Keysight Technologies E5052B Security Features

Page 1
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 1 of 10
E5052B Security Features
Rev. 2.4
Dec 2016
Page 2
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 2 of 10
Contacting Keysight Sales and Service Offices
Assistance with test and measurements needs and information on finding a local Keysight office is available on the internet at, http://www.Keysight.com/find/assist. If you do not have access to the internet, please contact your field engineer.
Note: In any correspondence or telephone conversation, refer to the signal source analyzer by its model number and full serial number. With this information, the Keysight representative can determine whether your unit is still within its warranty period.
Product Declassification and Security
Model Number(s): E5052B Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
This document describes instrument security features and the steps to declassify an instrument through memory sanitization or removal. For additional information please go
to www.keysight.com/find/ad and click on the security instrument tab.
Table of Contents
Terms and Definitions.……………………………………………......3
Instrument Memory………………………………………………...…4
Memory Clearing, Sanitization and/or Removal…………………...…6
User and Remote Interface Security ………...……………….…….…9
Procedure for Declassifying a Faulty Instrument……………..….…...10
Page 3
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 3 of 10
Terms and Definitions
Definitions:
Clearing – Clearing is the process of eradicating the data on media before reusing the media so that the
data can no longer be retrieved using the standard interfaces on the instrument. Clearing is typically used when the instrument is to remain in an environment with an acceptable level of protection.
Sanitization – Sanitization is the process of removing or eradicating stored data so that the data cannot
be recovered using any known technology. Instrument sanitization is typically required when an instrument is moved from a secure to a non-secure environment such as when it is returned to the factory for calibration. (The instrument is declassified) Keysight memory sanitization procedures are designed for customers who need to meet the requirements specified by the US Defense Security Service (DSS). These
requirements are outlined in the “Clearing and Sanitization Matrix” issued by the Cognizant Security Agency
(CSA) and referenced in National Industrial Security Program Operating Manual (NISPOM) DoD 5220.22M ISL 01L-1 section 8-301.
Security Erase – Refers to either the clearing or sanitization features of Keysight instruments.
Instrument declassification – A term that refers to procedures that must be undertaken before an
instrument can be removed from a secure environment such as is the case when the instrument is returned for calibration. Declassification procedures will include memory sanitization and or memory removal. Keysight declassification procedures are designed to meet the requirements specified by the DSS NISPOM security document (DoD 5220.22M chapter 8)
Page 4
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 4 of 10
Instrument Memory
This section contains information on the types of memory available in your instrument. It explains the size of memory, how it is used, its location, volatility, and the sanitization procedure.
Summary of instrument memory - base instrument
Memory Type
and Size
Writab
le During
Normal Operation?
Data Retained When
Powered Off?
Purpose/Contents
Data Input
Method
Location in
Instrument and
Remarks
Sanitization
Procedure
Main Memory (DDR SDRAM DIMM) 1 GB/ 2 GB/ 4 GB
Yes
No
Windows Operating system memory
Operating system (not user)
Digital Mother Board
Cycle power
Media Storage
(Hard Disk Drive) 40 GB/ 320 GB
Yes
Yes
Windows Operating system boot device, factory correction data, and users file including saved traces data, settings, or images.
User-saved data
Removable Hard Disk Drive (HDD)
Remove
Media Storage
(Solid State Drive) 80 GB
Yes
Yes
Windows Operating system boot device, factory correction data, and users file including saved traces data, settings, or images.
User-saved data
Removable Solid State Drive (SSD)
Remove
Memory for PCI and DSP (Static RAM)
2.5MB
Yes
No
Data Processing for measurement
Measureme nt (not user)
PCI DSP Card
Cycle power
Non-volatile memory (Flash EEPROM) 1MB
No
Yes
Firmware for instrument operation
Non-User Modifiable
PCI DSP Card
N/A
Non-volatile memory (Flash EEPROM) 256Mbit
No
Yes
Firmware for instrument operation
Non-User Modifiable
DSP Board
N/A Memory for Data Buffer (Static RAM) 36Mbit
Yes
No
Data Processing for measurement
Measureme nt (not user)
DSP Board
Cycle power
Page 5
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 5 of 10
Memory for Data Buffer (Static RAM) 512MB
Yes
No
Data Processing for measurement
Measureme nt (not user)
DSP Board
Cycle power
DSP Work Memory (Static RAM) 18Mbit
Yes
No
Data Processing for measurement
Measureme nt (not user)
DSP Board
Cycle power
Page 6
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 6 of 10
Memory Clearing, Sanitization and/or Removal Procedures
This section explains how to clear, sanitize, and remove memory from you instrument for all memory that can be written to during normal operation and for which the clearing and sanitization procedure is more than trivial such as rebooting your instrument.
<Memory type>
Description and purpose
Main Memory (DDR SDRAM) for Windows Operating system memory
Size
1. For MY471xxxxx/ SG471xxxxx – 1 GB RAM.
2. For MY472xxxxx/ SG472xxxxx; MY473xxxxx/ SG473xxxxx – 2 GB
RAM.
3. For MY474xxxxx/ SG474xxxxx – 4 GB RAM.
Memory clearing
Power rebooting. This is a volatile memory.
Memory sanitization
Power rebooting. This is a volatile memory.
Memory removal
This memory cannot be removed without damaging the instrument
Write protecting
N/A
Memory validation
N/A
Remarks
Confirmation or setting the BIOS Options: BIOS is the PC's built-in program describing the standard procedure of basic inputs and outputs for the system hardware. BIOS involves the system BIOS, start-up program and BIOS setup utility. The E5052B starts up first with the BIOS when the power is turned on. See the trouble shooting section in the service manual for the procedure to confirm or set the BIOS options, known as the BIOS setup utility.
Name: E5052B Signal Source Analyzer Service Guide
Location: http://www.keysight.com/find/ssa > Product Library > Manuals.
Description and purpose
Media Storage (Removable Hard Disk Drive) for Windows Operating system boot device, factory correction data, and users file including saved traces data, settings, or images.
Size
1. For MY471xxxxx/ SG471xxxxx - 40 GB HDD.
2. For MY472xxxxx/ SG472xxxxx; MY473xxxxx/ SG473xxxxx – 320 GB
HDD.
3. For MY474xxxxx/ SG474xxxxx – 80 GB SSD.
Memory clearing
N/A
Memory sanitization
N/A
Memory removal
Hard disk is set as a removable type.
Write protecting
N/A
Memory validation
N/A
Remarks:
Hard Disk Removal: Because it is virtually impossible to completely and selectively erase all user data on a hard drive without also destroying the operating system, the best method for maintaining security when the E5052B must be removed from a secure area is to replace the hard drive with a "non-secure" hard drive, i.e. a drive that has never had any sensitive data placed on it.
E5052B standard set is delivered with a removable hard disk unit.
Page 7
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 7 of 10
E5052BU-018/ 028/ 058 is the additional hard disk drive/ solid state drive to prepare the second unit for E5052B removable hard disk user.
For E5052B with SN: MY471xxxxx, SG471xxxxx; MY472xxxxx, SG472xxxxx; MY473xxxxx, SG473xxxxx; E5052BU-018/ 028 is discontinued. The E5052B unit needs to be upgraded with E5052BU-040 Digital hardware module upgrade kit by Keysight service center. The upgrade kit contains one removable SSD by default. If additional spare disk is required, procure E5052BU-058 Solid state drive kit.
For E5052B with SN: MY474xxxxx, SG474xxxxx; A spare disk is available as E5052BU-058.
E5052B Hardware, Software & Firmware Upgrades:
http://www.keysight.com/main/editorial.jspx?cc=MY&lc=eng&ckey=2082886&nid=-
35185.631410.00&id=2082886&cmpid=zzfinde5052b_upgrades
Removal Procedure:
http://ena.support.keysight.com/e5052b/manuals/webhelp/eng/product_information/maintenance/removing_mountin g_removable_hard_disk.htm
Description and purpose
Memory for PCI and DSP (Static RAM)
Size
2.5 MB Memory clearing
Power rebooting. This is a volatile memory.
Memory sanitization
Power rebooting. This is a volatile memory.
Memory removal
This memory cannot be removed without damaging the instrument
Write protecting
N/A
Memory validation
N/A
Remarks
Description and purpose
Non-volatile memory (Flash EEPROM) for Firmware for instrument operation
Size
1 MB
Memory clearing
Adjustment program performed by Keysight factory personnel or by calibration labs only.
Memory sanitization
Adjustment program performed by Keysight factory personnel or by calibration labs only.
Memory removal
This memory cannot be removed without damaging the instrument Write protecting
N/A
Memory validation
N/A
Remarks
The data is not stored by user under normal operation.
Page 8
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 8 of 10
Description and purpose
Non-volatile memory (Flash EEPROM) for Firmware for instrument operation
Size
256 Mbit
Memory clearing
N/A
Memory sanitization
N/A
Memory removal
This memory cannot be removed without damaging the instrument Write protecting
N/A
Memory validation
N/A
Remarks
The data is not stored by user under normal operation.
Description and purpose
Memory for Data Buffer while Data processing
Size
36 Mbit Memory clearing
Power rebooting. This is a volatile memory.
Memory sanitization
Power rebooting. This is a volatile memory.
Memory removal
This memory cannot be removed without damaging the instrument
Write protecting
N/A
Memory validation
N/A
Remarks
Description and purpose
Memory for Data Buffer while Data processing
Size
512 MB Memory clearing
Power rebooting. This is a volatile memory.
Memory sanitization
Power rebooting. This is a volatile memory.
Memory removal
This memory cannot be removed without damaging the instrument
Write protecting
N/A
Memory validation
N/A
Remarks
Description and purpose
DSP Work Memory
Size
18 Mbit Memory clearing
Power rebooting. This is a volatile memory.
Memory sanitization
Power rebooting. This is a volatile memory.
Memory removal
This memory cannot be removed without damaging the instrument
Write protecting
N/A
Memory validation
N/A
Remarks
Page 9
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 9 of 10
User and Remote Interface Security Measures
Screen and Annotation Blanking
You can prevent frequency information from appearing on the E5052B screen and printouts. To set security levels from the E5052B menu, go to Display, then Security Level. When the security level is set to Frequency Blank or All Numeric Blank, the following information is blanked.
Display annotation All marker readouts All tables All soft key menus All printouts Programming via GPIB or VBA
The frequency blank operation is supported on firmware revision A.02.00 or higher. The latest firmware can be downloaded from:
http://www.keysight.com/find/ssa > Technical Support >Software Downloads & Utilities
USB Mass Storage Device Security
The following procedure shows how to disable a USB Mass Storage Device.
1. [Save/Recall] > Explorer….
2. Double-click “DisableUsbStorage.exe” from D”\Agilent\Service.
3. Click OK in the SUCCEEDED message window that appears. If any USB mass storage device is
connected to the E5052B under this condition, the Hardware Wizard will start, but the USB mass storage device will not work.
The following procedure shows how to enable a USB Mass Storage Device.
1. [Save/Recall] > Explorer….
2. Double-click “EnableUsbStorage.exe” from D”\Agilent\Service.
3. Click OK in the SUCCEEDED message window that appears.
Note: If the program fails to run, it is possible that you have not logged in as a user in the Administrators Group. When you want to execute any of the above programs, make sure to log in as a user in the Administrators Group.
Note: For users who have E5052B with a serial prefix of MY421, these units do not contain the necessary programs in their HDD at shipment. Visit the following URL to obtain the program.
http://www.keysight.com/find/ssa > Technical Support >Software Downloads & Utilities > Program/Utility
Page 10
Product Declassification and Security Product Name: 10 MHZ TO 7 GHZ SIGNAL SOURCE ANALYZER
Model Number(s): E5052B
Page 10 of 10
Remote Access Interfaces
The user is responsible for providing security for the I/O ports for remote access by controlling physical access to the I/O ports. The I/O ports must be controlled because they provide access to all user settings, user states and the display image. The I/O ports include RS-232, GPIB and LAN. The LAN port provides the following services, which can be selectively disabled: http ftp sockets telnet
There is also a ‘ping’ service, which presently cannot be selectively disabled. The concern here
might be that it is possible to discover IP addresses of connected instruments in order to query their setups over the net or break into the code.
Procedure for Declassifying a Faulty Instrument
As shipped from the factory, all the E5052Bs have the following instrument-specific calibration files stored on the hard disk drive. When replacing a hard disk drive, in order to achieve specified performance, these files must be copied to the new hard drive. These files are located in the directory, D:\syscal.
Perform the procedure described on the E5052B User’s Guide to declassifying an E5052B if it needs to be removed from a secure area and be returned to a secure area.
The procedure can be found on Information on Maintenance on the E5052B User’s Guide. The latest manual can be also downloaded from:
http://www.keysight.com/find/ssa > Technical Support > Manuals & Guides
Loading...