Sales +91 89200 56551 +91 89203 84664 +91 88104 27243 +91 80763 22552 Support +91 120 4321443 Mon-Sat, 9:30 AM - 6:00 PM

USB Token

What a USB token is, why CCA mandates FIPS 140-2 certified devices, how ePass, mToken, ProxKey and TrustKey differ, and soft token vs USB token. Free drivers.

What is a USB token?

A USB token is also called a digital signature token, a DSC token, a digital signature pen drive or a DSC dongle. They all mean the same thing: the small hardware device your Digital Signature Certificate lives on. It looks like a pen drive but it is not one — you cannot copy files onto it, and you cannot copy the certificate off it.

If you do not need a token at all, and simply want to sign documents online, read about eSign instead.

USB Token is hardware device, which is used to store Digital Signatures Certificate for security. It is secure device and certified by International standards (FIPS). All Digital Certificate subscribers must to store their DSCs on FIPS Certified USB Tokens only. DSC stored in USB Token can not be copied to any other device. CCA (Controller of Certifying Authority) as well as all Certifying Authrorities i.e. eMudhra, (n)Code Solutions, Sify and TCS recommend to use FIPS certified tokens only. There are number of USB tokens available in India which are FIPS Certified, for example Watchdata USB Token, Trustkey Token from Watchdata Singapore, Aladdin eToken from Israel and few others like Gemalto, Athena, ePass from Fetian, China which are FIPS Certified. The only token which is FIPS Certified and plug n play (Built in driver with 1MB Flash memory) available is Trustkey from Watchdata.

USB Token is hardware mechanism used for password authentication via using identity management technique and provides hacking problem solution to the user. It fits in the USB port of the computer. Besides, it is also very useful where security is must like personal computer or cyber café pc. It can be most widely used in accessing E-banking, E-commerce, stock trading, and online data and money transactions tasks. Digital Signature Certificates are now used in various applications are of various types like Class II, Class III. Class 3 digital signature certificates are mostly used e-tendering and e-procurement. Class 2 digital signature certificate are mainly used for efiling e.g digital signature certificate for EPFO, Digital Signature for Income Tax, Digital Signature for MCA etc.

EPASS USB TOKEN

ePass PKI USB Token is the world’s foremost cryptographic identity verification module. ePass by FEITIAN provides a host of indispensable protective measures for digital communication and transaction through Public Key Infrastructure (PKI) data encryption technology. The token’s unique private key functions as an individual’s online ID card and brings a new level of accountability and nonrepudiation to the internet. ePass is a smart-card chip based token with a convenient USB insert rendering the device operable with almost all computers without the need for a reader. As a two factor authentication solution ePass can secure local and remote desktop and network log-on. Key cryptography and the digital signing of emails, documents, and transactions are performed onboard in the secure token framework which is impervious to after-market modification and manipulation.

MTOKEN USB TOKEN

mToken- CryptoID is a two-factor portable USB token that features smartcard technology. Its certificate-based technology generates and stores credentials, such as private keys, passwords and digital certificates within the protected environment of the smart card chip. The built-in Smartcard technology provides highly robust verification and authentication implemented in various industries. MToken CryptoID is certified by Microsoft HCK / HLK and installs Microsoft Windows Update drivers automatically.

TRUSTKEY USB TOKEN

The Trustkey USB Token is a hardware cryptographic module validated against the FIPS 140-2 at security level. It is a USB-based PKI, two-factor authentication token device. It provides digital signature generation/verification for online authentications and data encryption/decryption for online transactions. The user’s private and public key pairs can be generated and stored on the embedded chip. Trustkey has 32K EEPROM and 64K FLASH for the on-card file system divided into the basic areas and extended area. The user’s key pairs reside in the EEPROM. The private key can never be exported. The implementation of FIPS-Approved cryptographic algorithms are tested under the Cryptographic Algorithm Validation Program (CAVP).

Trustkey provides the USB interface that can connect the module to a General Purpose Computer (GPC) in a “plug and play” manner, which eliminates the need to install Smart Card Reader drivers. The WatchKey implements type A USB 1.1 (full speed) specifications and USB CCID (Circuit(s) Cards Interface Device) protocol which enables communication with ISO/IEC 7816 smart cards over USB.

HOW USB TOKEN WORKS?

  1. USB Token Application providers issue the USB token with authentication CA certificate to users.
  2. Users should insert the USB token if they want to use the applications.
  3. During users´ online transaction process, USB token should digitally sign the key information, and then send it to the back-end for verification.
  4. After the successful verification, the transaction process is completed; otherwise, the application system from the back-end should terminate the transaction.

Because step 3 happens inside the token, the private key never touches your computer’s memory or disk. That is the whole point of the device.

Which token should I buy?

TokenNotes
ePass Auto 2003 (FEITIAN)Smart-card chip in a USB body. Widely accepted. Driver on our downloads page.
mToken CryptoIDCertified by Microsoft HCK/HLK and pulls its driver from Windows Update automatically.
ProxKeyCommonly used for e-tendering and DGFT filings.
TrustKey (Watchdata)FIPS 140-2 validated and plug and play, with the driver built into the device.
Gemalto / StarKey / U-KeyAlso supported. Drivers on our downloads page.

If you are buying a certificate and a token together we will match the token to the portals you need to sign on. Some government e-tendering portals accept a narrower range of devices, so talk to us before ordering if you file on one.

Token drivers

Drivers for the tokens we supply are free to download from our downloads page. Install the driver before running your Certifying Authority’s download utility — if the driver is missing, the utility will not detect the token.

If your token is not detected after installing the driver, try a different USB port, close any other application holding the token open, and check it appears in Device Manager. If it still will not work, call us and we will sort it out with you over remote desktop.

USB token or soft token?

A soft token is a certificate stored as a file on your computer — usually a .pfx or .p12 file. A USB token is a hardware device that holds the certificate on a secure chip. The practical differences matter more than they first appear.

Soft token (PFX file)USB token (hardware)
Where the key livesA file on your diskInside a tamper-resistant chip
Can it be copiedYes, like any fileNo, the private key cannot be exported
Survives a format or reinstallOnly if you backed it upYes, it is on the device
Accepted for Class 3 filingsNoYes
Risk if the machine is compromisedThe certificate can be stolenThe certificate stays on the token
Signing on another computerCopy the file acrossPlug the token in

For Indian statutory filing the choice is already made for you. Since the CCA’s order effective 7 December 2013, Class 2 and Class 3 certificates are issued only onto FIPS 140-2 certified hardware tokens. A soft token is not an option for MCA, ROC, GST, EPFO, DGFT or e-tendering work.

If you want to sign without hardware at all, that is a different product — eSign, where the certificate is issued per signature and there is nothing to plug in.

What does a USB token cost?

A token is a one-off hardware purchase, separate from the certificate that goes on it. Three things move the price:

  • The device itself. Plug-and-play models with the driver built in, such as TrustKey, cost more than models that need a driver installed.
  • Whether you need it at all. If you already hold a working FIPS certified token with a spare slot, a new certificate can often go onto it and you do not need to buy another.
  • Quantity. Organisations ordering tokens for several directors or staff pay less per unit.

We would rather quote you accurately than publish a number that is wrong by the time you read it. Tell us which portals you file on and how many people need to sign, and we will price the token and the certificate together — our numbers are here.

How to get a token and put your certificate on it

There is no way to “create” a USB token yourself; it is a manufactured device that arrives blank, and the certificate is written onto it once.

  1. Choose the certificate class for the portals you file on — Class 3 for e-tendering, e-procurement and most government filing.
  2. Buy the token, either from us with the certificate or separately, as long as it is FIPS 140-2 certified.
  3. Complete the application for your Certifying Authority with your KYC documents. Forms for every CA we supply are on the downloads page.
  4. Install the token driver on the machine you will use, and plug the token in.
  5. Run the CA’s download utility and enter the credentials issued when your certificate was approved. If Vsign issued yours, use the Vsign download utility.
  6. Set a token password when prompted, and record it. A forgotten token password cannot be reset by us or by the Certifying Authority — the certificate has to be reissued.

The certificate can be written to a token once. Format the token or delete the certificate and it must be reissued, so keep the device somewhere safe.

Using your token day to day

Plug the token in before you open the portal or the document you intend to sign, not after — many signing applets only look for a certificate at startup.

When you sign, the application asks for your token password, not your portal password. That prompt is coming from the token itself, which is why it appears even on sites that already know who you are. Enter it, and the signature is generated inside the device.

Unplug the token when you have finished. Leaving it connected on a shared or public machine means anyone at that keyboard can sign as you for as long as the session lasts — the same reason the device is worth having in the first place.

Repeated wrong password attempts will lock the token. The number of attempts varies by make, and once locked, most devices cannot be recovered.

Other names for the same device

Search results and portal instructions use several names interchangeably. If you have been told to get any of the following, they all mean a USB token:

DSC token, digital signature token, crypto token, cryptographic USB token, USB crypto token, smart token, USB smart card token, authentication token, digital signature dongle, digital signature pen drive, or simply e-token.

They describe the same class of device: a smart-card chip in a USB body that generates and stores a private key, performs signing on-chip, and never lets the key leave. The only distinctions that matter when you buy are whether it is FIPS 140-2 certified, which is mandatory, and whether it is plug and play or needs a driver.

USB token questions

What is a USB token?
A USB token is a hardware device that stores a Digital Signature Certificate on a secure smart-card chip. It looks like a pen drive but works differently: you cannot copy files onto it, and the private key cannot be copied off it. Signing happens inside the device, so the key never reaches your computer’s memory or disk.
What is a USB crypto token?
The same device. Crypto token, cryptographic USB token, smart token, USB smart card token, DSC token, e-token, digital signature dongle and digital signature pen drive are all names for a USB token that holds a Digital Signature Certificate.
What is the difference between a soft token and a USB token?
A soft token is a certificate stored as a file, usually a .pfx or .p12, which can be copied like any other file. A USB token holds the certificate on a chip from which the private key cannot be exported. Since the CCA order effective 7 December 2013, Class 2 and Class 3 certificates in India are issued only onto FIPS 140-2 certified hardware tokens, so a soft token is not an option for statutory filing.
Do I have to use a FIPS certified token?
Yes. The Controller of Certifying Authorities requires Class 2 and Class 3 Digital Signature Certificates to be issued onto FIPS 140-2 certified crypto tokens. Certifying Authorities will not download a certificate onto a non-certified device.
How much does a USB token cost?
The token is a one-off hardware purchase, separate from the certificate. Price depends on the model, whether it is plug and play or needs a driver installed, and how many units you order. If you already hold a working FIPS certified token with a spare slot, a new certificate can often go onto it instead.
Which USB token should I buy?
ePass Auto 2003, mToken CryptoID, ProxKey, TrustKey, Gemalto, StarKey and U-Key are all used in India and all FIPS certified. TrustKey from Watchdata is plug and play with the driver built into the device. Some e-tendering portals accept a narrower range of devices, so confirm before ordering if you file on one.
Can I copy my certificate from the token to my computer?
No. The private key is generated inside the token and cannot be exported. This is the purpose of the device. To sign on another computer, install the token driver there and plug the token in.
What happens if I lose the token or forget its password?
The certificate cannot be recovered. A token password cannot be reset by the dealer or the Certifying Authority, and repeated wrong attempts will lock most devices permanently. In either case the certificate has to be reissued.
Why is my USB token not detected?
Usually a missing driver. Install the driver for your specific token make, then unplug and replug it. If it is still not found, try a USB port directly on the machine rather than a hub, close any other application holding the token open, and check it appears in Device Manager without a yellow warning triangle.
Do I need a different driver for eMudhra, Vsign, (n)Code or Sify?
No. The driver depends on the physical token you were given, not on the Certifying Authority that issued the certificate. An ePass token uses the ePass driver whether the certificate came from eMudhra, Vsign, (n)Code or Sify.

Need a Digital Signature Certificate today?

Talk to our sales team for retail or bulk pricing. Mon-Sat, 9:30 AM - 6:00 PM.