The DSC USB token, explained: why your signature lives on a device
People are often surprised that a digital signature comes on a small USB stick rather than as a file to download. That physical token is not a quirk — it is the whole security model. Here is what it does, why the key can never leave it, and the myths worth ignoring.
Typical reply within minutes during office hours.
Done right the first time
Rejections and re-filings cost weeks. Our checklists, drafted documents and daily practice exist so your application goes in clean — once.
Fixed fee. Written quote. Real office at Chhani Jakatnaka, Vadodara you can walk into.
Why a digital signature comes on a physical stick
A Class 3 digital signature has two parts: a certificate, which is public and says who you are, and a private key, which is secret and does the actual signing. The certificate could sit anywhere. The private key is the sensitive half — anyone who has it can sign as you — and that is why it is not handed to you as a downloadable file. Instead it lives inside a small hardware device: the USB cryptographic token.
This is not a matter of preference. The Controller of Certifying Authorities requires it. Under the CCA's security requirements for crypto devices, a Class 3 subscriber's private key must be generated and stored inside a hardware cryptographic module, and a soft copy of the key on a computer's disk is simply not permitted. The token is where your signing power is kept, and the reason your DSC is trusted. For the certificate side, see what a Class 3 DSC is; for the service, our USB token page.
What "FIPS-validated" actually means
You will see DSC tokens described as FIPS 140-2 or FIPS 140-3 Level 2 or higher. FIPS 140 is an internationally recognised security standard for cryptographic hardware, and "validated" means an independent authority has tested the device against it. The CCA requires DSC tokens to meet at least Level 2 of that standard, so the little stick in your hand is a properly certified security module, not ordinary USB storage.
In the Indian market the common validated tokens include Feitian ePass2003, Watchdata ProxKey, HYP2003, TrustKey and mToken. The specific brand does not change the certificate itself or its legal standing — what matters is that the device is FIPS-validated and supported by the Certifying Authority and its driver software. If a token is compatible and validated, it will do the job; the differences between models are practical, not legal.
Non-exportable keys, in plain words
The single most important property of the token is that the private key is non-exportable. That means the key can never be copied off the device. When you sign a document, the file is sent into the token, the signing happens inside it using the key, and only the signed result comes back out. The key itself stays locked in the hardware for its whole life.
This is what makes a token-based DSC trustworthy in a way a downloadable key file never could be. A key stored as a file on a laptop can be copied, emailed, backed up to the cloud, or stolen by malware — and once copied, it can be used by someone else without your knowledge. A non-exportable key on a token cannot. To use it at all, a person needs both the physical token and your PIN, and the token locks after repeated wrong PIN attempts. That combination — something you have plus something you know — is the everyday security that stands behind every filing you sign.
The trade-off you accept
The same property that protects you also means there is no backup. Because the key cannot be copied, it cannot be recovered if the token is lost or destroyed — you would obtain a fresh certificate on a new token. This is a deliberate design choice: unrecoverable is the price of uncopyable.
Token myths worth ignoring
- Myth: a token holds only one certificate. Not true. A single token can hold several certificates within its capacity — most obviously a signature and encryption certificate as a pair for tenders, or certificates for different validity periods. See DSC for tenders for where the pair matters.
- Myth: a bigger or costlier token gives a "stronger" signature. The signature's strength comes from the certificate and the CCA framework, not the token brand. Any FIPS-validated, supported token produces the same legally valid signature.
- Myth: the certificate can be backed up as a file "just in case". For Class 3 the key is non-exportable by rule, so there is no legitimate soft backup. If someone offers you a downloadable copy of a Class 3 signing key, be wary.
- Myth: one token can be shared across a whole office. A token is tied to the individual it was issued to, unlocked by that person's PIN. Each signatory needs their own — sharing defeats the purpose and is poor practice.
- Myth: you must buy a new token every renewal. Usually the existing token is reused; the fresh certificate is simply downloaded onto it. See DSC renewal explained.
Looking after your token
A token is small, valuable and hard to replace, so a little care goes a long way:
- Keep the PIN private and memorable. You set it; do not tape it to the token. Repeated wrong attempts lock the device.
- Install the right driver. The token's middleware must be on your computer for portals to see the certificate — without it the token is invisible. See common DSC errors and fixes and our installation guide.
- Remove it safely and store it dry. Treat it like a house key. Do not leave it plugged in on a shared machine.
- Track the expiry. The certificate on the token expires even though the hardware still works; renew before that date to avoid disruption.
- If it is lost, act on the PIN protection. Without the PIN the certificate cannot be used, but you will still need a fresh certificate on a new token.
None of this is difficult, and most of it is just good habits. The reassuring part is that the security is built into the device — you are simply keeping the device safe.
The bottom line
Every week we meet people who lost a month to a small avoidable mistake. The fee we charge exists to make sure you are not one of them. One message, a fixed written quote, and your paperwork moves.
USB token questions, answered plainly
Why does a DSC need a USB token?
What does a non-exportable key mean?
Can one USB token hold more than one certificate?
Which USB tokens are used for DSCs in India?
What happens if I lose my DSC token?
What is the token PIN and can it be reset?
Do I need to install anything to use the token?
Can I reuse the same token when I renew my DSC?
Token trouble, or a fresh DSC needed?
Whether your token is not being detected, you are unsure which one you need, or your certificate is due for renewal, tell us what is happening. We will guide you through it — with a fixed quote before any work begins.