Page 3
DDOC0099-000 6/29/20 Add Quick Start section. All other corrections / updates 0620-0012 noted by change bars. The Curtiss-Wright DTS1 CSfC User Guide (DDOC0099-000) is made up of the following individual chapters and appendices. Chapter / Appendix Topic Content Revision Introduction...
Page 12
RMC Module LED Fault Indications ...................... 9-2 Table 9.3 Encryptor Error Codes........................... 9-2 Table A.1 DTS1 / RMC Calculated Mean Time Between Failures ................ A-4 Table B.1 Power Connector J1 Signals ......................... B-1 Table B.2 Power Lab Cable (VS-DTS1PWRCAB-0) ..................... B-1 Table B.3...
Page 13
The unit requires the use of a Removable Memory Cartridge (RMC) module. From this point forward, the product will be referred to as the DTS1 and the associated cartridge will be referred to as the RMC module.
Page 14
DTN_support@curtisswright.com • Fax: (937) 252-1465 • World Wide Web address: www.cwcdefense.com Ordering Process To learn more about Curtiss-Wright Defense Solutions' products or to place an order, please use the following contact information. • E-mail: DTN_info@curtisswright.com • World Wide Web address: http://www.cwcdefense.com/...
Page 15
The Curtiss-Wright DTS1 (Figure 2.1) is a rugged Network Attached Storage (NAS) device with solid state storage capacities from 128 GB up to 4 TB. The DTS1 provides data storage to assorted network clients via two IEEE 802.3 / 802.3u / 802.3ab Ethernet ports. The DTS1 is a ruggedized unit designed to operate on vehicles, in field stations, or in laboratories.
Page 16
Connector J1 is used to connect the DTS1 to 28 VDC (operating voltage). In addition, the DTS1 has a removable panel located on the underside of the unit. It is removed to allow replacement of the crypto module battery.
Page 17
2.1.2 RMC Module One RMC module (Figure 2.5) is housed in the DTS1. The RMC module is accessed via a sealed door with a quarter-turn latch located on the front panel of the unit. The RMC module within the DTS1 is also a rugged compact unit that can be personally transported with minimal precautions to a secure location or deployment.
Page 18
The second security layer is software data encryption. Both encryption processes are performed in the DTS1, one in the HW crypto module, the other by the Processor. The hardware encryption key is retained in the DTS1 crypto module memory, the software encryption key is stored on the RMC module.
Page 19
The CLI then sends this data as a user-generated HMAC to the DTS1 HWE layer. The layer compares the user HMAC and the HWE layer HMAC. If they are the same, the user is logged in. If they do not compare, the user is denied access.
Page 20
Subsequent use of the RMC module is dependent upon the proper encryption key / passphrase being entered using the CL). Failure to enter the proper information will result in the RMC module being inaccessible for data storage or use. 2.3.3 Zeroize There are two methods to zeroize the DTS1: • Local • Remote To locally initiate zeroization, the KEY CLEAR button is depressed and held for a minimum of five seconds.
Page 21
Supported packet capture protocol • PCAP • Supported video stream capture protocol • • Client remote boot from DTS1 via Preboot eXecution Environment (PXE) • User control, status, & maintenance interface • Command Line Interface (CLI) via: • Secure shell (SSH) •...
Page 22
STATUS (green): on when RMC module is installed, mounted and ready for access • ACTIVITY (green): on when disk is accessed (not supported on some RMC module configurations) • FAULT (red): DTS1 system monitor has detected a fault with the RMC module DTS1 CSfC 2 - 8 Overview Revision 5.0...
Page 23
User Guide DDOC0099-000-AH Controls and Indicators Chassis Indicators The DTS1 has four LED status indicators (Figure 3.1) on the bottom of the front panel: • POWER • FAULT • KEY LOADED • DRIVE CAPACITY The brightness of the chassis LEDs can be independently set from 0 to 100% brightness. This accomplished by changing the duty cycle of the power applied to the individual LEDs.
Page 24
When this button is pushed and held for a minimum of 5 seconds, all encryption related material within the DTS1 will be erased. This includes loaded keys, stored keys, and all previously loaded login/authentication credentials (user names and passwords). After zeroization, the yellow KEY LOADED LED will turn off.
Page 26
Ethernet Lab Cable Inspection The DTS1 is a two-part data storage system that consists of a DTS1 chassis and a RMC module. Additional accessories may be included (if ordered). All received items should be inspected for damage. Inspect all units as follows: •...
Page 27
Dzus mount. If installation and removal of the RMC module is desired while the DTS1 remains mounted, be sure to allow clearance (Figure 4.4) for the door to open and the RMC to be positioned in front of the DTS1. DTS1 Standard Mount...
Page 28
0.994 (25.24) 4.00 (101.6) DDOC0099-0007 Figure 4.4 DTS1 Required Door Clearance Cables All connections to the DTS1 are on the rear panel (Figure 4.5). Be sure the power supply is off when making connections. RS-232 Ethernet Ethernet Power Ground DDOC0099-0009 Figure 4.5...
Page 29
Utility Lab Cable 4.4.3 Ethernet Cable The Ethernet Lab Cable (VS-DTS1ETHCAB-J3) (Figure 4.8) is used to make network connections to the DTS1. Refer to paragraph B.3 Ethernet Connector J3 / Ethernet Lab Cable for connector pin signal information. Connections •...
Page 30
Ground Cable A ground cable is required, but not provided. The ground cable (DTS1 Ground Connection) terminal is installed on the DTS1 ground stud E1. The provided nut should be torqued to 18 in. lb. to ensure proper connection. Torque Nut to 18 in. lb.
Page 31
The software layer password /passphrase can be incorrectly entered four times without issue. On the fifth try if an incorrect password / passphrase is entered, the DTS1 will automatically reboot. There is no limitation to the number of times an incorrect entry /reboot occurs.
Page 32
User Guide DDOC0099-000-AH Check Hardware Layer Status NOTE All values listed below should equal na or 0 for a new DTS1 / RMC module. 1. Check login status Command: cmlogin • init =0 not initialized / =1 initialized • login =0 not logged into / =1 active login Example: cw_dts>...
Page 33
MAC........... Message Authentication Code is a value used to validate messages carrying a key. CM ..........Crypto Module is the circuitry in the DTS1 that manages encryption keys and uses them to encrypt/decrypt data. Install ......... Sending the key from the user’s workstation to the encryption chip serving a specified RMC module slot.
Page 34
NTER Example cw_dts> cmkey -s 0 -d -p --force [cmkey] Please enter plaintext DEK: [User-generated plain text DEK string] Please enter current PSK: [Curtiss-Wright provided PSK string] CMKEY: action=inst slot=0 status=ok [!cmlogin] OK DTS1 CSfC 5 - 4 Encryption Revision 6.0...
Page 35
/ explained in paragraph 5.3.4.3 Status Report. 5.3.4.1 Pain Text DEK Type cmkey --save [0 thru 31] -d [User-generated plain text DEK string] - p [Curtiss-Wright provided PSK string] and press E key. NTER Example (DEK / PSK) cw_dts>...
Page 36
5.3.4.3 Status Report NOTE The DTS1 has only one RMC module available (s0), s1 and s2 will always be unavailable (=0). The cmkey command without options reports key status. To obtain the key status type cmkey and press E key.
Page 37
RMC modules from the field into a lab DTS1. In both cases the keys must be stored or restored in the DTS1 crypto module. To autoload a key type cmkey --auto –s 0 and press E key.
Page 38
The RMC module must have services assigned before the software encryption layer can be initial- ized / entered. The rmcctl -C command allows the user to view and alter the DTS1 disk encryption options. The software encryption layer uses containers to hold the data. Creation of a container requires the use of a password or passphrase.
Page 39
1. Type rmcctl -E and press E key. NTER NOTE After five failed attempts to open the SWE container, the DTS1 will reboot and another five attempts be granted. 2. Enter the password / passphrase and press E key. NTER ...
Page 45
Zeroization affects only the crypto module HWE key. It does not affect the RMC module. The data on the RMC module is still accessible: • If the RMC module can be placed in another DTS1 with the same DEK / EDEK loaded in its crypto module. •...
Page 47
Make sure no power is applied to DTS1 when inserting / removing RMC. NOTE At a minimum, the DTS1 CSfC must have an RMC installed and be connected to both a computer and 28 VDC power source. 1. Turn door latch CCW, open door, and insert RMC into DTS1.
Page 48
Initialization Quick Start Process Flow NOTE The PSK is provided on a removable label placed on top of DTS1 when shipped. 2. Using a 3rd-party application and factory supplied PSK, decrypt user token obtained in step 1. Save resulting decrypted user token for future use / logins.
Page 49
NONE ---- [!rmcctl] OK NOTE DTS1 CSfC units require use of software encryption in addition to hardware encryption. NOTE Disks cannot be partitioned after software encryption has been performed. NOTE The RMC module must have services assigned before software encryption layer can be initialized.
Page 50
---- [!rmcctl] OK 7. Open software encryption container: rmcctl -E 8. When prompted, enter same password / passphrase as previously entered. 9. View RMC status: rmcctl DTS1 is ready to use with CSfC encryption. cw_dts> rmcctl [rmcctl] RMC_S#: hcryp...
Page 51
Setup / Connections NOTE The DTS1 is powered by a user-supplied 28 VDC power supply and does not have a power switch of its own. The DTS1 is powered up by turning on the 28 VDC supply. 1. If not previously accomplished, connect cables to DTS1 connectors (Figure 7.1).
Page 52
Serial port access is recommended for initial configuration of the DTS1. This topic describes how to use the DTS1 Command Line Interface (CLI) to configure the DTS1. Refer to Command Line Interface section for more information on the commands used in this topic.
Page 54
-e eth0 -i [desired IP address] -n [desired netmask] NOTE The DTS1 can be configured as a DHCP client if desired. When configured in this manner, the IP address is set remotely by a DHCP server. 4. Configure the DTS1 as a DHCP client as follows: a.
Page 55
Example cw_dts> sysdate -d yyyy/mm/dd -t hh:mm:ss Login Logging into the DTS1 is a three-part process. Before the RMC module can be accessed or configured, the user must (in the following order): 1. Log into DTS1. 2. Initialize HWE layer.
Page 56
Storage Media NOTE The DTS1 must have the hardware encryption layer initialized and open before the RMC module (storage media) can be accessed. If desired, the RMC module disk can be used without partitioning. The unpartitioned disk must have services started and assigned before formatting and mounting.
Page 64
The DTS1 supports use of Internet Small Computer System Interface (iSCSI). It is configured to use either Ethernet port 0 or port 1. The desired Ethernet port must have an active link before running istarget.
Page 65
PCAP operation as well. The DTS1 supports use of the PCAP command to capture packets traveling over a network. Two data streams may be captured at any one time (Ethernet ports 0 and 1). A unique file name must be used with each recording in order to retain all recordings.
Page 66
[!pcap] OK Health The DTS1 has internal sensors that monitor critical environmental and operational parameters. The software provides this information to the user via the CLI when commanded. A FAIL status will be posted for any values that are out of tolerance.
Page 67
7.8.1 IBIT (Initiated BIT) NOTE Results will be provided as 1 (Pass), 0 (Fail), and NA (function not active) The ibit command provides a snap-shot of the DTS1 status. To view status, type ibit and press key. NTER • IBIT_MON line provides results for system monitor subsystem.
Page 68
The tarball will have to uncompressed and the digital signature verified before loading the files into the DTS1 flash memory. The fupdate command boots the DTS1 system into a RAM disk image where the user can install a new disk image onto the system. Upon logging into the new RAM disk image, a menu of operations to restore and verify the restoration of a new disk image activates.
Page 69
Access from Windows as NAS Device NOTE When the partitions are formatted and mounted, they can be accessed from a PC running Windows. 1. Log into the DTS1 via SSH. Refer to paragraph 7.2.1.2 Ethernet. 2. Type rmcctl and press E key. NTER ...
Page 70
NOTE When the partitions are formatted and mounted, they can be accessed from a PC running Linux. NOTE This procedure is performed via Ethernet connected to DTS1 port 0. 1. Open a terminal window 2. Type ssh admin@192.168.1.1. 3. Press E key.
Page 71
User Guide DDOC0099-000-AH System Configuration The commands below are used to configure the crypto module, DTS1, and associated RMC module. Crypto Module The cmlogin command allows for initialization of / logging into the Hardware Encryption (HWE) crypto module. For status information, issue cmlogin without options. Refer to paragraph 12.3.4 cmlogin for detailed information about initializing /logging into the HWE crypto module.
Page 72
RMC Module NOTE The DTS1 has only 1 RMC module slot. As a result, the -s option is always -s 0. Refer to paragraph 12.3.21 rmcctl and paragraph 12.3.27 serv for detailed information about configuring the RMC module.
Page 74
The chart below provides a basic failure analysis by observing status indicators. If any one of the LEDs exhibits the failure status, the DTS1 may not function properly. The investigative/remedial actions offered should only be tried one or two times. Refer to paragraph 3.1 Chassis Indicators for information regarding front panel LEDs.
Page 75
Encryptor battery dead. Replace battery. Refer to paragraph 11.2 Battery for detailed instructions. Encryptor Error Codes NOTE If problems persist, contact Curtiss-Wright Defense Solutions Customer Support. Refer to paragraph 1.5 Technical Support for contact information. Refer to Table 9.3 for fault information.RMC module Table 9.3...
Page 77
10.1 SNMP MIB The DTS1 supports Simple Network Management Protocol (SNMP). The user may configure SNMP for a Windows workstation via the Windows Control Panel. The user should consult with their network administrator for details on configuration and utilization of the SNMP traps and other data capture programs.
Page 80
If the problem persists, contact Curtiss-Wright Defense Solutions. NOTE Power must be applied to DTS1 for RMC module STATUS LED to turn ON. 7. Open the DTS1 door and observe the RMC module STATUS LED. When green LED turns ON, RMC module is ready. Slide...
Page 81
"-R" option instead of using the Removal button. 1. Rotate the door latch a quarter turn and open the door. 2. If the DTS1 is off, grasp the RMC module handle (Figure 11.2) and pull the unit straight out. NOTE Use rmcctl -r to initiate the removal process via the CLI.
Page 83
Perform packet capture (PCAP) recording to capture network traffic rtp ................RTP video stream recording control and status. reboot ........................Reboot the DTS1 sens*..................... View DTS1 sensor readings serv* ..................DTS1 service control and status utility shutdown ........................Halt the DTS1 sysdate* ..................Configure system time and date 12.2 RMC Module rmcctl* .........................
Page 84
12.3.1 amnt NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The amnt command is used to determine the configuration of the RMC auto mounter/starter daemon. The conditions that allow auto-mounting of NAS RMCs, and the auto-starting of iSCSI targets can be configured.
Page 86
NOTE Place the provided files in the root of the NAS folder (/rmc_shares/rmc0p1). NOTE Curtiss-Wright will be the only entity who provides a firmware update Syntax: cm_field_update [-h | --help | -v | --version] cm_field_update [-f <str>] [-s <str>]...
Page 87
12.3.3 cmkey NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The cmkey command allows for management of keys on the crypto module. For status information, issue cmkey without options.
Page 88
Example: Pass plain text key, load for RMC cw_dts> cmkey -s 0 -d -p [cmkey] Please enter plaintext DEK: [User-generated plain text DEK string] Please enter current PSK: [Curtiss-Wright provided PSK string] CMKEY: action=inst slot=<int> status=<sts> [!cmkey] <summary> Where [dek string] = 32 byte value represented by 64 hex characters [psk string] = 32 byte value represented by 64 hex characters Example: Pass plain text key, save to location 3.
Page 100
DDOC0099-000-AH 12.3.11 info NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The info command displays DTS hardware and software information, such as versions. Syntax info [-h | --help | --version | -R | -M | -A ]...
Page 104
DDOC0099-000-AH 12.3.13 istarget NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The istarget command starts, stops, and reports the status of the iSCSI target server. Syntax istarget [-h | --help | --version] istarget [--start | --stop | --status | --setTargetName <rmc idx>...
Page 107
DDOC0099-000-AH 12.3.15 NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The log command provides access to the DTS log files. Without options, a list of log files is printed.
Page 108
User Guide DDOC0099-000-AH 12.3.16 mbit NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The mbit command executes maintenance built-in tests. Syntax mbit [-h | --help | --version] Options -h, --help ......Print help message.
Page 113
User Guide DDOC0099-000-AH 12.3.19 pcap NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The pcap command controls PCAP recording functions. Syntax pcap [-s] -i interface --start filename [--ov][--filter filters]...
Page 115
12.3.21 rmcctl NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The rmcctl command performs control tasks on the RMCs, such as partitioning, formatting, mounting, and requesting removal. When an action is not requested, the current state is reported.
Page 118
User Guide DDOC0099-000-AH 12.3.22 rmcfree NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The rmcfree command displays RMC storage status and usage. Syntax rmcfree [-h | --help | --version]...
Page 119
User Guide DDOC0099-000-AH 12.3.23 rmcinfo NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The rmcinfo command displays RMC identification and manufacturing data. Syntax rmcinfo [-h | --help | --version]...
Page 121
12.3.24 rmcpurge NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The rmcpurge command allows the user to purge all data on a selected RMC by issuing an ATA Security Erase or ATA Security Enhanced Erase command to the selected storage device.
Page 125
12.3.27 serv NOTE The DTS1 has only 1 RMC slot. As a result, the -s option is always -s 0. Description The serv command allows the user to set the boot configuration for DTS services and to manually start/stop services. When no options are given, the current boot configuration and active status is displayed for all the services.
Page 132
These Mean Time Between Failure (MTBF) values (provided in hours) were calculated using Windchill Quality Solutions Relex 2011 software with MIL-HDBK- 217 FN2, Calculation model and the environmental factors listed. Table A.1 DTS1 / RMC Calculated Mean Time Between Failures Order Number MTBF VS-DTS1SL-F (L-Bracket Mounting) VS-DTS1SL-FD (DZUS Panel Mounting) Ground Benign / Controlled @ 20°C...
Page 133
User Guide DDOC0099-000-AH Table A.1 DTS1 / RMC Calculated Mean Time Between Failures Order Number MTBF VS-RMC4096M-00 (4 TB) Ground Benign / Controlled @ 20°C 173,040 Ground Mobile @ 30°C 68,654 Naval Sheltered @ 20°C 80,268 Airborne Uninhabited Cargo @ 30°C 42,964 Airborne Uninhabited Fighter @ 30°C...
Page 134
The Curtiss-Wright Data Transport System (DTS) was evaluated with respect to MIL-STD-461F electromagnetic interference (EMI) requirements. Testing was performed in accordance with the Standard. The DTS1 has passed and therefore complies with all of the following EMI requirements. The equipment was evaluated with respect to the following MIL-STD-461F requirements.
Page 135
Power Connector J1 / Power Lab Cable Table B.1 provides DTS1 bulkhead J1 connector pin signals. Figure B.1 show the DTS1 bulkhead J1 connector pinout. Table B.2 shows the DTS1 power lab cable connection pin signals. Figure B.1 show the power lab cable wiring diagram.
Page 136
Utility Connector J2 / Utility Lab Cable Table B.3 provides DTS1 bulkhead J2 connector pin signals. Figure B.3 show the DTS1 bulkhead J2 connector pinout. Table B.4 shows the DTS1 utility lab cable connection pin signals. Figure B.4 show the utility lab cable wiring diagram.
Page 139
Ethernet Lab Cable Wiring Diagram Ground Lug A ground cable is required, but not provided. The ground cable is installed on the DTS1 ground lug E1. The provided nut should be torqued to 18 in. lb. to ensure proper connection.
Page 140
DTS1 / RMC Module / Lab Cables This appendix contains the ordering numbers for the DTS1 CSfC chassis (Table C.1), RMC module (Table C.2), lab cables (Table C.3), and crypto battery (Table C.4). For an up to date list, or...
Need help?
Do you have a question about the DTS1 and is the answer not in the manual?
Questions and answers