Cryptnox Converged Identity & Access Smart Cards combine up to three complementary security technologies on a single contact and NFC smart card: FIDO2 for phishing-resistant MFA and passwordless authentication, PIV implementing NIST SP 800-73-4 for certificate-based smart-card logon, enterprise identity and digital signatures, and MIFARE DESFire EV2 4K or EV3 16K for physical access control.
Choose exactly the functionality your organization needs — from a dedicated FIDO2 Security Key or PIV smart card to a fully converged identity and access card for online authentication, workstation access and building access.
No vendor software required for standard FIDO2 authentication on supported platforms.
Buy it from CRYPTNOX shop directly
Three Security Technologies
![]() |
![]() |
![]() |
FIDO2 |
PIV |
MIFARE DESFire |
Phishing-Resistant Authentication |
Enterprise Identity & PKI |
Physical Access |
Hardware-backed FIDO2 and WebAuthn authentication for phishing-resistant 2FA, MFA and passwordless sign-in on compatible services. |
PIV smart-card functionality implementing NIST SP 800-73-4 for certificate-based authentication, Windows and Active Directory smart-card logon, digital signatures and enterprise PKI applications. |
MIFARE DESFire functionality for physical access control, employee badges and compatible building-access systems. Two MIFARE technology variants are available: DESFire EV2 4K · DESFire EV3 16K |
Security key · WebAuthn · MFA · Passwordless |
PIV · SP 800-73-4 · Smart-card logon · Digital signatures |
16K · Building access · Employee badge · DESFire EV2 / EV3 |
Card Configurations
Deploy only the security functions you need. Cryptnox cards are available in configurations ranging from a dedicated FIDO2 Security Key or PIV smart card to a converged FIDO2 + PIV + MIFARE identity and access card.
1.Cryptnox FIDO2 Security Key Smart Card |
2.Cryptnox FIDO2 + MIFARE DESFire EV2 4K Identity & Access Card |
FIDO2 |
FIDO2 + MIFARE DESFire EV2 4K |
Phishing-resistant 2FA, MFA and passwordless authentication. |
FIDO2 authentication plus physical access functionality on one employee card. |
Primary use: Online and cloud authentication |
Primary use: Online authentication + building access |
Cryptnox FIDO2 Security Key smart card — also as White PVC and 25-pack |
Cryptnox FIDO2 + MIFARE DESFire EV2 4K card — also as White PVC and 25-pack |
3.Cryptnox PIV Smart Card — NIST SP 800-73-4 |
4.Cryptnox FIDO2 + PIV Converged Authentication Smart Card |
PIV |
FIDO2 + PIV |
Certificate-based smart-card authentication, PKI identity and digital signatures. |
Modern phishing-resistant FIDO2 authentication plus certificate-based PIV enterprise identity. |
Primary use: Enterprise identity + smart-card logon |
Primary use: Cloud authentication + workstation/PKI identity |
5.Cryptnox FIDO2 + PIV + MIFARE DESFire EV2 4K Converged Identity & Access Card |
6.Cryptnox FIDO2 + PIV + MIFARE DESFire EV3 16K Converged Identity & Access Card |
FIDO2 + PIV + MIFARE DESFire EV2 4K |
FIDO2 + PIV + MIFARE DESFire EV3 16K |
Three complementary security functions on one corporate card. |
The three-function converged identity and access card with MIFARE DESFire EV3 16K. |
Primary use: Cloud + workstation + building access |
Primary use: Cloud + workstation + building access |
Consolidated Deployment
Organizations traditionally deploy separate devices or cards for online MFA, workstation authentication and building access. Cryptnox converged identity and access cards allow these functions to coexist on a single smart card while remaining logically separated.
Cloud & Online Accounts |
Workstations & Enterprise PKI |
Doors & Physical Access |
FIDO2 / WebAuthn |
PIV / NIST SP 800-73-4 |
MIFARE DESFire EV2 4K or EV3 16K |
Phishing-resistant MFA and passwordless sign-in for identity providers, SaaS platforms and websites that support FIDO2. |
Certificate-based smart-card logon for Windows and Active Directory, VPN access, digital signatures and document encryption. |
Employee-badge and building-access credentials for compatible access-control systems, after encoding by your facilities team or integrator. |
One employee card can therefore serve as a phishing-resistant FIDO2 security key, a certificate-based PIV enterprise identity card and a MIFARE DESFire physical access badge. The three functions remain logically separated and use their own security mechanisms, keys and access conditions.
The Cryptnox FIDO2 Security Key turns the smart card into a hardware-backed authenticator for FIDO2 and WebAuthn services. It can be used for phishing-resistant MFA, two-factor authentication and passwordless sign-in where supported by the service. A single Cryptnox FIDO2 card can be registered with multiple compatible services and accounts, with separate FIDO2 / WebAuthn credentials created for each registration. Setup instructions are in the FIDO2 setup tutorials, and the full data sheet is on the Cryptnox FIDO2 card technical specifications page.
The Cryptnox FIDO2 security key protects accounts against phishing, SIM-swapping and credential theft. There are no one-time codes to intercept and no shared secret to steal — the card signs a challenge with a private key that never leaves the secure element. The FIDO2 function is FIDO2 Level 1 certified, and the secure element carries a Common Criteria EAL6+ certification. See the FIDO2 card startup guide to register your first card.
Cryptnox provides a mobile application for managing your Cryptnox FIDO2 Security Key smart card, available for iOS and Android. Check card authenticity, set or change the PIN, and reset the card when required. You can also verify a card against a live relying party with the FIDO2 and WebAuthn testing tool.
Register the Cryptnox FIDO2 Card as a security key on Microsoft 365 and Microsoft Entra ID accounts for phishing-resistant MFA, and for passwordless sign-in where your tenant and licence enable it. See the Windows sign-in setup guide.
Register at least two Cryptnox FIDO2 Cards as Apple ID security keys on your iPhone, so that a lost card does not lock you out. Apple requires a minimum of two registered keys per Apple ID.
During registration the card generates a public/private key pair for that service. The private key stays on the card; only the public key is stored by the service. At sign-in the service sends a challenge, the card signs it, and the service verifies the signature against the stored public key. Because the signature is bound to the origin, a copied or look-alike site cannot reuse it. Passwordless sign-in is available where the service supports it; elsewhere the card is used as a phishing-resistant second factor
Cryptnox PIV cards provide certificate-based enterprise identity through a PIV implementation based on NIST SP 800-73-4. PIV enables smart-card logon, PKI authentication, digital signatures and certificate-based access using cryptographic keys protected by the smart card.
Cryptnox PIV cards implement NIST SP 800-73-4. PIV adds certificate-based smart-card logon for Windows and Active Directory, digital signatures, and encryption with keys up to RSA-4096. The card runs a PIV applet built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280). It is not deployed in the configuration covered by that certificate, and Cryptnox does not claim any FIPS certification at this stage. Full details are on the Cryptnox PIV card specifications page.
PIV is a certificate-based smart-card identity architecture. On a Cryptnox card it supports:
Cryptnox converged identity and access cards can include MIFARE DESFire for physical access control and employee-badge applications. Depending on the card configuration, MIFARE functionality is available as DESFire EV2 4K or DESFire EV3 16K. The MIFARE credential is encoded by your facilities team or access-control integrator and is independent of the FIDO2 and PIV functions on the same card. Read how the three functions work together on one printable badge in FIDO2, PIV and MIFARE DESFire EV3 16K on one enterprise smart card.
The MIFARE DESFire EV2 4K variant provides 4 KB of card memory for access-control credentials. It is used for building entry, employee badges and other physical-access applications on compatible reader infrastructure.
Fitted to the FIDO2 + MIFARE and FIDO2 + PIV + MIFARE EV2 4K configurations. Compatibility with proprietary access-control systems is not universal — test a sample card with your readers and software before a bulk rollout.
MIFARE DESFire technical specifications · Cryptnox FIDO2 card with MIFARE DESFire
The MIFARE DESFire EV3 16K variant is a newer DESFire generation with 16 KB of card memory, giving more room for multiple access applications on one badge.
Fitted to the FIDO2 + PIV + MIFARE DESFire EV3 16K configuration. As with EV2, verify compatibility with your access-control readers and software before deployment.
MIFARE DESFire technical specifications · FIDO2 + PIV + MIFARE DESFire EV3 16K card
Cryptnox identity and access cards are contact and NFC smart cards. The same functions can be reached over the contact interface using a smart-card reader, or contactlessly over NFC — which interface you use depends on the device and the function.
Insert the card into a contact smart-card reader for desktop use.
Tap the card against an NFC-capable phone or an NFC reader.
For a walk-through of how card-format security keys compare with USB-style tokens and what to look for when selecting one, read how to choose a FIDO2 security key. Card-specific data sheets: FIDO2 card specifications, PIV card specifications and MIFARE DESFire specifications.
FAQ
A converged identity and access smart card combines multiple credential technologies on one physical card. Cryptnox cards can combine FIDO2 authentication, PIV enterprise identity and MIFARE DESFire physical access, depending on the selected configuration.
Cryptnox cards are available in several configurations combining FIDO2, PIV and MIFARE DESFire. MIFARE-equipped variants use either MIFARE DESFire EV2 4K or DESFire EV3 16K depending on the card model.
The Cryptnox PIV functionality implements NIST SP 800-73-4, providing PIV smart-card functionality for certificate-based authentication, smart-card logon and digital-signature applications.
FIDO2 is designed primarily for phishing-resistant authentication to websites, applications and identity providers using public-key credentials. PIV is a certificate-based smart-card identity architecture used for enterprise PKI, workstation authentication, digital signatures and other certificate-based applications. A Cryptnox card can contain either technology individually or both on the same card.
MIFARE DESFire adds physical-access and badge functionality. Cryptnox offers MIFARE-equipped configurations using DESFire EV2 4K or DESFire EV3 16K, depending on the product. Compatibility depends on your access-control system and integration — test a sample card before a bulk rollout.
Yes. The appropriate FIDO2 + PIV + MIFARE configuration combines all three functions on one physical smart card: FIDO2 for online authentication, PIV for certificate-based enterprise identity and MIFARE DESFire for physical access. The FIDO2, PIV and MIFARE DESFire functions remain logically separate and use independent cryptographic keys and security mechanisms.
The Cryptnox FIDO2 Card is a hardware-based authenticator that supports the FIDO2 open authentication standard. It provides phishing-resistant two-factor authentication for compatible services, and is natively supported by the major operating systems for standard FIDO2 use — no vendor software installation required on supported platforms.
The card connects to phones and computers over NFC, or through a compatible contact smart-card reader. On Android, external NFC security keys are supported for CTAP1 / U2F rather than full FIDO2 / CTAP2. On Linux, FIDO2 use requires the open-source Cryptnox FIDO2 HID bridge, because browsers expect an HID authenticator and CCID readers do not present one.
The FIDO2 function is FIDO2 Level 1 certified, and the secure chip used carries a Common Criteria EAL6+ certification. These are separate certifications with separate scopes: a chip or platform certification does not certify the applications installed on it, and FIDO2 certification does not cover PIV or MIFARE functionality. Per-configuration detail is on the FIDO2 and PIV specification pages.
Yes, you can register your Cryptnox FIDO2 Card as a Microsoft security key and use it to sign in. A Microsoft 365 business subscription is required for Entra ID security-key sign-in.
Register at least two Cryptnox FIDO2 Cards on your iPhone as your Apple ID security keys — Apple requires a minimum of two. You can also use the card to authenticate your Google login.
Where a service supports it, the card allows passwordless and username-less sign-in, so there is no password to phish, reuse or leak. This depends on the service, browser and operating system; where passwordless is not supported, the card is used as a phishing-resistant second factor.
Many online platforms support FIDO2 security keys, including AWS, Shopify, X (Twitter), GitHub, GoDaddy, Apple, Facebook, Namecheap and many more. Support and feature level vary by service.
FIDO2 replaces shared secrets with public-key cryptography. The private key never leaves the card and signatures are bound to the origin, so credentials cannot be replayed on a look-alike site — which is what makes it phishing-resistant.
The card works with the major browsers and operating systems that support FIDO2, including recent Chrome, Firefox, Edge and Safari on Windows and macOS. Support is not identical everywhere: see the NFC and contact notes above for the iOS, Android, macOS and Linux caveats.
Always configure a backup authentication method or register a second card. For lost account access, contact the support team of the service concerned. For PIV deployments, revoke the certificates through your certificate authority; for MIFARE, remove the badge in your access-control system.
Cards are normally registered to a single user. Organizations deploy one card per employee, with each card individually registered and issued.
Register the card with each service that supports FIDO2 authentication. Follow the FIDO2 setup tutorials and the instructions of the service you are enrolling it with. PIV cards are provisioned with certificates from your own certificate authority.
Order a dedicated FIDO2 Security Key, a PIV smart card, or a converged FIDO2 + PIV + MIFARE DESFire identity and access card from the Cryptnox shop. For volume deployments and custom encoding, contact Cryptnox.