Mon–Sat 10–7 Chhani Jakatnaka, Vadodara
Harsiddhi Services Documentation & Compliance
Handling legal & government documents since 2017 Fixed price in writing before we start No hidden charges — government fees separate Rated by clients on Google
Home Knowledge Centre USB token explained
DSC Knowledge · India

The DSC USB token, explained: why your signature lives on a device

People are often surprised that a digital signature comes on a small USB stick rather than as a file to download. That physical token is not a quirk — it is the whole security model. Here is what it does, why the key can never leave it, and the myths worth ignoring.

Since 2017 FIPS-validated hardware Updated: July 2026

Typical reply within minutes during office hours.

9+ yearsIn service
6,000+Applications across services
CSC 136237240013Govt-approved CSC
GST 24ETLPP2031J1ZMRegistered business
PID 242000004888GPLGST practitioner
★ GoogleRead client reviews

Done right the first time

Rejections and re-filings cost weeks. Our checklists, drafted documents and daily practice exist so your application goes in clean — once.

Fixed fee. Written quote. Real office at Chhani Jakatnaka, Vadodara you can walk into.

Start on WhatsApp Fixed written quote before any work begins
Overview

Why a digital signature comes on a physical stick

A Class 3 digital signature has two parts: a certificate, which is public and says who you are, and a private key, which is secret and does the actual signing. The certificate could sit anywhere. The private key is the sensitive half — anyone who has it can sign as you — and that is why it is not handed to you as a downloadable file. Instead it lives inside a small hardware device: the USB cryptographic token.

This is not a matter of preference. The Controller of Certifying Authorities requires it. Under the CCA's security requirements for crypto devices, a Class 3 subscriber's private key must be generated and stored inside a hardware cryptographic module, and a soft copy of the key on a computer's disk is simply not permitted. The token is where your signing power is kept, and the reason your DSC is trusted. For the certificate side, see what a Class 3 DSC is; for the service, our USB token page.

The standard

What "FIPS-validated" actually means

You will see DSC tokens described as FIPS 140-2 or FIPS 140-3 Level 2 or higher. FIPS 140 is an internationally recognised security standard for cryptographic hardware, and "validated" means an independent authority has tested the device against it. The CCA requires DSC tokens to meet at least Level 2 of that standard, so the little stick in your hand is a properly certified security module, not ordinary USB storage.

In the Indian market the common validated tokens include Feitian ePass2003, Watchdata ProxKey, HYP2003, TrustKey and mToken. The specific brand does not change the certificate itself or its legal standing — what matters is that the device is FIPS-validated and supported by the Certifying Authority and its driver software. If a token is compatible and validated, it will do the job; the differences between models are practical, not legal.

The key idea

Non-exportable keys, in plain words

The single most important property of the token is that the private key is non-exportable. That means the key can never be copied off the device. When you sign a document, the file is sent into the token, the signing happens inside it using the key, and only the signed result comes back out. The key itself stays locked in the hardware for its whole life.

This is what makes a token-based DSC trustworthy in a way a downloadable key file never could be. A key stored as a file on a laptop can be copied, emailed, backed up to the cloud, or stolen by malware — and once copied, it can be used by someone else without your knowledge. A non-exportable key on a token cannot. To use it at all, a person needs both the physical token and your PIN, and the token locks after repeated wrong PIN attempts. That combination — something you have plus something you know — is the everyday security that stands behind every filing you sign.

The trade-off you accept

The same property that protects you also means there is no backup. Because the key cannot be copied, it cannot be recovered if the token is lost or destroyed — you would obtain a fresh certificate on a new token. This is a deliberate design choice: unrecoverable is the price of uncopyable.

Setting the record straight

Token myths worth ignoring

  • Myth: a token holds only one certificate. Not true. A single token can hold several certificates within its capacity — most obviously a signature and encryption certificate as a pair for tenders, or certificates for different validity periods. See DSC for tenders for where the pair matters.
  • Myth: a bigger or costlier token gives a "stronger" signature. The signature's strength comes from the certificate and the CCA framework, not the token brand. Any FIPS-validated, supported token produces the same legally valid signature.
  • Myth: the certificate can be backed up as a file "just in case". For Class 3 the key is non-exportable by rule, so there is no legitimate soft backup. If someone offers you a downloadable copy of a Class 3 signing key, be wary.
  • Myth: one token can be shared across a whole office. A token is tied to the individual it was issued to, unlocked by that person's PIN. Each signatory needs their own — sharing defeats the purpose and is poor practice.
  • Myth: you must buy a new token every renewal. Usually the existing token is reused; the fresh certificate is simply downloaded onto it. See DSC renewal explained.
Practical care

Looking after your token

A token is small, valuable and hard to replace, so a little care goes a long way:

  • Keep the PIN private and memorable. You set it; do not tape it to the token. Repeated wrong attempts lock the device.
  • Install the right driver. The token's middleware must be on your computer for portals to see the certificate — without it the token is invisible. See common DSC errors and fixes and our installation guide.
  • Remove it safely and store it dry. Treat it like a house key. Do not leave it plugged in on a shared machine.
  • Track the expiry. The certificate on the token expires even though the hardware still works; renew before that date to avoid disruption.
  • If it is lost, act on the PIN protection. Without the PIN the certificate cannot be used, but you will still need a fresh certificate on a new token.

None of this is difficult, and most of it is just good habits. The reassuring part is that the security is built into the device — you are simply keeping the device safe.

Before you decide

The bottom line

Every week we meet people who lost a month to a small avoidable mistake. The fee we charge exists to make sure you are not one of them. One message, a fixed written quote, and your paperwork moves.

Get the written quote

FAQs

USB token questions, answered plainly

Why does a DSC need a USB token?
CCA security requirements mandate that the private key of a Class 3 subscriber is generated and stored inside a hardware cryptographic module — a USB token — validated to FIPS 140-2 or 140-3 Level 2 or higher. The key never leaves the token and signing happens on the device, protected by a PIN. Storing the key as a soft file on a computer's disk is not permitted for Class 3.
What does a non-exportable key mean?
It means the private key cannot be copied off the token. The token performs the signing internally and only lets the result out, never the key itself. This is what stops your signing key being duplicated onto another machine, emailed, or stolen as a file. It is the core reason a DSC on a token is trustworthy.
Can one USB token hold more than one certificate?
Yes. The idea that a token holds only one certificate is a myth. A single token can hold multiple certificates — for example a signature and an encryption certificate as a pair, or certificates for different purposes — subject to the token's capacity. What a token cannot do is hold certificates for different people if that breaches the one-holder principle behind the PIN.
Which USB tokens are used for DSCs in India?
Common FIPS-validated tokens in the Indian market include Feitian ePass2003, Watchdata ProxKey, HYP2003, TrustKey and mToken. The exact model does not change the certificate itself; it must simply be a token that is FIPS-validated and supported by the Certifying Authority and its driver software.
What happens if I lose my DSC token?
Because the key is non-exportable, a lost token means the certificate on it cannot be recovered — there is no backup copy anywhere. You would need to obtain a fresh certificate on a new token through the usual eKYC and video verification. The PIN protects the token in the meantime, since without it the certificate cannot be used.
What is the token PIN and can it be reset?
The PIN is a password you set that unlocks the token for signing. You choose it, and it locks the token after repeated wrong attempts as a security measure. Depending on the token, a locked PIN may be reset using an administrator PIN or the token's management utility, but if that too is exhausted the token can become permanently locked.
Do I need to install anything to use the token?
Yes. The token's driver or middleware must be installed on your computer so that browsers and signing utilities can see the certificate. Government portals also need their own signing utility — for example emSigner for GST and emBridge or emsigner for income tax. Without the driver, the token will not be recognised.
Can I reuse the same token when I renew my DSC?
Usually yes. Renewal issues a fresh certificate, which can be downloaded onto your existing token provided the token model and firmware are still supported. A new token is not automatically required. Very old tokens may need a firmware or CSP upgrade, or occasionally replacement, but most users keep the same device.

Token trouble, or a fresh DSC needed?

Whether your token is not being detected, you are unsure which one you need, or your certificate is due for renewal, tell us what is happening. We will guide you through it — with a fixed quote before any work begins.