Watchdata Technologies WATCHKEY509 USB Token User Manual

Watchdata Technologies Pte Ltd USB Token

WatchKEY USB Token (K6) User manual_V2


WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
1. Introduction
1.1.CryptographicSmartCard
TIMECOS
Employ32bitmicroprocessorsecuritychipdesigncapableofmakingUSBcommunications.
FIPS1402(USFederalInformationProcessingStandards)compatible.
Highlysecured,supports1024bitand2048bitRSAasymmetricalencryptionalgorithm,and
generatesRSAkeypairsinsidecard.
Supportswiththeabilitytoproduce1024bitand2048bitRSAsignature,verify,encryption,
decryption.
ProvidesmultipleSecurityAlgorithms:DES,3DES,MAC,SHA1,SHA256,AESoptional.
Supports64KBEEPROM
CompliestoUSB1.1standardandUSB2.0fullspeed
1.2.Software/Middleware
SupportX.509V3certificateformat
SupportsISO7816part4filestructures:transparent,linearfixed,linearvariable,cyclic.
SupportsISO7816part8/9securityrelatedinterindustrycommandsandsecurityattributes.
SupportsPC/SCprotocolorUSBMassStorage.
SupportsMicrosoftCAPI2.0,PKCS#11v2.11,PKCS#1,7,8,10and12,PKCS#15

WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
SupportsWindows98/2000/XP/2003/Vista/Win7environment.
SupportsInternetExplorer5orabove,MozillaFirefoxandNetscape.
1.3.Specifications
Supportedoperatingsystems Windows2000/XP/Vista/2003/Windows7
SupportedbrowsersInternetExplorer5.0+;Firefox3.0+;Netscape
API&standardssupportPKCS#11v2.01,
MicrosoftCAPI2.0,
PC/SC,
X.509v3certificate
SSLv3,
MemorySize64K
Onboardsecurityalgorithms RSA1024bitand2048bit,
DES,3DES(TripleDES),MAC,AES
SHA1,SHA256
Securitycertificationssmartcardchip:FIPS1402
ISOspecificationsupportSupportforISO78161to4,8/9specifications
OperatingtemperatureCto70°C(32°Fto158°F)
Storagetemperature40°Cto85°C(40°Fto185°F)
Humidityrating0100%withoutcondensation
ConnectorUSBtypeA;supportsUSB1.1and2.0(fullspeedandhigh
speed)
MemorydataretentionAtleast10years
MemorycellrewritesAtleast500,000
WeightandSizeApprox.8g,78mm*23mm*9mm
2. WatchSAFE ND 3.4 Installation
AutoRunsupportedND(NoDriver)USBKeyintegratedinstallationprograminsideitself.InOS
(OperatingSystem)whichallowsCDautomaticrunning,theinstallationofmanagementtoolwill
automaticallyrunwhenUSBKeypluggedin.
ForotherNDUSBKey,amanagementtoolinstallationfromCDisneeded.Inthischapter,the
installationanduninstallofWatchSAFEND3.4willbeillustrated.

WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
2.1InstallWatchSAFEND3.4
AtthefirsttimeofplugginginNDUSBKey,theautorunsupportedproductwillautomatically
installcertificatemanagementtoolintheOSwhichallowsCDautomaticrunning.Forusingother
USBKeys,itisnecessarytoinstallthetoolfromCDatfirst.
Installationprocess:
AtthefirsttimeofinsertingUSBKey,aninstallationwindowlikefigure2.1.1willpopout.Inafew
seconds,youwillfindawindowdisplayingsuccessfullyinstalled.
Figure2.1.1ChinaConstructionBank’sUSBkeyautoinstallation
2.2UninstallWatchSAFEND3.4
There’retwomethodsforuninstallingthetool:
1. In‘ControlPanel,usingAdd/RemovePrograms’todelete‘WDUkeyUserToolv3.4’.
2. Usingthe‘Uninstall’optioninthesubcategoryof‘Start’‐>‘AllPrograms’‐>‘WDUKey
Toolv3.4’.
Step1:uponselect‘uninstall’,awindowlikefigure2.2.1appears.

WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
Figure2.2.1FirstpageofUSBkeyuninstall
Step2:clickthe‘Uninstall’button,thenanewwindowlikefigure2.2.2willcomeout.Clickthe
‘OK’buttontofinishuninstalloperation.
Figure2.2.1Completeuninstalled

WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
3.WatchSAFE ND 3.4 users tool
WatchSAFEND3.4userstoolismainlyusedtoachievethefollowingfunctions:
z Verifypassword
z Changepassword
z Checksystem
z Changelabel
z Showcertificate
z Registercertificate
z Revokecertificate
Inthischapter,theoperationstoimplementtheabovefunctionswillbeillustrated.
3.1StartWatchSAFEND3.4user’stool
WatchSAFEND3.4userstoolcanbestartedbyclick‘WDUKeyUserToolv3.4’intherouteof
‘Start‐>‘AllPrograms’‐>‘WDUKeyToolv3.4’.Itisalsoavailablebydoubleclicktheshortcuton
desktop.
WhenWatchSAFEND3.4userstoolisrunning,thelabelofthetoolwillbedisplayedattheright
bottomcornerasfigure3.2.1.
Figure3.2.1runninglabelofWatchSAFEND3.4userstool
3.2ExitWatchSAFEND3.4user’stool
Clickthe‘closebuttonatupperrightcornertoexitWatchSAFEND3.4UserInterface.
3.3TheuseofWatchSAFEND3.4user’stool
3.4.1 Multi-Key operation
WhenmorethanoneUSBKeyspluggedin,youcanselectadeviceasyouneed.Itisillustratedin
figure3.1.1thattherearetwoavailableUSBKeys:WatchSAFE_UDKaaaandWatchSAFE_UDK.

WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
3.4.2 Verify Password
ThisfunctionisdesignedforprovideabetterPINmanagementplatform.
Figure3.4.2.1theUIofchangepassword
3.4.3 Change Password
Thefunctionofchangepasswordprovidesabettersecurityforthekey’sholderandprevents
embezzlement.
Figure3.4.3.1theUIofchangepassword
Forexample,thePINofUSBKeyisinitiallysetas‘111111’.But,forsecuritypurpose,itshouldbe
changedintoasecretPINwhichisonlyknownbytheuser.
IfwrongPINisentered,apromptwillappearanddisplaythenumberofavailablePINretrytimes.

WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
IfPINisretriedmorethanthemaximum,theUSBKeywillbeautomaticallylocked.Then,the
USBKeycanonlybeunlockedbytheissuer.
3.4.4 Check System
Thefunctionofsystemcheckingprovidesuserswithclearinformationaboutthesystemandthe
USBKeystatus.
Figure3.4.4.1systemchecking
3.4.5 Change Label
ThefunctionofchangelabelisdesignedforhelpusersidentifyUSBKey.
Figure3.4.5.1theUIofchangelabel
3.4.6 Show Certificate
AfteranUSBKeyisselected,WatchSAFEND3.4userstoolwilllistalltheavailablecertificates.
Chooseacertificateandpress‘ShowCertbutton,anewwindowlikefigure3.4.6.1willdisplay
thecertificate’sdetailswhichincludeissuername,validdateandsoon.

WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
Figure3.4.6.1certificateinformation
4. Benefits
Simple:Plugandplaysimplicityforusers,withnoendpointsoftwareinstallation
StrongSecurity:Certificatebasedauthenticationwithonboardsmartcard
Interactive:LEDlightdisplayspowerandcommunicationstatus
Conveniently:smallandportable,easytouse.
ApplicationRich:Idealforexpandingonlineservicesandofferingsimpleandsecureaccess
topartners,customersandmobileworkersfromanylocation

WatchKEYUSBTokenUsermanual

WatchdataTechnologiesPteLtd
Admirax8AdmiraltyStreet#0207/08,
Singapore757438
www.watchdata.com
5. Typical Applications
OnlineBanking
Egovernment
Identificationauthenticationonnetwork
Secureecommerceandsecureremoteaccess
PublicKeyInfrastructurebasedApplication
PKCS#11&CSPcompliantsoftwareapplications
Customizedapplications
15.19(a)(3)
15.21
6. Compliance Statement
This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions:
(1) this device may not cause harmful interference, and
(2) this device must accept any interference received, including interference that may cause undesired operation.
Caution: The user is cautioned that changes or modifications not expressly approved by the party
responsible for compliance could void the user's authority to operate the equipment.
15.105(b)
For a Class B digital device or peripheral, the instructions furnished the user shall include the following or
similar statement, placed in a prominent location in the text of the manual:
Note: This equipment has been tested and found to comply with the limits for a Class B digital device,
pursuant to part 15 of the FCC Rules. These limits are designed to provide reasonable protection against
harmful interference in a residential installation. This equipment generates, uses and can radiate radio
frequency energy and, if not installed and used in accordance with the instructions, may cause harmful
interference to radio communications. However, there is no guarantee that interference will not occur in
a particular installation. If this equipment does cause harmful interference to radio or television reception,
which can be determined by turning the equipment off and on, the user is encouraged to try to correct the
interference by one or more of the following measures:
-Reorient or relocate the receiving antenna.
-Increase the separation between the equipment and receiver.
-Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
-Consult the dealer or an experienced radio/TV technician for help.

Navigation menu