R&S FPS Signal and Spectrum Analyzer Instrument Security Procedures



Similar documents
R&S FSWP Phase Noise Analyzer Instrument Security Procedures

R&S FSVA/FSV Signal and Spectrum Analyzer Instrument Security Procedures

R&S ESW EMI Test Receiver Instrument Security Procedures

Resolving Security Issues When Working with the R&S FSUP in Secure Areas

R&S RTO Digital Oscilloscope Resolving Security Issues When Working in Secure Areas

Contents. 1 Overview. R&S FSQ - Instrument Security

Resolving Security Issues When Working with the R&S ESU in Secure Areas

Resolving Security Issues when working with R&S UPV, R&S UPV66, R&S UPP200, R&S UPP400, R&S UPP800 in Secure Areas

USB Write Protection Utility

Firmware Release 4.42 SP2 (XP)

Release Notes. R&S ZVH4/ZVH8 Cable and Antenna Analyzer

Remote Monitoring and Control of the R&S RTO with a Web Browser Application Note

A+ Guide to Managing and Maintaining Your PC, 7e. Chapter 1 Introducing Hardware

Software Utility VNA Frequency Converter Leveling Tool Getting Started

Rohde & Schwarz Service that adds value

BIOS and CMOS. Overview. The Function of BIOS. The Bus

Agilent Technologies Truevolt Series Digital Multimeters

Surf it Easy. User Guide

USB. 16MB~2GB JetFlash. User s Manual

Remote Monitoring and Control of the R&S FSL with a Web Browser

Remote Monitoring and Control of the R&S FSV with a Web Browser

Broadcast Drive Test Software

ConnectKey 2.0 WorkCentre 6655i 6655

1. Introduction... 3 Introduction Deal command... 13

Using R&S NRP-Z Power Sensors with Android TM Handheld Devices. Application Note. Products:

Carry it Easy +Plus Bio. User Guide

Operating instructions TSE Wireless Software Home

SSD Firmware Update Utility Guide

Guide to SATA Hard Disks Installation and RAID Configuration

CSCA0201 FUNDAMENTALS OF COMPUTING. Chapter 5 Storage Devices

R&S RNMS3000 Radio Network Management System Utilization planning, radio network configuration and data distribution

Quick start to evaluating HP Windows Embedded Standard 2009 Thin Clients. HP t5630w, HP t5730w, HP t5740, HP gt7720

Carry it Easy. User Guide

Huawei E169 & E220 Status Lights

Avira System Speedup. HowTo

Computer Setup User Guide

R&S AFQ100A, R&S AFQ100B I/Q Modulation Generator Supplement

Keep it Simple Timing

and Measurement Software

USB FLASH DRIVE. User s Manual. USB 2.0 Compliant. Version A Version A10

R&S IP-GATE IP gateway for R&S MKS9680 encryption devices

Instrument Software Update Instructions

R&S VISA Release Notes Software Version 5.5.4

Updating to Windows 8.1

Windows 7 XP Mode for HP Business PCs

Intel Matrix Storage Manager 8.x

Using AORUS Notebook for the First Time

Laptop Recorder OPERATION GUIDE. Laptop Serial Number (System ID): Original Seneca Data Order Number: SoniClear Order Number:

Combi B PC software 8213X. Installation and operating instructions

R&S FS-K130PC Distortion Analysis Software Specifications

Fastboot Techniques for x86 Architectures. Marcus Bortel Field Application Engineer QNX Software Systems

1 Safety instructions. 2 Device components. Facility Pilot Server. Art. No. : FAPV-SERVER-REG Art. No. : FAPVSERVERREGGB. Operating instructions

3.5 EXTERNAL NETWORK HDD. User s Manual

Sprint 3G/4G Plug-in-Connect USB Web Browser Interface User Guide

Computer Components Study Guide. The Case or System Box

HP VMware ESXi 5.0 and Updates Getting Started Guide

RF and Microwave Accessories. CD-ROM Catalog. Find the right component for your Rohde & Schwarz test & measurement equipment

R&S NRPV Virtual Power Meter Release Notes Application Version 1.8.0

Measurements on DVB-S2 Transmitters

Intel Rapid Start Technology (FFS) Guide

Taurus - RAID. Dual-Bay Storage Enclosure for 3.5 Serial ATA Hard Drives. User Manual

ICS Technology. PADS Viewer Manual. ICS Technology Inc PO Box 4063 Middletown, NJ

Intel architecture. Platform Basics. White Paper Todd Langley Systems Engineer/ Architect Intel Corporation. September 2010

Common Operating-System Components

Network analyzer and spectrum analyzer two in one

Chapter 4 System Unit Components. Discovering Computers Your Interactive Guide to the Digital World

IPMI Firmware Update (AMI) In WEB-GUI/DOS/WIN/Linux

Transfer of Trace Data From R&S Network Analyzer ZVx To Microsoft Excel

FTP Automation Guide

PCI SATA Controller Card Model: SY-PCI40010

is605 Dual-Bay Storage Enclosure for 3.5 Serial ATA Hard Drives FW400 + FW800 + USB2.0 Combo External RAID 0, 1 Subsystem User Manual

This section will focus on basic operation of the interface including pan/tilt, video, audio, etc.

Installation and Operation Back-UPS 1250, 1300, 1500

Shearwater Research Dive Computer Software Manual

Only smart people read the manual.

GEIGER COUNTER "Gamma Check Pro"

JUSTOP Smart TV Player With Android 4.0. User Manual

User Manual. 2 ) PNY Flash drive 2.0 Series Specification Page 3

Anti-Virus Scan Tool

Weather Direct Displays show Lost Forecast (blank boxes in the picture icons)

PRORAE REMOTE HOST CONTROLLER: COMMUNICATION TROUBLESHOOTING GUIDE

Discovering Computers Living in a Digital World

Quick Start Guide Vodafone Mobile Broadband USB Stick. Designed for Vodafone

Quick Start to Evaluating. HP t5630w, HP t5730w, HP gt7720

PowerProtector: Superior Data Protection for NAND Flash

R&S IP-GATE IP gateway for ISDN encryption devices

PLEASE TAKE GOOD CARE OF THIS DVD, we are under no obligation and in some cases unable to provide replacement copies of this Restore DVD.

MEDMONT STUDIO 5 BASE REQUIRMENTS

Chapter 2 Array Configuration [SATA Setup Utility] This chapter explains array configurations using this array controller.

CYAN SECURE WEB APPLIANCE. User interface manual

HP Z220, Z420, Z620, and Z820 Workstations Microsoft Windows XP Installation Reference Guide

Gotcha! Catch every moment. Find thousands more great ideas online

USER MANUAL. FLASH DUPLICATOR CopyKing II CPY220

SYMBOL MC9060 HAND HELD TERMINAL USER MANUAL

PU-USBX. USB over Ethernet Extender OPERATION MANUAL

FLASH USB Introduction ENGLISH

PCI-to-SATA RAID Adapter AEC-6890M. User s Manual Version:1.0

Transcription:

Signal and Spectrum Analyzer Instrument Security Procedures Resolving security issues when working in secure areas Based upon the user s security requirements, this document describes the Rohde & Schwarz options available to address the user s signal and spectrum analyzer needs. It also covers the different memory types and locations where user information can be stored in the R&S FPS. For secure environments, it describes an approach to physically remove the user data from the R&S FPS. (;Úèë2) 1176.9093.02 02 Test & Measurement Instrument Security Procedures

This document describes all R&S FPS models. 2015 Rohde & Schwarz GmbH & Co. KG Mühldorfstr. 15, 81671 München, Germany Phone: +49 89 41 29-0 Fax: +49 89 41 29 12 164 E-mail: info@rohde-schwarz.com Internet: www.rohde-schwarz.com Subject to change Data without tolerance limits is not binding. R&S is a registered trademark of Rohde & Schwarz GmbH & Co. KG. Trade names are trademarks of the owners. The following abbreviations are used throughout this manual: R&S FPS is abbreviated as R&S FPS.

Contents Contents 1 Overview... 3 2 Battery Information...3 3 Types of Memory and their Security Concerns...4 4 Information Storage within the R&S FPS...5 5 Information Security in Highly Sensitive Areas... 5 6 Performing Service, Calibration and Maintenance on the R&S FPS... 6 7 Performing Firmware Updates and Backing-Up User Data in Sensitive Areas...7 8 Special Considerations for USB Ports...8 1 Overview In many cases it is imperative that the R&S FPS be used in a secured environment. Generally these highly secured environments will not allow any test equipment to leave the area unless it can be proven that no user information will leave with the test equipment. Security concerns can arise when test equipment needs to leave a secured area to be calibrated or serviced. This document describes the types of memory and their usage in the R&S FPS. It also addresses methods of ensuring that no user data will leave the secured area should the product be removed for calibration or service needs. 2 Battery Information There are no batteries in the R&S FPS other than the one on the CPU board used to power the clock in the chipset. 3

Types of Memory and their Security Concerns 3 Types of Memory and their Security Concerns SDRAM The R&S FPS has 16 GByte of SDRAM on the CPU board. In addition, the R&S FPS is equipped with 2 GByte of SDRAM/DDR3 on the detector board. SDRAM is volatile memory and it loses its memory as soon as power is removed. The SDRAM will be unreadable within one minute after the power is removed from the instrument. The SDRAM is not a security concern. EEPROM Each board assembly in the R&S FPS has one serial EEPROM device. These devices hold up to 1 MByte and contain information related to the installed hardware, such as board serial number, options, correction constants, etc. The EEPROM does not hold user data nor can the user access the EEPROM storage. The EEPROM is not a security concern. FLASH The CPU board of the R&S FPS has a 8 MByte flash memory device which contains the BIOS. The FLASH memory device does not hold user data nor can the user access the flash memory. The FLASH memory is not a security concern. Removable Solid-State Drive The R&S FPS is equipped with a removable solid-state (flash) drive. The solid-state drive is used to store:: Instrument operating system (Windows 7, 64 bit) Instrument firmware and firmware options (measurement personalities) with option license keys Instrument states and setups Trace data Limit lines, transducer tables Screen images The solid-state drive content is non-volatile, so nothing is lost when power is removed from the instrument. Furthermore, an optional Secure User Mode (R&S FPS-K33) is available, in which the instrument's solid-state drive is write-protected. Thus, no user data can be written to the solid state drive permanently (see also "Secure user Mode (R&S FPS-K33)" on page 5). The hard drive is not a security concern because it can be physically removed from the instrument and left in the secure area. 4

Information Storage within the R&S FPS 4 Information Storage within the R&S FPS Data SDRAM Not a security concern EEPROM Not a security concern FLASH Not a security concern Removable solid-state drive Not a security concern Temporary information storage for CPU operation (CPU cache and swap area) Hardware info, serial number, product options and calibration correction constants X X X BIOS X Operating system and instrument firmware Instrument states, setups, limit lines and transducer tables Trace data, measurement results and screen images (X)* (X)* X X X *) only if optional Secure User Mode (K33) is active 5 Information Security in Highly Sensitive Areas Since the SDRAM is erased when power is removed from the R&S FPS it does not pose a security risk. No user data is written to the EEPROM and FLASH memories; hence, it is deemed that they do not pose a risk either. The Removable solid-state drive is the only device that does not lose its memory when power is removed and can contain user data. It can be removed from the R&S FPS, leaving the customer assured that no user data is stored within the R&S FPS. Secure user Mode (R&S FPS-K33) If it is not possible to remove the solid-state drive and store it securely, or if users must not obtain knowledge of other user's data, an optional Secure User Mode (R&S FPS- K33) is available. In secure user mode the instrument s solid-state drive is write-protected so that no information can be written to memory permanently. Data that the R&S FPS normally stores on the solid-state drive is redirected to volatile memory instead, which remains available only until the instrument is switched off. 5

Performing Service, Calibration and Maintenance on the R&S FPS Data that is stored in volatile memory can be accessed by the user just as in normal operation; however, when the instrument s power is removed, all data in this memory is cleared. Thus, in secure user mode, the instrument always starts in a defined, fixed state when switched on. The R&S FPS equipped with the REMOVABLE SOLID-STATE DRIVE address the needs of customers working in highly sensitive areas. 6 Performing Service, Calibration and Maintenance on the R&S FPS R&S FPS equipped with the removable solid-state drive Before performing service, calibration, or maintenance tasks on the R&S FPS, remove the classified solid-state drive (with the user data). This can be done without opening the instrument. To remove the solid-state drive IMPORTANT - SHOCK HAZARD: Switch off the instrument and disconnect the power plug before removing the solid-state drive! Unscrew the two knurled screws and remove the solid-state drive at the front of the device. This removes all user data from the R&S FPS. The R&S FPS, without the removable solid-state drive, can now leave the secured area. Once the R&S FPS is outside the secured area, installing a second non-classified removable solid-state drive (without any user data), allows the R&S FPS to function properly for service or other needs. Prior to re-entering the secured area, remove the non-classified removable solid-state drive (without the user data). When the R&S FPS is back within the secured area, the original classified removable solid-state drive can be reinstalled. To hold classified user data in the secure areas, use the REMOVABLE solid-state drive which comes with the instrument. To hold non-classified user data in the non-secure areas, use a second REMOV- ABLE solid-state drive (Option R&S FPS-B18). 6

Performing Firmware Updates and Backing-Up User Data in Sensitive Areas Validity of the Instrument s Calibration After Exchanging the Removable Hard Disk The calibration ensures the user that their measurements are traceable to a government standard. Rohde & Schwarz highly recommends that users follow the calibration cycle suggested for their instrument. The EEPROM is the only memory type used to hold permanent adjustment values required to maintain the validity of the R&S FPS's calibration. Hence, replacing one removable solid-state drive with another does not affect the validity of the instrument s calibration. After exchanging the removable solid-state drive, perform a self-alignment once, by doing one of the following: Using the R&S FPS mini display, select "System Commands > Selfalign". Using a remote desktop connection to the R&S FPS, select "Setup > Alignment > Start Self Alignment". This function uses the high-stability internal reference generator to produce the temporary adjustment values. Using the permanent and temporary values, the necessary adjustment information is then stored on the removable solid-state drive. Rohde & Schwarz recommends that users perform the self-alignment function on a weekly basis after the R&S FPS has had sufficient time to warm-up. 7 Performing Firmware Updates and Backing- Up User Data in Sensitive Areas Rohde & Schwarz highly recommends, but does not require, the users of its products to maintain their products with the latest updates and to regularly backup important user data that can be erased. Firmware updates are available from the Rohde & Schwarz website. How does a user perform firmware updates and backup user data in sensitive areas? There are several options available for the user to safely perform these operations without compromising the security of the sensitive areas. Secure User Mode If Secure User Mode is activated (see "Secure user Mode (R&S FPS-K33)" on page 5), firmware updates cannot be performed. In this case, deactivate the secure user mode for the duration of the update. Via the USB port The R&S FPS is equipped with USB ports as standard equipment. The instrument firmware update can be performed directly from the USB stick. The USB stick can likewise hold or transport user data back-ups to an approved storage medium. As described in Special Considerations for USB Ports, users can disable the capability of the 7

Special Considerations for USB Ports USB ports to save data (set to "read only"). For users that have not elected to disable the USB ports for writing data, a memory stick can be used to backup user data. Via the LAN interface The R&S FPS is equipped with a LAN interface as standard equipment. A user can transport the firmware update into the secure area via a CD or another medium that meets the security requirements. The update can then be placed on a system on the LAN within the secure area. The R&S FPS can be updated directly from the LAN. The LAN can likewise be used to backup user data to an approved storage medium. 8 Special Considerations for USB Ports USB ports can pose a security threat in high-security locations. Generally, this threat comes from small USB pen drives (also known as memory sticks, key drives, etc.) which can be very easily concealed, yet can quickly read or write several GBytes of data. Disable USB Ports for Writing User Data The R&S FPS can be updated with a utility to disable the write capability on any USB port for storage devices. This utility is available from the R&S FPS product web site without any charge. To disable the write capability copy the utility software to the R&S FPS and run it once. After reboot of the instrument the write capability on any USB memory device is disabled. 8