YubiKey 5Ci FIPS


5CiFIPS.png

Note: This article lists the technical specifications of the YubiKey 5Ci FIPS. If you're looking for deployment considerations, refer to this article. If you're looking for a usage guide, refer to this article.

 

The YubiKey 5Ci FIPS is FIPS 140-2 certified (Overall Level 1 and Level 2, Physical Security Level 3) and based on the YubiKey 5Ci. The YubiKey 5Ci FIPS has five distinct applications, which are all independent of each other and can be used simultaneously. Note: The YubiKey 5 FIPS Series does not support OpenPGP. Should you need this functionality, you will need either the YubiKey FIPS (4 Series) or the YubiKey 5 Series (non-FIPS). 

 

Interface

The YubiKey 5Ci FIPS uses a USB 2.0 interface as well as an Apple Lightning® interface. All of the applications are available through both interfaces.

 

Applications

 

FIDO2

The FIDO2 application allows for secure single and multi-factor authentication, and can store up to 25 resident credentials. These credentials, which are protected by a PIN, enable passwordless login, where the YubiKey, unlocked by a PIN and authorized by touch, can log you in to your accounts without entering a username or password. The FIDO2 application is FIDO certified.

USB/Apple Lightning® Interface: FIDO

More about FIDO 2

 

U2F

Note: The YubiKey 5 FIPS Series U2F application cannot be used in a FIPS 140-2 Level 2 mode. In place of the U2F functionality, use the FIDO WebAuthn application. For more information, refer to the YubiKey 5 FIPS Series Technical Manual.

The U2F application can hold an unlimited number of U2F credentials and is FIDO certified.

USB/Apple Lightning® Interface: FIDO

 

OTP

The OTP application contains two programmable slots, each can hold one of the following credentials:

  • Yubico OTP
  • HMAC-SHA1 Challenge-Response
  • Static Password
  • OATH-HOTP

USB/Apple Lightning® Interface: OTP

 

OATH

The YubiKey 5 FIPS Series can hold up to 32 OATH credentials and supports both OATH-TOTP (time based) and OATH-HOTP (counter based). Accessing this application requires Yubico Authenticator.

USB/Apple Lightning® Interface: CCID

 

PIV (Smart Card)

This application provides a PIV-compatible smart card. On Windows, the smart card functionality can be enhanced with the YubiKey Smart Card Minidriver.

Default Values:

  • PIN: 123456
  • PUK: 12345678
  • Management Key: 010203040506070801020304050607080102030405060708

Supported Algorithms:

  • RSA 1024
  • RSA 2048
  • ECC P256
  • ECC P384

Slot Information:

  • Slot 9a: Authentication
  • Slot 9b: Management Key
  • Slot 9c: Digital Signature
  • Slot 9d: Key Management
  • Slot 9e: Card Authentication
  • Slot f9: Attestation
  • Slots 82-95: Retired Key Management

USB/Apple Lightning® Interface: CCID

More info about PIV

 

Physical Specifications

 

Form Factor

Connector: USB-C, Apple Lightning®

Dimensions: 12mm x 40.3mm x 5mm

Weight: 2.9g

Physical Interfaces: USB, Apple Lightning®

 

Temperatures

Operational range: 0 °C - 40 °C (32 °F - 104 °F)

Storage range: -20 °C - 85 °C (-4 °F - 185 °F)