Secure Session Encryptor (SSE) |
Secure Session Encryptor (SSE)Hardware AES Encryption over Network or Dial-UpSecure Session Encryptor (SSE) is a USB based hardware encryption device that allows Triple AES communication over IP networks or dial-up connections to remote CDI devices in the field. The SSE can be installed at NOC sites or can be portable with laptop computers. The device requires CDI's Secure Session Terminal (SST) software client to enable the SSE to function. The SST software is included in the purchase of an SSE. The SSE is managed by CDI's DDM manager. |
The problem with Secure Shell (SSH)
SSH is a popular “freeware” protocol meant to replace clear text Telnet by adding encryption. The problem is many implementations of SSH have a variety of security vulnerabilities which are reported frequently on security websites. As each vulnerablitiy is patched, others appear. This is compounded by the fact that anyone who has access to the internet can download an SSH client from hundreds of sites that offer them for free. SSH is software based. SSH provides no authentication and carries no government sanctions or credibility.
The Solution- Secure Session Encryptor-SSE
SSE is a hardware based AES/3DES encryptor that attaches to the USB port on any workstation or laptop. With a CDI proprietary client installed (SST), the SSE encryptor can encrypt/decrypt all communications data on a connected PC. Each encryptor has a unique ID along with a 128 bit
encryption key and utilizes AES/3DES encryption. The device has tamper switches which zero all sensitive data in the event the device is opened. The SSE will generate a unique session key for each session established with a remote device. The device is USB powered so no power adapter is required.
Security Management
DDM, Distributed Database Manager , can manage an unlimited number of SSE’s remotely as well as all other CDI products from a single workstation. This eliminates the need to update each unit individually when there is a database change. Audit trail reports are extracted automatically.
Deployment
The SSE is a portable device that can be used from remote laptops or fixed workstations on a network. The device can be keyed remotely by a DDM manager.
| SSE |
|
| Length | 3.5 Inches (8.9 CM) |
| Width | 2.7 Inches (6.9 CM) |
| Height | 1.1 Inches (2.8 CM) |
| Weight | 6.0 Ounces (180 Grams) |
| Power | USB powered 100ma |
| Misc | NIST AES TDES, FCC PART 15, CE |
| POWER | Indicates power from the USB cable |
| TX | Indicates SSE is sending data to computer |
| RX | Indicates the SSE has established a Secure Session and is in encrypted mode |
| SEC | Indicates the SSE has established a Secure Session and is in encrypted mode |
| ALM | Indicates an Alarm condition has occurred (No Key loaded!). |

Secure Session Terminal
Secure Session Terminal is an MS/Windows based client software that works in conjunction with the SSE encryptor to provide encrypted Telnet and dial-up to remote CDI devices. The SST itself contains no security. All the security is contained and performed in the hardware SSE. The SST will work in clear text mode by itself without an SSE connection. The SST prompts the user to enter IP addresses or phone numbers for remote connections. Communication ports and other parameters are also configurable. The SST communicates with the SSE via a USB connection.
Secure Session Encryptor Indicators
| POWER | Indicates power from the USB cable |
| TX | Indicates SSE is sending data to computer |
| RX | Indicates SSE is receiving data from the computer |
| SEC | Indicates the SSE has established a Secure Session and is in encrypted mode |
| ALM | Indicates an Alarm condition has occurred (No Key loaded!). |
See the Cable/Adapter Specifications Guide.