Air-gapped systems and the AIC kits
Analog Informatics Corporation (AIC) kits run on air-gapped systems. An air-gapped system is isolated from general network reach. The same kits run where a general network connection exists. The agent still rotates credentials, propagates changes, and handles validated elevation in both cases.
What stays available when the system is air-gapped
| Work | Kit module |
|---|---|
| Rotate and vault credentials | Privileged Identity Management |
| Elevate and delegate privilege | Privileged User Management |
| Connect and broker a session inside the boundary | Privileged Access Management and Jump |
| Record evidence | Assessment Binder and Audit |
| Check configuration against a baseline | Configuration compliance |
| Monitor configuration compliance and raise alerts inside the boundary | Incident Response and Current State Compliance |
| Bring in outside threat feeds | Incident Response |
A secure enclave is a common place to run these kits. The enclave can be air-gapped or generally connected. See Secure enclaves.
Two ways to run
| Mode | What it means |
|---|---|
| Connected | The AIC Agent talks to AIC Server |
| Fully air-gapped | The Agent never reaches AIC Server. Rotation, elevation, and audit run on the system itself |
Password rotation with no server connection
High-security sites and sites that are normally disconnected still need passwords that change on a schedule. The AIC Agent does this on the system itself, with no connection to AIC Server or any outside service.
- Share a seed - When the system is enrolled, AIC Server and the Agent share a cryptographic seed. Both sides keep the seed in protected storage.
- Derive on schedule - When a password is due, the Agent derives the next password from the seed, the account, and a change counter, using HMAC-SHA256. No network is needed.
- Apply locally - The Agent sets the new password with the native method on each platform: the Windows account interface,
chpasswdon Linux, anddsclon Apple Mac. - Propagate locally - The Agent runs the local propagation steps so services and applications on the system pick up the new password.
- Record - The Agent writes the change to its local audit record.
- Recover when needed - An authorized administrator derives the same current password from AIC Server, so the password is never stored in a vault to be stolen.
Capability
- Time-based automatic rotation from a shared seed, with no server connection
- Local propagation to services and applications on the system
- Password recovery by an authorized administrator without storing the password
- Signed rotation and elevation packages carried across the air gap on approved media, refused if they cannot be verified
Elevation on air-gapped and connected systems
Elevation works on the local system through the Agent or by remote control from AIC Server. On an air-gapped system the Agent checks a one-time activation code, a challenge and response, or a signed grant package on the system itself. On a connected system AIC Server can push a signed grant, or run the elevation job over WinRM or SSH with no agent on the target. Every grant ends on time and is recorded. See Privileged User Management.
Any platform, any environment
Where it runs
- AIC Agent on Windows, Linux, and Apple Mac
- AIC Server on Windows, Linux, and Apple Mac
- On premises, in customer-controlled cloud infrastructure, in virtual machines, and in Docker and Kubernetes
Events can stay inside the boundary: the audit trail, the Windows Event Log, and syslog to a collector on the site. See Logging, SIEM, and event forwarding.
Screenshots
More on Product screenshots.
Related References
- CMMC: Kits, Level 1, Level 2, Level 3, Defense contractors, C3PAO
- Defense contract requirements: SPRS score, DFARS 252.204-7012, DFARS 252.204-7021, NIST SP 800-171 self-assessment, CUI marking, CMMC Phase 2