Jump to content

Document:10-1163 Key Load Procedure

From Calamity Wiki
Revision as of 15:33, 13 September 2026 by Vertex (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

KEY LOAD PROCEDURE (HARDLINE 10-SERIES)

This procedure must be performed with a 10-series Key Directive Loader (KDL) that is Load Authority (LA) certified. KDLs that are only Command Authority (CA) Certified CANNOT be used to perform key load operations, and will not display the Load submenu in the Material menu. 10-series KDLs with Load Authority (LA) will be marked with a PURPLE stripe, and display a serial number starting with "LAS". For further advice, please contact Metatron support.

Notice: This procedure must be carried out by appropriately trained and cleared personnel and not deviated from except when approved. Metatron is not responsible for injuries or fatalities sustained by personnel operating hardware in a negligent or improper manner. While handling the module, keep all areas marked with a yellow cross clear and do not touch them; contact with these areas risks setting off module tamper alarms.

  1. Follow Section 25-A: KDL Attachment Procedure.
  2. Follow Section 31-A: Module Offline Procedure.
  3. Select Material > Load > New.
  4. Wait for the Ready for material load message to appear on the KDL display.
  5. Follow section 26-A: RT Attachment Procedure.
  6. The KDL display changes to display the RT serial, expiry, and contents. Confirm the presence of the key to be loaded, as well as its serial and classification level.
  7. Select Preload. You will be prompted to re-enter your SAM PIN.
  8. The module runs its checks against the key.
    1. If you receive Code E-206, the classification level of the module is insufficient to load the key material. The key load cannot continue.
    2. If you receive Code E-207, the required cryptographic algorithm for the key is not installed in the module, or the authority to use said algorithm has expired. Contact Metatron to request installation or renewal.
    3. If you receive Code E-210, the module secure memory is full and cannot accommodate the qubit length of the new key. Consider zeroizing any keys that are no longer needed (Material > Destroy > Zeroize) or use a different module.
    4. If you receive Code E-300, the RAC Residency Policy (RRP) determined the module does not fulfil the Module, Location, or Time requirements set on the key policy. View the details of the policy violation to diagnose the issue.
    5. If you receive Code E-306, the current SAM credential is not authorised to load the key. Contact Internal Security if necessary to ensure the validity of the SAM.
    6. If you receive Code E-310, the Tree Root Key (TRK) loaded in the module is a mismatch for the TRK that wraps the key. Contact Metatron support.
    7. If you receive Code E-500, contact Metatron support.
  9. Re-confirm all details of the key on the Confirm Load page.
    1. If the KDL displays RT Burn Notice, the policy set on the key or RT requires the RT be burned (erased) subsequent to the key load operation. Ensure that you intend to burn the key before continuing.
  10. Select Load.
  11. Wait for Confirm material actuation on MFP to appear on the KDL display.
  12. Follow section 6-A: Confirm Command.
  13. Confirm the KDL displays Key Load Success.
  14. Follow section 26-B: RT Removal Procedure.
  15. Follow Section 31-B: Module Online Procedure.
  16. Follow Section 25-B: KDL Removal Procedure.

6-A CONFIRM COMMAND

  1. The Pending Command (PC) light on the MFP begins flashing blue.
  2. On the MFP keypad, press the EXECUTE key.
    1. Note that there is a 10-second window to confirm the operation. If this window expires, the module will delete the pending command and the KDL will display an error.

25-A KDL ATTACHMENT

  1. Use the physical operator key to unlock each side of the Module Front Panel (MFP) cover.
  2. Locate the DTL-38999 port marked "KDL" and remove the dust cover.
  3. Connect the KDL to the DTL-38999 to the KDL port using a Type-A shielded cable, and ensure both ends of the cable lock into position. WARNING: Ensure the KDL is powered OFF before making or breaking connections with the module.
  4. Power on the KDL. Slide your Raven badge (smart card) or other SAM-based identity card into the IDENT slot on the KDL, and enter your PIN. Confirm the KDL enters the unlocked state.

25-B KDL REMOVAL
25. Disconnect the KDL from the KDL port and replace the dust cover.
26. Close and lock the Module Front Panel (MFP) and re-lock using the operator key.

26-A RED TOKEN ATTACHMENT
5. Locate the port marked "KEY" on the module and remove the dust cover.
6. Remove the source Red Token (RT) from its Standard Shielding Enclosure (SSE). Confirm the serial number printed on the side of the RT matches your job audit documentation.
7. Push the RT into the KEY port on the module until it clicks into place.
1. If the module display flashes Code E-105, the module port has detected an improper electromagnetic seal between the chassis and the RT. If you have heard a click, try removing the RT from the port and re-inserting it after gently cleaning the electromagnetic gasket. If the error continues to persist, the gasket may be damaged; contact Metatron and order a replacement for FRU 112-81088005.
2. If the module display flashes Code E-110, the module is unable to communicate with the RT hardware. Try removing the RT from the port and re-inserting it. If the error persists, either the RT or the port may be damaged; contact Metatron support.
3. If the module display flashes Code E-121, the module is unable to communicate with the RT because one or both sides of the token-core key exchange (TCKE) failed. The token cannot be used; contact Metatron support.

26-B RED TOKEN REMOVAL

  1. Remove the RT from the KEY port.
  2. Replace the RT within its Standard Shielding Enclosure (SSE).
  3. Replace the KEY port dust cover.

31-A OFFLINE MODULE

  1. Confirm the module control display shows 10-1163 Online.
  2. Select Module > State > Modify. Select Offline. Wait for the Confirm mode actuation on MFP message to appear on the KDL display.
    1. If you receive Error: Pending transactions in progress, ensure all users of the module have disconnected.
  3. Follow section 6-A: Confirm Command.
  4. Confirm the module control display shows 10-1163 Offline.

31-B ONLINE MODULE

  1. Confirm the module control display shows 10-1163 Offline.
  2. Select Module > State > Modify. Select Online. Wait for the Confirm mode actuation on MFP message to appear on the KDL display.
  3. Follow section 6-A: Confirm Command.
  4. Confirm the module control displays shows 10-1163 Online.

ALGORITHM LOAD (HARDLINE 10-SERIES)

This procedure MAY be performed with either a Load Authority (LA) or Command Authority (CA) KDL. It may not be performed with an Audit Authority (AA) KDL.

  1. Follow Section 25-A: KDL Attachment Procedure.
  2. Follow Section 31-A: Module Offline Procedure.
  3. Select Module > Algorithms > Load.
  4. Wait for the Ready for algorithm load message to appear on the KDL display.
  5. Follow section 26-A: RT Attachment Procedure.
  6. The KDL display changes to display the RT serial, expiry, and contents. Confirm the presence of the algorithm to be loaded, as well as its serial and classification level.
  7. Select Load.
  8. You will be prompted for the 32-character Activation code, which is generated by Metatron support and unique to each module and cipher binding. This value is case insensitive
  9. You will be prompted for the 64-character ECMS Codebook value. Refer to current Internal Security guidance for more information.
  10. Wait for Confirm firmware actuation on MFP to appear on the KDL display.
  11. Follow section 6-A: Confirm Command.
  12. Confirm the KDL displays Algorithm Load Success. The module then reboots.
  13. Follow section 26-B: RT Removal Procedure.
  14. Wait for the restart to complete.
  15. It is best practice to run an algorithm test as outlined in Section 61-A.
  16. Follow Section 31-B: Module Online Procedure.
  17. Follow Section 25-B: KDL Removal Procedure.
  18. It is now possible to generate and load key material under the relevant algorithm.

MODULE DEPLOYMENT (HARDLINE 10-SERIES)

This procedure MUST be performed with an


Activation code: Support generated value that specifies the license entitlement (authority) to use that algorithm together with that specific module.

ECMS Codebook value: Acts as an algorithm customiser sort of part of an “IV” for all keys. There is one codebook value per algorithm, per Tree Root Key (master organisational unit key, that is loaded into the module). It is not key material, but it is secret.


Hardline Module Lifecycle

  1. Manufacturing: The module is manufactured at the factory by Metatron.
  2. Certification: The module is transported to a Raven CERT facility where the supply chain security of its production is verified.
  3. Arming: Conventional or antimatter charges are loaded alongside the module’s fission batteries. The module is sealed and armed under the supervision of a Technical Systems Crypto Engineer. Once sealed and armed, its Endorsement Key is loaded by the CE. The two Module CIKs are also generated by TechSys. Afterwards, the module is returned to Metatron.
  4. Transport: The module is transported to the internal (i.e. AS, SIO, Reality Control) or external (i.e. IRTO, CORE) customer.
  5. Activation: The customer loads the initial algorithm set and permanently binds the module to their root keys. Two Metatron engineers perform the activation in cooperation with the customer. The module is now ready for use.
  6. Configuration: The customer configures the module for their needs.
  7. Key loading: The customer loads their operational key set to begin using it.
  8. Decommissioning: At the end of its lifecycle, the module is returned to TechSys for controlled destruction.

License authority

A RAC license does not refer to a commercial license to use a specific algorithm. Rather, it refers to the authority granted by Raven to an organisation intending to use RAC-II or RAC-III cryptography. For external (non-Raven) customers, this authority must be renewed on a regular basis, as an organisation’s authority is tied to their Dimensional Research Agreement or General Services Agreement contract and may lapse. If an algorithm authority is allowed to lapse, the Hardline module will no longer process cryptographic operations until a new activation code is presented.