- Generation of ES keys and approval keys
- Formation and verification electronic signature
- Import of programmatically generated ES private keys - to enhance their security
- Updating the installation base of the crypto-provider "CryptoPro CSP"
Peculiarities
The main feature (previously the product was called "CryptoPro eToken CSP") is the use of functional key carrier technology (FKN).
Functional key carrier (FKN)- the architecture of software and hardware products based on smart cards or USB tokens, which implements a fundamentally new approach to ensuring the safe use of a key on a smart card or USB token.
Due to the presence of a secure communication channel between the token and the crypto provider, part cryptographic transformations, including storage of private keys and ES keys in a non-retrievable form, is transferred to a smart card or USB token.
In addition to hardware generation of keys, their secure storage and the formation of ES in the microprocessor of the key carrier, the FKN architecture allows you to effectively resist attacks associated with the substitution of a hash value or signature in the communication channel between the CSP software and hardware.
In "CryptoPro FKN CSP" version 3.9, a specially developed JaCarta CryptoPro token, presented in the form factors of a smart card and a USB token, acts as a key carrier.
Part CIPF "CryptoPro FKN CSP" version 3.9 includes a specially developed JaCarta CryptoPro token with the ability to calculate ES using the CRYPTO-PRO FKN technology and produced in the form factors of a USB token (in a Nano or XL case) or a smart card.
JaCarta CryptoPro securely stores and uses private ES keys, performs mutual authentication of the CSP and the token, as well as strong two-factor authentication of the user-owner of the token.
Key Benefits of JaCarta CryptoPro
- It is the fastest token among FKN devices (it is ahead of existing products working with FKN in terms of the speed of generating an electronic signature by almost 3 times - based on the Protocol for measuring the speed of FKN devices "CRYPTO-PRO" dated 08.12.2014).
- Principle applied Secure by design- uses a secure microcontroller, designed to be secure, for security purposes, has built-in protection both at the hardware and software levels against cloning, hacking and all other attacks known today.
- The generation of ES keys, approval keys, as well as the creation of ES takes place inside the JaCarta CryptoPro token.
- Uses a secure data transmission channel with the software part "CryptoPRO FKN CSP".
Compound
"CryptoPro FKN CSP" version 3.9 consists of two key components.
1. USB token or JaCarta CryptoPro smart card:
- is a functional key carrier (FKN), in which Russian cryptography is implemented in hardware;
- allows you to safely store and use private keys EP;
- generates an ES "under the mask" - K(h), which allows you to protect the exchange channel between the token (smart card) and the software crypto provider (CSP);
- performs mutual authentication of the CSP and the token and strong two-factor authentication of the user - the owner of the token.
2. Crypto provider (CSP):
- is high level software interface(MS CAPI) for external applications and provides them with a set of cryptographic functions;
- from the signature "under the mask" received from the hardware token (smart card) - K(h), "removes" the mask K(s) and forms a "normal" signature understandable for external applications
Architecture "CryptoPro FKN CSP" version 3.9
Specifications of the JaCarta CryptoPro token
Characteristics of the microcontroller | Manufacturer | INSIDE Secure |
Model | AT90SC25672RCT | |
EEPROM Memory | 72 Kb | |
Characteristics operating system | operating system | Athena Smartcard Solutions OS755 |
International certificates | CC EAL4+ | |
Supported cryptalgorithms | GOST R 34.10-2001, GOST 28147-89, GOST R 34.11-94 | |
Supported interfaces | USB | Yes |
Contact interface (ISO7816-3) | T=1 | |
Security Certifications | FSB of Russia | Certificate of conformity of the FSB of Russia No. SF / 114-2734 Certificate of conformity of the FSB of Russia No. SF / 114-2735 |
Supported OS | Microsoft Windows Server 2003 | (32/64-bit platforms) |
Microsoft Windows Vista | (32/64-bit platforms) | |
Microsoft Windows 7 | (32/64-bit platforms) | |
Microsoft Windows Server 2008 | (32/64-bit platforms) | |
Microsoft Windows Server 2008 R2 | (32/64-bit platforms) | |
CentOS 5/6 | (32/64-bit platforms) | |
Linpus Lite 1.3 | (32/64-bit platforms) | |
Mandriva Server 5 | (32/64-bit platforms) | |
Oracle Enterprise Linux 5/6 | (32/64-bit platforms) | |
Open SUSE 12 | (32/64-bit platforms) | |
Red Hat Enterprise Linux 5/6 | (32/64-bit platforms) | |
SUSE Linux Enterprise 11 | (32/64-bit platforms) | |
Ubuntu 8.04/10.04/11.04/11.10/12.04 | (32/64-bit platforms) | |
ALT Linux 5/6 | (32/64-bit platforms) | |
Debian 6 | (32/64-bit platforms) | |
FreeBSD 7/8/9 | (32/64-bit platforms) | |
Execution time of cryptographic operations | Key import | 3.2 op/s (USB token), 2.4 op/s (smart card) |
Create a signature | 5.8 op/s (USB token), 3.9 op/s (smart card) | |
Available key media | smart card | JaCarta CryptoPro |
USB token | JaCarta CryptoPro |
Security Certifications
confirming that the cryptographic information protection tool (CIPF) "CryptoPro FKN CSP" Version 3.9 (version 1) meets the requirements of GOST 28147-89, GOST R 34.11-94, GOST R 34.10-2001, the requirements of the FSB of Russia for encryption (cryptographic) means of the class KS1, the requirements for electronic signature tools, approved by the order of the Federal Security Service of Russia dated December 27, 2011 No. 796, established for the KS1 class, and can be used for cryptographic protection (creation and management of key information, encryption of data contained in the area random access memory, calculation of the hash value for data contained in the RAM area, protection of TLS connections, implementation of electronic signature functions in accordance with the Federal Law of April 6, 2011 No. 63-FZ "On Electronic Signature": creation of an electronic signature, verification electronic signature, creation of an electronic signature key, creation of an electronic signature verification key) information that does not contain information constituting a state secret.
confirming that the cryptographic information protection tool (CIPF) "CryptoPro FKN CSP" Version 3.9 (version 2) complies with the requirements of GOST 28147-89, GOST R 34.11-94, GOST R 34.10-2001, the requirements of the FSB of Russia for encryption (cryptographic) means of the class KS2, the requirements for electronic signature tools, approved by the order of the Federal Security Service of Russia dated December 27, 2011 No. 796, established for the KS2 class, and can be used for cryptographic protection (creation and management of key information, encryption of data contained in the RAM area, calculation of the value hash functions for data contained in the RAM area, protection of TLS connections, implementation of electronic signature functions in accordance with the Federal Law of April 6, 2011 No. 63-FZ "On Electronic Signature": creation of an electronic signature, verification of an electronic signature, creation of an electronic signature key, creation of an electronic signature verification key) information that does not contain information constituting a state secret.
To install a system without installation disk you must download and install all distributions of components from this manual. The installation must be performed with local administrator rights.
Installation of CIPF CryptoPro CSP
Download and install the CryptoPro CSP distribution kit according to the purchased license.
Open the CryptoPro CSP program and enter serial number licenses. Depending on the computer, this can be done in different ways:
Installing the RuToken driver
Download and install the components for working with the RuToken media. (if the certificates are stored on flash media, skip this step). When installing components, disconnect RuToken from the computer.
Installing Capicom
Installing CA Certificates
Download and install CA certificates
Installing and configuring the browser
The system works in the following browsers: Internet Explorer version 11 or higher, Mozilla Firefox, Google Chrome, Yandex.Browser, Opera.
For installation .
For correct operation Internet Explorer with the Kontur.Extern system, you must run the utility to configure the browser.
You can also manually configure the browser. To do this, use this.
For installation of other browsers, contact your system administrator.
Installing Adobe Reader
Download and install Adobe Reader. Use the link to the official Adobe website. To start the installation, you must select the version of the operating system and language.
Installing a shortcut
For ease of login, save to your desktop. After installation is complete, you must restart your computer. Before you start working in the reporting system, do not forget to install the signing certificate. Use the instructions for installing a personal certificate.
Installation completed