The Advanced Network Infrastructure Security (ANIS) GigaCryptor is a compact IP network encryption device, offering gigabit throughput and high reliability. Armed with a full set of self-defending mechanisms, the ANIS GigaCryptor is able to detect various forms of attacks. The privacy of the key is maintained, under any circumstances.
The ANIS GigaCryptor can actively defend itself, even when the power supply is removed. The size and performance of the ANIS GigaCryptors makes it an ideal solution for a wide range of network security applications, especially in non-trusted environments, such as the encryption of the IP traffic in data centers.
Performance Overview
| ANIS GigaCryptor |
| 1000 MBit/s Throughput in Half Duplex |
| 1000 Mbit/s Throughput in Full Duplex |
Encryption Algorithms Supported
256/128-bits AES
168-bits Triple DES
112-bits Extended DES
Proprietary Algorithms
|
| 40,000 Clients/Subnets Supported |
| Optimised for Small Packets for Real-time Traffic |
| High Reliability - No Moving Parts |
Self Defending Mechanisms
The ANIS GigaCryptor features a full complement of self-defending mechanisms that can detect even the most sophisticated attacks. The self-defending mechanisms are combined with various alarm actions to form a product that is able to fully protect the device and the keys stored in it. Each of the alarms can be configured in GlobalAdmin, and can be dynamically turned-on or turned-off for easy administration.
Some of the different self-defending mechanisms and alarm actions are:
| Touch Sensors |
Detects physical opening of the device and probing of the PCB |
| Motion Sensors |
Detects when the ANIS GigaCryptor is being moved |
| Secondary Power |
Self-defending mechanism can work even when power is removed |
| Hidden Alarms |
Silently sends an encrypted alarm to the GlobalAdmin station |
Modes of Operation
The ANIS GigaCryptor is available in either a bridge mode or gateway mode. The bridge-mode GigaCryptor
works as a bump-in-the-wire concept and can be easily deployed into existing networks, or MPLS networks.
Gateway-mode ANIS GigaCryptor encapsulate the original IP packet with new headers, allowing the original IP headers to be concealed, as well as secure remote access from client machines using IPCrypt Client.
Enhanced IPSec
The ANIS GigaCryptor provide an alternative key management protocol called Enhanced IPSec developed by CE-Infosys. Using Enhanced IPSec, faster connections can be made as there is no need for lengthy session key negotiations using IKE to establish a tunnel. In addition, each IP packet is implicitly authenticated with any modified or malicious packets automatically discarded. In addition, the session keys used for encryption can be changed as rapidly as every 1, 5, 10, or 20 packets to defeat any attempts at statistical analysis of the encrypted packets.
Central Management
The ANIS GigaCryptor can be easily managed using GlobalAdmin. This central management station provides an intuitive Graphical User Interface for simple administration of the ANIS GigaCryptor. Using GlobalAdmin, keys and policies used by the ANIS GigaCryptor can be pushed down remotely. In addition, firmware upgrades can be sent remotely to the
ANIS GigaCryptor.
Highest Reliability
As a high end product for the most demanding customers, reliability is a key asset. The ANIS GigaCryptor is
designed for reliability. No mechanical moving parts are found in the ANIS GigaCryptor. No high voltage components
are used in the products.
Designed to withstand demanding conditions and suitable to be utilised in cars, trucks, and other vehicles,
the ANIS GigaCryptor has an outstanding MTBF rate and is resistant against dust, sand and humidity.
Miscellaneous
| Size |
230 mm X 147 mm X 45 mm
2 ANIS GigaCryptors can be placed in a 1U slot in a standard
19-inch rack
|
| Interfaces |
2 x 10/100 MBit/s auto-sensing Copper Ethernet Interface
Optional Fibre-optic Interface
RS232 Diagnostic Port
USB slot for USB token |
| Power Specification |
12V/1A DC input
An external power adapter for 110/230V 50-60 Hz AC is provided with each product |
| Logging and Reporting |
Syslog and Syslog-Mail
SNMP
GlobalAdmin |
| Additional Features |
UDP Tunneling
Source and Destination NAT
Configurable Routes
Configurable Bypass Rules
IP Address Pools
High Availability and Load-sharing |
> top <