Curtiss-Wright CNS4 CSfC User manual

CNS4 CSfC
Common Airborne Recorder
CSfC Encrypted Data Storage
User Guide
Part Number: DDOC0108-000-A2

This Page Intentionally Left Blank

User Guide DDOC0108-000-A2
CNS4 CSfC i
Front Matter
Revisions
NOTE
The content revision level remains unchanged for chapters / appendices impacted only by nomen-
clature change (implemented by revision A2).
The Curtiss-Wright CNS4 CSfC DDOC0108-000-A2 User Guide is made up of the following
individual chapters / appendices:
Changes to content are shown through the use of change bars placed in the left margin next to the
changed material.
Document
Number Media Revision Date Description PCN
DDOC0108-000 PDF A0 02/12/19 NIAP Review NA
DDOC0108-000 PDF A0.1 02/12/19 Incorporate Gossamer comments NA
DDOC0108-000 PDF A1 03/06/19 Initial Release 0319-0001
DDOC0108-000 PDF A2 03/20/19 Change nomenclature to CNS4 CSfC 0319-0002
Chapter / Appendix Topic Content Revision
1.0 Introduction 0.0
2.0 Overview 1.0
3.0 Controls and Indicators 0.0
4.0 Installation 1.0
5.0 Quick Start 1.0
6.0 Operation 1.0
7.0 System Configuration 0.0
8.0 Troubleshooting 0.0
9.0 Simple Network Management Protocol 0.0
10.0 Remove / Replace 2.0
11.0 Command Line Interface 0.0
A Specifications 0.0
B Cables / Connectors 0.0
C Ordering Information 1.0

User Guide DDOC0108-000-A2
CNS4 CSfC ii
Safety
WARNING
HAZARD. A potential hazard that could result in serious injury or death.
Information contained in WARNINGS applies to dangers and hazards that may result in injury and
/ or death to personnel. The actual hazard is provided in CAPITALIZED letters and the information
that mitigates the danger is provided in sentence case. This information typically precedes
procedural steps. It also may be present in narrative text to warn operators or maintenance
personnel of dangers present in the equipment.
CAUTION
HAZARD. A potential hazard that could result in equipment damage or improper operation.
Information contained in CAUTIONS applies to dangers and hazards that may result in damage to
equipment or improper operation. The actual hazard is provided in CAPITALIZED letters and the
information that mitigates the danger is provided in sentence case. This information typically
precedes procedural steps. It also may be present in narrative text to warn operators or
maintenance personnel of dangers present in the equipment.
NOTE
Amplifying information that helps in making a task of procedure more easily understood.
NOTES are used to supply amplifying information that will result in ease of testing or be beneficial
to personnel. This information typically precedes procedural steps. It also may be present in
narrative text as well.
Style and Conventions
This user guide uses the following typographical conventions.
This style Refers to
Ready
Text the software displays.
go
Anything you type, exactly as it appears, whether referenced in text or
at a prompt.
ENTER Special keys on the keyboard, such as enter, alt, and spacebar.
Save Software command buttons and sections of dialog boxes, such as
group boxes, text boxes, and text fields.
File Open A menu and a specific menu command.
ALT+F1Pressing more than one key at the same time.
ALT, TAB Pressing more than one key in sequence.
xx,yy Variable in error messages and text.
jobfile.dat File names.
Denotes the result of an action or procedure.
xyz Hyperlink.
STOP Controls on equipment.

CNS4 CSfC User Guide
Table of Contents
DD0C0108-000-A2 iii
Table of Contents
Introduction
1.1 Purpose ..................................................................................................................................................... 1-1
1.2 Scope ........................................................................................................................................................ 1-1
1.3 Quality Assurances.................................................................................................................................... 1-2
1.4 Related Information ................................................................................................................................... 1-2
1.5 Technical Support...................................................................................................................................... 1-2
1.6 Ordering Process....................................................................................................................................... 1-3
Overview
2.1 Description................................................................................................................................................. 2-1
2.1.1 Chassis ........................................................................................................................................... 2-1
2.1.2 FSM-C Module ................................................................................................................................ 2-3
2.1.3 ILE Module ...................................................................................................................................... 2-4
2.2 CNS4 Features.......................................................................................................................................... 2-6
2.3 Protocols.................................................................................................................................................... 2-7
2.4 CSfC Encryption ........................................................................................................................................ 2-7
2.4.1 Hardware Layer Encryption ............................................................................................................. 2-7
2.4.1.1 Hardware Layer Account Creation ........................................................................................ 2-7
2.4.1.2 Hardware Layer Account Log In ............................................................................................ 2-8
2.4.2 Software Layer Encryption .............................................................................................................. 2-9
Controls and Indicators
3.1 CNS4 Chassis Controls / Indicators .......................................................................................................... 3-1
3.1.1 Chassis LED Brightness ................................................................................................................. 3-1
3.2 ILE Module Controls / Indicators ............................................................................................................... 3-1
3.3 FSM-C Module Controls / Indicators ......................................................................................................... 3-2
Installation
4.1 Package..................................................................................................................................................... 4-1
4.2 Inspection .................................................................................................................................................. 4-1
4.3 Mounting.................................................................................................................................................... 4-2
4.3.1 Mounting - User Defined ................................................................................................................. 4-2
4.3.2 Mounting - ARINC Tray ................................................................................................................... 4-2
4.4 CNS4 Install / Remove .............................................................................................................................. 4-2
4.4.1 Install (User Defined Mount) ........................................................................................................... 4-2
4.4.2 Install (ARINC Tray) ........................................................................................................................ 4-3
4.4.3 Remove (User Defined Mount) ....................................................................................................... 4-3
4.4.4 Remove (ARINC Tray) .................................................................................................................... 4-3
4.5 Cables ....................................................................................................................................................... 4-4
4.5.1 Power / RS-232 Cable .................................................................................................................... 4-5
4.5.2 Ethernet Cable ................................................................................................................................ 4-5
Quick Start
5.1 Connections and Controls ......................................................................................................................... 5-1
5.2 Communications Setup ............................................................................................................................. 5-1
5.3 Login.......................................................................................................................................................... 5-1

CNS4 CSfC User Guide
Table of Contents
DD0C0108-000-A2 iv
5.3.1 CNS4 ............................................................................................................................................... 5-1
5.4 Hardware Layer ......................................................................................................................................... 5-1
5.5 Software Layer .......................................................................................................................................... 5-1
5.6 Partition Disks............................................................................................................................................ 5-1
5.6.1 Erase All Partitions / All Slots .......................................................................................................... 5-1
5.6.2 Check Drive Status ......................................................................................................................... 5-1
5.6.3 Create Single Partition on FSM0 ..................................................................................................... 5-2
5.6.4 Create Single Partition on FSM1 ..................................................................................................... 5-2
5.6.5 Create Single Partition on FSM2 ..................................................................................................... 5-3
5.6.6 Create Single Partition on FSM3 ..................................................................................................... 5-4
5.6.7 Create NAS Partitions on FSM0 - 3 ................................................................................................ 5-4
5.7 Create Software Encryption Containers on FSM2 and FSM3 ................................................................... 5-5
5.8 Open Software Encryption Containers on FSM2 and FSM3 ..................................................................... 5-6
5.8.0.1 Method 1 ................................................................................................................................ 5-6
5.8.0.2 Method 2 ................................................................................................................................ 5-7
5.9 Format / Mount NAS Partitions.................................................................................................................. 5-8
5.10 Unformat NAS Partitions ......................................................................................................................... 5-9
5.11 Close Software Encryption Containers.................................................................................................... 5-9
5.12 Erase Software Encryption Containers.................................................................................................. 5-10
5.13 ILE Account Logout ............................................................................................................................... 5-11
5.14 Access from Windows as NAS Device .................................................................................................. 5-11
5.15 Access from Linux as NAS Device ........................................................................................................ 5-12
5.16 External Key Passing Example ............................................................................................................. 5-12
Operation
6.1 Lab Setup / Connections ........................................................................................................................... 6-1
6.2 Basic Operation ......................................................................................................................................... 6-2
6.2.1 Initial Configuration ......................................................................................................................... 6-2
6.2.1.1 Time ....................................................................................................................................... 6-2
6.2.1.2 Passwords ............................................................................................................................. 6-2
6.2.2 Communications ............................................................................................................................. 6-2
6.2.2.1 Terminal Emulation ................................................................................................................ 6-3
6.2.2.2 Ethernet ................................................................................................................................. 6-4
6.2.3 Account Management ..................................................................................................................... 6-5
6.2.4 Storage Media ................................................................................................................................. 6-5
6.2.4.1 Preparation ............................................................................................................................ 6-5
6.2.4.2 Assigning Services to Partitions ............................................................................................ 6-5
6.2.4.3 Preparation ............................................................................................................................ 6-5
6.2.4.4 Creating a RAID .................................................................................................................... 6-6
6.2.4.5 Partitioning ............................................................................................................................. 6-6
6.2.4.6 Assign NAS Service .............................................................................................................. 6-6
6.2.4.7 Format Partitions ................................................................................................................... 6-7
6.2.4.8 Mounting NAS Partition ......................................................................................................... 6-7
6.2.4.9 Verification ............................................................................................................................. 6-7
6.2.5 Health .............................................................................................................................................. 6-7
6.2.6 Built-In Test ..................................................................................................................................... 6-8
6.2.6.1 CBIT (Continuous Built-In Test) ............................................................................................. 6-8
6.2.6.2 IBIT (Initiated Built-In Test) .................................................................................................... 6-8
6.2.6.3 PBIT (Power-On Built In Test ................................................................................................ 6-9

CNS4 CSfC User Guide
Table of Contents
DD0C0108-000-A2 v
6.3 Update ....................................................................................................................................................... 6-9
6.3.1 CNS4 Operating System Update .................................................................................................... 6-9
6.3.2 ILE Module Firmware .................................................................................................................... 6-10
6.4 Encryption................................................................................................................................................ 6-11
6.4.1 Zeroize .......................................................................................................................................... 6-11
6.4.2 Hardware Encryption Layer ........................................................................................................... 6-12
6.4.2.1 LE Account - Internal / External Key Storage ...................................................................... 6-12
6.4.2.2 Internal Security Mode ......................................................................................................... 6-13
6.4.2.3 External Security Mode ....................................................................................................... 6-13
6.4.2.4 ILE Account Creation ........................................................................................................... 6-13
6.4.2.5 ILE Login ............................................................................................................................. 6-14
6.4.2.6 Key Transfer ........................................................................................................................ 6-14
6.4.3 Software Encryption ...................................................................................................................... 6-15
6.4.3.1 Software Encryption Container ............................................................................................ 6-15
System Configuration
7.1 add............................................................................................................................................................. 7-2
7.2 all ............................................................................................................................................................... 7-2
7.3 file .............................................................................................................................................................. 7-3
7.4 format ........................................................................................................................................................ 7-3
7.5 free ............................................................................................................................................................ 7-4
7.6 fsck ............................................................................................................................................................ 7-4
7.7 fsep............................................................................................................................................................ 7-5
7.8 getDevName.............................................................................................................................................. 7-5
7.9 getFreeDisks ............................................................................................................................................. 7-5
7.10 getNfsOpt ................................................................................................................................................ 7-5
7.11 help.......................................................................................................................................................... 7-6
7.12 hide.......................................................................................................................................................... 7-6
7.13 iscsi0, 1, 2, 3............................................................................................................................................ 7-6
7.14 isMounted ................................................................................................................................................ 7-7
7.15 mount....................................................................................................................................................... 7-7
7.16 multi ......................................................................................................................................................... 7-8
7.17 nas........................................................................................................................................................... 7-8
7.18 numFreeDisks ......................................................................................................................................... 7-9
7.19 numFsmDisks.......................................................................................................................................... 7-9
7.20 numPartitions........................................................................................................................................... 7-9
7.21 part .......................................................................................................................................................... 7-9
7.22 raid......................................................................................................................................................... 7-10
7.23 raidStatus .............................................................................................................................................. 7-10
7.24 remove................................................................................................................................................... 7-11
7.25 rescan.................................................................................................................................................... 7-11
7.26 scan ....................................................................................................................................................... 7-11
7.27 setNfsOpt............................................................................................................................................... 7-12
7.28 status ..................................................................................................................................................... 7-12
7.29 sw .......................................................................................................................................................... 7-13
7.30 trim......................................................................................................................................................... 7-13
7.31 umount................................................................................................................................................... 7-14
7.32 verb........................................................................................................................................................ 7-14
7.33 version ................................................................................................................................................... 7-14

CNS4 CSfC User Guide
Table of Contents
DD0C0108-000-A2 vi
7.34 wipe ....................................................................................................................................................... 7-14
7.35 wrap....................................................................................................................................................... 7-15
7.36 writecfg .................................................................................................................................................. 7-15
Troubleshooting
8.1 LED Indicators ........................................................................................................................................... 8-1
8.2 Error Codes ............................................................................................................................................... 8-1
Simple Network Management Protocol
9.1 SNMP MIB................................................................................................................................................. 9-3
Remove / Replace
10.1 ILE Module - Install / Remove ............................................................................................................... 10-1
10.1.1 Remove ....................................................................................................................................... 10-1
10.1.2 Install ........................................................................................................................................... 10-1
10.2 FSM-C Module - Install / Remove ......................................................................................................... 10-2
10.2.1 Remove ....................................................................................................................................... 10-2
10.2.2 Install ........................................................................................................................................... 10-3
10.3 Chassis Battery Replacement ............................................................................................................... 10-3
10.3.1 Remove ....................................................................................................................................... 10-3
10.3.2 Install ........................................................................................................................................... 10-4
10.4 ILE Module Battery Replacement.......................................................................................................... 10-4
10.4.1 Remove ....................................................................................................................................... 10-4
10.4.2 Install ........................................................................................................................................... 10-4
Command Line Interface
11.1 CLI Commands...................................................................................................................................... 11-1
11.1.1 CNS4 Commands ....................................................................................................................... 11-1
11.1.2 FSM-C Module Commands ......................................................................................................... 11-1
11.1.3 ILE Commands ........................................................................................................................... 11-1
11.2 Commands ............................................................................................................................................ 11-1
Specifications
A.1 Envelope / Mounting Dimensions..............................................................................................................A-1
A.2 Physical Dimensions / Weight...................................................................................................................A-3
A.3 Power Dissipation .....................................................................................................................................A-3
A.4 Electrical Requirements ............................................................................................................................A-3
A.5 Mean Time Between Failure .....................................................................................................................A-3
A.6 Environment ..............................................................................................................................................A-3
A.6.1 Temperature ...................................................................................................................................A-3
A.6.2 Humidity ..........................................................................................................................................A-3
A.6.3 Vibration, Operating ........................................................................................................................A-3
A.7 EMI............................................................................................................................................................A-3
Cables / Connectors
B.1 Power / RS-232.........................................................................................................................................B-1
B.2 Ethernet.....................................................................................................................................................B-2
Ordering Information

CNS4 CSfC User Guide
List of Figures
DDOC0108-000-A2 vii
List of Figures
Figure 1.1 CNS4 CSfC CAR LRU..................................................................................................................... 1 - 1
Figure 2.1 CNS4 Assembly............................................................................................................................... 2 - 2
Figure 2.2 FSM-C Module Block Diagram ........................................................................................................ 2 - 3
Figure 2.3 FSM-C Module................................................................................................................................. 2 - 4
Figure 2.4 ILE Module Block Diagram .............................................................................................................. 2 - 5
Figure 2.5 ILE Module....................................................................................................................................... 2 - 5
Figure 2.6 Hardware Layer Account Creation................................................................................................... 2 - 8
Figure 2.7 Hardware Layer Account Log In ...................................................................................................... 2 - 8
Figure 3.1 CNS4 Chassis Indicators................................................................................................................. 3 - 1
Figure 3.2 ILE Module Controls / Indicators...................................................................................................... 3 - 2
Figure 3.3 FSM-C Module Controls / Indicators................................................................................................ 3 - 2
Figure 4.1 Anti-Tamper Label Locations........................................................................................................... 4 - 1
Figure 4.2 Required Door Clearance ................................................................................................................ 4 - 2
Figure 4.3 CNS4 Mounting - ARINC Tray......................................................................................................... 4 - 3
Figure 4.4 CNS4 Installed on ARINC Tray ....................................................................................................... 4 - 4
Figure 4.5 CNS4 Connectors............................................................................................................................ 4 - 4
Figure 4.6 Power / RS-232 Lab Cable.............................................................................................................. 4 - 5
Figure 4.7 Ethernet Lab Cable.......................................................................................................................... 4 - 5
Figure 6.1 CNS4 Test Setup............................................................................................................................. 6 - 1
Figure 6.2 PuTTY Terminal Emulator ............................................................................................................... 6 - 3
Figure 6.3 PuTTY Terminal Emulator (SSH) .................................................................................................... 6 - 4
Figure 6.4 CNS Update Utility......................................................................................................................... 6 - 10
Figure 6.5 ILE Firmware Update..................................................................................................................... 6 - 11
Figure 9.1 OID Tree .......................................................................................................................................... 9 - 1
Figure 10.1 ILE Module Replacement .............................................................................................................. 10 - 1
Figure 10.2 FSM-C Module Replacement ........................................................................................................ 10 - 2
Figure 10.3 Chassis Battery Replacement ....................................................................................................... 10 - 3
Figure 10.4 ILE Module Battery Replacement.................................................................................................. 10 - 5
Figure A.1 CNS4 Envelope/ Mounting Dimensions........................................................................................... A - 1
Figure B.1 Power / RS-232 Lab Cable.............................................................................................................. B - 1
Figure B.2 CNS4 Bulkhead Power Connector .................................................................................................. B - 1
Figure B.3 Ethernet Lab Cable.......................................................................................................................... B - 2
Figure B.4 CNS4 Bulkhead Ethernet Connectors ............................................................................................. B - 2

CNS4 CSfC User Guide
List of Tables
DDOC0108-000-A2 viii
List of Tables
Table 6.1 Ethernet Interfaces ................................................................................................................................ 6-3
Table 6.2 Security Modes.................................................................................................................................... 6-12
Table 7.1 Sysconfig Flags and Options................................................................................................................. 7-1
Table 8.1 LED Indicators....................................................................................................................................... 8-1
Table 8.2 Error Code List ...................................................................................................................................... 8-1
Table B.1 Power / RS-232 Lab Cable Pinout ........................................................................................................ B-1
Table B.2 Ethernet Lab Cable Pinout .................................................................................................................... B-2
Table C.1 Ordering Information ............................................................................................................................. C-1

User Guide DDOC0108-000-A2
CNS4 CSfC 1 - 1 Introduction
Revision 0.0
Introduction
1.1 Purpose
The purpose of this manual is to describe the Curtiss-Wright CNS4 CSfC Common Airborne
Recorder (CAR) Line Replaceable Unit (LRU) and to guide users through the process of
unpacking, installing, configuring, and using the unit. The CNS4 CSfC (Figure 1.1) requires the
use of multiple Flash Storage Modules-Carriers (FSM-C) and an In-Line Encryptor (ILE) to
operate. From this point forward, the product will be referred to as the CNS4; the associated
storage modules as FSM-C modules; and the associated encryptor module as the ILE module.
Figure 1.1 CNS4 CSfC CAR LRU
1.2 Scope
The information in this user guide is intended for information systems personnel, systems
coordinators, or highly skilled network users. This manual contains the following information:
• An overview of the CNS4.
• Unpacking, installation, and setup information.
• User interface connections.
• User input.
• Configuration options.
• Product specifications.
• Operation requirements.
• Environmental restrictions.
• Connector pinout and specifications.
• Ordering information for related products and parts
DDOC0108-0001
FSM-C Modules
ILE Module
CNS4 Chassis

User Guide DDOC0108-000-A2
CNS4 CSfC 1 - 2 Introduction
Revision 0.0
1.3 Quality Assurances
Curtiss-Wright Controls, Inc., Electronic Systems is committed to leveraging our technology
leadership to deliver products and services that meet or exceed customer requirements. In
addition to the physical product, the company provides documentation, sales and marketing
support, hardware and software technical support, and timely product delivery. Our quality
commitment begins with product concept and continues after receipt of the purchased product.
Curtiss-Wright Controls, Inc., Electronic Systems' Quality Management System is accredited to the
latest revision of the aerospace standard, AS9100 Quality Management Systems - Requirements
for Aviation, Space, and Defense Organizations.
Our Quality System addresses the following basic objectives:
• Achieve, maintain, and continually improve the quality of our products and service through
established design, test, production and service procedures.
• Improve the quality of our operations to meet the needs of our customers, suppliers, and other
stakeholders.
• Provide our employees with the tools and overall work environment to fulfill, maintain, and
improve product and service quality.
• Ensure our customer and other stakeholders that only the highest quality product or service
will be delivered.
Eagle Registrations Inc. assessed Curtiss-Wright's Quality Management System and confirmed
conformance to AS9100D including ISO 9001:2015 with Certificate No. 5819. The scope of the
registration is as follows: "Design, manufacture, test and repair of board level products, electronic
sub-systems, related software and services for commercial, aerospace and military applications.”
Customer feedback is integral to our quality and reliability program. We encourage customers to
contact us with questions, suggestions, or comments regarding any of our products or services.
We guarantee professional and quick responses to your questions, comments, or problems.
1.4 Related Information
• AES (Advanced Encryption Standard). https://csrc.nist.gov/publications/fips/fips197/ fips-
197.pdf
• EIA-232 RS-232 electrical characteristics single-ended voltage digital interface circuit.
http://www.eia.org/
• VITA 46, 47, 48, and 58. http://www.vita.com/vso-stds.html
• FIPS 140-2. https://csrc.nist.gov/publications/fips/fips197/ fips-197.pdf
• EMI Mil-Std-461
• NAS, http://www.pdl.cmu.edu/PDL-FTP/NASD/hotnet99.pdf
• Ruggedization, Curtiss-Wright, http://www.cwcelectronicsystems.com
• Curtiss-Wright Defense Solutions http://www.cwcdefense.com
• PuTTy User Manual (client program for SSH, Telnet, and Rolgin network protocols)
• Technical Note 8004 CNS4 CSfC Software and Firmware History
• NSA CSfC Program https://www.iad.gov/iad/programs/iad-initiatives/commercialsolutionsfor-
classified.cfm
1.5 Technical Support
Technical documentation is provided with all of our products. This documentation describes the
technology, its performance characteristics, and includes some typical applications. It also
includes comprehensive support information, designed to answer any technical questions that
might arise concerning the use of this product. We also publish and distribute technical briefs and
application notes that cover a wide assortment of topics. Although we try to tailor the applications
to real scenarios, not all possible circumstances are covered.

User Guide DDOC0108-000-A2
CNS4 CSfC 1 - 3 Introduction
Revision 0.0
While we have attempted to make this document comprehensive, you may have specific problems
or issues this document does not satisfactorily cover. Our goal is to offer a combination of products
and services that provide complete, easy-to-use solutions for your application.
If you have any technical or non-technical questions or comments, contact us. Hours of operation
are from 8:00 a.m. to 5:00 p.m. Eastern Standard/Daylight Time.
• Phone: (937) 252-5601 or (800) 252-5601
• E-mail: [email protected]
• Fax: (937) 252-1465
• World Wide Web address: www.cwcdefense.com
1.6 Ordering Process
To learn more about Curtiss-Wright Defense Solutions' products or to place an order, please use
the following contact information.
• E-mail: [email protected]
• World Wide Web address: http://www.cwcdefense.com/
To contact a local Curtiss-Wright sales representative go to: http://www.cwcdefense.com/
sales.html, point to your location on the map presented, then click on the pop-up with the sales
representative's name.

User Guide DDOC0108-000-A2
CNS4 CSfC 2 - 1 Overview
Revision 1.0
Overview
2.1 Description
The CNS4 is a high-performance multimedia data acquisition and encrypting network file storage
device. The CNS4 is protocol flexible, providing CIFS, NFS, FTP, HTTP, DHCP, SNMP, and iSCSI
file access protocols, making it ideal for sharing critical data in a harsh environment. The CNS4 is
a modular design, consisting of
• CNS4 chassis
• ILE module
• One to four FSM-C module(s)
The ILE module and FSM-C module(s) plug into a high-insertion rate backplane in the CNS4
chassis. The unit has four 1-Gbps Ethernet ports accessed via front panel connectors.
2.1.1 Chassis
The CNS4 chassis (Figure 2.1) is made up of the following major subassemblies:
• Backplane Subassembly
• Storage Backplane
• ILE Backplane
• Holdup Subassembly
• Power Supply Subassembly
• USB Flash Module
• COM Express PCB / Memory Module
• Main Carrier Subassembly
It also contains one AA battery to supply power to the Real Time Clock (RTC) and two external
trigger monitoring circuits.
The backplane is used to provide a means of interconnecting the FSM-C modules and the ILE
module to the main carrier subassembly. The backplane is made of two joined components that
have multiple low-force insertion sockets. Both backplane components plug into the main carrier.
The main carrier subassembly provides overall system interconnection. As a result, the power
supply and hold up sub-assemblies are connected to it as well. In addition, it supports external
communications through the four Ethernet connectors and power / RS-232 connector that are
installed on it. The Ethernet connectors (GBE0 through GBE3 support 0, 100, and 1000 Base-T
Ethernet. They support Ethernet IEEE 802.3ab standard over copper in full duplex.Refer to
Cables / Connectors section for additional information regarding the interface connectors and
associated cables. The subassembly also has a set of utility connectors used for manufacturing
and service activities. Contact Curtiss-Wright for more information about end-user utilization of
these connectors.
The COM Express PCB contains the main CPU and RAM memory for the unit. The USB flash
module contains the BIOS and operating system.
The power supply assembly takes the 28 VDC input power, cleans and conditions it, and then
distribute it to the entire system. The holdup subassembly consists of a series of capacitors and a
power monitoring circuit. It ensures the unit can power down in an orderly fashion if the 28 VDC
input power is suddenly removed.
The chassis has four status LEDs. Refer to paragraph 3.1 CNS4 Chassis Controls / Indicators
for information regarding the LEDs.
Control of CNS4 chassis functions is established through the Command Line Interface (CLI). Refer
to Command Line Interface section for additional information regarding applicable CLI
commands. Multiple CNS4 chassis functions are monitored to ensure proper operation. Refer to
paragraph 6.2.5 Health for additional information.

User Guide DDOC0108-000-A2
CNS4 CSfC 2 - 2 Overview
Revision 1.0
Figure 2.1 CNS4 Assembly
DDOC0108-0002
Power Supply Subassembly
Main Carrier Subassembly
Holdup Subassembly
Storage Backplane
ILE Backplane
ILE Module
Ethernet Connectors
Power/ RS-232 Connector
Power Supply Subassembly
Main Carrier Subassembly
Battery
COM Express Module
Memory Module
Utility Connectors
eUSB Flash Module

User Guide DDOC0108-000-A2
CNS4 CSfC 2 - 3 Overview
Revision 1.0
2.1.2 FSM-C Module
CAUTION
EQUIPMENT DAMAGE. Do not remove / install a FSM-C module with power applied or damage to
the FSM-C module and / or CNS4 will occur.
CAUTION
EQUIPMENT DAMAGE. Use ESD precautions when handling a FSM-C module. Failure to
properly handle FSM-C modules can result in damage.
CAUTION
EQUIPMENT DAMAGE. Ensure wedge-lock levers are in closed position when FSM-C module is
installed in CNS4 chassis. The levers are thermally conductive and must be closed to provide
proper heat dissipation for the FSM-C module. Failure to close levers will result in improper
operation / failure of the FSM-C module.
Up to four FSM-C modules can be installed in the CNS4 chassis. Each FSM-C module is a 2.0 TB
storage module that uses EMLC type memory. The FSM-C modules are installed behind an
access door located on the front of the CNS4 chassis. Each FSM-C module has three status LEDs
and a removal request button. Refer to paragraph 3.3 FSM-C Module Controls / Indicators for
information regarding the LEDs and button. Refer to Figure 2.2 for a block diagram of the FSM-C
module.
Figure 2.2 FSM-C Module Block Diagram
The FSM-C module design supports dynamic and static data wear-leveling enforcing an even
distribution of erase/write cycles. This prevents excessive writes to the same flash locations
extending the life cycle of the memory. An ECC engine is present to provide bit error detection and
correction in the physical NAND memory. In addition, a Bad Block Management (BBM) algorithm is
included to replace bad-blocks. Wear-leveling, ECC, and BBM techniques provide an extended
endurance rating for the FSM-C module storage. The FSM-C supports Serial Advanced
Technology Attachment (SATA I/II) interface bus. It is capable of data transfer rates of 1.5 Gbps
and 3.0 Gbps (SATA I and SATA II respectively).
The FSM-C model (Figure 2.3) enclosure is constructed of two custom-machined anodized
aluminum covers fastened together with screws. The internal structure is designed to dissipate
component heat and provide rigidity. This closed structure makes the FSM-C module less
susceptible to problems due to adverse environments and provides silent vibration-free operation.
The FSM-C module uses conduction cooling. Its internal structure transfers heat to a physically
connected aluminum enclosure, which in turn conducts the heat through the wedgelock guide rails
to the CNS4 chassis. The interconnect plug is keyed to ensure the FSM-C module is inserted
correctly into the CNS4 chassis.
The FSM-C module is NOT hot-swappable, the CNS4 MUST be powered down prior to removal or
installation of any modules. The module is removed by grasping a pair of wedgelock levers and
pulling them away from the module's body. An additional eject lever is provided to assist with
removing the module. After removal, the FSM-C module can be transported in an ESD-safe
carrying case.
Removal
Request
Button
Status LED
Fault LED
Power LED
SATA PORT
POWER
DDOC0108-0010
I2C Register EPROM
Temperature Sensor
Voltage Sensor
SYSTEM
MANAGEMENT
2.5 SATA
Solid State Drive

User Guide DDOC0108-000-A2
CNS4 CSfC 2 - 4 Overview
Revision 1.0
Figure 2.3 FSM-C Module
Control of FSM-C module functions is established through the Command Line Interface (CLI).
Refer to Command Line Interface section for additional information regarding applicable CLI
commands. Several FSM-C functions are monitored to ensure proper operation. Refer to
paragraph 6.2.5 Health for additional information. Refer to Ordering Information section for the
FSM-C module part number. Refer to paragraph 10.2 FSM-C Module - Install / Remove for
instruction on installing or removing the FSM-C module.
2.1.3 ILE Module
CAUTION
EQUIPMENT DAMAGE. Do not remove / install a ILE module with power applied or damage to the
ILE module and / or CNS4 will occur.
CAUTION
EQUIPMENT DAMAGE. Use ESD precautions when handling a ILE module. Failure to properly
handle ILE modules can result in damage.
The CNS4 uses the Curtiss-Wright FIPS 140-2 certifiable ILE module for hardware encryption. For
CSfC, the ILE module works in conjunction with software encryption present on each FSM-C
module. The FSM-C module(s) accepts the cipher text written from the ILE module and retains it
until read and decoded by the ILE module. The ILE module has two encryption modes:
• Internally generated Date Encryption Key (DEK).
• Externally provided DEK.
The ILE module uses the Advanced Encryption Standard (AES) and a 256-bit encryption key. As a
result, sensitive data can be protected when processed through the ILE module. Refer to Figure
2.4 for a block diagram of the ILE module.
Wedgelock
Lever
Wedgelock
Lever
Eject Lever
Power LED Status LED
Fault LED
DDOC0108-0009
Removal Request
Button
DETAIL A
Standard Keying
See DETAIL A

User Guide DDOC0108-000-A2
CNS4 CSfC 2 - 5 Overview
Revision 1.0
Figure 2.4 ILE Module Block Diagram
The ILE module (Figure 2.5) is NOT hot-swappable, the CNS4 MUST be powered down prior to
removal or installation of the module. The module is removed by rotating a pair of Allen screws to
lower the wedge locks. The unit is removed by grasping the eject lever and pulling the module
from the chassis. After removal, the ILE module can be transported in an ESD-safe carrying case.
Figure 2.5 ILE Module
A single ILE module contains four encryptors which performs the data encryption for all installed
FSM-C modules. The four encryptors are labeled A through D, with encryptor A assigned to FSM-
C module 0, B to 1, C to 2, and D to 3. As a result a single DEK can be assigned to all installed
FSM-C modules or a separate DEK can be assigned to each FSM-C module.
RS-232 (Optional)
I2C
Status
Key Purge
RS-232 (Reserve Keep Alive)
Zeroize
Button
Power LED
Key LED
Fault LED
5V
AES256-bit
Encryption
AES256-bit
Encryption
AES256-bit
Encryption
AES256-bit
Encryption
SRAM
Battery Backup
AES KEY
Storage
Admin / Use Login
Default Settings
DC-DC
Power
µController
SATA Ports
To FSM-C
Modules
DDOC0108-0014
ZEROIZE
ILE
PFS
DDOC0108-0015
Power LED Status LED
Fault LED
Eject Lever
Wedge Locks
Allen Screw
Zeroize Button

User Guide DDOC0108-000-A2
CNS4 CSfC 2 - 6 Overview
Revision 1.0
The ILE module is located behind a front panel access cover labeled FIPS CRYPTO. The ILE
module has three status LEDs and a zeroize button. Refer to paragraph 3.2 ILE Module Controls
/ Indicators for information regarding the LEDs and button.
The ILE module encryption key(s) can be zeroized (removed) by one of the three methods:
• Pressing the zeroize button on the ILE.
• Applying an external trigger via a signal applied through the Power / RS-232 connector / cable.
• Sending a software command via the Command Line Interface (CLI).
Refer to paragraph 6.4.1 Zeroize for more information regarding removing the encryption key from
the CNS4 / ILE module.
NOTE
The 1st account created on the ILE is always the crypto officer account (had admin privileges).
Four additional user accounts can be created as well.
Control of ILE module functions is established through the CLI. Refer to Command Line Interface
section for additional information regarding applicable CLI commands.Several ILE functions are
monitored to ensure proper operation. Refer to paragraph 6.2.5 Healthfor additional information.
Refer to paragraph Figure 10.1 ILE Module Replacement for instruction on installing or removing
the ILE module. The ILE requires use of an account to access data. Refer to paragraph 6.4.1
Zeroizet for additional information.
2.2 CNS4 Features
• Built-In-Test
• Power-On (PBIT)
• Initiated (IBIT)
• Continuous (CBIT)
• Command Line Interface
• Encryptor Features
• CSfC Associated Encryption
• Hardware Encryption Layer
• Software Encryption Layer
• Local Zeroization
• Remote Zeroization
• Five-second Power Hold Up
• Four 1 Gigabit Ethernet Ports
• Health Monitor (with Front Panel Indicator)
• Indicator Brightness Control
• Multiple Protocols
• Common Internet File System (CIFS)
• Dynamic Host Configuration Protocol (DHCP)
• File Transfer Protocol (FTP)
• HyperText Transfer Protocol (HTTP)
• Internet Small Computer System Interface, (iSCSI)
• Network File System (NFS)
• Secure Shell Protocol (SSH)
• Simple Network Management Protocol (SNMP)
• Power / RS-232 Port
• Solid-state Storage
• Thermal Overtemp Sensors

User Guide DDOC0108-000-A2
CNS4 CSfC 2 - 7 Overview
Revision 1.0
2.3 Protocols
The CNS4 supported protocols include CIFS, NFS, FTP, HTTP, DHCP, SNMP, and iSCSI in
addition to its RS-232 console port. These protocols are disabled by default. The unit also
supports SSH, which is always enabled. The user can enable the desired protocols to support their
application. Refer to paragraph 11.2.23 serv for additional information.
The FDEEEcPP20 and FDEAAcPP20 Protection Profiles did not consider, nor did they include
networking protocols as part of the security functional requirements, and as a result, did not
include any requirements for addressing those protocols.
Therefore, as per the FDEEEcPP20 and FDEAAcPP20, the protocols have not been examined as
part of the required assurance activities and consequently the evaluation can make no claims
about the CNS4’s networking protocols.
It is suggested that a customer using the product consider the impact of utilizing remote
administration via SSH across the network (rather than through the console) based upon their
specific use case. The customer should factor into their risk management decision the
environment in which the CNS4 operates (dedicated, segregated, private network versus residing
in a Demilitarized Zone [DMZ] accessible to the Internet), and the value of data to be protected.
2.4 CSfC Encryption
Commercial Solutions for Classified (CSfC) encryption is based on a National Security Agency
(NSA) specification. The CSfC program requires multi-layered security. Hardware data encryption
is used for the first security layer. The second security layer is software data encryption. The
hardware encryption is performed in the ILE module, the software encryption is performed on the
FSM-C module(s) loaded in the CNS4 chassis.
Proper encryption / decryption is dependent on the use of keys and passphrases. The key resides
in hardware layer on the ILE module. As a result, if an ILE module is changed, unless the exact
same key is loaded on the second module, the FSM-C modules will not be accessible. The
passphrase resides in the software layer on the FSM-C module. So if a FSM-C module is
swapped, unless the second FSM-C has been encrypted with the same passphrase, its stored
data will not be accessible.
2.4.1 Hardware Layer Encryption
CAUTION
IMPROPER OPERATION / LOST DATA. If the specific user token key is lost, the user account will
be rendered unusable.
NOTE
Refer to paragraph 6.4.2 Hardware Encryption Layer for information regarding the actual
commands and procedures used to create and log into the hardware layer.
2.4.1.1 Hardware Layer Account Creation
Before use, an account must be created () on the hardware layer. To start the account creation, the
user logs into the CNS4 / ILE module via the Command Line Interface (CLI). Once logged in,
additional commands are entered to create an account on the ILE hardware layer. The hardware
layer contains a Pre-Shared Key (PSK) which is generated at initial equipment power-on at the
manufacturer and provided separately by Curtiss-Wright. The PSK cannot be read out of the ILE
module.
When the account is created, a user token key is internally generated by the hardware layer. The
layer then keywraps the user token key using the PSK and supplies it to the end user through the
CLI. The keywrapped user token key is validated on a third-party system by comparing the ILE-
generated HMAC and the third party-generated HMAC. If both match, the user token is unwrapped
using the PSK. The unwrapped user token key is then used in subsequent log ins as the specific-
user token.
Table of contents