Chip PC Thin Clients  
 
     
Jack PC
Overview
Accessories
Resources
FAQs
Technical Support
Training Center
Next Steps
How to Buy
Contact Us
Home > Products > Jack PC Thin Client
Frequently Asked Questions

Flex-Jack PoE Functionality
Peripherals Security  
     
Security
What security benefits Flex-Jack provides?
There are several key security features: a. Physical securing of devices to the network (no exposed LAN connections) b. Physical securing of devices to the wall c. Always-on security scheme d. Location Authentication technology to match between devices and physical locations
Return to Top

How can I manage Jack-PC USB security risks?
Chip PC provides the strongest USB protection locking at the lowest level (bellow OS and BIOS). Chip PC solution is part of the system security certification and is based on the following features: 1. Option to block USB port for any USB device other than keyboard and mouse. Option to enable only printers. 2. Option to block USB by users (Group policy applied per user) 3. Option to block USB by device (Group policy applied per device) 4. Option to authenticate connected storage device (PKI) 5. Unauthorized USB device is disabled by shutting down power to that port. 6. Keyboard authentication option to avoid logging keyboards / modified keyboards (based on unique keyboard ID) 7. Detection of USB sniffer and USB logger devices 8. Detection, logging and security events detection of any USB connection / disconnection by Xcalibur Global security manager 9. Storage device can be mapped locally (to the device) or to the session through policy.
Return to Top

Can Jack-PC user change the device settings?
Typically not - administrators can easily control through policies the level of user settings that they will open to their users. This can vary from nothing (all locked) to full access to local settings and connections.
Return to Top

Can Jack-PC user / administrator access the device storage or RAM in any way?
No. There is no access (read or write). These resources are not accessible to anyone.
Return to Top

Does Jack-PC contain any user information after the user is logging off?
No. All user information is completely deleted. This includes user credentials and connection caching.
Return to Top

Can Jack-PC user load software to the device?
No. All device loadable software components (images, XPIs, hot-fixes) are componentized and encapsulated featuring strong signature to assure that no other (unauthorized) code can be loaded.
Return to Top

How secure is the Jack-PC management solution? Can management traffic be encrypted?
The Jack-PC management system called Xcalibur Global is by far the most secured client management solution in the market. This system security features including: a. Management and thin-client image passed many security certifications including Common-Criteria to level 5. Same management system is widely in used by leading intelligence and defense agencies worldwide. Special product derivatives are available for TEMPEST applications and field tactical deployment. b. Xcalibur Global uses an Independent Management Protocol (XIMP) that has built-in support for secured (SSL) communication, multiple data encryption levels, compression, port number and bandwidth control. c. Range of standard and proprietary management traffic encryption including SSL and 128 bit AES. d. Xcalibur Global is the only thin-client management solution that fully implemented and uses Windows Security. e. Option to map encryption method by physical layout (farm or IP scopes). f. Strong device authentication using unique components ID and special OTP areas. Chip PC have several patents in the area of strong device authentication. This technology is the only technology available in any desktop / thin-client to assure very strong client device authentication. g. Xcalibur Global together with strong device authentication technology ensures that only authorized (registered) Thin Client devices can be connected to the system and used. Xcalibur Global enables applying various rules and settings on both unauthenticated and authenticated devices. For example, Xcalibur Global automatically locks unauthenticated devices.
Return to Top

Does Jack-PC support smart-cards?
Yes. External USB based smart-card readers can be connected to the Jack-PC to authenticate users. Currently SCM readers are supported.
Return to Top

Do I need to buy a special lock to secure the Jack-PC to the wall?
No. The lock is an integrated part of the Jack-PC.
Return to Top

How can I protect the Jack-PC from being stolen?
Jack-PC is locked in its Flex-Jack by special security lock and therefore requires a special key to for removal. Unauthorized removal of the device can be detected in real-time by the management system. Devices with matched keys can be ordered specially to manage locks per site / project.
Return to Top

<< | 1 | 2 | 3 | >>

 
Copyright Chip PC. All rights reserved.