NXP and Swissbit teamed up to secure digital and physical access by combining Fast Identity Online (FIDO) authentication with MIkron FARE Collection System (MIFARE) Digital Encryption Standard – Fast Innovative Reliable Enhanced, Evolution 3 (DESFire EV3) in a single security key.
Enterprise access control has traditionally involved separate systems for physical and digital authentication. Employees often use a badge to enter the building and a dedicated security key to access corporate IT systems, resulting in multiple credentials to manage.
To address this challenge, Swissbit collaborated with NXP to deliver the iShield Key 2 , a FIDO security key that unifies both logical and physical access in a single, compact device. This integration enables a secure, intuitive and reliable access experience, bringing physical and digital authentication together.
Swissbit’s Vision for Unified Authentication
Swissbit’s initial challenge was one of compatibility. While digital authentication systems increasingly rely on FIDO for strong, phishing‑resistant security, most FIDO‑capable hardware cannot interface with physical entry systems. Swissbit recognized a clear opportunity: create a solution that seamlessly bridges modern passwordless authentication with established physical access infrastructures.
To realize this vision, Swissbit required a high‑performance secure microcontroller with ample memory and MIFARE support backed by industry‑leading security certifications. The project demanded compliance with Common Criteria (CC) EAL6+ and FIPS 140‑3 Level 3 standards, essential for delivering the highest level of trust and protection expected in enterprise and critical infrastructure environments.
NXP’s comprehensive hardware and software stack—including the JCOP platform, MIFARE libraries and robust support—made development and R&D remarkably straightforward for our team. Their flexible platform enabled us to seamlessly integrate FIDO, PKI and advanced physical access features all within a single chip, setting our solution apart in the market.
Alexander Summerer, Head of Authentication at Swissbit
Behind the Key: Java Card Open Platform (JCOP) ID 2 and MIFARE DESFire EV3
NXP provided exactly the hardware platform Swissbit needed to streamline digital and physical access. Swissbit selected NXP’s JCOP ID2 platform, which combines proven secure hardware with a robust Java Card operating system and integrated MIFARE support.
Simplify your security. Explore our MIFARE portfolio for secure credential management across multi-site access management systems.
The iShield Key 2 runs on a powerful stack of NXP technologies:
- NXP SmartMX3 P71D600: A secure microcontroller (MCU) combining CC EAL6+ and FIPS 140‑3 certifications with high‑performance across multiple interfaces, strong attack resistance and large on‑chip memory, providing a trusted hardware foundation for modern FIDO tokens
- JCOP 4.5: A market‑proven, updatable Java Card OS with certified security, outstanding flexibility and unmatched reliability, supporting diverse identity and authentication use cases
- MIFARE DESFire EV3: Supported on JCOP 4.5, DESFire EV3 delivers advanced security, rapid performance and broad ecosystem compatibility, enabling secure, scalable and widely interoperable physical access solutions, all on a single FIDO token
NXP’s Collaborative Approach
Achieving such a deep level of integration was only possible through tight collaboration.
NXP’s engineering teams worked closely with Swissbit to guide the development of their custom Java applets on JCOP 4.5 while providing dedicated support to seamlessly integrate the SmartMX3 P71D600 into their chip-on-board(CoB) module, enabling an optimized USB token design.
By working together, we developed a solution that:
- Unifies access control: The iShield Key 2 seamlessly brings together FIDO2‑based logical authentication and MIFARE DESFire physical access in one compact device
- Is highly secure: The FIDO solution is phishing-resistant and is certified to meet industry security standards, including CC EAL6+ and FIPS 140-3 Level 3 certifications
- Is future proof: Secure software stack updates allow adaptation to evolving security requirements and support deploying new applications to devices already in the field
Delivering a Secure Future
Through this collaboration, NXP continues to empower innovators like Swissbit to solve complex security challenges with flexible, certified technologies. Together with our partners, NXP is pioneering solutions that make the smarter world more secure, accessible and intuitive than ever before.
Ready to secure your workspace? Check out our smart access solutions.
Related content: Building Scalable and Secure Access Systems with MIFARE DUOX.