Secure KVM-over-IP solution
The keyboard and mouse data are transmitted bidirectionally via the second port,
the so-called communication port.
The key exchange for the highly security-relevant keyboard and mouse data as well
as the control data is fully dynamic and occurs every 40 to 80 minutes.
Video data is transmitted directly from the computer module to the console module
via UDP and MultiCast/UniCast (data port). For audio, GenericUSB and RS232
data as well as the video stream, which is converted to G&D's own proprietary pro-
tocol before being sent, AES128 Counter Mode (CTR) is used. A secret device key,
which is required to unpack the video data, provides additional protection.
The proprietary protocol for dedicated connections is supplemented by fully
dynamic encryption for KVM-over-IP. The key exchange for this high-speed data
takes place every three to five hours or in the case of switching events. Each time a
console module connects to a computer module, a security key is generated for that
connection. Whenever another console module connects to this computer module
within matrix operation, both console modules receive new security keys. In
reverse, a new security key is also sent to the remaining console module when the
other module is disconnected.
By separating control data (control port) and keyboard and mouse data (communi-
cation port) from video, audio, GenericUSB and RS232 data (data port), diverse
attack scenarios, such as man-in-the-middle attacks, are prevented from the outset.
If the target IP address or VPN tunnel is compromised, no new security keys are
issued and the KVM end devices as well as the matrix system switch to security
mode and stop the transmission of data.
G&D VisionXS-IP-F-TypeC-UHR · 9