Home > Key Management
Introduction


Your X-Wall product is specifically engineered to encrypt/decrypt the entire disk drive bit-by-bit real-time including boot sector and operating system. It does NOT need special device driver support, making it completely independent from all operating systems. Your privacy, confidentiality and valuable information assets on the disk drive are safely guarded via a NIST (National Institute of Standards & Technology) and CSE (Communication Security Establishment) certified DES, TDES (Triple DES) and AES algorithms. Though the chips are engineered to be 100% compatible with all IDE disk drives, there maybe occasions that various system configurations may cause difficulties in installation, which maybe referenced to Q&A for possible problem solving.

Especially noted is that your product comes with a pair of portable Secure KEY (key token) (key token) used for authentication and operation of the X-Wall cryptographic engine. Without the presence of the enclosed key tokens, your computer will NOT be able to boot (if you choose the intended disk drive as the Primary Master); or the data on the disk drive will NOT be seen (if you choose the intended disk drive as the Slave). As the "Secret Key" of the X-Wall real-time cryptographic engine is stored in the key token, it's extremely important that you always maintain one key token accessible while shelf the other to a safe repository. The decryption process relies solely on the Secret Key, which is stored inside the key token. Losing both tokens will make your daily computing life so miserable as the recovery of encrypted data is EXTREMELY hard without the right Secret Key.

ALWAYS SHELF THE OTHER AVAILABLE KEY TOKEN TO A SAFE REPOSITORY!!!

It is natural for you to assume that we at Enova® Technology might have a duplicate of the random database such that recovery of the key token should not be a concern. You would be wrong if you've made such a bold assumption. It is the company policy that we destroy the random database after it is written into the key token. There isn't any duplication of the random database within the company's premise.

IT'S THE COMPANY POLICY THAT WE DESTROY THE RANDOM DATABASE AFTER IT IS WRITTEN INTO THE KEY TOKEN. WE DO NOT KEEP THE DUPLICATES AND NO ONE IN THIS WORLD OTHER THAN YOU HAS THE DUPLICATES.


1. Which stores the "Secret Key" values required for the operational X-Wall cryptographical engine. The Secret Key is a random combination of digitized bit of "0" and "1" in a specified length such as 40, 64, 128 or 192-bit, depending on the X-Wall chip strength..
   
2. Depends on the encryption strength you have chosen, a DES 40-bit encryption maybe a bit easier to decrypt. A DES 64-bit encryption is extremely hard to decrypt and the process will consume lots of time and money. The decryption of TDES 128 and/or 192-bit without the right Secret Key is physically impossible.
   
3. It is used to write the formatted Secret Key value to every key token.
 
Services for distribution/channel/corporate partners

Lost Keys?

So what will happen if you or your customers lose all available key tokens? Try our new Hawk-IIc Key Management Platform to generate, duplicate, recover and distribute key tokens. The Hawk-IIc Key Management Platform is specifically engineered to facilitate flexible key management. Through its light weight, compact form factor design and economic price tag, the service of key token can be easily managed. To obtain a copy of user's guide of Hawk-IIc Key Management Platform please contact your authorized Enova® Technology representatives.

 
About Hawk-IIc hardware programmer unit
The Hawk-IIc hardware programmer unit has two standard Enova® specific key receptacles which allow users to generate, duplicate, and distribute key tokens. It can be working without a host PC connected to it (Stand Alone Mode) or with a host PC (Host Mode) via USB interface. Figure shown below is the Hawk-IIc hardware programmer unit.

Chick here to enlarge

What does the Platform consist of?

The Hawk-IIc Key Management Platform consists of the following critical elements:

1. Software installation CD ROM 1
2. Hawk-IIc hardware programmer unit; 1
3. USB Cable 1
4. Power cord 1
5. This User's Guide 1
6. Enova® specific key token (empty) 10
7. Enova® Random Number Generator Suite 1(optional, please refer to Note 1)
Note 1:
  The Enova® Random Number Generator Suite that contains programs for random key codes generation, formatting, and testing for randomness according to FIPS 140-2 randomness test, can be licensed. Use of this Suite is subject to Enova® Technology's terms and conditions as spelled out in License Agreement for which you may contact Enova® Technology (info@enovatech.com) or authorized distributor for details. Without this Suite, Hawk-IIc hardware programmer unit can only be used to dubplicate and maintain existing key tokens.

Figure below illustrates Hawk-IIc Key Management Platform content.

 

 

Services for manufacturing partners

Manage Your Own Key Distribution
The Enova® Hawk-II Key Management Platform (hereafter as "Platform") is engineered specifically to manage distribution of all X-Wall Secure Keys (key tokens). It is designed to meet OEM mass production requirement regarding key token programming and management. It provides functions such as Read, Blank Check, Program, Verify, and Erase to facilitate X-Wall Secure Key programming and verification process. The Platform consists two main parts: the Enova® Random Number Generator suite and the Hawk-II hardware programmer unit. You may use this Platform to create new keys, duplicate existing keys, erase old keys, and verify keys for error.

For enterprises, Government agencies, and OEM manufacturers that would manage key token distribution, Enova® offers the Platform to facilitate your KEY management process. The User’s Guide maybe downloaded to help your understanding about the Platform.
 
Figure1 Enova® Hawk-II Key management Platform Figure2 Hawk-II Hardware Programming Unit
   
About Hawk-II hardware programmer unit
The Hawk-II hardware programmer unit comes with eight (8) 1394 (firewire)-like ports which are capable of programming up to eight (8) X-Wall Secure Keys at a time for mass production. For instance, you may program all 8 keys with same value (the “8x1” mode) or all 8 keys with different values (the “1x8” mode). More programming modes are available. The Hawk-II hardware programmer unit can be operated independently or connected to a host PC through standard parallel port.

The Hawk-II Key Management Platform consists of the following critical
  elements:
- Hawk-II Hardware Programming Unit x 1 set
- Enova® Random Number Generator Suite x 1 set (included in the CD-ROM)
- Application software CD ROM x 1 set
- USB Cable x 1 set
-

Power cord x 1 set

- User's Guide x 1 set

 
How to acquire the Hawk-II Key Management Platform?
Enova® Technology offers interested parties three years license to operate the Platform. To obtain the details of license agreement, please contact your authorized Enova® Technology representatives or send inquiry to info@enovatech.com.

Don't like the Secure Key?

We understand you might have preference over using other authentication devices for authentication. Attempt to replace the external key token is possible with some level of system engineering efforts. Please note, the current X-Wall SE/LX version has a hardwired interface which communicates directly to the external key token upon boot up. One can easily emulate the interface (protocol) such that BIOS PIN/Password and/or any other third party authentication device makers such as Smartcard or Fingerprint can function with X-Wall SE/LX to replace the external key token. Please contact us for an in depth engineering architecture.

 
 


Copyright © 2008 Enova® Technology Corporation. All Rights Reserved.

Chick here to enlarge