OneSpan DIGIPASS FX1 BIO User manual

DIGIPASS FX1 BIO
User Manual
Version:2023-10-05

Copyright Notice
Copyright © 2023 OneSpan North America, Inc. All rights reserved.
Trademarks
OneSpan™, DIGIPASS®and CRONTO®are registered or unregistered trademarks of OneSpan North America Inc.,
OneSpan NV and/or OneSpan International GmbH (collectively "OneSpan") in the U.S. and other countries.
OneSpan reserves all rights to the trademarks, service marks and logos of OneSpan and its subsidiaries.
All other trademarks or trade names are the property of their respective owners.
Intellectual Property
OneSpan Software, documents and related materials (“Materials”) contain proprietary and confidential information.
All title, rights and interest in OneSpan Software and Materials, updates and upgrades thereof, including software
rights, copyrights, patent rights, industrial design rights, trade secret rights, sui generis database rights, and all other
intellectual and industrial property rights, vest exclusively in OneSpan or its licensors. No OneSpan Software or Mater-
ials may be downloaded, copied, transferred, disclosed, reproduced, redistributed, or transmitted in any form or by
any means, electronic, mechanical or otherwise, for any commercial or production purpose, except as otherwise
marked or when expressly permitted by OneSpan in writing.
Disclaimer
OneSpan accepts no liability for the accuracy, completeness, or timeliness of content, or for the reliability of links to
and content of external or third party websites.
OneSpan shall have no liability under any circumstances for any loss, damage, or expense incurred by you, your com-
pany, or any third party arising from the use or inability to use OneSpan Software or Materials, or any third party
material made available or downloadable. OneSpan will not be liable in relation to any loss/damage caused by modi-
fication of these Legal Notices or content.
Reservation
OneSpan reserves the right to modify these Notices and the content at any time. OneSpan likewise reserves the right
to withdraw or revoke consent or otherwise prohibit use of the OneSpan Software or Materials if such use does not
conform to the terms of any written agreement between OneSpan and you, or other applicable terms that OneSpan
publishes from time to time.
Contact us
Visit our website: https://www.onespan.com
Resource center: https://www.onespan.com/resource-center
Technical support and knowledge base: https://www.onespan.com/support
If there is no solution in the knowledge base, contact the company that supplied you with the OneSpan product.
Date: 2023-10-05

Contents
1 Product overview 1
1.1Device overview 2
1.2PIN protection 4
1.3Fingerprint sensor 5
1.4LED indicators 7
1.5Charge the battery 9
2 Getting started 10
2.1First steps 10
2.2Initial authenticator setup 11
2.3Use the authenticator 14
3 FIDO authentication 15
3.1Get started with FIDO authentication 16
4 Manage the authenticator 17
4.1Manage Bluetooth settings 18
4.2Change the PIN 20
4.3Manage fingerprints 22
4.4Remove FIDO credentials 25
4.5Reset authenticator 26
DIGIPASS FX1 BIO User Manual i

Procedures
To set the PIN (Windows Settings app) 11
To enroll a fingerprint (Windows Settings app) 12
To set the PIN (Google Chrome) 12
To enroll a fingerprint (Google Chrome) 12
To register the authenticator 16
To sign in using FIDO authentication 16
To enable advanced Bluetooth devices discovery 18
To pair a new device 18
To change the PIN (Windows Settings app) 20
To change the PIN (Google Chrome) 20
To enroll an additional fingerprint (Windows Settings app) 22
To enroll an additional fingerprint (Google Chrome) 22
To delete all fingerprint templates (Windows Settings app) 23
To delete a fingerprint template (Google Chrome) 24
To remove FIDO credentials (Google Chrome) 25
To reset the authenticator (Windows Settings app) 26
To reset the authenticator (Google Chrome) 27
DIGIPASS FX1 BIO User Manual v

1
Product overview
Welcome to the DIGIPASS FX1 BIO User Manual! DIGIPASS FX1 BIO is a
phishing-resistant authenticator that works out-of-the-box with hundreds of FIDO2–
enabled services.
The FIDO Alliance develops standards for passwordless authentication. With FIDO
(Fast IDentity Online), user authentication does not rely on static passwords or one-
time passwords. Instead, users are authenticated via biometrics and FIDO–compliant
authenticators.
The DIGIPASS FX1 BIO authenticator works in connected mode via USB, Bluetooth LE
(BLE), or NFC.
1.1Device overview 2
1.2PIN protection 4
1.3Fingerprint sensor 5
1.4LED indicators 7
1.5Charge the battery 9
1 Product overview
DIGIPASS FX1 BIO User Manual 1

1.1Device overview
1.1.1Authenticator front
Figure 1: Authenticator front
1Power button/Bluetooth pairing mode button
2Foldable USB-C cable
3LED indicators
4Fingerprint sensor
1.1.2Authenticator back
Regulatory identifiers are printed on the back of the authenticator.
1 Product overview
DIGIPASS FX1 BIO User Manual 2

Figure 2: Authenticator back
1.1.3USB cable manipulation
The USB cable can be folded at the back of the authenticator, thanks to a magnetic
mechanism. You do not need a separate USB cable for USB-connected operations.
Figure 3: USB-C cable
To unclip the USB cable, lift the metallic part of the USB plug to release the magnet
(1), or pull the cable at the tip of the plastic cap (2).
CAUTION: To ensure maximum longevity, do not twist or fold the cable at sharp
angles, since this can damage the cable.
Do not hold the authenticator’s main body to pull the USB cable. Pull the authen-
ticator by holding the plastic plug.
1 Product overview
DIGIPASS FX1 BIO User Manual 3

1.2PIN protection
The DIGIPASS FX1 BIO authenticator performs user verification primarily by fin-
gerprint, and by PIN as a fall-back method.
Since the DIGIPASS FX1 BIO authenticator has no keypad, the PIN is entered on the
device to which the authenticator is connected (typically a PC or a smartphone).
The PIN is composed of alphanumeric characters and must comply with the following
rules:
lMinimum length: 4 decimal digits or 4 characters
lMaximum length: 63 bytes in UTF-8 representation. This corresponds to 63 char-
acters if only standard ASCII characters are used, but corresponds to fewer char-
acters if special characters are used (e.g. accented, Chinese,…).
NOTE: After 3 consecutive incorrect PIN attempts, the authenticator must be turned
off and restarted before a new PIN attempt can be made. In case of a USB con-
nection, this is done by removing and re-inserting the USB cable. In case of BLE or
NFC communication, this is done by either explicitly turning off the authenticator
with the Power button, or letting the device turn off automatically via time-out, and
then turning it on again.
CAUTION: After a total of 8 consecutive incorrect PIN attempts, the authenticator is
locked. The authenticator must be reset, which effectively removes all data (cre-
dentials, accounts, fingerprint, PIN) and reverts the authenticator to factory settings.
1 Product overview
DIGIPASS FX1 BIO User Manual 4

1.3Fingerprint sensor
The fingerprint sensor is used to verify the user. The sensor is a 360° sensor and recog-
nizes a fingerprint in any orientation. There are two verification modes:
lTouch only. In this mode, the fingerprint LED blinks BLUE ●●●. Any finger can
be used. This mode confirms the user’s presence, but not their identity.
NOTE: In case of an NFC connection, the method for confirming the user pres-
ence can vary depending on the relevant service. You may need to tap the
authenticator against the NFC reader field, or touch the fingerprint.
lVerification. In this mode, the fingerprint LED blinks MAGENTA ●●●. This mode
is used to verify the user if at least one fingerprint is enrolled. You need to use a
fingerprint that has been enrolled.
CAUTION: After 5 consecutive unsuccessful fingerprint attempts without any cor-
rect PIN entry in between, fingerprint verification is disabled until a correct PIN is
entered. While the fingerprint verification is disabled, the PIN must be entered
instead, followed by a finger touch on the sensor (to verify user presence).
A correct PIN entry resets both the PIN error counter and the fingerprint error
counter. A correct fingerprint match resets only the fingerprint error counter, and not
the PIN error counter.
1.3.1Fingerprint enrollment
Fingerprint enrollment is the process of registering a fingerprint template, i.e. a math-
ematical image of a fingerprint, in the authenticator. With this, it is possible to identify
the user by a simple finger touch on the fingerprint sensor. You need to configure the
PIN before you can enroll a fingerprint. This is because the PIN serves as a fall-back
method in case of unsuccessful fingerprint attempts.
The authenticator can save up to 5 fingerprint templates. If you try to enroll an addi-
tional fingerprint, the device returns an error message to indicate that no fingerprint
enrollment can be performed. You can then free up space by removing one or several
fingerprint templates. For information about deleting enrolled fingerprints, see 4.3.2
Delete enrolled fingerprints.
1 Product overview
DIGIPASS FX1 BIO User Manual 5

NOTE: In the Windows Settings app, if you try to enroll a fingerprint and the fin-
gerprint storage is already full, a general error message will be displayed, indicating
that something went wrong during enrollment.
1 Product overview
DIGIPASS FX1 BIO User Manual 6

1.4LED indicators
The device has three LEDs on its front side, which indicate the status of Bluetooth, fin-
gerprint, and battery level.
LED Description
Off Bluetooth is disabled, or enabled but there is no con-
nection, and pairing mode is not currently active.
●●●Blinking BLUE Bluetooth pairing mode.
●BLUE Connected to a Bluetooth host.
Table 1: Description of Bluetooth LED
LED Description
Off Idle state.
●●●Blinking BLUE Waiting for finger touch for user presence detection.
Any finger can be used.
●●●Blinking MAGENTA Waiting for finger touch for user verification. An enrolled
finger must be used.
-OR-
Waiting for finger touch during fingerprint enrollment.
●MAGENTA Finger on the sensor, only for user verification.
●GREEN Fingerprint match successful for user verification.
-OR-
Fingerprint image captured during enrollment.
●●●●●Fast blinking RED 5 times Fingerprint match failed for user verification.
●YELLOW Fingerprint image rejected because mobility is too low
or coverage is too low, during enrollment. You are
requested to slightly move/shift your finger and try
again.
Table 2: Description of fingerprint LED
LED Description
Off Authenticator is turned off.
Table 3: Description of battery LED
1 Product overview
DIGIPASS FX1 BIO User Manual 7

LED Description
●●●●●Fast blinking RED 5 times
then power off
Battery at critical level, USB not connected.
●●●Blinking ORANGE Battery at warning level or lower, USB not connected.
●●●Blinking GREEN Battery charging, USB connected.
●GREEN Battery fully charged, USB connected.
-OR-
Battery at normal level, USB not connected.
●●●●●Fast blinking MAGENTA Battery charging disabled because out of operational
temperature range (under 0°C or above 45°C).
Table 3: Description of battery LED (continued)
1 Product overview
DIGIPASS FX1 BIO User Manual 8

1.5Charge the battery
To recharge the authenticator, plug the USB cable into the USB port of a PC, phone, or
wall charger. Once the battery is fully charged, the battery LED indicator stops blink-
ing and turns GREEN ●.
NOTE: As a safety measure, battery charging is disabled if the device is out of its
operational temperature range (0°C–45°C). On the authenticator, this protection is
visualized by a fast blinking of the battery LED in MAGENTA ●●●●●.
1 Product overview
DIGIPASS FX1 BIO User Manual 9

2
Getting started
2.1First steps
2.1.1Turn the authenticator on/off
In standalone mode (without USB connection)
lTo turn on the authenticator, press the Power button for one second.
lTo turn off the authenticator, press and hold the Power button.
lThe authenticator will automatically turn off after 60 seconds of inactivity.
In USB-connected mode
lTo turn on the authenticator, plug the USB cable.
lTo turn off the authenticator, unplug the USB cable.
NOTE: When you use the DIGIPASS FX1 BIO authenticator for the first time, you
need to connect the authenticator via USB. You will not be able to turn it on by press-
ing the Power button.
2.1.2Connect your authenticator
You can connect your authenticator via Bluetooth LE, USB, or NFC.
2 Getting started
DIGIPASS FX1 BIO User Manual 10

2.2Initial authenticator setup
The following applications provide facilities to set up and manage your authenticator:
lOn Windows, you can manage your authenticator in the Windows Settings app.
lOn macOS and Linux, you can manage your authenticator via the Google
Chrome security settings.
The initial authenticator setup involves the following steps:
1. Set the PIN
2. Enroll a fingerprint
NOTE: You need to set the PIN before you can enroll a fingerprint.
2.2.1Windows
▶To set the PIN (Windows Settings app)
1. Connect your authenticator.
2. Click the Start button on your computer and select Settings to open the Win-
dows Settings app.
3. Select Accounts > Sign-in options.
4. Click Security Key, then click Manage.
5. When prompted, touch the fingerprint sensor on the authenticator.
The Windows Hello setup dialog is displayed.
6. Under Security Key PIN, click Add.
7. Specify and confirm the authenticator PIN, and click OK. See 1.2 PIN protection
for PIN requirements.
2 Getting started
DIGIPASS FX1 BIO User Manual 11

▶To enroll a fingerprint (Windows Settings app)
1. In the Windows Hello setup dialog, under Security Key Fingerprint, click Set up.
2. Enter your PIN and click OK.
3. Follow the on-screen instructions to enroll your fingerprint.
4. When fingerprint enrollment is completed, click Done.
2.2.2macOS and Linux
▶To set the PIN (Google Chrome)
1. Connect your authenticator.
2. In Google Chrome, navigate to the Manage security keys page:
lClick ⋮Customize and control Google Chrome and select Settings > Privacy
and security > Security > Manage security keys.
-OR-
lType the following address in the address bar: chrome://-
settings/securityKeys
3. Click Create a PIN.
4. When prompted, touch the fingerprint sensor on the authenticator.
5. Specify and confirm the PIN, and click Save. See 1.2 PIN protection for PIN
requirements.
6. Click OK to complete the PIN creation.
▶To enroll a fingerprint (Google Chrome)
1. On the Manage security keys page, click Fingerprints.
2. When prompted, touch the fingerprint sensor on the authenticator.
3. Enter the PIN and click Continue.
2 Getting started
DIGIPASS FX1 BIO User Manual 12

4. In the Manage fingerprints dialog, click Add.
5. Follow the on-screen instructions to enroll your fingerprint.
6. When the fingerprint has been captured, click Continue.
7. Specify a name for the fingerprint and click Continue.
8. Click Done to complete the fingerprint enrollment.
2 Getting started
DIGIPASS FX1 BIO User Manual 13
Table of contents