Watchdata WatchKEY User manual

WatchKEYUSBTokenUserManual
1.Introduction
1.1.CryptographicSmartCard
TIMECOS
Employ32‐bitmicroprocessorsecuritychipdesigncapableofmakingUSBcommunications.
FIPS140‐2(USFederalInformationProcessingStandards)compatible.
Highlysecured,supports1024‐bitand2048‐bitRSAasymmetricalencryptionalgorithm,and
generatesRSAkeypairsinsidecard.
Supportswiththeabilitytoproduce1024‐bitand2048‐bitRSAsignature,verify,encryption,
decryption.
ProvidesmultipleSecurityAlgorithms:DES,3DES,MAC,SHA‐1,SHA‐256,AESoptional.
Supports64KBEEPROM
CompliestoUSB1.1standardandUSB2.0fullspeed
1.2.Software/Middleware
SupportX.509V3certificateformat
SupportsISO7816part4filestructures:transparent,linearfixed,linearvariable,cyclic.
SupportsISO7816part8/9securityrelatedinterindustrycommandsandsecurityattributes.
SupportsPC/SCprotocolorUSBMassStorage.
SupportsMicrosoftCAPI2.0,PKCS#11v2.11,PKCS#1,7,8,10and12,PKCS#15
SupportsWindows98/2000/XP/2003/Vista/Win7environment.
SupportsInternetExplorer5orabove,MozillaFirefoxandNetscape.

WatchKEYUSBTokenUserManual
1.3.Specifications
Supportedoperatingsystems Windows2000/XP/Vista/2003/Windows7
SupportedbrowsersInternetExplorer5.0+;Firefox3.0+;Netscape
API&standardssupportPKCS#11v2.01,
MicrosoftCAPI2.0,
PC/SC,
X.509v3certificate
SSLv3,
MemorySize64K
Onboardsecurityalgorithms RSA1024‐bitand2048‐bit,
DES,3DES(TripleDES),MAC,AES
SHA‐1,SHA‐256
Securitycertificationssmartcardchip:FIPS140‐2
ISOspecificationsupportSupportforISO7816‐1to4,8/9specifications
Operatingtemperature0°Cto70°C(32°Fto158°F)
Storagetemperature‐40°Cto85°C(‐40°Fto185°F)
Humidityrating0‐100%withoutcondensation
ConnectorUSBtypeA;supportsUSB1.1and2.0(fullspeedandhigh
speed)
MemorydataretentionAtleast10years
MemorycellrewritesAtleast500,000
WeightandSizeApprox.8g,78mm*23mm*9mm
2.WatchSAFEND3.4Installation
AutoRunsupportedND(NoDriver)USBKeyintegratedinstallationprograminsideitself.InOS
(OperatingSystem)whichallowsCDautomaticrunning,theinstallationofmanagementtoolwill
automaticallyrunwhenUSBKeypluggedin.
ForotherNDUSBKey,amanagementtoolinstallationfromCDisneeded.Inthischapter,the
installationanduninstallofWatchSAFEND3.4willbeillustrated.
2.1InstallWatchSAFEND3.4
AtthefirsttimeofplugginginNDUSBKey,theauto‐runsupportedproductwillautomatically
installcertificatemanagementtoolintheOSwhichallowsCDautomaticrunning.Forusingother
USBKeys,itisnecessarytoinstallthetoolfromCDatfirst.

WatchKEYUSBTokenUserManual
Installationprocess:
AtthefirsttimeofinsertingUSBKey,aninstallationwindowlikefigure2.1.1willpopout.Inafew
seconds,youwillfindawindowdisplayingsuccessfullyinstalled.
Figure2.1.1ChinaConstructionBank’sUSBkeyauto‐installation
2.2UninstallWatchSAFEND3.4
There’retwomethodsforuninstallingthetool:
1. In‘ControlPanel’,using‘Add/RemovePrograms’todelete‘WDUkeyUserToolv3.4’.
2. Usingthe‘Uninstall’optioninthesubcategoryof‘Start’‐>‘AllPrograms’‐>‘WDUKey
Toolv3.4’.
Step1:uponselect‘uninstall’,awindowlikefigure2.2.1appears.
Figure2.2.1FirstpageofUSBkeyuninstall
Step2:clickthe‘Uninstall’button,thenanewwindowlikefigure2.2.2willcomeout.Clickthe
‘OK’buttontofinishuninstalloperation.

WatchKEYUSBTokenUserManual
Figure2.2.1Completeuninstalled
3.WatchSAFEND3.4user’stool
WatchSAFEND3.4user’stoolismainlyusedtoachievethefollowingfunctions:
zVerifypassword
zChangepassword
zChecksystem
zChangelabel
zShowcertificate
zRegistercertificate
zRevokecertificate
Inthischapter,theoperationstoimplementtheabovefunctionswillbeillustrated.
3.1StartWatchSAFEND3.4user’stool
WatchSAFEND3.4user’stoolcanbestartedbyclick‘WDUKeyUserToolv3.4’intherouteof
‘Start’‐>‘AllPrograms’‐>‘WDUKeyToolv3.4’.Itisalsoavailablebydouble‐clicktheshortcuton
desktop.
WhenWatchSAFEND3.4user’stoolisrunning,thelabelofthetoolwillbedisplayedattheright
bottomcornerasfigure3.2.1.

WatchKEYUSBTokenUserManual
Figure3.2.1runninglabelofWatchSAFEND3.4user’stool
3.2ExitWatchSAFEND3.4user’stool
Clickthe‘close’buttonatupperrightcornertoexitWatchSAFEND3.4UserInterface.
3.3TheuseofWatchSAFEND3.4user’stool
3.4.1 Multi-Key operation
WhenmorethanoneUSBKeyspluggedin,youcanselectadeviceasyouneed.Itisillustratedin
figure3.1.1thattherearetwoavailableUSBKeys:WatchSAFE_UDKaaaandWatchSAFE_UDK.
3.4.2 Verify Password
ThisfunctionisdesignedforprovideabetterPINmanagementplatform.
Figure3.4.2.1theUIofchangepassword
3.4.3 Change Password
Thefunctionofchangepasswordprovidesabettersecurityforthekey’sholderandprevents
embezzlement.

WatchKEYUSBTokenUserManual
Figure3.4.3.1theUIofchangepassword
Forexample,thePINofUSBKeyisinitiallysetas‘111111’.But,forsecuritypurpose,itshouldbe
changedintoasecretPINwhichisonlyknownbytheuser.
IfwrongPINisentered,apromptwillappearanddisplaythenumberofavailablePINretrytimes.
IfPINisretriedmorethanthemaximum,theUSBKeywillbeautomaticallylocked.Then,the
USBKeycanonlybeunlockedbytheissuer.
3.4.4 Check System
Thefunctionofsystemcheckingprovidesuserswithclearinformationaboutthesystemandthe
USBKeystatus.
Figure3.4.4.1systemchecking
3.4.5 Change Label
ThefunctionofchangelabelisdesignedforhelpusersidentifyUSBKey.

WatchKEYUSBTokenUserManual
Figure3.4.5.1theUIofchangelabel
3.4.6 Show Certificate
AfteranUSBKeyisselected,WatchSAFEND3.4user’stoolwilllistalltheavailablecertificates.
Chooseacertificateandpress‘ShowCert’button,anewwindowlikefigure3.4.6.1willdisplay
thecertificate’sdetailswhichincludeissuername,validdateandsoon.
Figure3.4.6.1certificateinformation

WatchKEYUSBTokenUserManual
4.Benefits
Simple:Plugandplaysimplicityforusers,withnoend‐pointsoftwareinstallation
StrongSecurity:Certificate‐basedauthenticationwithonboardsmartcard
Interactive:LEDlightdisplayspowerandcommunicationstatus
Conveniently:smallandportable,easytouse.
ApplicationRich:Idealforexpandingonlineservicesandofferingsimpleandsecureaccess
topartners,customersandmobileworkersfromanylocation
5.TypicalApplications
OnlineBanking
E‐government
Identificationauthenticationonnetwork
Securee‐commerceandsecureremoteaccess
PublicKeyInfrastructurebasedApplication
PKCS#11&CSP‐compliantsoftwareapplications
Customizedapplications

WatchKEYUSBTokenUserManual
15.19(a)(3)
15.21
6. Compliance Statement
This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions:
(1) this device may not cause harmful interference, and
(2) this device must accept any interference received, including interference that may cause undesired operation.
Caution: The user is cautioned that changes or modifications not expressly approved by the party
responsible for compliance could void the user's authority to operate the equipment.
15.105(b)
For a Class B digital device or peripheral, the instructions furnished the user shall include the following or
similar statement, placed in a prominent location in the text of the manual:
Note: This equipment has been tested and found to comply with the limits for a Class B digital device,
pursuant to part 15 of the FCC Rules. These limits are designed to provide reasonable protection against
harmful interference in a residential installation. This equipment generates, uses and can radiate radio
frequency energy and, if not installed and used in accordance with the instructions, may cause harmful
interference to radio communications. However, there is no guarantee that interference will not occur in
a particular installation. If this equipment does cause harmful interference to radio or television reception,
which can be determined by turning the equipment off and on, the user is encouraged to try to correct the
interference by one or more of the following measures:
-Reorient or relocate the receiving antenna.
-Increase the separation between the equipment and receiver.
-Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
-Consult the dealer or an experienced radio/TV technician for help.
Table of contents
Popular Computer Hardware manuals by other brands

Alarm Lock
Alarm Lock AL-DTM-III Setup & configuration instructions

Texas Instruments
Texas Instruments DAC38RF8x Application report

SilverStone
SilverStone REDLINE Series installation guide

Digital Equipment
Digital Equipment MS11-BC Maintenance manual

HBM
HBM eDAQXR quick start guide

ST
ST STEVAL-IFP047V1 user manual