A binding code is an 8-character randomly generated combination of numbers and letters. It is used for one-to-one binding between the imKey and the imToken or imKey Manager, ensuring unauthorized clients cannot access imKey. Please make sure to back up your binding code carefully, as it will be required for rebinding your imKey in the future. The binding code is automatically generated by imKey and cannot be manually modified.
Note:
You will need the binding code to rebind in the following situations:
- Unpairing
- Logging out of imToken identity
- Uninstalling the imToken client
- Switching to a new phone
How to View the Binding Code?
- If the binding code has not been completed yet:
A binding code will be generated during the binding process. Please back it up carefully. - If the binding code has already been completed:
Open the imToken client and follow these steps:- Go to Me > Manage Wallets
- Select the paired imKey wallet
- Enter imKey Management and select "Binding Code" to view it
(Note: You need to enable Bluetooth on your phone and connect to the imKey during this process.)
- If the binding code cannot be viewed or was not backed up properly:
Don’t worry! As long as you have backed up your mnemonic phrase, you can reset the imKey and generate a new binding code. Follow these steps:- Prepare the mnemonic phrase for your imKey hardware wallet.
- Reset your imKey.
- Set the language and PIN code.
- Restore the wallet on your imKey using the mnemonic phrase.
- Rebind the imToken wallet. During this process, a new binding code will be generated.
- Back up the new binding code.
How imKey Secure Pairing Works
When you connect imKey for the first time, imToken establishes a Bluetooth connection with the device and completes device certificate verification, session key negotiation, and binding code confirmation. This creates a trusted pairing between the imToken App and the hardware wallet.
1. Verify the Device’s Identity
After imKey is paired with imToken via Bluetooth, its device certificate is sent through imToken to the server for verification. Once verified, the imToken App obtains the public key of the imKey Secure Element (SE) to confirm the identity of the connected device.
2. Establish an Encrypted Session
The imToken App generates a key pair and uses ECDH to derive the same session key as the imKey Secure Element. Data transmitted during the pairing process is protected by this session key.
3. Confirm the Binding Code
imKey generates and displays an eight-character binding code on its screen. You must manually enter this code in the imToken App to confirm that you are pairing with the imKey device currently in your possession.
The binding code is used only to establish or restore the pairing between the imToken App and imKey. It is not a recovery phrase, private key, PIN, or wallet password.
4. Complete Encrypted Verification and Pairing
The imToken App generates verification data using the binding code, the imToken App’s public key, and the public key of the imKey Secure Element. It then encrypts the data with the session key and sends it to imKey.
Once verification succeeds, the Secure Element stores the binding code and the App public key, completing the one-to-one pairing.
5. Verify Subsequent Transaction Requests
After pairing is complete, the imToken App uses the binding key to authenticate transaction requests awaiting signature. imKey verifies the source of each request using the public key of the paired imToken App.
Only after verification succeeds will imKey parse the transaction and display key details on its screen, including the recipient address, transfer amount, and network fee.
6. Sign After User Confirmation
You must independently review the transaction details on the imKey screen and press the button to confirm. Only then will the Secure Element use the wallet private key stored in imKey to sign the transaction.
The wallet private key always remains inside the imKey Secure Element and is never transmitted to the phone. After the signature is returned to the imToken App, the App assembles the transaction and broadcasts it to the blockchain network.
What Protection Does This Mechanism Provide?
Through imKey certificate verification, manual binding code confirmation, encrypted transmission of pairing data, imToken App authentication, and on-device transaction confirmation, imKey’s secure pairing mechanism helps:
- Verify the identity of the connected device;
- Reduce the risk of unauthorized imToken Apps accessing imKey;
- Reduce the risk of pairing data being intercepted or tampered with during transmission;
- Ensure that transaction requests are initiated through the paired imToken App;
- Ensure that transactions are signed only after the user has reviewed and confirmed the details on the imKey screen.
Even when a transaction is initiated through the imToken App, you must still review and confirm it on the imKey device before it can be signed. Always rely on the address, amount, and network fee displayed on the hardware wallet screen.
If you encounter any issues when viewing the binding code, resetting the device, or pairing it again, email imKey Support at support@imkey.im.
imKey Support will never ask for your recovery phrase, private key, PIN, or wallet password.
Important Notice:imKey sells physical security hardware products only and does not provide any virtual asset trading, custody, or funds-related services. References to third-party wallets, exchanges, or decentralized applications are for compatibility purposes only; related functions and services are provided independently by third parties.
0 comments
Please sign in to leave a comment.