Yubico has received FIPS 140-3 validation from the National Institute of Standards and Technology for an upgraded version of its YubiKey 5 FIPS Series, the company’s hardware authenticator targeted at federal and regulated environments. The validation, issued under NIST Cryptographic Module Validation Program certificate number 5291, is the federal standard for cryptographic modules used in non-classified US government systems, and it applies to the same line of keys that tap onto an Android or iOS device over NFC for mobile authentication.
The upgraded YubiKey 5 FIPS Series supports the same range of authentication mechanisms as the broader YubiKey 5 line, including FIDO2 and WebAuthn for phishing-resistant passkeys, Personal Identity Verification smart card credentials, OpenPGP, and OATH one-time passwords. The federal angle is that the validated module is authorized by the US Department of Defense to hold both Department of Defense Public Key Infrastructure credentials and FIDO2 passkeys on the same device, a combination Yubico describes as unique among hardware authenticators.
For mobile users, the relevant variants in the FIPS line are the YubiKey 5 NFC, the YubiKey 5C NFC, and the YubiKey 5Ci, the form factors that interact with smartphones either by tapping the key against the phone’s NFC reader or by plugging into a USB-C or Lightning port. The FIPS 140-3 validation extends to that mobile interaction, letting an agency or regulated enterprise present a smartphone-based passkey or PIV credential that is hardware-anchored on a federally validated key.
“YubiKey 5 FIPS Series is the only authenticator authorized by the US Government to hold both Department of Defense PKI credentials and FIDO2 passkeys,” said Albert Biketi, Chief Product and Technology Officer at Yubico. The dual-credential design matters for agencies that have run PIV smart card programs on smartphones and laptops for years and are now adding passkeys for systems that do not consume PIV.
FIPS 140-3 is the current generation of the US federal cryptographic module standard, replacing FIPS 140-2. Hardware authenticators that achieve a FIPS 140-3 validation can be deployed into US federal environments and into regulated private-sector buyers that require federally validated cryptography.
The validation lands as Yubico continues to position its keys against cloud-synced passkey alternatives. The company has previously advocated for device-bound passkeys over cloud-synced options for enterprise environments. The same mobile reach extends to consumer iPhones following Apple’s NFC update that enabled YubiKey authentication through standard NFC tap interactions.
The upgraded YubiKey 5 FIPS Series is available through Yubico’s existing channels.
Sources: Yubico
–
By the Mobile ID World Editorial Team