Step 2: Register Your Account
tiCrypt has multiple account types. If you need to register a Site-Key Admin account, see Site-Key Admin Training. For an Escrow User account, see Escrow User Training.
- Register a user account
- Verify your email address
- Reset your password
- Enable high contrast mode
- Understand the login mechanism
Prerequisites
Access Level:
User, Sub-admin
Permission Requirements
- None.
When you register, tiCrypt generates a private key stored in a key file on your device. This key encrypts and decrypts all your data. If you lose both your password and your key file, your data cannot be recovered (unless your deployment has key escrow configured). After registration:
- Download your key file and store backup copies in multiple secure locations.
- Never share your key file with anyone, including administrators.
- Changing your password generates a new key file and invalidates the old one.
Register a User Account in tiCryptโ
Prefer a video walkthrough? Watch the registration video below, or follow the step-by-step instructions.
To create a new user account in tiCrypt, follow these steps:
- Open Connect Application.
- Select your deployment card.
- In the login window, select the tiCrypt category.
- Click the Create new user account button in the center.
- In the new window, click Register with MFA.
- In the pop-up, enter your login ID (usually your university email), first name, and last name.
- Click Login.
- Click Continue to password.
- Next, enter your password twice to confirm.
- Click Continue to optional information.
- Enter an optional contact email, your department, position, and any notes for your administrator.
- Click Review account.
- Review your information and click on the field you wish to update.
- Once you have updated the field, click the Return to review button.
- Click Finish registration to proceed.
- Select a folder for your public-private key pair and click Save.
- Click the Redownload private key button to re-download the private key.
- Click Continue to tiCrypt.
- Wait for an admin to activate your account.
- Once active, click Load key on the login page.
- Open the key file that you saved locally.
- Enter your password.
- Click Login.
- In the MFA pop-up, enter your email and details.
- You are logged in.
The system assigns you a unique color and icon for your key on the login page.
Video Walkthroughโ
Verify Your Email After Registrationโ
- Log into tiCrypt.
- Click the Open User Menu button in the top toolbar.
- Select My profile.
- In the overlay, click the Three-dot button on your profile card in the top-center panel.
- Select Edit metadata.
- In the prompt, verify your contact email information.
- Click Save.
Reset Your Passwordโ
- Contact your administrator.
- Your administrator will initiate a key recovery process.
- You will receive a temporary password by email.
- Log in with the temporary password, then set a new password from your user profile.
- Download your new key file and store it securely.
You cannot use the previous key to log in to the system.
If your administrator did not generate an escrow key for your account initially, you will never be able to log in or recover your account if you forget your password.
Enable High Contrast Modeโ
- Open Connect Application.
- Select your deployment card.
- In the login window, select the tiCrypt category.
- Click the Accessibility Mode button.
High contrast mode uses WCAG AA-compliant colors for improved readability.
Exit Login Page to Select New Deploymentโ
- Open Connect Application.
- Select your deployment card.
- In the login window, select the tiCrypt category.
- Click the Exit tiCrypt button in the bottom center.
The Login Mechanism in tiCryptโ
Every user in tiCrypt has a private key and a public key. Your public key can be shared freely with other users. Your private key must never be shared with anyone, including administrators.
If your private key were stored in a single location, anyone who compromised that location could steal it and access your data. tiCrypt avoids this risk through key escrow: when your account is escrowed, your private key is cryptographically split into fragments and distributed across independent escrow groups. No single group holds enough information to reconstruct the key.
If you ever lose your private key, recovery requires one designated member from each escrow group to retrieve and combine their fragment. Because the groups are independent of one another, no individual and no single group can reconstruct your key alone.
tiCrypt requires a minimum of three escrow groups per deployment. The more groups configured, the more resilient the recovery process.
Each escrow group delegates one member to hold their group's fragment of the key.