Pattern KV-A

Shared workstation with physical KVM switching

Four properties separate a secure KVM from an ordinary one: EDID emulation, one-way HID, no shared buffer, tamper indication.

Area
KVM & VTC
Environments
4
Products used
10

How it is built

The peripherals are shared. That is why they are the channel, and why the switch has to be physical.Operator positionDomainsKeyboard, mouse, headsetSecure USB DisconnectSecure KVM switchDisplay without an OSDomain 1Domain 2HID onlyactive domainno buffersurvives theswitch
The peripherals are shared. That is why they are the channel, and why the switch has to be physical.Operator positionDomainsKeyboard, mouse,headsetSecure USB DisconnectSecure KVM switchDisplay without an OSDomain 1Domain 2HID onlyactive domainno buffersurvives theswitch
  • Data path
  • Path that does not exist
The peripherals are shared. That is why they are the channel, and why the switch has to be physical.

How it works

One set of peripherals, several domains, and a physical switch between them. The peripherals are shared, which is precisely why they are the channel that has to be governed.

Four properties separate a secure KVM from an ordinary one

An emulated EDID presented to each source rather than the display’s own. A keyboard and mouse path that is unidirectional in hardware. No buffer, memory or configuration that survives a switch. And tamper indication on everything that affects those three.

USB is the part that gets forgotten

Only HID class belongs across a domain boundary. Storage devices, composite devices and devices that change class after enumeration have to be rejected — and a keyboard with its own memory is a shared object whether or not anyone thinks of it that way.

The indication has to be real

Driven by the state of the equipment, not by a control system’s belief about it. An operator who has to infer which domain is active will eventually infer wrong.

In the catalogue

Equipment from the catalogue

TEMPEST Level A · RÖS U1

Secure KVM Switch

Certified for both TEMPEST Level A and RÖS U1 for protection against intercepting signals and is designed to…

Product no 60-00-7831

TEMPEST Level A · RÖS U1

VTC Audio Unit

Intended to be a part of a RÖS U1 and TEMPEST Level A-approved videoconferencing system and allows for the…

Product no 60-00-7634

TEMPEST Level A · RÖS U1

Webcamera

TEMPEST Level A and RÖS U1 protected with integrated physical lens cover used for secure video calls with…

Product no 60-00-7887

TEMPEST Level A · RÖS U1

Thin Client 27"

CPU
Intel CPU i3-N305
Optimal (recommended) resolution
3840 x 2160
Display area
596 x 335 (WxH) mm

Product no 60-00-9161

TEMPEST Level A · RÖS U1

Ergo Line JODAV Device

TEMPEST Level A/EMSEC/RÖS U1 approved Roto-Seal sealed module that allows connection of an ergonomic mouse to…

Product no 60-00-7130

TEMPEST Level B · RÖS U2

HDMI Diode

The Fibersystem HDMI Diode protects sensitive systems by ensuring that video and audio can only travel in one…

Product no 60-00-9155

Standard

Card Module HDMI HDBaseT KVMX Toslink

Secure, remote CPU location with extended range and sustained transfer rate using HDBaseT technology over…

Product no 60-00-6932

Standard

Secure USB Disconnect Desktop

Dimensions
38 x 100 x 100 (HxWxD) mm
Weight
300 Gram

Product no 60-00-0234

TEMPEST Level A · RÖS U1

KVM Monitor 32" HDBaseT

Optical system budget
Depends on type of SFP
Fiber optic connector
LC

Product no 60-00-7401

Standard

Secure Key Switch

Control of VTC Codec Switches in VTC Systems.

Product no 60-00-7996

Hands soldering a circuit board under a work lamp

Next step

Designing something that is not here?

Send us the constraints. We build from idea to certified end product, and most of what is in the catalogue started that way.

Verified credentials

All certifications