Change algorithms without changing hardware.
With IDMS Mobile Credential, the phones your workforce already carries become hardware-backed PIV credentials — so you can accelerate your PQC transition, encrypt PACS credentials at the reader, and migrate an entire population by changing policy instead of distributing new hardware.
Issue ML-DSA certificates alongside RSA and ECC on the same phone, and pilot post-quantum before it is mandatory.
See the algorithms →Close the cleartext gap between credential and reader that makes legacy proximity cards trivial to clone.
See how doors work →Change what an entire population carries by editing IDMS policy — no reissue, no new hardware to distribute.
See enrollment →Crypto-agility, delivered via mobile
Hardware credentials take years to re-issue. Mobile credentials take a policy change. IDMS Mobile Credential adds depth to an existing MFA program rather than replacing it — issuing a converged mobile ID from IdExchange to the devices people already carry, then using that deployment speed to push new cryptographic protections across the enterprise.
Driven by customizable identity policies, a single issuance session provisions three credentials at once: PIV certificates for phishing-resistant logon and signing, a mobile access credential for doors, and a digital ID for in-person verification. Keys are generated inside the phone’s hardware security chip and never leave it. What gets issued, and in which cryptographic algorithm, is decided centrally by your IDMS — not hard-coded in the app.
One enrollment. Everything provisioned.
The device doesn’t decide what it gets. It asks the IDMS, and the IDMS policy response drives exactly which credentials — and which algorithms — are issued, all in a single pass that replaces three separate provisioning workflows.
Generates keys and certificate signing requests inside the Secure Enclave.
A configuration listing what this identity should hold.
In one round-trip batch — no repeat visits.
PIV certificates
One certificate per slot, in the algorithm the policy assigns — RSA, ECC, or post-quantum. The phone then presents itself to Windows as a PIV smart card over an encrypted Bluetooth link: logon and digital signatures with a real certificate, no password.
Physical access
A door-credential invitation the app redeems automatically into the phone’s secure element, where the HID Origo / Seos credential lives. Tap the phone to a reader to open the door — no physical prox card.
Digital ID (mDOC)
The IDMS-signed, device-bound verifiable credential in ISO/IEC 18013-5 mDOC format, delivered ready to present — with selective disclosure and holder consent, to any conformant reader. This is an employer-issued identity credential, not a driver’s license.
Certificates in every algorithm — including post-quantum
During enrollment the phone generates a key pair per PIV slot and receives a matching certificate. It then serves each certificate and signs challenges with the correct algorithm — so a relying system authenticates the user with a genuine PIV certificate, classical or post-quantum, with no card reader.
Post-quantum authentication signature (FIPS 204).
Post-quantumElliptic-curve signing — compact and fast.
ClassicalBroad compatibility with existing PKI.
ClassicalThe slot-to-algorithm map is policy-driven, not fixed — the device reads each algorithm from the enrolled certificate. Run RSA, ECC, and post-quantum credentials side by side on the same phone, then migrate an entire population by flipping a switch centrally: no app release, no reissued plastic, no desk visits.
Physical access that can’t be copied from across the room
Most badge populations still run on credential technology designed before cloning tools cost thirty dollars. Moving the credential to the phone closes the gap — because the phone can do cryptography the card never could.
The card talks in the clear
A legacy proximity card broadcasts a fixed number to any reader that asks for it. There is no mutual authentication, and nothing ties the exchange to a particular moment — so a cloner carried past a badge holder in a lobby or an elevator copies the credential in seconds. The copy is indistinguishable from the original, and nothing in the access log will ever show which one opened the door.
The phone and the reader encrypt the exchange
The phone and the reader mutually authenticate and pass the credential over an AES-encrypted channel. Nothing static crosses the air gap, so there is no number to capture and nothing to replay. The credential is bound to the device’s secure element, gated behind the holder’s PIN or biometric, and revoked centrally from the IDMS the moment someone leaves.
Multi-technology readers accept both card and mobile credentials, so a population can migrate in phases rather than a single cutover.
Secure two-phase registration
A device can’t simply enroll itself. Getting a credential onto a phone takes two phases with an out-of-band identity check in between, so a stolen phone or an intercepted code can’t self-provision.
Register the device and get a request code
The app registers the device with the IDMS and shows a short, time-limited request code the employee relays to an administrator — the identity-proofing checkpoint. Nothing is issued yet.
Confirm, then issue
The administrator’s one-time confirmation code is entered on the phone and validated by the server before anything is issued. Only on success does the IDMS release the credentials — and the code is single-use, so it can’t be replayed.
The employee then sets a PIN that gates use of the credential — the mobile equivalent of a smart-card PIN. Lost or replaced phone? Delete the credential and re-enroll remotely; the old one is orphaned.
Amplifying your identity ecosystem with mobile agility
With IDMS Mobile Credential, your established credentialing investments gain a dynamic, software-defined layer. Mobile credentials complement your foundational assets, providing the advanced capabilities modern security and operational demands require.
Accelerating crypto-agility
While core infrastructure provides much-needed stability, mobile credentials introduce the flexibility needed for the next era of cryptography. Adopt Post-Quantum Cryptography through software updates, keeping your identity strategy resilient against emerging threats without retooling your entire environment.
Strengthening the communication layer
Add another layer of defense to your access protocols. Mobile credentials leverage advanced encryption and automated key rotation, providing a high-assurance communication channel that reinforces your existing security perimeter.
Enabling dynamic identity augmentation
Expand beyond static data sets. The mobile layer lets you inject rich, real-time metadata — risk scores, device health, and context-aware attributes — directly into the authentication process for more granular access control.
Achieving unified lifecycle management
Bridge the gap between disparate access silos. By unifying logical (IT) and physical (Facilities) access under a single mobile-driven policy, identity deprovisioning becomes absolute and instantaneous across your entire enterprise footprint.
A post-quantum test bed you can run today
The migration to post-quantum cryptography is coming, and it is easier to pilot before it is mandatory. IDMS Mobile Credential already runs on ML-DSA-87 (FIPS 204) certificates end to end — enroll a post-quantum credential, sign a live authentication challenge, and log in — on real devices and middleware.
Because algorithms are chosen by policy per slot, a security team can stand up a PQC pilot alongside RSA and ECC, measure it against real workflows, and build crypto-agility into the identity program without replacing infrastructure.
A derived credential for federal workflows
IDMS Mobile Credential is built on the NIST SP 800-157 derived PIV credential model: a credential derived from an employee’s PIV identity and carried on a mobile device for use where a card reader isn’t practical. Because it is issued from the same IDMS that issued the card, the derived credential shares the card’s identity proofing, lifecycle, and audit trail.
On that basis the phone can stand in for the card across a federal workflow — PIV-authenticated logon and digital signing, physical access, and a presentable digital ID — hardware-bound in the Secure Enclave and PIN-protected, issued and governed from the IDMS.
Built on standards, not proprietary cryptography
IDMS Mobile Credential is built from published, independently reviewed standards.
Smart-card credential model — slots, certificates, and the card-edge commands the phone answers.
Mobile derived credential — a PIV-derived identity carried on a device.
Post-quantum signatures — ML-DSA-87 credentials issued and used live.
Classical algorithms — for compatibility with existing PKI.
Verifiable credential format — issuer-signed, device-bound, offline-verifiable.
Mobile physical access — the door credential in the phone’s secure element.
Secure device-to-computer link — a paired, encrypted Bluetooth channel for logon.
Hardware key isolation — private keys generated in, and never leaving, the chip. IDMS Mobile Credential runs on iPhone.
Plain-language glossary
The government smart-card standard for identity — here, emulated by the phone.
A PIV credential carried on a mobile device instead of a card (NIST SP 800-157).
Identity Management System — the central authority that registers devices and issues credentials. Here that is IdExchange, the CyberArmed platform HID licenses as PIV IDMS.
A signature algorithm designed to resist future quantum computers (FIPS 204).
A tamper-resistant chip in the iPhone that stores keys the rest of the phone can’t read.
Authentication with no shared secret or code to steal — a certificate proves identity.
Physical Access Control — the door-reader credential (HID Origo / Seos).
The ISO/IEC 18013-5 container format for a signed, device-bound verifiable credential. The standard is best known for mobile driver’s licenses; IDMS Mobile Credential uses the same certified format to carry an employer-issued identity credential.
Ready to see IDMS Mobile Credential in action?
Schedule a walkthrough and watch a phone enroll, receive a post-quantum PIV certificate, unlock a door, and sign a live authentication challenge — end to end.
