
PAGE 7IRONKEY USER GUIDE
Identity Manager Protection
The IronKey Identity Manager and my.ironkey.com work together, giving
you the ability to back up your online passwords to your Online Security
Vault at my.ironkey.com. First, you must unlock your IronKey device, which
requires two-factor authentication. Your passwords are securely stored
generated keys encrypted with a SHA-256 hash of your device password.
All of this data is then doubly encrypted with 128-bit or 256-bit AES
hardware encryption.This is the strongest password protection we have
ever seen in the industry.
When you back up your passwords online, IronKey performs a
complicated public key cryptography handshake with IronKey’s services
using RSA 2048-bit keys. After successful authentication, your encrypted
block of password data is securely transmitted over SSL to your
encrypted Online Security Vault within one of our highly-secure data
facilities.
IRONKEY SERVICES SECURITY
Secure Facilities
IronKey hosts its online services at state-of-the-art third-party data
center facilities. Physical access to the IronKey systems requires multiple
levels of authentication, including but not limited to hand geometry
biometric readers,“man trap” entry, government-issued photo ID
is equipped with numerous surveillance cameras, motion detectors, and
a sophisticated alarm system.The IronKey infrastructure resides in a
secured cage.The entire facility is monitored by dedicated on-site security
personnel on a 24x7 basis.
Secure Environments and Policies
Logical access to the IronKey environments is controlled by multiple
prevention systems and application security appliances. For additional
protection, IronKey partitions its online services and backend applications
into different network segments with independent security rules and
policies.
Secure Communications and Data at Rest
When users access IronKey web sites and services, all information is
exchanged over an encrypted channel.This is accomplished through
applications encrypt all sensitive data prior to transmitting it within the
IronKey network and storing in databases.