Features of the
AEP Keyper Professional include:
| |
 |
Built on ACCE
technology |
| |
 |
Scalable, modular, flexible resilient enhanced security
product |
| |
|
Network connected /available device |
| |
|
Highly tamper resistant incorporating physical and
environmental security mechanisms to Actively Zeroise (erase) key
material and configuration data |
| |
|
Ultimate assurance - FIPS 140-1 level 4 / ITSEC E3 |
| |
|
On host PKCS#11 v2.01 and Microsoft Crypto
API (RSA Full Provider) interfaces |
| |
|
Hardware support for 3-DES, DES, RSA, DSA,
Diffie Hellman and other algorithms |
| |
|
Secure software / algorithm download at
customer site |
| |
|
Small footprint allows desktop use and
19" rack-mounting |
| |
|
Integrated smart card reader |
| |
|
Integrated keypad |
| |
|
Integrated display |
| |
|
Remote management |
| |
|
Very cost effective |
| |
|
10/100 Mbps Ethernet interface |
| |
|
TCP/IP communication |
| |
|
OEM options available |
Choice of Host Interfaces
AEP Keyper Professional can be connected to
a range of systems and applications through two interfaces:
| |
 |
PKCS#11 v2.01 |
| |
 |
Microsoft CryptoAPI - RSA Full Provider Cryptographic
Service Provider (CSP) |
Any PKI application and cryptographic toolkit can communicate with
AEP Keyper Professional via PKCS#11 whereas the Microsoft Certificate
Services can communicate via the AEP RSA Full Provider CSP.
Fully Integrated Design
A key benefit of AEP Keyper Professional is its fully integrated design
incorporating all security, access control and backup components in
a single device.
AEP Keyper Professional offers:
| |
 |
A keypad for PIN and key entry. |
| |
 |
A smart card reader for access control and key backup.
|
| |
|
A physical key switch for control to the
front panel services. |
| |
|
A Liquid Crystal Display (LCD) for menu
traversing. |
| |
|
Multiple Light Emitting Diodes (LEDs) for
network communications and tamper/power functions. |
| |
|
A serial (RS232) connection for audit extraction.
|
| |
|
A 10/100 Mbps Ethernet interface for communications
with host services and applications. |
Increased Performance
AEP Keyper Professional is capable of performing over 160 1024 bit
RSA signs per second, or 350 1024 bit RSA verifies. Whether a single
or multiple modules are connected to a host, the performance required
can be doubled, trebled, quadrupled or more. By processing crypto operations
in a dedicated hardware module the server is relieved of CPU intensive
operations. This can often result in reducing the number of servers
required to support systems where large numbers transactions are being
processed.
Secure Updates
AEP Keyper Professional can be securely upgraded with new firmware
or algorithms using a simple utility supplied with each unit. Users
can realize the benefit of functionality and crypto enhancements by
simply downloading new software to the device.
Secure Application and Key Store
Unlike a number of solutions on the market, AEP Keyper Professional
generates, stores and manages key and application material in an area
protected for physical, electrical and environmental attack, as specified
by the FIPS 140-1 standard. AEP Keyper Professional has an internal
secure key store, which can hold a maximum of one of the following:
| |
 |
2000 512 bit RSA keys |
| |
 |
1000 1024 bit RSA keys |
| |
|
500 2048 bit RSA Keys |
Network Independence
AEP Keyper Professional has an Ethernet connection making it completely
independent of server platform and can be used with different operating
systems without requiring individual modules for each platform or application
server.
Scalability, Flexibility and Fault Tolerance
AEP Keyper Professional, when used with AEP Load Balancer, provides
a highly scalable and fault tolerant solution. Being Ethernet connected
it operates in the same way as any other network resource and therefore
can be shared with multiple servers and applications.

If one host application fails, AEP Keyper Professional will continue
to offer services to the other applications on that host and other hosts
without requiring a restart of the Keyper service.
AEP Keyper's Ethernet connection enables system architectures to be
defined based on the users requirements rather than based on the performance
required by the system - issues often found when factoring a PCI or
SCSI solution.
Load Balancing
Where increased performance or fault tolerance is required, AEP Load
Balancer (software) can be used to share multiple modules with single
or multiple servers. The Load Balancer enables all or defined sets of
modules to be shared from a server and has the added flexibility of
being configurable, thereby enabling all servers to communicate with
all AEP Keyper Professionals on the private network. Maximum performance
can be available to all hosts, or can be individually configured to
assign specific modules to specific hosts, therefore maximising performance
available to high performing hosts.
OEM Option
For a personalized look and feel, OEM users have the option to customize
AEP Keyper Professional to complement their product, system, service
or corporate branding. This option is only available on request and
is generally reserved for high volume users.
|