home *** CD-ROM | disk | FTP | other *** search
- <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
- <HTML>
- <HEAD>
- <META HTTP-EQUIV="Htm-Help" CONTENT="Multipass.htm#Main_Contents">
- <TITLE>Multipass Help</TITLE>
- </HEAD>
- <BODY BGCOLOR="#FFFFFF" TEXT="#000000">
- <!-- PegHelp -->
- <P><A NAME="Main_Contents"></A><B>Multipass Help</B></P><BR>
- <p><B>About</B><p>
- <blockquote>
- <A HREF="Multipass.htm#About">About Blueice Research AB</A><BR>
- </blockquote>
- <p><B>Install/Uninstall</B><p>
- <blockquote>
- <A HREF="Multipass.htm#Install">Installing the Multipass</A><BR>
- <A HREF="Multipass.htm#Uninstall">Uninstalling the Multipass</A><BR>
- </blockquote>
- <p><B>Using the Multipass</B><p>
- <blockquote>
- <A HREF="Multipass.htm#Overview">Overview of the Multipass</A><BR>
- <A HREF="Multipass.htm#Login">Logging into the Multipass</A><BR>
- <A HREF="Multipass.htm#Settings">Setting Application Preferences</A><BR>
- <A HREF="Multipass.htm#Offline">Off-line Functionality</A><BR>
- <A HREF="Multipass.htm#Online">On-line Functionality</A><BR>
- <A HREF="Multipass.htm#Cryptography">Cryptographic Functionality</A><BR>
- <A HREF="Multipass.htm#Troubleshooting">Troubleshooting</A><BR>
- </blockquote>
- <BR CLEAR=ALL>
- <!-- PegHelp --><HR>
- <!-- ************************Topic Break************************* -->
-
-
- <A NAME="About"></A><B>About</B>
- <BR><BR>
- Blueice Research, founded in February 2000, is a software security company.
- From its headquarters in Stockholm, Sweden, Blueice Research develops and
- markets infrastructure security products that enable secure electronic
- transaction on mobile devices. Further information regarding Blueice
- Research can be found at:<BR><BR>
- http://blueiceresearch.com
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Install"></A><B>Installing the Multipass</B>
- <BR><BR>
- The Multipass application installation file can be downloaded from the following
- web address:
- <BR><BR>
- http://multipass.com
- <BR><BR>
- The correct type of device you are using should be selected from the list of options. Currently the
- StrongARM, SH3 and MIPS processors are supported. The file that will be downloaded is called
- MP12PPC.CPU.cab, where CPU is the name of the selected processor. This file should be saved in a
- temporary location on your Pocket PC. Complete the installation by following the steps below:
- <BR><BR>
- 1. Launch the installation procedure by tapping the downloaded installation file. Use the file explorer to
- locate the installation file.
- <BR><BR>
- 2. Follow the instructions making selections where applicable. You will be asked to accept the
- license agreement.<BR>
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Uninstall"></A><B>Uninstalling the Multipass</B>
- <BR><BR>
- <B>Note:</B> You must exit the Multipass application before removing Multipass from the system. To exit
- Multipass choose "Exit" from the "Tools" menu, or stop the program from the wihtin the Settings menu on the PocketPC.
- <BR><BR>
- The Multipass application can be uninstalled using the Settings menu as follows:
- <BR><BR>
- 1. Select the System page.<BR><BR>
- 2. Tap the "Remove Programs" icon.<BR><BR>
- 3. Select the Multipass from the list of installed applications.<BR><BR>
- 4. Tap the "Remove" button to start the uninstall program.<BR><BR>
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Overview"></A><B>Overview of the Multipass</B>
- <BR><BR>
- The Multipass client (hereafter referred to as the Multipass) is an integral part of the Multipass product
- family. The Multipass is a secure storage application for user digital credentials and personal information.
- It is designed for installation on and usage with mobile devices such as PDAs, handheld computers, and PCs.
- <BR><BR>
- When used in off-line mode the Multipass is used to store personal information such as PIN codes for
- accessing buildings, user names and passwords for web sites, private personal information such as medical
- information, certificates for authentication, keys for signing transactions, etc. The Multipass provides an
- ideal storage area that is protected using strong encryption and ensures protection of private information
- in the event that the device should be lost or stolen.
- <BR><BR>
- The Multipass can also be used in online mode to conduct cryptographic transactions such as digital
- signatures as well as certificate based (PKI) authentication. In this online scenario the Multipass is used
- in conjunction with the Multipass Server from Blueice Research.
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Login"></A><B>Logging into the Multipass</B>
- <BR><BR>
- The first time a login is performed to the Multipass, an information dialogue screen is presented. Following
- acknowledgement of the information screen, a passphrase must be given and confirmed. This is the passphrase
- that will subsequently be given whenever the Multipass is to be unlocked for usage. The passphrase chosen must
- be of at least 6 characters in length and is case sensitive. It is recommended that the passphrase is at least
- 8 characters in length and is alphanumeric. As the word indicates, the passphrase may consist of several words
- or a sentence. The degree of security of the stored information depends on the strength of this passphrase.
- <BR><BR>
- <B>Note:</B> This passphrase must be remembered. If the passphrase is lost then there is no way to recover the secret
- information stored in the Multipass.
- <BR><BR>
- When the passphrase has been entered and confirmed the Multipass will open. If the passphrases do not match,
- a warning message will appear and following a confirmation of the message the passphrase can be re-entered.
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Settings"></A><B>Setting Application Preferences</B>
- <BR><BR>
- Within the Multipass, several application settings can be set. These include:
- <BR><BR>
- 1. Disabling or enabling the feature to automatically lock the Multipass after a specific period of time. <B>Note:</B>
- If the autolock feature is enabled and the device is set in suspended mode, the auto-lock timer is also suspended.
- If you set the device in the suspended mode be sure to lock the Multipass first. The auto-lock time can be set between
- 1-60 minutes.
- <BR><BR>
- 2. Changing the passphrase used to unlock the Multipass. Before the passphrase can be changed the existing
- passphrase must be entered correctly.
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Offline"></A><B>Off-line Functionality</B>
- <BR><BR>
- The Multipass gives the possibility of storing personal information in a secure manner on the handheld device.
- Tapping on the Personal Folder shows the personal information store. PIN codes, access codes, private notes, web site
- usernames and passwords, etc can be stored in this area. All information stored in the Multipass is encrypted
- and protected using strong encryption and the 3-DES encryption algorithm. Further information on the encryption
- used in the Multipass is available in the <A HREF="Multipass.htm#Cryptography">Cryptographic Functionality</A>
- section.
- <BR><BR>
- Information can be viewed according to pre-defined categories. The layout of the view can be selected from the
- view menu.
- <BR><BR>
- Selecting "New Entry" in the "Tools" menu allows you to create new entries. When creating a
- new entry the category for the entry is selected depending on the current position in the view.
- <BR><BR>
- Existing entries can be edited and deleted by opening the entry and changing the information in the various fields.
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Online"></A><B>On-line Functionality</B>
- <BR><BR>
- The Multipass allows users to perform a PKI authentication when accessing online services and also to digitally
- sign transactions performed on-line. In on-line mode, the Multipass plugs in to the Pocket Internet Explorer
- browser, providing crypto functionality to the browser. This allows for the crypto functionality of
- the Multipass client to be made available when accessing on-line services. The Multipass on-line functionality
- includes authentication and the possibility of digitally signing conducted transactions. Advanced PKI
- functionality, such as key generation and certificate handling, is also available using the Multipass in on-line
- mode.
- <BR><BR>
- When used in on-line mode the Multipass Server is required to activate the Multipass for this usage. The Multipass
- Server provides certificate registration, authentication, digital signature verification as well as digital
- signature issuance functionality when used in conjunction with the Multipass Client. For further information on
- the Multipass Server please refer to:
- <BR><BR>
- http://blueiceresearch.com
- <BR><BR>
- Information regarding the different on-line services that have been activated on the Multipass can be obtained
- by selecting the Online Services folder.
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Cryptography"></A><B>Cryptographic Functionality</B>
- <BR><BR>
- The Multipass provides symmetric and asymmetric functionality. Industry standards are followed in both of these
- areas. Triple DES is the symmetric encryption algorithm used with a key length of 168 bits. Standard X.509v3
- certificates are used for PKI authentication. The following table lists the standards followed and what they
- are used for within the product.
- <BR><BR>
- <table COLS=2 WIDTH="100%" >
- <tr>
- <td>X.509v3</td>
- <td>Certificate format</td>
- </tr>
- <tr>
- <td>ANSI X9.57</td>
- <td>DSA Signatures</td>
- </tr>
- <tr>
- <td>RSA and DSA</td>
- <td>Asymmetric encryption</td>
- </tr>
- <tr>
- <td>MD5 and SHA1</td>
- <td>Hash algorithms</td>
- </tr>
- <tr>
- <td>Triple DES</td>
- <td>Symmetric encryption</td>
- </tr>
- <tr>
- <td>PKCS#1</td>
- <td>RSA Encryption</td>
- </tr>
- <tr>
- <td>PKCS#7</td>
- <td>Digital signatures</td>
- </tr>
- <tr>
- <td>PKCS#10</td>
- <td>Certificate request</td>
- </tr>
- <tr>
- <td>PKCS#11</td>
- <td>Cryptographic token interface</td>
- </tr>
- </table>
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="Troubleshooting"></A><B>Troubleshooting</B>
- <BR><BR>
- For information on troubleshooting the Multipass installation, please visit the Multipass Website to get access
- to the latest FAQ.
- <BR><BR>
- http://multipass.com
-
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="PassphraseHelp"></A><B>Passphrase Help</B>
- <BR><BR>
- The first time that you login into the Multipass you will be required to give and confirm a passphrase that will
- subsequently be given whenever the Multipass is to be unlocked for usage. The passphrase chosen must be of at
- least 4 characters in length and is case sensitive. It is recommended that the passphrase is at least 8 characters
- in length and is alphanumeric. The degree of security of the stored information depends on the strength of this
- passphrase.
- <BR><BR>
- Note: This passphrase must be remembered. If the passphrase is lost then there is no way to recover the secret
- information stored in the Multipass.
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="ServiceRegistration1"></A><B>Service Registration</B>
- <BR><BR>
- The service you are accessing is asking if you want to register to get a digital certificate. Press the "Yes"
- button to proceed with the registration or the "No" button to abort the registration.
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
- <A NAME="ServiceRegistration2"></A><B>Service Registration</B>
- <BR><BR>
- The service you are accessing needs a username and a password to be able to continue with the on-line registration
- procedure. This username and password is service provider specific and should have been given to you by the
- service provider.
- <BR CLEAR=ALL >
- <!-- PegHelp -->
- <HR>
- <!-- **********Topic Break********** -->
-