UKey Introduction

The ePass FIDO Plus Security Key is a security device that provides a full range of security features. With multiple authentication application integrated inside the security key, the user can use the ePass FIDO-NFC Plus security key with different kinds of scenarios with strong security. The supported security protocols are:

Personal Identity Verification (PIV)

This product is FIPS 140-2 Level 3 certified, complies with NIST SP 800-73 standards, and is based on PKI public key cryptography technology and secure chips. It provides secure and reliable key pair generation, certificate storage, and cryptographic operations, and supports PKI authentication and digital signatures.

FIDO Authentication (FIDO U2F + FIDO2)

The FIDO application inside ePass FIDO-NFC Plus Security Key is both FIDO2 and FIDO U2F certified, and is verified by Microsoft Azure. By using the FIDO function, users are able to achieve passwordless authentication and strong second factor authentication at the same time.

OATH OTP (HOTP + TOTP + Static Password)

The ePass FIDO have embedded OATH OTP functions for traditional 2FA authentication. With the FEITIAN Authenticator APP, users can use the ePass FIDO Plus Security Key to store 2FA credentials securely.

OpenPGP

The OPEN PGP application inside the security key adds a strong cryptography protection layer for your email with digital signing and encryption capabilities.

Applicable Scenarios

  • VPN login, SSH login
  • Windows login, domain login
  • Portal login, network login
  • Digital signature, code signing, document signing
  • Online banking transaction signature
  • Email signing, email encryption and decryption
  • File and disk encryption
  • Electronic tax filing

Specifications

Supported Operating Systems
Windows,macOS,Linux,Chrome OS,iOS,iPadOS,Android
Certifications
FIDO2/U2F Certified, FIPS 140-2 Level 2, Common Criteria EAL 6+ (for chip)
Compliance Certification
CE,FCC,RoHS,REACH,UKCA,WEEE
Interface type
USB,NFC
Transport protocol
USB CCID, USB HID, ISO 14443
Algorithm Support
On-chip key pair generation
FIDO: AES-128/256,ECC P-256,SHA256,HMAC-SHA256,HKDF
PIV:RSA 2048/3072/4096,AES-128/192/256,3DES,ECC P-256/384
OTP: HMAC-SHA1,HMAC-SHA256
OpenPGP:RSA 2048,3DES
API and Standard Support
Microsoft CAPI, Microsoft CNG, PKCS#11, Microsoft Smart Card Mini-driver
PC/SC, CCID, CTAP HID
FIDO2/WebAuthn, PIV, OpenPGP
ISO 7816-1,2,3,4(Smart Card)
X.509 V3, SSL v3, IPSec/IKE
Size
K9D (USB-A): 43.9 × 20.8 × 3.1 mm
Data storage life
At least 10 years
Programming cycles
100,000 times
Working voltage
5.0V
Working current
22mA
Power
0.11W
Working temperature
-10ºC ~ 50ºC
Storage temperature
-20ºC ~ 70ºC
Indicator
Green LED light