Document:10-1163 Key Load Procedure
KEY LOAD PROCEDURE (HARDLINE 10-SERIES)
This procedure must be performed with a 10-series Key Directive Loader (KDL) that is Load Authority (LA) certified. KDLs that are only Command Authority (CA) Certified CANNOT be used to perform key load operations, and will not display the Load submenu in the Material menu. 10-series KDLs with Load Authority (LA) will be marked with a PURPLE stripe, and display a serial number starting with "LAS". For further advice, please contact Metatron support.
Notice: This procedure must be carried out by appropriately trained and cleared personnel and not deviated from except when approved. Metatron is not responsible for injuries or fatalities sustained by personnel operating hardware in a negligent or improper manner. While handling the module, keep all areas marked with a yellow cross clear and do not touch them; contact with these areas risks setting off module tamper alarms.
- Confirm the module control display shows
10-1163 Online. - Use the physical operator key to unlock each side of the Module Front Panel (MFP) cover.
- Locate the DTL-38999 port marked "KDL" and remove the dust cover.
- Connect the KDL to the DTL-38999 to the KDL port using a Type-A shielded cable, and ensure both ends of the cable lock into position. WARNING: Ensure the KDL is powered OFF before making or breaking connections with the module.
- Power on the KDL. Slide your Raven badge (smart card) or other SAM-based identity card into the IDENT slot on the KDL, and enter your PIN. Confirm the KDL enters the unlocked state.
- Select
Module > State > Modify. Select Offline. Wait for theConfirm mode actuation on MFPmessage to appear on the KDL display. - The Pending Command (PC) light on the MFP begins flashing blue.
- On the MFP keypad, press the EXECUTE key.
- Note that there is a 10-second window to confirm the operation. If this window expires, the module will delete the pending command and the KDL will display an error.
- Confirm the module control display shows
10-1163 Offline. - Select
Material > Load > New. - Wait for the
Ready for material loadmessage to appear on the KDL display. - Locate the port marked "KEY" on the module and remove the dust cover.
- Remove the source Red Token (RT) from its Standard Shielding Enclosure (SSE). Confirm the serial number printed on the side of the RT matches your job audit documentation.
- Push the RT into the KEY port on the module until it clicks into place.
- If the module display flashes
Code E-105, the module port has detected an improper electromagnetic seal between the chassis and the RT. If you have heard a click, try removing the RT from the port and re-inserting it after gently cleaning the electromagnetic gasket. If the error continues to persist, the gasket may be damaged; contact Metatron and order a replacement for FRU 112-81088005. - If the module display flashes
Code E-110, the module is unable to communicate with the RT hardware. Try removing the RT from the port and re-inserting it. If the error persists, either the RT or the port may be damaged; contact Metatron support. - If the module display flashes
Code E-121, the module is unable to communicate with the RT because one or both sides of the token-core key exchange (TCKE) failed. The token cannot be used; contact Metatron support.
- If the module display flashes
- The KDL display changes to display the RT serial, expiry, and contents. Confirm the presence of the key to be loaded, as well as its serial and classification level.
- Select
Preload. You will be prompted to re-enter your SAM PIN. - The module runs its checks against the key.
- If you receive
Code E-206, the classification level of the module is insufficient to load the key material. The key load cannot continue. - If you receive
Code E-207, the required cryptographic algorithm for the key is not installed in the module, or the authority to use said algorithm has expired. Contact Metatron to request installation or renewal. - If you receive
Code E-210, the module secure memory is full and cannot accommodate the qubit length of the new key. Consider zeroizing any keys that are no longer needed (Material > Destroy > Zeroize) or use a different module. - If you receive
Code E-300, the RAC Residency Policy (RRP) determined the module does not fulfil the Module, Location, or Time requirements set on the key policy. View the details of the policy violation to diagnose the issue. - If you receive
Code E-306, the current SAM credential is not authorised to load the key. Contact Internal Security if necessary to ensure the validity of the SAM. - If you receive
Code E-310, the Tree Root Key (TRK) loaded in the module is a mismatch for the TRK that wraps the key. Contact Metatron support. - If you receive
Code E-500, contact Metatron support.
- If you receive
- Re-confirm all details of the key on the
Confirm Loadpage.- If the KDL displays
RT Burn Notice, the policy set on the key or RT requires the RT be burned (erased) subsequent to the key load operation. Ensure that you intend to burn the key before continuing.
- If the KDL displays
- Select
Load. - Wait for
Confirm material actuation on MFPto appear on the KDL display. - The Pending Command (PC) light on the MFP begins flashing blue.
- On the MFP keypad, press the EXECUTE key.
- Note that there is a 10-second window to confirm the operation. If this window expires, the module will delete the pending command and the KDL will display an error.
- Confirm the KDL displays
Key Load Success. - Remove the RT from the KEY port.
- Select
Module > State > Modify. Select Online. Wait for theConfirm mode actuation on MFPmessage to appear on the KDL display. - The Pending Command (PC) light on the MFP begins flashing blue.
- On the MFP keypad, press the EXECUTE key.
- Note that there is a 10-second window to confirm the operation. If this window expires, the module will delete the pending command and the KDL will display an error.
- Confirm the module control displays shows
10-1163 Online. - Disconnect the KDL from the KDL port and replace the dust cover.
- Close and lock the Module Front Panel (MFP) and re-lock using the operator key.