User's Manual

EUTRON Infosecurity - Key Solutions for IT Security Tel. +39 035 - 6970.80 Fax: + 39 035 - 6970.92
Via Gandhi 12 - I-24048 Treviolo (Bergamo) e-mail: info@eutron.com web: http://www.eutron.com
1. Introduction
CRYPTOCOMBO is an “all-in-one” device in a USB key, which
offers the following functions:
Smart Card + Smart Card reader + USB memory
Thanks to Smart Card technology, CryptoCombo can securely
store in the memory the user’s data (personal profiles, digital
certificates, X.509); the flash memory chip on the key allows you
to save data and applications, with a self-limiting solution. The
private key used to sign electronic documents is securely and
secretly stored within a cryptographic chip, thus the access is protected by means of a customizable PIN:
having the CryptoCombo hardware device and knowing its PIN are two basic elements of this authentication
"double factors" procedure.
CryptoCombo allows you to generate a couple of cryptographic keys within and apply the digital signature. It
is equipped with security devices that prevent exporting and copying the private key outside the device that
has generated it. The wide memory, both for reading and writing, allows you to transfer data and
applications.
When connected to the PC, it will make available as separate resources both an embedded smart card chip
(and its reader) and a removable hard drive for general purpose storage.
To put it another way, CryptoCombo is the result of combining, in a single compact USB token, two existing
Eutron's products:
CryptoIdentity, the embedded smart card chip and its reader
PicoDisk, the removable hard drive for general purpose storage
Therefore,
CRYPTOCOMBO = CryptoIdentity + PicoDisk
and all the documentations, tools, and software do not refer directly to CryptoCombo, but to its constituent
parts, CryptoIdentity and PicoDisk. For example, the documentation for CryptoCombo is the combination of
the manuals provided for CryptoIdentity and PicoDisk. Similarly, the installation of CryptoCombo results from
the installation of CryptoIdentity and PicoDisk
.
2.
Features
RSA Keys: "on board" generation of the public/private couple of RSA cryptographic keys (up to 2048 bit for
CryptoCombo 2048 model). The private key is never exposed to external environment and cannot leave the
device. All the public key-based operations are carried out on the token. The public key can be exported at
any time.
The multiple memorizations of keys, managed by separated access control mechanisms, are allowed.
User Access: the device is equipped with alphanumeric PIN and PUK, to control the access to data stored in
the cryptographic chip memory (usually, digital certificates). In case of several failed access procedures, the
user’s PIN is stopped and the token cannot be used any longer.
Standards used: the device supports the following standards: ISO 7816 3-4, USB CCID, PKCS#11 v2.11,
PC/SC, Microsoft CAPI, S/MIME, IPSec/IKE and X.509 v3.
Algorithms supported: RSA up to 2048 bit, AES, DES, 3DES, SHA1, MD2, MD5
Cryptographic chip memory: 64 KB
Flash memory: 64MB - 128MB - 256MB - 512MB
Cryptographic chip specifications
: chip of the ATMEL AT90SC family with Algorithmic Research mask, able
to ensure the secure storage of files and directories within a multilevel hierarchic structure.