CryptoMate64. USB Cryptographic Token. Technical Specifications V1.03. Subject to change without prior notice. info@acs.com.hk www.acs.com.

Similar documents
ACR122U USB NFC Reader

ACR122U USB NFC Reader

MaaS360 Cloud Extender

Serv-U Distributed Architecture Guide

AccessData Corporation AD Lab System Specification Guide v1.1

CSC IT practix Recommendations

risk2value System Requirements

Junos Pulse Instructions for Windows and Mac OS X

SMART Product Drivers 11.3 for Windows and Mac computers

Learn More Cloud Extender Requirements Cheat Sheet

FAQs for Webroot SecureAnywhere Identity Shield

USF Remote Desktop Gateway

Fermilab Time & Labor Desktop Computer Requirements

How To Upgrade A Crptocard To A 6.4 Migratin Tl (Cpl) For A 6Th Generation Of A Crntl (Cypercoder) On A Crperd (Cptl) 6.

Serv-U Distributed Architecture Guide

SBClient and Microsoft Windows Terminal Server (Including Citrix Server)

ROSS RepliWeb Operations Suite for SharePoint. SSL User Guide

Licensing Windows Server 2012 for use with virtualization technologies

AvePoint High Speed Migration Supplementary Tools

Treasury Gateway Getting Started Guide

Configuring and Monitoring AS400 Servers. eg Enterprise v5.6

Bitrix Intranet. Product Requirements

Setup PPD IT How-to Guides June 2010

ACTIVITY MONITOR Real Time Monitor Employee Activity Monitor

Improved Data Center Power Consumption and Streamlining Management in Windows Server 2008 R2 with SP1

Customers FAQs for Webroot SecureAnywhere Identity Shield

Securely Managing Cryptographic Keys used within a Cloud Environment

Level 1 Technical. RealPresence Web Suite and Web Suite Pro. Contents

Alexsys Team 2 Service Desk

April 3, Release Notes

Installation Guide Marshal Reporting Console

Introduction to Mindjet MindManager Server

Licensing Windows Server 2012 R2 for use with virtualization technologies

Instant Chime for IBM Sametime Quick Start Guide

.Net Strong Authentication API

Wireless Light-Level Monitoring

4394 Gazzetta tal-gvern ta Malta MINISTRY OF FINANCE. Value Added Tax Department. Fiscal Cash Register Specifications

Adobe Sign. Enabling Single Sign-On with SAML Reference Guide

Network Layout. Browser/Client Requirements. Features. Graphics

Click Studios. Passwordstate. RSA SecurID Configuration

Readme File. Purpose. Introduction to Data Integration Management. Oracle s Hyperion Data Integration Management Release 9.2.

TECHNICAL BULLETIN. Title: Remote Access Via Internet Date: 12/21/2011 Version: 1.1 Product: Hikvision DVR Action Required: Information Only

Password Reset for Remote Users

BACnet Field Panel Web Server with Application MC and Kiosk Mode Graphics

Identify Major Server Hardware Components

SMART Product Drivers 10 for Windows and Mac computers

FEITIAN PKI Authentication Token. epass2003 with FIPS Cer tification

2. When logging is used, which severity level indicates that a device is unusable?

USF Remote Desktop Gateway

Cloud Services Frequently Asked Questions FAQ

Copyright 2013, SafeNet, Inc. All rights reserved. We have attempted to make these documents complete, accurate, and

ScaleIO Security Configuration Guide

StarterPak: Dynamics CRM Opportunity To NetSuite Sales Order

RedCloud Security Management Software 3.6 Release Notes

Installation Guide Marshal Reporting Console

IMT Standards. Standard number A GoA IMT Standards. Effective Date: Scheduled Review: Last Reviewed: Type: Technical

Welcome to Remote Access Services (RAS)

User Guide Version 3.9

How To Install Fcus Service Management Software On A Pc Or Macbook

Call recording for IP telephony and contact centers

Firewall/Proxy Server Settings to Access Hosted Environment. For Access Control Method (also known as access lists and usually used on routers)

Gateway Agent - First Amendment to the High Level Design Document

Optimal Payments Extension. Supporting Documentation for the Extension Package v1.1

Client Application Installation Guide

Corente Cloud Services Exchange (CSX) Corente Cloud Services Gateway Site Survey Form

FOCUS Service Management Software Version 8.5 for Passport Business Solutions Installation Instructions

Ten Steps for an Easy Install of the eg Enterprise Suite

Setup O365 mailbox access on MACs

The user authentication process varies from client to client depending on internal resource capabilities, and client processes and procedures.

Introduction Getting help Getting started Prerequisites 5 Installation 6 Entering License Key 8 Checking Current License

Datasheet. PV4E Management Software Features

RECOMMENDATIONS SECURITY ONLINE BANK TRANSACTIONS. interests in the use of IT services, such as online bank services of Société Générale de Banques au

TaskCentre v4.5 Send Message (SMTP) Tool White Paper

Intransa VideoAppliance VA1020 Series Server/Storage Appliance V1.3

Restricted Document. Pulsant Technical Specification

Attunity RepliWeb SSL Guide

Paraben s P2C 4.4. Release Notes

StarterPak: Dynamics CRM On-Premise to Dynamics Online Migration - Option 2. Version 1.0

E-Biz Web Hosting Control Panel

ViPNet CSP 4.0. User's Guide

Interworks Cloud Platform Citrix CPSM Integration Specification

WatchDox for Windows User Guide

LogMeIn Rescue Web SSO via SAML 2.0 Configuration Guide

Thuraya Satellite Telecommunications Company. ThurayaGmPRS. Frequently Asked Questions. February 2007

Webalo Pro Appliance Setup

Avatier Identity Management Suite

ASUS PC Diagnostics Guide

SYSTEM MONITORING PLUG-IN FOR MICROSOFT SQL SERVER

Simmons GMAIL Client Setup

Transcription:

CryptMate64 USB Cryptgraphic Tken Technical Specificatins V1.03 Subject t change withut prir ntice inf@acs.cm.hk www.acs.cm.hk

Table f Cntents 1.0. Intrductin... 3 2.0. Features... 4 2.1. Cryptgraphic Smart Card and Crypt-prcessr Features... 4 2.2. Tken Features... 4 3.0. Typical Applicatins... 5 4.0. Middleware... 6 5.0. Technical Specificatins... 7 List f Figures Figure 1 : CryptMate64 System Blck Diagram... 3 Figure 2 : Middleware Diagram... 6 Page 2 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk

1.0. Intrductin CryptMate64 is a lightweight USB tken that prvides users with strng authenticatin slutins and the CCID cmpliant versin f the CryptMate tken. Similarly, it is a lightweight tken, weighing nly 6 grams, making it ne f the mst prtable and mst secured cryptgraphic USB tken in the market. It enables users t perfrm digital signature, email encryptin, nline payments, Windws lg-n and ther Public Key Infrastructure (PKI) applicatins. CryptMate64 has a built-in ACOS5-64 chip which has 64 KB f EEPROM cmplies with varius internatinal standards such as with CC EAL5+, ISO 7816 1-4, 8, 9. CryptMate64 s casing is designed t be tamper evident s that any unauthrized physical access will be easily visible. Aside frm this, it als prtects sensitive credentials and cryptgraphic keys since cryptgraphic peratins such as RSA-4096, SHA-256, AES-256 and 3K3DES are perfrmed inside the ACOS5-64-based Smart Card IC inside the tken. With this, imprtant and sensitive infrmatin is prtected frm being hacked r sniffed achieving a high level f security fr applicatins. Cmputer 12 Mbps USB Interface Reader MCU ACOS5-64 Smart Card CryptMate Figure 1: CryptMate64 System Blck Diagram Furthermre, CryptMate-64 supprts a number f security infrastructures and applicatins, including: Micrsft Crypt-API, Micrsft CNG and PKCS #11 Middlewares Secure Online Certificate Generatin Micrstf Outlk, Windws Mail, Micrsft Outlk Express and Mzilla Thunderbird mail signing and encryptin (S/MIME) Mzilla Firefx Internet Explrer Windws Smart Card Lg-n Micrsft Office Open Office Adbe Reader Ltus Ntes Page 3 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk

2.0. Features 2.1. Cryptgraphic Smart Card and Crypt-prcessr Features Embedded ACOS5-64 chip User memry: 64 KB f EEPROM Cmmn Criteria EAL5+ (Chip Level) ISO 7816 Parts 1, 2, 3, 4, 8, 9 Cmpliant FIPS 140-2 (US Federal Infrmatin Prcessing Standards) cmpatible Supprts ISO 7816 Part 4 File Structures: Transparent, Linear Fixed, Linear Variable, Cyclic Cryptgraphic capabilities: DES, 3DES and 3K3DES with 64/128/192 bit keys data encryptin in ECB and CBC mde. AES 128/192/256-bit is als supprted Secure n-card RSA key pair generatin with 512-bit t 4096-bit keys in 256-bit steps RSA cmputatin and verificatin with 512-bit t 4096-bit keys in 256-bit steps Private and secret key file read access can be set t Never Mutual authenticatin (terminal-t-card and card-t-terminal) using Triple DES with sessin key generatin fr encryptin and MAC SHA-1 and SHA-256 hashing algrithm Secure Messaging functin fr cnfidential and authenticated data transfers File access cnditin capability with ISO 7816 cmpliant Secure Attribute - Cmpact. File access is nly allwed if the prper security cnditins are met (e.g., PIN submissin) Cmmand executin cnditin capability per Dedicated File (DF) with ISO 7816 cmpliant Secure Attribute - Extended. Cmmands are allwed nly if the prper security cnditins are met (e.g., PIN submissin) Prvides ease f integratin with varius sftware applicatins such as Internet Explrer, Mzilla, Micrsft Office, and Adbe PDF Reader with the use f ACS middlewares. Cnfigurable baud rates Cnfigurable ATR Custmizable Key and PIN cde Supprts X.509 V3 Certificate Strage and SSL v3 2.2. Tken Features Extremely lightweight: 6 grams Pcket size: 53.5 mm x 15.7 mm x 7.8 mm Keychain hle USB 2.0 Full Speed Interface CCID Cmpliant (Plug and Play) Smart card pwer supply thrugh USB prt NSH-1 (ICP-Brazil) Certified CE and FCC Certified Micrsft WHQL Certified RHS Cmpliance Tamper-evident casing Blue Status LED Page 4 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk

3.0. Typical Applicatins e-gvernment e-banking and e-payment e-healthcare Netwrk Security Lgical Access Cntrl Public Key Infrastructure Digital Signature Secured Email Windws Smart Card Lg-n Page 5 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk

4.0. Middleware T use the CryptMate64 fr PKI applicatins with yur wn digital certificates, an applicable middleware is needed. ACS prvides the ACS CSP and ACS KSP middleware fr MS-CAPI applicatins, and the ACS PKCS #11 middleware fr all ther applicatins such as Mzilla Firefx as shwn in the figure belw: Micrsft Applicatins Smart Card Lgn ACS Applicatin Nn-Micrsft Applicatins Applicatins Micrsft CryptAPI: Next Gen ACS Key Strage Prvider (KSP) Micrsft CryptAPI ACS CSP (Cryptgraphic Service Prvider) ACS PKCS #11 (fr Nn-Micrsft Applicatins) Middleware Windws Resurce Manager ACS Smart Card Reader/Tken Driver OS Layer Figure 2: Middleware Diagram Please cntact us at inf@acs.cm.hk fr inquiries abut the middleware supprt fr the CryptMate64 tken. Page 6 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk

5.0. Technical Specificatins Universal Serial Bus Interface Type... USB Full Speed, Fur Lines: +5 V, GND, D+ and D- Pwer Surce... Frm USB Speed... 12 Mbps (Full Speed) ACOS5 Cryptgraphic Smart Card Chip Memry... 64 KB f EEPROM Endurance... 500,000 write/erase cycles Data Retentin... 10 years Cryptgraphic Capability... 3K3DES, 3DES (ECB, CBC), MAC, AES-128, AES-192, AES-256, RSA-512, 1024/2048/3072/4096 bits and Secure Messaging Hashing Capability... SHA-1, SHA-256 Middleware Supprt... ACS PKCS #11, ACS CSP (based n Micrsft s CryptAPI), ACS KSP (based n Micrsft s CNG) Physical Specificatins Dimensins... 53.5 mm (L) x 15.7 mm (W) x 7.8 mm (H) Clr... Black Weight... 6 g Status LED... Blue Clr Casing... Tamper-evident Others... Keychain hle fr prtability Operating Cnditins Temperature... 0 C 50 C Humidity... 40% 80% Certificatins/Cmpliance NSH-1 (ICP Brazil), FIPS 140-2 Cmpatible, Cmmn Criteria EAL5+ (Chip Level), X.509 V3 Certificate Strage, SSL v3, CE, FCC, RHS, PC/SC, USB Full Speed Micrsft WHQL fr Windws 2000, Windws XP, Windws Vista, Windws 7, Windws 8, Windws 8.1, Windws Server 2008 R2, Windws Server 2012, Windws Server 2012 R2 Page 7 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk

Device Driver Operating System Supprt Windws XP, Windws Vista, Windws 7, Windws 8, Windws 8.1, Windws Server 2003, Windws Server 2003 R2, Windws Server 2008, Windws Server 2008 R2, Windws Server 2012, Windws Server 2012 R2 Linux, Mac OS, Andrid 3.1 and abve Adbe and Reader are registered trademarks r trademarks f Adbe Systems Incrprated in the United States and/r ther cuntries. Andrid is a trademark f Ggle Inc. Linux is the registered trademark f Linus Trvalds in the U.S. and ther cuntries. Ltus Ntes is a registered trademark f IBM Crpratin. Mac OS is a trademark f Apple Inc. Internet Explrer, Micrsft, Windws and Windws Vista are either registered trademarks r trademarks f the Micrsft Crpratin in the United States and/r ther cuntries. Page 8 f 8 CryptMate64 Technical Specificatins Versin 1.03 inf@acs.cm.hk www.acs.cm.hk