Converged Identity & Access Smart Cards

One Card. Up to Three Security Technologies.​

Cryptnox Converged Identity & Access Smart Cards combine up to three complementary security technologies on a single contact and NFC smart card: FIDO2 for phishing-resistant MFA and passwordless authentication, PIV implementing NIST SP 800-73-4 for certificate-based smart-card logon, enterprise identity and digital signatures, and MIFARE DESFire EV2 4K or EV3 16K for physical access control.

Choose exactly the functionality your organization needs — from a dedicated FIDO2 Security Key or PIV smart card to a fully converged identity and access card for online authentication, workstation access and building access.

Cryptnox hardware wallets

FIDO2  ·  PIV  ·  MIFARE DESFire

No vendor software required for standard FIDO2 authentication on supported platforms.

Buy it from CRYPTNOX shop directly

Cryptnox accepted payment methods

Preferred shopping solution for US:

Also available on other Amazon shops:
DE, FR, IT, BE, SE, ES, PL, NL, CA, MX, AU

Cryptnox FIDO2 security key NFC smart card video

Three Security Technologies

One Card. Three Security Functions.

FIDO2

PIV

MIFARE DESFire

Phishing-Resistant Authentication

Enterprise Identity & PKI

Physical Access

Hardware-backed FIDO2 and WebAuthn authentication for phishing-resistant 2FA, MFA and passwordless sign-in on compatible services.

PIV smart-card functionality implementing NIST SP 800-73-4 for certificate-based authentication, Windows and Active Directory smart-card logon, digital signatures and enterprise PKI applications.

MIFARE DESFire functionality for physical access control, employee badges and compatible building-access systems. Two MIFARE technology variants are available: DESFire EV2 4K · DESFire EV3 16K

Security key · WebAuthn · MFA · Passwordless

PIV · SP 800-73-4 · Smart-card logon · Digital signatures

16K · Building access · Employee badge · DESFire EV2 / EV3

Card Configurations

Choose Your Cryptnox Card Configuration

Deploy only the security functions you need. Cryptnox cards are available in configurations ranging from a dedicated FIDO2 Security Key or PIV smart card to a converged FIDO2 + PIV + MIFARE identity and access card.

1.Cryptnox FIDO2 Security Key Smart Card

2.Cryptnox FIDO2 + MIFARE DESFire EV2 4K Identity & Access Card

FIDO2

FIDO2 + MIFARE DESFire EV2 4K

Phishing-resistant 2FA, MFA and passwordless authentication.

FIDO2 authentication plus physical access functionality on one employee card.

Primary use: Online and cloud authentication

Primary use: Online authentication + building access

3.Cryptnox PIV Smart Card — NIST SP 800-73-4

4.Cryptnox FIDO2 + PIV Converged Authentication Smart Card

PIV

FIDO2 + PIV

Certificate-based smart-card authentication, PKI identity and digital signatures.

Modern phishing-resistant FIDO2 authentication plus certificate-based PIV enterprise identity.

Primary use: Enterprise identity + smart-card logon

Primary use: Cloud authentication + workstation/PKI identity

5.Cryptnox FIDO2 + PIV + MIFARE DESFire EV2 4K Converged Identity & Access Card

6.Cryptnox FIDO2 + PIV + MIFARE DESFire EV3 16K Converged Identity & Access Card

FIDO2 + PIV + MIFARE DESFire EV2 4K

FIDO2 + PIV + MIFARE DESFire EV3 16K

Three complementary security functions on one corporate card.

The three-function converged identity and access card with MIFARE DESFire EV3 16K.

Primary use: Cloud + workstation + building access

Primary use: Cloud + workstation + building access

Consolidated Deployment

One Corporate Card Instead of Multiple Tokens

Organizations traditionally deploy separate devices or cards for online MFA, workstation authentication and building access. Cryptnox converged identity and access cards allow these functions to coexist on a single smart card while remaining logically separated.

Cloud & Online Accounts

Workstations & Enterprise PKI

Doors & Physical Access

FIDO2 / WebAuthn

PIV / NIST SP 800-73-4

MIFARE DESFire EV2 4K or EV3 16K

Phishing-resistant MFA and passwordless sign-in for identity providers, SaaS platforms and websites that support FIDO2.

Certificate-based smart-card logon for Windows and Active Directory, VPN access, digital signatures and document encryption.

Employee-badge and building-access credentials for compatible access-control systems, after encoding by your facilities team or integrator.

One employee card can therefore serve as a phishing-resistant FIDO2 security key, a certificate-based PIV enterprise identity card and a MIFARE DESFire physical access badge. The three functions remain logically separated and use their own security mechanisms, keys and access conditions.

FIDO2 Security Key for Phishing-Resistant Authentication

The Cryptnox FIDO2 Security Key turns the smart card into a hardware-backed authenticator for FIDO2 and WebAuthn services. It can be used for phishing-resistant MFA, two-factor authentication and passwordless sign-in where supported by the service. A single Cryptnox FIDO2 card can be registered with multiple compatible services and accounts, with separate FIDO2 / WebAuthn credentials created for each registration. Setup instructions are in the FIDO2 setup tutorials, and the full data sheet is on the Cryptnox FIDO2 card technical specifications page.

Phishing-Resistant Two-Factor Authentication

The Cryptnox FIDO2 security key protects accounts against phishing, SIM-swapping and credential theft. There are no one-time codes to intercept and no shared secret to steal — the card signs a challenge with a private key that never leaves the secure element. The FIDO2 function is FIDO2 Level 1 certified, and the secure element carries a Common Criteria EAL6+ certification. See the FIDO2 card startup guide to register your first card.

Device Admin with the FIDO2 Card Manager app

Cryptnox provides a mobile application for managing your Cryptnox FIDO2 Security Key smart card, available for iOS and Android. Check card authenticity, set or change the PIN, and reset the card when required. You can also verify a card against a live relying party with the FIDO2 and WebAuthn testing tool.

FIDO2 Security Key for Microsoft Windows

Register the Cryptnox FIDO2 Card as a security key on Microsoft 365 and Microsoft Entra ID accounts for phishing-resistant MFA, and for passwordless sign-in where your tenant and licence enable it. See the Windows sign-in setup guide.

FIDO2 Security Key for Apple ID

Register at least two Cryptnox FIDO2 Cards as Apple ID security keys on your iPhone, so that a lost card does not lock you out. Apple requires a minimum of two registered keys per Apple ID.

How FIDO2 Passwordless Authentication Works

During registration the card generates a public/private key pair for that service. The private key stays on the card; only the public key is stored by the service. At sign-in the service sends a challenge, the card signs it, and the service verifies the signature against the stored public key. Because the signature is bound to the origin, a copied or look-alike site cannot reuse it. Passwordless sign-in is available where the service supports it; elsewhere the card is used as a phishing-resistant second factor

PIV Smart Card — NIST SP 800-73-4 Enterprise Identity​

Cryptnox PIV cards provide certificate-based enterprise identity through a PIV implementation based on NIST SP 800-73-4. PIV enables smart-card logon, PKI authentication, digital signatures and certificate-based access using cryptographic keys protected by the smart card.

PIV — NIST SP 800-73-4

Cryptnox PIV cards implement NIST SP 800-73-4. PIV adds certificate-based smart-card logon for Windows and Active Directory, digital signatures, and encryption with keys up to RSA-4096. The card runs a PIV applet built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280). It is not deployed in the configuration covered by that certificate, and Cryptnox does not claim any FIPS certification at this stage. Full details are on the Cryptnox PIV card specifications page.

What PIV Adds to the Card

PIV is a certificate-based smart-card identity architecture. On a Cryptnox card it supports:

  • Smart-card logon to Windows and Active Directory
  • Certificate-based authentication to VPNs, workstations and enterprise applications
  • Digital signatures for documents and email
  • Encryption and key management with RSA keys up to 4096 bits
  • PKI identity issued and managed by your own certificate authority

MIFARE DESFire for Physical Access

Cryptnox converged identity and access cards can include MIFARE DESFire for physical access control and employee-badge applications. Depending on the card configuration, MIFARE functionality is available as DESFire EV2 4K or DESFire EV3 16K. The MIFARE credential is encoded by your facilities team or access-control integrator and is independent of the FIDO2 and PIV functions on the same card. Read how the three functions work together on one printable badge in FIDO2, PIV and MIFARE DESFire EV3 16K on one enterprise smart card.

MIFARE DESFire EV2 4K

The MIFARE DESFire EV2 4K variant provides 4 KB of card memory for access-control credentials. It is used for building entry, employee badges and other physical-access applications on compatible reader infrastructure.

Fitted to the FIDO2 + MIFARE and FIDO2 + PIV + MIFARE EV2 4K configurations. Compatibility with proprietary access-control systems is not universal — test a sample card with your readers and software before a bulk rollout.

MIFARE DESFire technical specifications · Cryptnox FIDO2 card with MIFARE DESFire

MIFARE DESFire EV3 16K

The MIFARE DESFire EV3 16K variant is a newer DESFire generation with 16 KB of card memory, giving more room for multiple access applications on one badge.

Fitted to the FIDO2 + PIV + MIFARE DESFire EV3 16K configuration. As with EV2, verify compatibility with your access-control readers and software before deployment.

MIFARE DESFire technical specifications · FIDO2 + PIV + MIFARE DESFire EV3 16K card

Contact and NFC: How the Card Connects

Cryptnox identity and access cards are contact and NFC smart cards. The same functions can be reached over the contact interface using a smart-card reader, or contactlessly over NFC — which interface you use depends on the device and the function.

Over a Contact Reader

card-reader-product-image

Insert the card into a contact smart-card reader for desktop use.

  • Windows 10/11— full FIDO2 support across the major browsers, and the native path for PIV smart-card logon.
  • PIV— certificate-based logon is normally driven over the contact interface, and needs the usual smart-card middleware and certificate provisioning for your environment.
  • Linux— browsers expect a FIDO2 authenticator to present an HID interface, which CCID smart-card readers do not. Use the open-source Cryptnox FIDO2 HID bridge for any FIDO2 use on Linux.

Over NFC

contactless-card-reader-product-image

Tap the card against an NFC-capable phone or an NFC reader.

  • iOS— FIDO2 over NFC is generally consistent on iPhone 7 and later with iOS 13.3+.
  • Android— external NFC security keys are supported for CTAP1 / U2F rather than full FIDO2 / CTAP2, so the card works as a second factor on most mainstream services but not for passkey-style passwordless sign-in. Test with your target service first.
  • macOS— FIDO2 over NFC varies by macOS version and browser; test before relying on it.
  • MIFARE DESFire physical access is always contactless.
Cryptnox FIDO2 Card Manager app download

Download our FIDO2 Card Manager application

Manage your Cryptnox FIDO2 Security key with the Cryptnox FIDO2 Card Manager app. This app will allow you to manage all the configurations available on your Cryptnox FIDO2 Card, via NFC communication.

Technical and Security Highlights

Card Platform
  • Format — ID-1 contact and NFC smart card; no battery, no moving parts.
  • Secure element — keys are generated and held in a secure element carrying a Common Criteria EAL6+ certification. Certification of the platform does not by itself certify the applications installed on it; see the per-product specifications for what is covered.
  • Security functions — FIDO2, PIV and MIFARE DESFire are provisioned independently and use independent cryptographic keys.
FIDO2 / WebAuthn
  • FIDO2 Level 1 certified; supports FIDO2 / WebAuthn and legacy U2F (CTAP1).
  • Phishing-resistant MFA and two-factor authentication; passwordless sign-in where the service supports it.
  • PIN management, card reset and authenticity checks through the Cryptnox FIDO2 Card Manager app.
  • Works with Microsoft 365 and Microsoft Entra ID, Apple ID, Google Workspace and other WebAuthn services.
PIV / NIST SP 800-73-4
  • PIV functionality implementing NIST SP 800-73-4 for certificate-based authentication.
  • Windows and Active Directory smart-card logon, digital signatures, encryption and enterprise PKI.
  • RSA keys up to 4096 bits; certificates issued and managed by your own certificate authority.
  • Runs a PIV applet built from the same codebase certified under FIPS 140-3 (NIST CMVP #5280), not deployed in the configuration covered by that certificate. Full certification detail is on the PIV card specifications page.
MIFARE DESFire
  • DESFire EV2 4K — 4 KB of card memory for access-control credentials.
  • DESFire EV3 16K — newer DESFire generation with 16 KB of card memory.
  • Encoded by your facilities team or access-control integrator; verify reader compatibility before rollout.
Choosing a Security Key

For a walk-through of how card-format security keys compare with USB-style tokens and what to look for when selecting one, read how to choose a FIDO2 security key. Card-specific data sheets: FIDO2 card specifications, PIV card specifications and MIFARE DESFire specifications.

FAQ

Frequently Asked Questions

What is a converged identity and access smart card?

A converged identity and access smart card combines multiple credential technologies on one physical card. Cryptnox cards can combine FIDO2 authentication, PIV enterprise identity and MIFARE DESFire physical access, depending on the selected configuration.

Which functions can I combine on a Cryptnox card?

Cryptnox cards are available in several configurations combining FIDO2, PIV and MIFARE DESFire. MIFARE-equipped variants use either MIFARE DESFire EV2 4K or DESFire EV3 16K depending on the card model.

Which PIV standard does the Cryptnox PIV card implement?

The Cryptnox PIV functionality implements NIST SP 800-73-4, providing PIV smart-card functionality for certificate-based authentication, smart-card logon and digital-signature applications.

What is the difference between FIDO2 and PIV?

FIDO2 is designed primarily for phishing-resistant authentication to websites, applications and identity providers using public-key credentials. PIV is a certificate-based smart-card identity architecture used for enterprise PKI, workstation authentication, digital signatures and other certificate-based applications. A Cryptnox card can contain either technology individually or both on the same card.

What does MIFARE DESFire add?

MIFARE DESFire adds physical-access and badge functionality. Cryptnox offers MIFARE-equipped configurations using DESFire EV2 4K or DESFire EV3 16K, depending on the product. Compatibility depends on your access-control system and integration — test a sample card before a bulk rollout.

Can one Cryptnox card handle online login, Windows smart-card authentication and building access?

Yes. The appropriate FIDO2 + PIV + MIFARE configuration combines all three functions on one physical smart card: FIDO2 for online authentication, PIV for certificate-based enterprise identity and MIFARE DESFire for physical access. The FIDO2, PIV and MIFARE DESFire functions remain logically separate and use independent cryptographic keys and security mechanisms.

What is the Cryptnox FIDO2 Card?

The Cryptnox FIDO2 Card is a hardware-based authenticator that supports the FIDO2 open authentication standard. It provides phishing-resistant two-factor authentication for compatible services, and is natively supported by the major operating systems for standard FIDO2 use — no vendor software installation required on supported platforms.

How does the Cryptnox FIDO2 Card work with mobile phones and computers?

The card connects to phones and computers over NFC, or through a compatible contact smart-card reader. On Android, external NFC security keys are supported for CTAP1 / U2F rather than full FIDO2 / CTAP2. On Linux, FIDO2 use requires the open-source Cryptnox FIDO2 HID bridge, because browsers expect an HID authenticator and CCID readers do not present one.

What certifications does the Cryptnox FIDO2 Card have?

The FIDO2 function is FIDO2 Level 1 certified, and the secure chip used carries a Common Criteria EAL6+ certification. These are separate certifications with separate scopes: a chip or platform certification does not certify the applications installed on it, and FIDO2 certification does not cover PIV or MIFARE functionality. Per-configuration detail is on the FIDO2 and PIV specification pages.

Can I use the Cryptnox FIDO2 Card for signing into Microsoft Windows or Microsoft 365?

Yes, you can register your Cryptnox FIDO2 Card as a Microsoft security key and use it to sign in. A Microsoft 365 business subscription is required for Entra ID security-key sign-in.

How can I use the Cryptnox FIDO2 Card with my Apple ID?

Register at least two Cryptnox FIDO2 Cards on your iPhone as your Apple ID security keys — Apple requires a minimum of two. You can also use the card to authenticate your Google login.

What are the benefits of passwordless authentication with the Cryptnox FIDO2 Card?

Where a service supports it, the card allows passwordless and username-less sign-in, so there is no password to phish, reuse or leak. This depends on the service, browser and operating system; where passwordless is not supported, the card is used as a phishing-resistant second factor.

Which other platforms accept a FIDO2 card for login?

Many online platforms support FIDO2 security keys, including AWS, Shopify, X (Twitter), GitHub, GoDaddy, Apple, Facebook, Namecheap and many more. Support and feature level vary by service.

 How does FIDO2 improve online security?

FIDO2 replaces shared secrets with public-key cryptography. The private key never leaves the card and signatures are bound to the origin, so credentials cannot be replayed on a look-alike site — which is what makes it phishing-resistant.

Is the Cryptnox FIDO2 Card compatible with all browsers and operating systems?

The card works with the major browsers and operating systems that support FIDO2, including recent Chrome, Firefox, Edge and Safari on Windows and macOS. Support is not identical everywhere: see the NFC and contact notes above for the iOS, Android, macOS and Linux caveats.

What happens if I lose my Cryptnox card?

Always configure a backup authentication method or register a second card. For lost account access, contact the support team of the service concerned. For PIV deployments, revoke the certificates through your certificate authority; for MIFARE, remove the badge in your access-control system.

Can one card be used by multiple users?

Cards are normally registered to a single user. Organizations deploy one card per employee, with each card individually registered and issued.

How do I set up the card for the first time?

Register the card with each service that supports FIDO2 authentication. Follow the FIDO2 setup tutorials and the instructions of the service you are enrolling it with. PIV cards are provisioned with certificates from your own certificate authority.

FIDO2 Front

Choose Your Cryptnox Card​

Order a dedicated FIDO2 Security Key, a PIV smart card, or a converged FIDO2 + PIV + MIFARE DESFire identity and access card from the Cryptnox shop. For volume deployments and custom encoding, contact Cryptnox.