Cryptnox PIV Smart Card Technical Specifications

PIV — FIPS 201 / NIST SP 800-73-4 Specifications

Execution Environment

  • NXP SmartMX3 P71 secure element, Java Card platform — JCOP 4.5 on P71D600 (PIV-only, FIDO2 + PIV, and FIDO2 + PIV + MIFARE DESFire EV3 16K cards) or JCOP 4 on P71D321 (FIDO2 + PIV + MIFARE DESFire EV2 4K card)
  • PIV applet: — NIST SP 800-73-4 / SP 800-78-4 conformant implementation of the FIPS 201-3 Personal Identity Verification (PIV) data model

PIV applet characteristics

  • Personal Identity Verification (PIV) card application per NIST FIPS 201-3 — SP 800-73-4 data model and command interface, SP 800-78-4 cryptographic algorithms
  • Four PIV key slots: 9A (PIV authentication), 9C (digital signature), 9D (key management), 9E (card authentication)
  • RSA-4096, RSA-2048, ECC P-256 and ECC P-384 — on-card key generation; private keys never leave the secure element
  • NFC (ISO/IEC 14443 Type A) contactless and ISO/IEC 7816 contact interfaces
  • Passive card — no battery; powered by the reader’s RF field

Card management & secure channel — SCP03

All Cryptnox PIV smart cards are managed over the GlobalPlatform SCP03 secure channel.

Operating system compatibility (PIV)

  • Windows 10/11: native PIV smart-card logon (Windows mini-driver / Base CSP)
  • macOS: PIV via CryptoTokenKit / OpenSC
  • Linux: PIV via OpenSC / PKCS#11

Works with standard PC/SC smart-card readers and NFC readers — see the Cryptnox card readers.

Card body

  • ISO/IEC 7810 ID-1 format (CR80, credit-card size)
  • Blank white PVC face, ready for ID card printers (dye-sublimation or thermal transfer) — printable as a photo ID badge
  • Durability: ISO 7816 / 14443 smart-card lifecycle — typically rated for 500,000+ contactless transactions

Certifications

Each part of the card is certified independently; there is no single whole-card certification.

Chip & platform (Common Criteria)

  • PIV-only, FIDO2 + PIV, and FIDO2 + PIV + MIFARE DESFire EV3 16K cards — JCOP 4.5 on P71D600: secure controller NXP N7122 A1, Common Criteria EAL6 augmented (ALC_FLR.1, ASE_TSS.2) — BSI-DSZ-CC-1149-V4-2025; platform JCOP 4.5 P71, Common Criteria EAL6 augmentedNSCIB-CC-2300127-02
  • FIDO2 + PIV + MIFARE DESFire EV2 4K card — JCOP 4 on P71D321: secure controller NXP N7121 B1, Common Criteria certified (composed with BSI-DSZ-CC-1136-V5-2026); platform JCOP 4 P71, Common Criteria EAL6 augmentedNSCIB-CC-2300172-02
  • AIS-31 compliant true random number generator (chip-level)

Applet-level certification

  • PIV applet: built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280), NIST SP 800-73-4 / SP 800-78-4 conformant. That certificate was issued on the NXP P71D600 secure element — the chip used in this card. The applet is not deployed in the configuration covered by that certificate, and Cryptnox does not claim any FIPS certification at this stage. Card management uses SCP03.
  • On the FIDO2 + PIV + MIFARE DESFire EV2 4K card the applet is the same validated version, running on P71D321 — the underlying platform differs from the validated P71D600 configuration. The FIDO2 + PIV + MIFARE DESFire EV3 16K card runs on P71D600, the platform the module was validated on; as a multi-application configuration Cryptnox does not claim any FIPS certification for the finished card at this stage.

FIPS status (background)

  • Chip-level FIPS validations exist for the underlying NXP platforms: JCOP 4.5 / P71D600 — FIPS 140-3, Overall Level 3 with Physical Security Level 4 (NIST CMVP #4679, active); JCOP 4 / P71D321 — FIPS 140-2, Overall Level 3 with Physical Security Level 4 (NIST CMVP #3746, historical status).
  • These NXP validations cover only the exact module and applet configuration NIST validated. The additional Cryptnox applets result in a different module configuration outside the applicable NXP FIPS validation — the finished cards are not as complete products.
  • The PIV applet is built from the same codebase certified under FIPS 140-3 (CMVP #5280) (see Certifications above); all Cryptnox PIV cards use SCP03 secure-channel card management.

Compliance

  • ISO/IEC 7810 (card form factor), ISO/IEC 7816 (contact interface), ISO/IEC 14443 (NFC interface)
  • NIST FIPS 201-3 (PIV); NIST SP 800-73-4 / SP 800-78-4
  • Supports deployments aligned with OMB M-22-09, NIST SP 800-63B, PCI DSS v4, NIS2, DORA and eIDAS

PIV smart cards in the Cryptnox shop

Buy Cryptnox PIV smart cards

Related resources