User's Manual Part 1

Introduction
3
The "TopSec 701" provides a mobile employee with secure
access to data in the head office. It has been implemented as
a PCMCIA card and behaves like a modem card.
All information transmitted via the" TopSec 701" can be encrypted.
A modem has not been integrated into the "TopSec 701" but
rather is connected externally. This provides the greatest flexibility
since any modem can be connected to the serial port. Mobile
telephones which contain modem functionality can be connected
through the infrared (IrDA) interface.
When using devices from the TopSec family, data which is to
be transmitted between two TopSec devices over a public
network can be encrypted. Therefore between two TopSec 701
devices any data can be exchanged in an encrypted form as
long as the connecting modems can communicate with each
other. In addition it is possible to exchange data between
"TopSec 701" devices and TopSec devices in an ISDN network
(TopSec 703/730). Top Sec ISDN devices support V.110 protocol
for adapting the data rate of the modem connected to the
"TopSec 701".
Operating
In the factory the devices are configured so that they can
communicate in a so-called public user group. The "TopSec 701"
can be operated encrypted or unencrypted. The type of operation
is chosen by a mode number which is prefixed onto the telephone
number of the remote end when dialing.
Additional security is provided by the administration of a TopSec
device. The device is given an individual certificate from the
administrator site (accessory). The device checks the certificate
from the remote site after a connection has been established.
In this way closed systems can be established. Issuing
certificates and assigning rights is done by the customer from
the administrator site.
Introduction
Product Description
Encryption
TopSec devices work according to public key procedures. This
makes key management easier for the user. The user data is
encrypted using a symmetrical algorithm according to a
procedure developed by Siemens. This algorithm uses a 128 bit
key. Both partner devices need the same key for this procedure.
This is achieved by Diffie Hellmann key negotiation procedures
using random numbers. The Diffie Hellmann procedure works
with TopSec devices using a 1024 bit key. After the symmetric
key's period of use is over, the key is deleted and re-created
at the next connection.
An authentication is additionally carried out for administration
devices. This is done according to the RSA procedure. This
procedure also uses a 1024 bit key.
c
Siemens AG
Remote Devices
"TopSec 701" serves to protect the transmission of any
electronic data from access by third parties in public
communications networks. Example: Safe transmission of
confidential information to mobile employees.
Applications
Mobile phones with integrated modem function.
Terminal adapter with V.110 support.
Analogue modems (no connection to TopSec ISDN devices).
TopSec 701