Cryptnox FIDO2 Card technical specifications

FIDO2 v2.1 Specifications

Execution Environment

  • JCOP 4 / 4.5 from NXP with ECC module (other chips on request) – JCOP 4 / DESFire EV2
  • Applet Size: 68 kb (with 64 credential slots)

Applet Certification

  • FIDO2 / CTAP2.1 — FIDO Alliance Certified, Authenticator Level 1 — certificate FIDO20020240806001
  • U2F / 1.2 — FIDO Alliance Certified, Authenticator Level 1 — certificate U2F100020240806001
  • Both issued 6 August 2024. Chip-platform certifications are listed separately below (Underlying Secure-Element Platform section).

FIDO Alliance Certification — Cryptnox Fido 2.1

FIDO Alliance certificate FIDO20020240806001 - Cryptnox Fido 2.1, FIDO2 CTAP2.1 Authenticator Level 1FIDO Alliance certificate U2F100020240806001 - Cryptnox Fido 2.1, U2F 1.2 Authenticator Level 1

Applet characteristics

  • U2Fv2, FIDO 2.0 and FIDO 2.1 standards
  • NFC ISO 14443 contactless and ISO 7816 contact interfaces
  • EC Digital Signature (ECDSA) with NIST P256 (256R1) parameters
  • 32 bits signature counter, reset to 0 upon authenticator reset
  • Multiple accounts per Relying Party
  • Resident keys credentials (64 credential slots)
  • CredManagement commands

Operating System Compatibility (FIDO2)

  • Windows 10/11: full FIDO2 / passkey support
  • iOS: FIDO2 over NFC on iPhone 7+ running iOS 13.3 or later
  • Android: external NFC keys mainly via CTAP1 / U2F second-factor (older FIDO1 protocol); not full FIDO2 / passwordless
  • macOS: FIDO2 over NFC support varies by macOS version and browser
  • Linux: FIDO2 sign-in requires the open-source Cryptnox FIDO2 HID bridge

Card body

  • ISO 7810 ID-1 format (CR80, credit-card size)
  • Durability: ISO 7816 / 14443 smart-card lifecycle — typically rated for 500,000+ contactless transactions

Chip platform certifications

The Cryptnox FIDO2 applet runs on NXP’s SmartMX3 P71 secure-element platform. Two chip variants are used across the FIDO2 product line:

  • Single-application FIDO2 cards (no MIFARE applet) — JCOP 4.5 on P71D600:
    • Secure controller NXP N7122 A1: Common Criteria EAL6 augmented (ALC_FLR.1, ASE_TSS.2) — BSI-DSZ-CC-1149-V4-2025 (valid to 2030-09-04)
    • Platform JCOP 4.5 P71: Common Criteria EAL6 augmentedNSCIB-CC-2300127-02 (issued 2025-12-15)
    • FIPS background: NXP has validated a specific JCOP 4.5 / P71D600 module configuration to FIPS 140-3 Level 3 with Physical Security Level 4 under CMVP certificate #4679. Cryptnox installs additional Java Card applets that are not included in that module configuration, so the finished product is not claimed as FIPS validated.
  • Combo FIDO2 + MIFARE DESFire cards — JCOP 4 on P71D321:
    • Secure controller NXP N7121 B1: Common Criteria EAL6 augmented (ASE_TSS.2, ALC_FLR.1) — BSI-DSZ-CC-1136-V5-2026 (valid to 2031-01-29)
    • Platform JCOP 4 P71: Common Criteria EAL6 augmentedNSCIB-CC-2300172-02 (issued 2026-02-12)
    • Historical FIPS background: NXP previously validated a specific JCOP 4 / P71D321 module configuration to FIPS 140-2 Level 3 with Physical Security Level 4 under CMVP certificate #3746; that certificate is now historical. The Cryptnox applets and finished product are not covered by it and are not claimed as FIPS validated.
    • The platform includes support for an NXP MIFARE DESFire implementation (capability — no separate product certification is claimed for it).

Both platforms include an AIS-31 compliant True Random Number Generator at the chip level (used as entropy source for FIDO2 challenges, nonces, and key generation).

Common Criteria certification applies to the identified NXP secure controller and JCOP operating platform in their evaluated configurations. Installed Cryptnox applications and the complete multi-application product are not independently Common Criteria certified. The Cryptnox FIDO2 applet carries its own FIDO Alliance certification (see the Applet Certification section above). Cryptographic operations within the FIDO2 applet use NIST P-256 only — the platforms support additional curves (Brainpool, Secp256k1, etc.) but the FIDO2 applet does not expose them.

Applet Options

  • HmacSecret
  • CredProtect
  • CredBlob for Resident-Keys
  • minPinLength: stores up to 4 authorized RPs

Client Management Application

  • iOS and Android mobile application for PIN change, factory reset, and resident-key management

AAGUID

  • 1d1b4e33-76a1-47fb-97a0-14b10d0933f1