Search Keyword : 20
-
How to set up TrueCrypt for ACOS5/ CryptoMage usage?
TrueCrypt is a software application used for real-time on-the-fly encryption. It is distributed without cost, and has source code available, although under a restrictive licence. It can create a virtual encrypted disk within a file or a device-hosted encrypted volume on either an individual partition or an entire storage device. It supports Microsoft Windows, Mac OS X and Linux (using FUSE) and encrypted volumes can be made portable ( Figure 1). ACOS5/CryptoMate can be used as the storage for key(s) that will be used in Encrypting/Decrypting of a TrueCrypt Volume. Figure 1: TrueCrypt main window To Initialize your TrueCrypt with ACOS5/CryptoMate, follow the steps below: If you have a fresh card/token, please make sure to Initialize it first. Install the TrueCrypt software first by downloading the latest installer in http://www.truecrypt.org/downloads . In the TrueCrypt main menu, select "Settings" and click "Security Tokens...". The "TrueCrypt - Securty Token Preferences" should pop up ( Figure 2 ). Figure 2: Security Token Preferences window. Click the button "Auto-Detect Library". If you have multiple PKCS Library installed in the system, then click "Select Library . . ." button and navigate to the Program Files, Advanced Card Systems Ltd., then ACOS5 SDK, Middleware and finally the PKCS folder. Select the acospkcs11.dll file. Once you have selected the proper PKCS#11 Library, click the "OK" button on the "Securty Token Preferences" dialog.
https://www.acs.com.hk/en/frequently-asked-questions/1/smart-cards-smart-card-os/ -
How to create an encrypted volume using ACOS5/CryptoMate?
After you have successfully set-up your TrueCrypt settings, follow the steps below to create an encrypted volume using ACOS5/Cryptomate. On the TrueCrypt main window, click the "Create Volume" button. The "TrueCrypt Volume Creation Wizard" should pop-up ( Figure 3 ). Figure 3: TrueCrypt Volume Creation Wizard. In the Volume Creation Wizard, select the "Create an encrypted file container" option and click "Next". In the "Volume Type" selection, click the "Standard TrueCrypt volume" option and click "Next". In the "Volume Location" selection, Select the file in which you want to create your TrueCrypt Volume. Make sure to read the WARNING in this dialog ( Figure 4 ). Figure 4: TrueCrypt Volume Creation Wizard, Volume Location selection. Select "Next" once you have selected the desired file. Next, you will be asked on the "Encryption Options" for your Volume. You can leave the default settings as it is and click "Next" Next, you will be asked on the desired size for your volume. Click "Next" once you have specified the desired size for your Volume. The size that you specify here will be the allocated space for the file that you have created in Step 5 ( Figure 5 ). Figure 5: Specify the size you want for your volume. Next, you will be asked for the Volume Password and (optionally) for the Keyfile that will be used to encrypt/decrypt your TrueCrypt volume. Enter your desired password and select the "Use keyfiles" check box. Selecting to use keyfiles will allow you to store securely the keyfiles to your ACOS5/CryptoMate device. ( Figure 6 ). Figure 6: Enter your password and select the "Use keyfiles" option Once you have set your password, and selected the "Use keyfiles" selection. Click the "Keyfiles.." button. The "TrueCrypt - Keyfiles" will appear ( Figure 7 ). Figure 7: TrueCrypt Keyfiles window. Remember the password that you have entered in this step. You can select any files for your keyfile (as stated in Figure 7). You can also generate a random keyfile of your own, to do this just click "Generate Random Keyfile. . ." button. The "TrueCrypt Keyfile Generator" will appear. Click the "Generate and Save Keyfile. . ." button. Save your randomly generated keyfile to a temporary file in your hard drive. Once saved, a confirmation box will appear. ( Figure 8 ). Figure 8: Randomly Generate your own Keyfile. Once you have saved your Randomly generated Keyfile. Click the "Close" button in the "TrueCrypt Keyfile Generator". Click Click the "Add Token Files. . ." button in the "TrueCrypt - Keyfiles" dialog window. When prompted, enter the ACOS5/CryptoMate User PIN. ( Figure 9 ). Figure 9: Enter your ACOS5/CryptoMate User PIN when prompted. After successfully validating the PIN, the "Select Security Token Keyfiles" dialog window will show up. In the "Select Security Token Keyfiles" dialog, click "Import Keyfile to Token". Select the file that you have generated and saved in Step 10 Once selected, You will be prompted for a verification. Just Click OK on the "New Security Token Keyfile Properties" dialog. Wait for a while, the process might take some time depending on the size of the Keyfile. Once the Keyfile has been saved, it will be available for selection. ( Figure 10a and Figure 10b ). Figure 10b: Set the Keyfile Name or you can leave the default and select "OK" Figure 10a: The Keyfile is now saved in the ACOS5/CryptoMate token. Select the newly created Keyfile and Click "OK". You should now see your Keyfile in the Keyfiles list ( Figure 11). Figure 11: Newly Created Keyfile in the list.. Select "OK" and you will now go back to the "TrueCrypt Volume Creation Wizard" In the "TrueCrypt Volume Creation Wizard" Click "Next...". In the next Dialog you will be asked to Format your TrueCrypt Volume. Click the "Format" button and wait until the formatting process is done. The formatting process might take a while depending on the Volume size you specified in Step 7 above ( Figure 12 ). Figure 12: Your TrueCrypt Volume is now being formatted. After successfully formatting you Volume/ Your Volume is now created and ready for use ( Figure 13 ). Figure 13: Your TrueCrypt Volume is now being formatted. Click "Next" and then Click "Exit". Now that you have created an Encrypted Volume, you can now delete the file that you have generated in Step 10.
https://www.acs.com.hk/en/frequently-asked-questions/1/smart-cards-smart-card-os/ -
How to mount / dismount a TrueCrypt volume?
Once you have created an encrypted volume. You can now Mount / Unmount it and saved data into it. Follow the steps below in mounting / unmounting an encrypted volume. Open up the TrueCrypt main window ( Figure 1 in How to set up TrueCrypt for the ACOS5/ CryptoMage usage). In the TrueCrypt main window, click the "Select File" button. Navigate to the folder where you haved saved the file you have created in this step. Click the "Mount" button. In the "Enter Password" dialog box, enter the volume password. Also select the "Use keyfiles" options. ( Figure 14 ). Figure 14: TrueCrypt Password dialog box. In the TrueCrypt password dialog box. Click "Keyfiles..." button. The "TrueCrypt Keyfiles" will appear ( Figure 7 in How to create an encrypted volume using ACOS5/ CryptoMate). Click the "Add Token file..." button. When prompted, enter the ACOS5/CryptoMate User PIN. ( Figure 9 in How to create an encrypted volume using ACOS5/ CryptoMate) The "Select Security Token Keyfiles" will appear ( Figure 10a & 10b in How to create an encrypted volume using ACOS5/ CryptoMate). In here you can select the proper keyfiles to use for the your volume to be mounted. Select the proper Keyfiles ans Click "OK". In the "TrueCrypt Keyfiles" dialog window, select the Keyfiles that you have selected in the previous step and click "OK". The mounting process might take a while, when the mounting process is done, you can now see the mounted volume in the TrueCrypt main window ( Figure 14 ). Figure 14: Mounted TrueCrypt Volume. Once a TrueCrypt volume has been successfully mounted, you can have access to it similar to a normal volume or Hard Disk partition ( Figure 15 ). Figure 15: The Mounted TrueCrypt Volume as seen in "My Computer". To dismount a TrueCrypt Volume, Select the appropriate Volume you want to Dismount in the TrueCrypt main window. Select the "Dismount" button to remove the volume and save all its contents securely ( Figure 14 ).
https://www.acs.com.hk/en/frequently-asked-questions/1/smart-cards-smart-card-os/ -
How to create an encrypted portable volume using ACOS5 and ACR100?
The ACR100 SIMFlash (CCID) is a reliable and cost-effective smart card reader for security-related applications. It is a USB full-speed plug-in card reader that, with the paired mass storage, enables you to do more than simply back up and manage your SIM card information on the PC. It supports most memory cards, MCU cards with T=0 and T=1 protocols, and GSM cards conforming to Spec 11.11 The ACR100 SIMFlash (CCID) also has a built-in 1-GB flash memory. Designed both to access SIM cards and for data or application storage, it is ideal for GSM solutions such as GSM management software and VoIP applications, electronic payment systems, e-commerce, home banking, transportation, and computer/network access. Designed both to access SIM cards and for data or application storage, it is ideal for GSM solutions such as GSM management software and VoIP applications, electronic payment systems, e-commerce, home banking, transportation, and computer/network access (Figure 1). Figure 1: ACR100 Reader With the the use of an ACR100, a sim-sized ACOS5 and TrueCrypt. You can create an Encrypted Portable Volume. The Encryption Key (that decrypts the Encrypted Volume) is stored in the sim-sized ACOS5 Card and the Encrypted Volume itself is stored in the ACR100. Follow the steps below to Create an Encrypted, Portable Volume: Insert your sim-sized ACOS5 card in the ACR100 Reader Slot. Insert your ACR100 (preferably ACR100F CCID) to an empty USB slot. The system should automatically detect the Removable Media and the Smart Card reader at once. Initialize the sim-sized ACOS5 card using the ACOS5 Initialization Tool. The ACOS5 Initialization Tool should detect the ACR100 Smart Card Reader as " CCID USB Reader x" (Figure 2). Figure 2: ACR100 Reader in ACOS5 Initialization Tool After successfully initializing your ACOS5 Card. You can optionally run Admin Tool to change the Token Name. Changing the Token Name can be useful to easily identify which token belongs to a particular person. Create an Encypted Volume using the sim-sized ACOS5 inside the ACR100 Device (the ACR100 is detected as a removable media in Windows Explorer) using the steps discussed here. Once an Ecrypted Volume has been created. Create a "Traveler Disk" so that you can use your encrypted volume on any PC. To create a "Traveler Disk", run TrueCrypt and on the main menu, select "Tools" and then "Traveler Disk Setup. . ." (Figure 3). Figure 3: Creating a Traveler Disk In the "TrueCrypt Traveler Disk Setup", click the "Browse" button in the "File Settings" field. Select the ACR100 Removable Disk (Figure 4). In the "Autorun Configuration" field, select "Auto-mount TrueCrypt volume". In the "Mount Settings" filed click the "Browse. . ." button and select the Volume that you have created in Step 6 above (Figure 4). Figure 4: Travel Disk Setup Click the "Create" button to Create the "Traveler Disk" files in the ACR100 Removable Media. Take note of the warning after creating the "Traveler Disk" (Figure 5). Figure 5: Travel Disk Warning Once you have created the "Traveler Disk". Some TrueCrypt files will be copied to the ACR100 Removable Device. One of these files is an "autorun.inf" file that tells the Windows operating system to load the Encrypted volumes when an ACR100 device is plugged-in (Figure 6). Figure 6: Travel Disk Files You have to edit the autorun.inf file so that the sim-sized ACOS5 card will be utilized when decrypting the Volume that is stored in your ACR100 device (more in this later). Before Editing the autorun.inf file, copy the required ACS' PKCS Files first. Go to the directory; Program Files->Advanced Card Systems Ltd->ACOS5 SDK->Middleware->PKCS. Copy the file "acospkcs11.dll" and paste it in the ACR100 device inside the folder "TrueCrypt". Go to the system32 folder. (Click "Start"->"Run" and type in system32). Look for the files; libeay32.dll, MSVCRTD.DLL and MSVCIRTD.DLL. Copy these files and paste it in the ACR100 device inside the folder "TrueCrypt". Once you have copied all the files to the ACR100 Removable media, the TrueCrypt folder inside the ACR100 should look like the one in Figure 7. Figure 7: Travel Disk Files with the PKCS#11 middleware and its dependencies Open the autorun.inf that is stored in the ACR100 removable media. After following all the steps above, the autorun.inf file should look like the one below: [autorun] label=TrueCrypt Traveler Disk icon=TrueCryptTrueCrypt.exe action=Mount TrueCrypt volume open=TrueCryptTrueCrypt.exe /q background /m rm /v "PortableEncryptedVolume" shellstart=Start TrueCrypt Background Task shellstartcommand=TrueCryptTrueCrypt.exe shelldismount=Dismount all TrueCrypt volumes shelldismountcommand=TrueCryptTrueCrypt.exe /q /dFigure 8: The Traveler Disk autorun.inf Edit the 5th line so that it would look like the one below:[autorun] label=TrueCrypt Traveler Disk icon=TrueCryptTrueCrypt.exe action=Mount TrueCrypt volume open=TrueCryptTrueCrypt.exe /q background /m rm /tokenlib "Truecryptacospkcs11.dll" /k "token://slot/0/file/RandomKeyFile" /v "PortableEncryptedVolume" shellstart=Start TrueCrypt Background Task shellstartcommand=TrueCryptTrueCrypt.exe shelldismount=Dismount all TrueCrypt volumes shelldismountcommand=TrueCryptTrueCrypt.exe /q /dFigure 9: The Updated Traveler Disk autorun.inf. The texts in red are the added parameters. RandomKeyFile is the Keyfile used to decrypt the volume. Modify the "RandomKeyFile" to the the Keyfile that is currently stored in the sim-sized ACOS5 card. Also modify the "PortableEncryptedVolume" to the TrueCrypt Volume that you have created in Step 6. You can now plug-in the ACR100 to a system and your volume will be automatically mounted to the system.
https://www.acs.com.hk/en/frequently-asked-questions/1/smart-cards-smart-card-os/ -
In MS Outlook/Outlook Express, how to set up digital certificate?
Before Signing/Encrypting an E-Mail, MS Outlook and Outlook Express should know which Digital Certificate(s) to use for each operation. Make sure that you already had requested a Digital Certificate from a Certificate Authority before doing the steps below. To set-up the digital certificate to be used for signing/encrypting e-mails in MS Outlook/Outlook Express: Make sure that you have requested a certificate in a Certificate Authority. The e-mail address that you registered when requesting a certificate SHOULD be the same e-mail account tbe the same e-mail account that you will be using in MS Outlook/Outlook Express. After successfully requesting a digital certificate. Launch MS Outlook or Outlook Express.Navigate thru Tools->Options. Select the "Security" tab (Figure 1). Figure 1: Security Tab in MS Outlook. Click the "Settings" button In the Security tab, select "Settings". The "Change Security Settings" will be displayed. In the "Certificates and Algorithms" panel, select "Choose..." to select your Signing Certificate. Figure 2: Select "Choose..." to select your Signing Certificate. Figure 3: A "Select Certificate" dialog should appear, choose the digital certificate you want to use for signing e-mails. If your certificate is not present in the "Select Certificate" dialog (Figure 3), then close the dialog and then re-inser), close the dialog and then re-insert the card/token to the reader/USB slot. Wait until the reader/token had stopped blinking. Repeat step 5 and see if the certificate present in your card/token can already be selected. Select the digital certificate that you want to use in "Select Certificate" dialog. If you still can't see the Digital Certificate that you have requested, then make sure that the E-Mail account you are using in MS Outlook is the same with the E-Mail account found in the "Subject Alternative Name" of the certificate (Figure 4). You can view the certificate in Admin Tool's Certificate Manager dialog. Figure 4: The Subject Alternative Name of the certificate should be the same account you are using in MS Outlook or Outlook Express. Once you have successfully selected your signing certificate, you can now choose an "Encryption Certificate". Select the second "Choose..." button in the "Change Security Settings" dialog (Figure 2). Check "Send these certificates with signed Check "Send these certificates with signed messages". If everything goes well then your Security settings should look like the one below (Figure 5) Figure 5: Security Settings for using Card/Token in your MS Outlook/Outlook Express E-mail client. Click "OK" in the "Security Settings" dialog and click "Apply" in the "Options" dialog. Close the "Options" dialog.
https://www.acs.com.hk/en/frequently-asked-questions/1/smart-cards-smart-card-os/ -
What are the different ACS Dynamic Password Generators?
APG8201 is a standalone handheld device for generating one-time passwords from the user’s EMV card and PIN. It is compliant to major banking standards such as EMV Level 1, MasterCard CAP and VISA DPA. APG8201 can also support PC-linked operations that can be used for Secure PIN Entry (SPE) to protect the PIN from security attacks. APG8202 is a standalone handheld device for generating one-time passwords from the user’s EMV card and PIN. It is compliant to major banking standards such as EMV Level 1, MasterCard CAP and VISA DPA.
https://www.acs.com.hk/en/frequently-asked-questions/9/dynamic-password-generators/ -
In what types of applications can the APG8201, APG8202 and APG8205 be used?
The one-time password (OTP) functionality of the APG8202, APG8202 and APG8205 makes them suitable for online banking applications. The OTPs can serve as added security before several transactions like banking logons, online transactions and telephone orders can be performed. Also, APG8201 is equipped with a Secure PIN Entry (SPE) function, which ensures safe PIN entry and PIN change in a PC environment. The PIN is securely entered on the device rather than on the vulnerable PC or workstation, hence eliminating the possibility of a Virus/Trojan getting of the PIN. This security feature is helpful in home banking and government e-ID applications.
https://www.acs.com.hk/en/frequently-asked-questions/9/dynamic-password-generators/ -
How do the APG8201, APG8202 and APG8205 use OTPs for online banking applications?
Generally, there are different modes to using OTP for online banking. Different modes would require different sets of information from users, e.g. challenge number, amount of money, account number, etc. For details, please refer to our demo video for a clearer presentation: http://www.apg8202.com/pages/dynamic-password-generators/demo
https://www.acs.com.hk/en/frequently-asked-questions/9/dynamic-password-generators/ -
What are the cards supported by APG8201, APG8202 and APG8205?
The devices support MCU cards following the ISO 7816 standard, and cards using either T=0 or T=1 protocol.
https://www.acs.com.hk/en/frequently-asked-questions/9/dynamic-password-generators/ -
What are the key features of APG8201, APG8202 and APG8205?
The devices support OTP (One-Time Password), Challenge-Response and Transaction Data Signing Modes. They also feature: Graphical LCD for logos and multiple-language characters Durable tactile keypad with 20 silicon rubber keys Monotone buzzer Two (2) CR2032 batteries Certifications/Compliance include: MasterCard® Chip Authentication Program (CAP) VISA Dynamic Passcode Authentication (DPA) EMV Level 1
https://www.acs.com.hk/en/frequently-asked-questions/9/dynamic-password-generators/







