What is a USB token?
A USB token is also called a digital signature token, a DSC token, a digital signature pen drive or a DSC dongle. They all mean the same thing: the small hardware device your Digital Signature Certificate lives on. It looks like a pen drive but it is not one — you cannot copy files onto it, and you cannot copy the certificate off it.
If you do not need a token at all, and simply want to sign documents online, read about eSign instead.
USB Token is hardware device, which is used to store Digital Signatures Certificate for security. It is secure device and certified by International standards (FIPS). All Digital Certificate subscribers must to store their DSCs on FIPS Certified USB Tokens only. DSC stored in USB Token can not be copied to any other device. CCA (Controller of Certifying Authority) as well as all Certifying Authrorities i.e. eMudhra, (n)Code Solutions, Sify and TCS recommend to use FIPS certified tokens only. There are number of USB tokens available in India which are FIPS Certified, for example Watchdata USB Token, Trustkey Token from Watchdata Singapore, Aladdin eToken from Israel and few others like Gemalto, Athena, ePass from Fetian, China which are FIPS Certified. The only token which is FIPS Certified and plug n play (Built in driver with 1MB Flash memory) available is Trustkey from Watchdata.
USB Token is hardware mechanism used for password authentication via using identity management technique and provides hacking problem solution to the user. It fits in the USB port of the computer. Besides, it is also very useful where security is must like personal computer or cyber café pc. It can be most widely used in accessing E-banking, E-commerce, stock trading, and online data and money transactions tasks. Digital Signature Certificates are now used in various applications are of various types like Class II, Class III. Class 3 digital signature certificates are mostly used e-tendering and e-procurement. Class 2 digital signature certificate are mainly used for efiling e.g digital signature certificate for EPFO, Digital Signature for Income Tax, Digital Signature for MCA etc.
EPASS USB TOKEN
ePass PKI USB Token is the world’s foremost cryptographic identity verification module. ePass by FEITIAN provides a host of indispensable protective measures for digital communication and transaction through Public Key Infrastructure (PKI) data encryption technology. The token’s unique private key functions as an individual’s online ID card and brings a new level of accountability and nonrepudiation to the internet. ePass is a smart-card chip based token with a convenient USB insert rendering the device operable with almost all computers without the need for a reader. As a two factor authentication solution ePass can secure local and remote desktop and network log-on. Key cryptography and the digital signing of emails, documents, and transactions are performed onboard in the secure token framework which is impervious to after-market modification and manipulation.
MTOKEN USB TOKEN
mToken- CryptoID is a two-factor portable USB token that features smartcard technology. Its certificate-based technology generates and stores credentials, such as private keys, passwords and digital certificates within the protected environment of the smart card chip. The built-in Smartcard technology provides highly robust verification and authentication implemented in various industries. MToken CryptoID is certified by Microsoft HCK / HLK and installs Microsoft Windows Update drivers automatically.
TRUSTKEY USB TOKEN
The Trustkey USB Token is a hardware cryptographic module validated against the FIPS 140-2 at security level. It is a USB-based PKI, two-factor authentication token device. It provides digital signature generation/verification for online authentications and data encryption/decryption for online transactions. The user’s private and public key pairs can be generated and stored on the embedded chip. Trustkey has 32K EEPROM and 64K FLASH for the on-card file system divided into the basic areas and extended area. The user’s key pairs reside in the EEPROM. The private key can never be exported. The implementation of FIPS-Approved cryptographic algorithms are tested under the Cryptographic Algorithm Validation Program (CAVP).
Trustkey provides the USB interface that can connect the module to a General Purpose Computer (GPC) in a “plug and play” manner, which eliminates the need to install Smart Card Reader drivers. The WatchKey implements type A USB 1.1 (full speed) specifications and USB CCID (Circuit(s) Cards Interface Device) protocol which enables communication with ISO/IEC 7816 smart cards over USB.
HOW USB TOKEN WORKS?
- USB Token Application providers issue the USB token with authentication CA certificate to users.
- Users should insert the USB token if they want to use the applications.
- During users´ online transaction process, USB token should digitally sign the key information, and then send it to the back-end for verification.
- After the successful verification, the transaction process is completed; otherwise, the application system from the back-end should terminate the transaction.
Because step 3 happens inside the token, the private key never touches your computer’s memory or disk. That is the whole point of the device.
Which token should I buy?
| Token | Notes |
|---|---|
| ePass Auto 2003 (FEITIAN) | Smart-card chip in a USB body. Widely accepted. Driver on our downloads page. |
| mToken CryptoID | Certified by Microsoft HCK/HLK and pulls its driver from Windows Update automatically. |
| ProxKey | Commonly used for e-tendering and DGFT filings. |
| TrustKey (Watchdata) | FIPS 140-2 validated and plug and play, with the driver built into the device. |
| Gemalto / StarKey / U-Key | Also supported. Drivers on our downloads page. |
If you are buying a certificate and a token together we will match the token to the portals you need to sign on. Some government e-tendering portals accept a narrower range of devices, so talk to us before ordering if you file on one.
Token drivers
Drivers for the tokens we supply are free to download from our downloads page. Install the driver before running your Certifying Authority’s download utility — if the driver is missing, the utility will not detect the token.
If your token is not detected after installing the driver, try a different USB port, close any other application holding the token open, and check it appears in Device Manager. If it still will not work, call us and we will sort it out with you over remote desktop.
USB token or soft token?
A soft token is a certificate stored as a file on your computer — usually a
.pfx or .p12 file. A USB token is a hardware device that holds the
certificate on a secure chip. The practical differences matter more than they
first appear.
| Soft token (PFX file) | USB token (hardware) | |
|---|---|---|
| Where the key lives | A file on your disk | Inside a tamper-resistant chip |
| Can it be copied | Yes, like any file | No, the private key cannot be exported |
| Survives a format or reinstall | Only if you backed it up | Yes, it is on the device |
| Accepted for Class 3 filings | No | Yes |
| Risk if the machine is compromised | The certificate can be stolen | The certificate stays on the token |
| Signing on another computer | Copy the file across | Plug the token in |
For Indian statutory filing the choice is already made for you. Since the CCA’s order effective 7 December 2013, Class 2 and Class 3 certificates are issued only onto FIPS 140-2 certified hardware tokens. A soft token is not an option for MCA, ROC, GST, EPFO, DGFT or e-tendering work.
If you want to sign without hardware at all, that is a different product — eSign, where the certificate is issued per signature and there is nothing to plug in.
What does a USB token cost?
A token is a one-off hardware purchase, separate from the certificate that goes on it. Three things move the price:
- The device itself. Plug-and-play models with the driver built in, such as TrustKey, cost more than models that need a driver installed.
- Whether you need it at all. If you already hold a working FIPS certified token with a spare slot, a new certificate can often go onto it and you do not need to buy another.
- Quantity. Organisations ordering tokens for several directors or staff pay less per unit.
We would rather quote you accurately than publish a number that is wrong by the time you read it. Tell us which portals you file on and how many people need to sign, and we will price the token and the certificate together — our numbers are here.
How to get a token and put your certificate on it
There is no way to “create” a USB token yourself; it is a manufactured device that arrives blank, and the certificate is written onto it once.
- Choose the certificate class for the portals you file on — Class 3 for e-tendering, e-procurement and most government filing.
- Buy the token, either from us with the certificate or separately, as long as it is FIPS 140-2 certified.
- Complete the application for your Certifying Authority with your KYC documents. Forms for every CA we supply are on the downloads page.
- Install the token driver on the machine you will use, and plug the token in.
- Run the CA’s download utility and enter the credentials issued when your certificate was approved. If Vsign issued yours, use the Vsign download utility.
- Set a token password when prompted, and record it. A forgotten token password cannot be reset by us or by the Certifying Authority — the certificate has to be reissued.
The certificate can be written to a token once. Format the token or delete the certificate and it must be reissued, so keep the device somewhere safe.
Using your token day to day
Plug the token in before you open the portal or the document you intend to sign, not after — many signing applets only look for a certificate at startup.
When you sign, the application asks for your token password, not your portal password. That prompt is coming from the token itself, which is why it appears even on sites that already know who you are. Enter it, and the signature is generated inside the device.
Unplug the token when you have finished. Leaving it connected on a shared or public machine means anyone at that keyboard can sign as you for as long as the session lasts — the same reason the device is worth having in the first place.
Repeated wrong password attempts will lock the token. The number of attempts varies by make, and once locked, most devices cannot be recovered.
Other names for the same device
Search results and portal instructions use several names interchangeably. If you have been told to get any of the following, they all mean a USB token:
DSC token, digital signature token, crypto token, cryptographic USB token, USB crypto token, smart token, USB smart card token, authentication token, digital signature dongle, digital signature pen drive, or simply e-token.
They describe the same class of device: a smart-card chip in a USB body that generates and stores a private key, performs signing on-chip, and never lets the key leave. The only distinctions that matter when you buy are whether it is FIPS 140-2 certified, which is mandatory, and whether it is plug and play or needs a driver.