Quick Start Guide

Table Of Contents
Core Service Quick Start Guide
Page 22 of 45
9 Setup Security
The security concept is based on individual registration codes for each label. Not only that the new
concept simplifies installations, it also provides stronger encryption and a secure key exchange with
individual communication key derived from a user defined network key.
9.1 General encryption features and how does it work
l Solid improved safety
l Encrypted data type AES128 (Advanced Encryption Standard)
l User defined 128 bit network key for each installation
l Key is distributed to labels automatically
The system requires a user defined 128 bit network key for each installation. The key is derived from a
passphrase that is defined by the customer and stored in the SES-imagotag Core Service and used
by all ESL access points connected to that SES-imagotag Core Service to encrypt data
communication to the labels.
A per-label communication key is transmitted to the labels during the registration of them. Each label
is assigned an individual registration code (it combines label ID and PIN code and it’s an
alphanumeric case-sensitive code with 11 characters). The SES-imagotag Core Service will than
automatically start the key exchange with the label secured by the PIN extracted from the registration
code.
9.2 Set the encryption key
First step is to set the parameter “encryptionPassphrase“under System Configuration (you can
choose the encryption passphrase on your own).
FIGURE 1-18: Set encryption key
Note: Do not change encryption passphrase if labels are already connected and encrypted (if you
want to change the encryption passphrase you’ll first have to unlock all labels see Troubleshooting
on page 36).