, you need to:

  1. Reinitialize the HSM.

  2. Reinitialize the audit role and reconfigure auditing.

  3. Recreate the partitions.

  4. Reinitialize the partition roles.

  5. Reset the system kscfg system reset.

  6. Setup the HSM as described in Hardware Security Module.

At this point, you can recreate encryption keys on CipherTrust Manager.

Power Consumption for k470 and k570 Models

When installed and connected to appropriate electrical power sources, CipherTrust Manager k470 or k570 Appliance draws power as follows:

ActivityDraw
Standby (connected to AC electrical mains but not powered on)26W (typical)
Power-on Input Surge15A (typical)
40A at 90-132VAC (max)
60A at 180-265VAC (max)
Active (under load from clients)84W to 90W (typical)
100W to 105W (max)

The appliance has two power supplies, each rated at 350W, either of which is capable of running the system alone.

Hardware Specifications for k160 Model

The TCT CipherTrust Manager k160 Appliance is a compact cryptographic key management platform that protects and manages cryptographic keys and associated policies used to encrypt the most sensitive data-at-rest. This cost-effective solution is ideal for small to medium sized deployments commonly found in small offices, remote sites, and tactical environments. The k160 includes a FIPS 140-2 Level 3 token or a high assurance cryptographic token as its hardware root of trust. The token hardware security module (HSM) operates as a secure root of trust by encrypting all sensitive objects (e.g. keys, certificates, etc.) in CipherTrust Manager, with keys that are generated by, and reside in, the token HSM. The removable token HSM provides and easy to use method to support common key management scenarios such as rapid key delivery disablement, key destruction, cryptographic erase, and time of use restrictions. Simply removing the token allows for keeping mission critical data safe.

k160 model

k160 Technical Specifications

Physical Characteristics

  • CipherTrust k160 Dimensions: 6.5” x 4.0” x 1.5”

  • Weight: 1.2 lbs.

  • Direct mount or 1U 19in. rack mount (optional accessory)

  • Thermal Storage: -30°C ~ 80°C

  • Thermal Operation: -30 ~ 65°C

  • Storage Humidity: 5 ~ 95% @ 40C

  • Operating Humidity: 0% ~ 90% relative humidity

  • Vibration Testing: Random, 1Grm, 5~500Hz

  • Power: included external power supply; locking DC power connector

  • Power Range: input 120-240V AC, 1.5A, 50-60Hz; output 12V DC, 40W

Interfaces

  • Web UI Management

  • Serial and SSH command line

  • KMIP, NAE-XML, and REST API

  • 1G Ethernet interface

  • Integrated Token HSM connection

k160 Front Panel

The front panel is illustrated below, showing the High Assurance token inserted:

k160 front panel

ItemNameDescription
APower On/OffPowers the appliance on or off.
BRound button 1Reserved for future use.
CRound button 2Reserved for future use.
DUSB HSM tokenHigh Assurance Token.

k160 Rear Panel

The rear panel is illustrated below:

k160 rear panel

ItemNameDescription
AConsole PortConnect a terminal to this port using the included DB9 to USB cable.
BDC 12VPower Adapter connection.
CVGAConnect a standard VGA monitor.
DUSB portsDisabled/Not used.
ELANCAT5 Networking Port