About the Kobra VS storage devices: Kobra Drive VS
and Kobra Stick VS
The external encrypted data storage devices Kobra Drive VS as well as Kobra Stick VS
(1FF) and Kobra Stick VS (2FF) are an external USB-C storage device (HDD/SSD) and
USB-C memory stick with hardware-based encryption in stable, elegant metal housings
with integrated keyboard. The storage devices provide the same security features and
differ only in their form-factor, design and storage capacities. For this reason, they are
all referred to as Kobra VS in this Administrator’s Guide.
The Kobra VS storage devices enable the GDPR/EU-DSGVO data protection compliant
storage and safekeeping as well as secure transport of sensitive, personal and
confidential information up to the classification level NATO Restricted, EU Restricted
and VS-NfD (classified information – for official use only). These data carriers were
developed in accordance with the “Technical Guidelines” of the German Federal Office
for Information Security (BSI) and bear the quality mark “IT-Security made in Germany”.
They correspond to the current “state of technology” (German: Stand der Technik) and,
due to their security functions, are currently one of the safest ways to store and transport
data on mobile devices.
The data stored on the Kobra VS data carrier is protected against unauthorized access
with regard to the confidentiality of the information, for example if the Kobra VS storage
device is lost, misplaced or stolen. In doing so, it resists logical and physical attacks.
Thanks to the built-in storage in 2.5” format, the Kobra Drive VS is already small and
handy as an HDD. The optional SSD version offers additional protection against shocks
and vibrations. The data transfer and power supply are provided via the USB-C port. The
Kobra Stick VS (1FF) and Kobra Stick VS (2FF) offer the same security features as the
Kobra Drive VS, only in an even more compact format.
Kobra VS devices can be delivered in a PKI-based or stand-alone environment. There
are two basic application scenarios. In the PKI-based variant, only Kobra VS devices
are provided. These are set up by the user’s administrators. Therefore, the PKI-related
properties of the Kobra VS are also regulated by the administrator’s IT security concepts.
7
Deutsch
This mainly concerns the generation and storage of the key pair (consisting of a public
and a private key), the User-PIN and SO-PIN specifications (length and number of failed
attempts) and other organizational measures. For this reason, the properties of the
Kobra VS storage device are described in detail below, mainly regarding the stand-alone
environment.
The stand-alone scenario, on the other hand, involves the delivery of the Kobra VS
together with two Digittrade smart cards (Atos Card OS 5.3, CC EAL 4+) in the completely
preset state. This Kobra VS can basically be used immediately in case of urgent need.
In the VS-NfD approved configuration, however, the user may only put the Kobra VS
into operation after changing the User-PIN and SO-PIN and generating a new DEK (Data
Encryption Key) on the Kobra VS device itself.
In order to use the security features of the Kobra VS storage devices to the full extent
and within the scope of the VS-NfD approval, the following steps are required:
– Ensure that your host system has adequate protection for all data accessed
from the protected area of the Kobra VS
– After receiving the Kobra VS, check the completeness and correctness of the
delivery (Chapter 10)
– Check via the host system that the USB properties of the device match the
model name and serial number on the back of the Kobra VS (chapter 1.12)
– Change the User-PIN and SO-PIN on both Digittrade smartcards
(chapter 4.3, 4.5)
– Change the Admin-PIN if you have administrator rights (Chapter 4.6)
– When selecting the Admin-PIN, User-PIN and SO-PIN, trivial PINs should not be
considered and standard PINs should be excluded
– Create a new DEK (Data Encryption Key) on the Kobra VS storage device
(Chapter 4.7)
– Check if the registration is possible with all activated Digittrade smartcards
(or your PKI card)
– Protect your authentication features (smartcard and PIN), they must remain
confidential
For a detailed description of the above steps, refer to the appropriate chapters in this
Administrator’s Guide. The model name and serial number can be found on the back
of each Kobra VS. This information can be obtained using the supplied Kobra Client VS
software and the USB device information on the host system.