User's Manual

CryptoIdentity User Guide – 1. Introduction to CryptoIdentity and CryptoKit
For security reasons, if a wrong CryptoIdentity PIN is inserted consequently
for 12 times, the CryptoIdentity PIN is LOCKED.
If a wrong Security Officer PIN is inserted consequently for 6 times, the
Security Officer PIN is LOCKED and NO MORE USABLE.
It is possible to customize the counter of wrong attempts before the PIN and
Security Officer PIN are locked. To do so, refer to section "1.1.4
CryptoIdentity default configuration.
If you need CryptoIdentity tokens which already have this customization
according to your needs, please contact Eutron Infosecurity Sales
Department at info@eutron.com
Each CryptoIdentity has already been initialized during the manufacturing process. The
manufacturing initialization process set into the CryptoIdentity USB token a standard PIN
and Security Officer PIN.
Therefore there is no need to initialize a CryptoIdentity before starting to use it.
The default PIN set during manufacturing process is : “12345678”.
The default Security Officer PIN set during manufacturing process is "11111111" (8 times
"1").
For security reasons, it is strongly suggested to change the default PIN
before using the CryptoIdentity token. Please refer to section "3.2
Password Change Utility" to change the PIN. If you wish to change the
Security Officer PIN, please refer to section "3.3 InitToken".
You can change the CryptoIdentity PIN and Security Officer PIN also
through the AR Genie utility. For details refer to section "3.1 AR Genie".
If you need CryptoIdentity tokens with different default PINs, please contact
Eutron Infosecurity Sales Department at info@eutron.com and require this
customization.
1. 1. 4 CRYPTOIDENTITY DEFAULT CONFIGURATION
Since normal operations with CryptoIdentity require preliminary configuration (PIN
expiration period, min PIN length, max PIN length, number of PIN and SO PIN attempts,
max number of RSA private keys), these parameters are supplied as default value during
the CryptoIdentity Initialization process.
The initialization process sets into CryptoIdentity the parameters read from the following
Windows registry key:
HKEY_LOCAL_MACHINE\Software\ARL\SmartAdaptor\SC_PROVIDERS\Provider_0\
VendorDefined