CryptMate64 USB Cryptgraphic Tken Technical Specificatins V1.03 Subject t change withut prir ntice inf@acs.cm.hk www.acs.cm.hk
Table f Cntents 1.0. Intrductin... 3 2.0. Features... 4 2.1. Cryptgraphic Smart Card and Crypt-prcessr Features... 4 2.2. Tken Features... 4 3.0. Typical Applicatins... 5 4.0. Middleware... 6 5.0. Technical Specificatins... 7 List f Figures Figure 1 : CryptMate64 System Blck Diagram... 3 Figure 2 : Middleware Diagram... 6 Page 2 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk
1.0. Intrductin CryptMate64 is a lightweight USB tken that prvides users with strng authenticatin slutins and the CCID cmpliant versin f the CryptMate tken. Similarly, it is a lightweight tken, weighing nly 6 grams, making it ne f the mst prtable and mst secured cryptgraphic USB tken in the market. It enables users t perfrm digital signature, email encryptin, nline payments, Windws lg-n and ther Public Key Infrastructure (PKI) applicatins. CryptMate64 has a built-in ACOS5-64 chip which has 64 KB f EEPROM cmplies with varius internatinal standards such as with CC EAL5+, ISO 7816 1-4, 8, 9. CryptMate64 s casing is designed t be tamper evident s that any unauthrized physical access will be easily visible. Aside frm this, it als prtects sensitive credentials and cryptgraphic keys since cryptgraphic peratins such as RSA-4096, SHA-256, AES-256 and 3K3DES are perfrmed inside the ACOS5-64-based Smart Card IC inside the tken. With this, imprtant and sensitive infrmatin is prtected frm being hacked r sniffed achieving a high level f security fr applicatins. Cmputer 12 Mbps USB Interface Reader MCU ACOS5-64 Smart Card CryptMate Figure 1: CryptMate64 System Blck Diagram Furthermre, CryptMate-64 supprts a number f security infrastructures and applicatins, including: Micrsft Crypt-API, Micrsft CNG and PKCS #11 Middlewares Secure Online Certificate Generatin Micrstf Outlk, Windws Mail, Micrsft Outlk Express and Mzilla Thunderbird mail signing and encryptin (S/MIME) Mzilla Firefx Internet Explrer Windws Smart Card Lg-n Micrsft Office Open Office Adbe Reader Ltus Ntes Page 3 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk
2.0. Features 2.1. Cryptgraphic Smart Card and Crypt-prcessr Features Embedded ACOS5-64 chip User memry: 64 KB f EEPROM Cmmn Criteria EAL5+ (Chip Level) ISO 7816 Parts 1, 2, 3, 4, 8, 9 Cmpliant FIPS 140-2 (US Federal Infrmatin Prcessing Standards) cmpatible Supprts ISO 7816 Part 4 File Structures: Transparent, Linear Fixed, Linear Variable, Cyclic Cryptgraphic capabilities: DES, 3DES and 3K3DES with 64/128/192 bit keys data encryptin in ECB and CBC mde. AES 128/192/256-bit is als supprted Secure n-card RSA key pair generatin with 512-bit t 4096-bit keys in 256-bit steps RSA cmputatin and verificatin with 512-bit t 4096-bit keys in 256-bit steps Private and secret key file read access can be set t Never Mutual authenticatin (terminal-t-card and card-t-terminal) using Triple DES with sessin key generatin fr encryptin and MAC SHA-1 and SHA-256 hashing algrithm Secure Messaging functin fr cnfidential and authenticated data transfers File access cnditin capability with ISO 7816 cmpliant Secure Attribute - Cmpact. File access is nly allwed if the prper security cnditins are met (e.g., PIN submissin) Cmmand executin cnditin capability per Dedicated File (DF) with ISO 7816 cmpliant Secure Attribute - Extended. Cmmands are allwed nly if the prper security cnditins are met (e.g., PIN submissin) Prvides ease f integratin with varius sftware applicatins such as Internet Explrer, Mzilla, Micrsft Office, and Adbe PDF Reader with the use f ACS middlewares. Cnfigurable baud rates Cnfigurable ATR Custmizable Key and PIN cde Supprts X.509 V3 Certificate Strage and SSL v3 2.2. Tken Features Extremely lightweight: 6 grams Pcket size: 53.5 mm x 15.7 mm x 7.8 mm Keychain hle USB 2.0 Full Speed Interface CCID Cmpliant (Plug and Play) Smart card pwer supply thrugh USB prt NSH-1 (ICP-Brazil) Certified CE and FCC Certified Micrsft WHQL Certified RHS Cmpliance Tamper-evident casing Blue Status LED Page 4 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk
3.0. Typical Applicatins e-gvernment e-banking and e-payment e-healthcare Netwrk Security Lgical Access Cntrl Public Key Infrastructure Digital Signature Secured Email Windws Smart Card Lg-n Page 5 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk
4.0. Middleware T use the CryptMate64 fr PKI applicatins with yur wn digital certificates, an applicable middleware is needed. ACS prvides the ACS CSP and ACS KSP middleware fr MS-CAPI applicatins, and the ACS PKCS #11 middleware fr all ther applicatins such as Mzilla Firefx as shwn in the figure belw: Micrsft Applicatins Smart Card Lgn ACS Applicatin Nn-Micrsft Applicatins Applicatins Micrsft CryptAPI: Next Gen ACS Key Strage Prvider (KSP) Micrsft CryptAPI ACS CSP (Cryptgraphic Service Prvider) ACS PKCS #11 (fr Nn-Micrsft Applicatins) Middleware Windws Resurce Manager ACS Smart Card Reader/Tken Driver OS Layer Figure 2: Middleware Diagram Please cntact us at inf@acs.cm.hk fr inquiries abut the middleware supprt fr the CryptMate64 tken. Page 6 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk
5.0. Technical Specificatins Universal Serial Bus Interface Type... USB Full Speed, Fur Lines: +5 V, GND, D+ and D- Pwer Surce... Frm USB Speed... 12 Mbps (Full Speed) ACOS5 Cryptgraphic Smart Card Chip Memry... 64 KB f EEPROM Endurance... 500,000 write/erase cycles Data Retentin... 10 years Cryptgraphic Capability... 3K3DES, 3DES (ECB, CBC), MAC, AES-128, AES-192, AES-256, RSA-512, 1024/2048/3072/4096 bits and Secure Messaging Hashing Capability... SHA-1, SHA-256 Middleware Supprt... ACS PKCS #11, ACS CSP (based n Micrsft s CryptAPI), ACS KSP (based n Micrsft s CNG) Physical Specificatins Dimensins... 53.5 mm (L) x 15.7 mm (W) x 7.8 mm (H) Clr... Black Weight... 6 g Status LED... Blue Clr Casing... Tamper-evident Others... Keychain hle fr prtability Operating Cnditins Temperature... 0 C 50 C Humidity... 40% 80% Certificatins/Cmpliance NSH-1 (ICP Brazil), FIPS 140-2 Cmpatible, Cmmn Criteria EAL5+ (Chip Level), X.509 V3 Certificate Strage, SSL v3, CE, FCC, RHS, PC/SC, USB Full Speed Micrsft WHQL fr Windws 2000, Windws XP, Windws Vista, Windws 7, Windws 8, Windws 8.1, Windws Server 2008 R2, Windws Server 2012, Windws Server 2012 R2 Page 7 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk
Device Driver Operating System Supprt Windws XP, Windws Vista, Windws 7, Windws 8, Windws 8.1, Windws Server 2003, Windws Server 2003 R2, Windws Server 2008, Windws Server 2008 R2, Windws Server 2012, Windws Server 2012 R2 Linux, Mac OS, Andrid 3.1 and abve Adbe and Reader are registered trademarks r trademarks f Adbe Systems Incrprated in the United States and/r ther cuntries. Andrid is a trademark f Ggle Inc. Linux is the registered trademark f Linus Trvalds in the U.S. and ther cuntries. Ltus Ntes is a registered trademark f IBM Crpratin. Mac OS is a trademark f Apple Inc. Internet Explrer, Micrsft, Windws and Windws Vista are either registered trademarks r trademarks f the Micrsft Crpratin in the United States and/r ther cuntries. Page 8 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk