Summary
USB security devices like dongles, HSMs and smart cards were designed to be physically present, but managing them at the endpoint creates real security and operational risks. Digi AnywhereUSB Plus solves this by centralizing those devices in a locked rack and delivering access over IP using USB over IP technology — so users connect to the device they need, do their work and disconnect, with no physical handling required. Every session is encrypted and authenticated via Digi TrustFence, access is always exclusive to one user at a time and the setup is fully compatible with existing applications, virtual machines and RDP environments.
USB security devices — dongles, HSMs, smart cards and FIDO tokens — were designed to be physically present. That assumption no longer works.
Managing USB security devices across an organization is harder than it looks. Most organizations still handle them the old way: a device plugged into a workstation, passed between people, locked in a desk drawer overnight, or left connected to a machine nobody monitors. It works until it does not. A misplaced dongle brings down a license server. A lost token disrupts authentication for an entire team. A USB port on an unattended machine becomes an attack surface no one thought to audit.
There is a better architecture. It is not new technology. It is a discipline problem with a hardware answer.
What Is USB Over IP?
USB over IP, sometimes called USB device virtualization or USB-over-Ethernet, lets a host machine access a physically remote USB device as if it were locally attached. The device lives in one place. The software sees it somewhere else.
The mechanics are straightforward. A USB hub connects to the IP network. Software on the host machine establishes a session to a device group on that hub. The operating system enumerates the USB device normally. Applications interact with it exactly as they would with a device plugged directly into the machine.
When the session ends, the device is released. The next user can connect.
That is the entire model. Physical security is preserved because the hardware never moves. Logical access is controlled because sessions are authenticated and exclusive.

Why USB Security Device Management Matters
Auditors across frameworks including ISO 27001, SOC 2 and PCI-DSS increasingly ask about endpoint USB controls. Most organizations cannot answer confidently.
A license dongle sitting on a developer's desk is a physical asset on an uncontrolled endpoint. Anyone with access to that desk has access to that dongle.
HSMs and smart card tokens carry higher stakes. They hold private keys, signing credentials or authentication certificates. Physical access to the token can mean physical access to what it protects. Keeping those devices in a locked rack, where no user has physical contact, is not paranoia. It is basic access control.
Programming tools and hardware security keys have the same problem. One device serves multiple users. Sharing means whoever has it last has it until someone asks for it back. There is no enforcement, no audit trail, no exclusivity guarantee.
USB Security Device Virtualization Solves This at the Architecture Level, Not the Policy Level
How Digi AnywhereUSB Plus Works

Digi AnywhereUSB Plus is a network-attached USB hub that uses USB over IP technology to give host machines secure, centralized access to USB security devices over a standard LAN. Devices connect to the hub's ports. The hub connects to the IP network. Users access devices through the Digi AnywhereUSB Manager software running on their PC, VM or server.
Three hub models cover the range of deployment sizes:
- AW02: 2 ports. Desktop or panel-mount. Single workstation or developer bench.
- AW08: 8 ports. Desktop or rack. Departmental dongle pool or shared HSM access.
- AW24: 24 ports. 1U rack-mount, dual power supplies, dual Ethernet for redundancy. Data center infrastructure and license server farms.
All models support USB 3.1 Gen 1 compatible devices or lower and Gigabit Ethernet. The AW08 and AW24 add 10G Ethernet and SFP+ options. The AW24 supports Ethernet bonding for failover.
Access is exclusive by design. A device group can only be held by one client at a time. Disconnect releases the group immediately. No manual coordination. No waiting for someone to remember to unplug it.
Digi AnywhereUSB Plus Deployment Patterns
Interactive Users on Linux or Windows
A developer needs a code-signing dongle. A security engineer needs an HSM token. The device lives in the locked rack. The user opens Digi AnywhereUSB Manager, connects to the group holding the device, runs their tooling and disconnects when done. The group is immediately available for the next person.
Digi AnywhereUSB Manager works the same on Linux, whether graphical or headless, and on Windows. No special drivers are required beyond the Manager software. Existing USB device workflows are unchanged.
Unattended VMs in Service Mode
License servers, build agents and encryption services often need a USB device present before any user logs in. Running Digi AnywhereUSB Manager as a Windows service handles this. It connects to the device group at startup, before user login. The device enumerates as locally attached. If the network drops or the hub reboots, the Manager reconnects automatically. No human action required.
This is the pattern for always-reliable infrastructure, where a gap in USB device availability means a gap in service.
Windows Workstations in Enterprise Environments
The mechanics are the same as the Linux case, with one additional note: on Windows, device groups are accessible via right-click in the Manager tray icon. Connect. Work. Disconnect. The power-cycle-on-disconnect behavior built into AW02 and AW08 ensures security devices are properly reset between sessions, which many devices require.
Remote Desktop Sessions and Digi AnywhereUSB RDP

RDP USB redirection is the deployment pattern that causes the most confusion. Here is what you need to know.
Microsoft's RDP architecture redirects USB devices from the client side into the remote session. It does not redirect from the server side. This is by design and cannot be changed.
If you install Digi AnywhereUSB Manager on the RDP server, it will not work. The device needs to appear local to the client machine. RDP then redirects it into the remote VM session normally.
Digi AnywhereUSB Plus makes the correct architecture simple to implement. Digi AnywhereUSB Manager runs on the local PC. It connects to the hub over IP. The USB device appears locally attached. The user opens an RDP session. RDP redirects the device class, whether smart card, RemoteFX or WebAuthn, into the remote session. Applications on the remote VM see the device as expected.
This is the only architecture that works for USB security device access in RDP environments. Digi AnywhereUSB Plus makes it reliable.
What Stays the Same When You Deploy Digi AnywhereUSB Plus
The most common concern about any USB-over-IP implementation is compatibility. The question IT teams ask: will our applications still work?
Yes. The operating system sees a locally-attached USB device. Applications have no visibility into whether that device is physically present or accessed over the network. Code-signing tools, VPN clients, license managers, authentication clients and hardware programming utilities interact with the device driver the same way they always have.
Device-specific behavior is preserved. The USB descriptor, device class and protocol are identical to a direct connection. If your application worked before, it works over Digi AnywhereUSB Plus.
How Digi TrustFence Secures USB Over IP Deployments
Digi AnywhereUSB Plus uses Digi TrustFence, which means USB-over-IP traffic is encrypted and authenticated by default. This is not optional and cannot be disabled, which is the right default for security-critical devices.
Beyond traffic encryption:
- Each hub has a unique password out of the box.
- Each Manager instance gets a unique Client ID; the hub enforces exclusivity based on it.
- Network services (mDNS, HTTP/HTTPS and SSH) are individually configurable.
Management through Digi Remote Manager gives visibility into hub health, firmware status and device settings from a central dashboard.
One-year Digi LifeCycle Assurance with 24x7 expert support is included with every Digi AnywhereUSB Plus hub.
USB Security Devices at the Endpoint: A Risk You Can Eliminate

A dongle on a workstation costs nothing to set up and fails on a Tuesday when the person who had it last is out of office.
A USB security device centralized on a Digi AnywhereUSB Plus hub, in a locked rack, accessible over IP with encrypted and authenticated sessions, is a recoverable, auditable and manageable asset.
The hardware cost is a one-time decision. The operational cost of leaving USB security devices at the endpoint accumulates quietly until it doesn't: lost tokens, shared credentials, audit gaps, service disruptions.
Frequently Asked Questions
Can two users access the same USB security device at the same time on Digi AnywhereUSB Plus?
No. Digi AnywhereUSB Plus enforces exclusive group access. Only one client can hold a device group at a time, and that group is unavailable to all other users until they disconnect. Disconnect releases the group immediately, making it available to the next user without any manual coordination.
How is USB over IP traffic secured against interception on the network?
Digi AnywhereUSB Plus uses Digi TrustFence to encrypt and authenticate all USB-over-IP traffic by default. This encryption is built in and cannot be disabled, making it appropriate for environments handling sensitive credentials, private keys and authentication certificates. Each hub ships with a unique password and each Digi AnywhereUSB Manager instance is assigned a unique Client ID, ensuring that even on a shared network, only authorized clients can establish a connection to a device group.
Does Digi AnywhereUSB Plus work with VMware and virtual environments?
Yes. Digi AnywhereUSB Plus is specifically designed and tested for virtualized environments including VMware. USB devices connected to the hub appear as locally attached to virtual machines running on remote hosts. Existing VM configurations, applications and workflows require no changes, as the operating system enumerates the USB device exactly as it would with a directly connected peripheral.
Where do I install Digi AnywhereUSB Manager when using RDP?
Install Digi AnywhereUSB Manager on the local PC, not the RDP server. Microsoft's RDP architecture redirects USB devices from the client side into the remote session, not from the server side. With the Manager running on the local PC, the USB device appears locally attached and RDP redirects it into the remote session normally, whether the device is a smart card, RemoteFX token or WebAuthn key.
What security certifications and compliance frameworks does Digi AnywhereUSB Plus support?
Digi AnywhereUSB Plus is built on the Digi TrustFence security framework, which aligns with FIPS 140-3 for government and military environments, PCI-DSS for retail and HIPAA for healthcare. All USB-over-IP traffic is encrypted and authenticated by default and cannot be disabled. Device groups are assigned to specific users or teams, making Digi AnywhereUSB Plus a defensible choice for regulated environments where USB device access needs to be both controlled and verifiable.
How do I choose between the AW02, AW08 and AW24 models?
The right model depends on the scale of your deployment and your resilience requirements. The AW02 is ideal for individual workstations or small developer environments needing two centralized USB ports over Gigabit Ethernet. The AW08 steps up to eight ports with 10G Ethernet, SFP+ fiber support and optional LTE cellular connectivity via a Digi CORE module, making it well suited for departmental or shared security device pools. The AW24 is built for data center and enterprise environments, with 24 ports, dual redundant power supplies and dual 10G Ethernet for failover. All three models include Digi TrustFence security and one year of Digi LifeCycle Assurance.