IDMS MOBILE CREDENTIAL

Change algorithms without changing hardware.

With IDMS Mobile Credential, the phones your workforce already carries become hardware-backed PIV credentials — so you can accelerate your PQC transition, encrypt PACS credentials at the reader, and migrate an entire population by changing policy instead of distributing new hardware.

9:45
IDMS Mobile
My Device
Employee Credential
Jane Doe
Signature Valid
Computers
Sign in to your computer
Connected
Doors
Always on — just hold your phone up
Scanning
Show My ID
Choose what to share, then generate a code

Crypto-agility, delivered via mobile

Hardware credentials take years to re-issue. Mobile credentials take a policy change. IDMS Mobile Credential adds depth to an existing MFA program rather than replacing it — issuing a converged mobile ID from IdExchange to the devices people already carry, then using that deployment speed to push new cryptographic protections across the enterprise.

Driven by customizable identity policies, a single issuance session provisions three credentials at once: PIV certificates for phishing-resistant logon and signing, a mobile access credential for doors, and a digital ID for in-person verification. Keys are generated inside the phone’s hardware security chip and never leave it. What gets issued, and in which cryptographic algorithm, is decided centrally by your IDMS — not hard-coded in the app.

One enrollment. Everything provisioned.

The device doesn’t decide what it gets. It asks the IDMS, and the IDMS policy response drives exactly which credentials — and which algorithms — are issued, all in a single pass that replaces three separate provisioning workflows.

Device
Asks to enroll

Generates keys and certificate signing requests inside the Secure Enclave.

IDMS
Returns a policy

A configuration listing what this identity should hold.

Device
Provisions all of it

In one round-trip batch — no repeat visits.

Credentials Installed On the Device
Inside this device

PIV certificates

One certificate per slot, in the algorithm the policy assigns — RSA, ECC, or post-quantum. The phone then presents itself to Windows as a PIV smart card over an encrypted Bluetooth link: logon and digital signatures with a real certificate, no password.

Physical access

A door-credential invitation the app redeems automatically into the phone’s secure element, where the HID Origo / Seos credential lives. Tap the phone to a reader to open the door — no physical prox card.

Digital ID (mDOC)

The IDMS-signed, device-bound verifiable credential in ISO/IEC 18013-5 mDOC format, delivered ready to present — with selective disclosure and holder consent, to any conformant reader. This is an employer-issued identity credential, not a driver’s license.

Certificates in every algorithm — including post-quantum

During enrollment the phone generates a key pair per PIV slot and receives a matching certificate. It then serves each certificate and signs challenges with the correct algorithm — so a relying system authenticates the user with a genuine PIV certificate, classical or post-quantum, with no card reader.

slot 9A
ML-DSA-87

Post-quantum authentication signature (FIPS 204).

Post-quantum
slot 9C
ECDSA P-256

Elliptic-curve signing — compact and fast.

Classical
slot 9D / 9E
RSA-2048

Broad compatibility with existing PKI.

Classical
This is crypto-agility in practice.

The slot-to-algorithm map is policy-driven, not fixed — the device reads each algorithm from the enrolled certificate. Run RSA, ECC, and post-quantum credentials side by side on the same phone, then migrate an entire population by flipping a switch centrally: no app release, no reissued plastic, no desk visits.

Physical access that can’t be copied from across the room

Most badge populations still run on credential technology designed before cloning tools cost thirty dollars. Moving the credential to the phone closes the gap — because the phone can do cryptography the card never could.

Today’s badge population

The card talks in the clear

A legacy proximity card broadcasts a fixed number to any reader that asks for it. There is no mutual authentication, and nothing ties the exchange to a particular moment — so a cloner carried past a badge holder in a lobby or an elevator copies the credential in seconds. The copy is indistinguishable from the original, and nothing in the access log will ever show which one opened the door.

With IDMS Mobile Credential

The phone and the reader encrypt the exchange

The phone and the reader mutually authenticate and pass the credential over an AES-encrypted channel. Nothing static crosses the air gap, so there is no number to capture and nothing to replay. The credential is bound to the device’s secure element, gated behind the holder’s PIN or biometric, and revoked centrally from the IDMS the moment someone leaves.

Multi-technology readers accept both card and mobile credentials, so a population can migrate in phases rather than a single cutover.

Secure two-phase registration

A device can’t simply enroll itself. Getting a credential onto a phone takes two phases with an out-of-band identity check in between, so a stolen phone or an intercepted code can’t self-provision.

1

Register the device and get a request code

The app registers the device with the IDMS and shows a short, time-limited request code the employee relays to an administrator — the identity-proofing checkpoint. Nothing is issued yet.

2

Confirm, then issue

The administrator’s one-time confirmation code is entered on the phone and validated by the server before anything is issued. Only on success does the IDMS release the credentials — and the code is single-use, so it can’t be replayed.

The employee then sets a PIN that gates use of the credential — the mobile equivalent of a smart-card PIN. Lost or replaced phone? Delete the credential and re-enroll remotely; the old one is orphaned.

Amplifying your identity ecosystem with mobile agility

With IDMS Mobile Credential, your established credentialing investments gain a dynamic, software-defined layer. Mobile credentials complement your foundational assets, providing the advanced capabilities modern security and operational demands require.

Accelerating crypto-agility

While core infrastructure provides much-needed stability, mobile credentials introduce the flexibility needed for the next era of cryptography. Adopt Post-Quantum Cryptography through software updates, keeping your identity strategy resilient against emerging threats without retooling your entire environment.

Strengthening the communication layer

Add another layer of defense to your access protocols. Mobile credentials leverage advanced encryption and automated key rotation, providing a high-assurance communication channel that reinforces your existing security perimeter.

Enabling dynamic identity augmentation

Expand beyond static data sets. The mobile layer lets you inject rich, real-time metadata — risk scores, device health, and context-aware attributes — directly into the authentication process for more granular access control.

Achieving unified lifecycle management

Bridge the gap between disparate access silos. By unifying logical (IT) and physical (Facilities) access under a single mobile-driven policy, identity deprovisioning becomes absolute and instantaneous across your entire enterprise footprint.

Future-proofing

A post-quantum test bed you can run today

The migration to post-quantum cryptography is coming, and it is easier to pilot before it is mandatory. IDMS Mobile Credential already runs on ML-DSA-87 (FIPS 204) certificates end to end — enroll a post-quantum credential, sign a live authentication challenge, and log in — on real devices and middleware.

Because algorithms are chosen by policy per slot, a security team can stand up a PQC pilot alongside RSA and ECC, measure it against real workflows, and build crypto-agility into the identity program without replacing infrastructure.

Federal alignment

A derived credential for federal workflows

IDMS Mobile Credential is built on the NIST SP 800-157 derived PIV credential model: a credential derived from an employee’s PIV identity and carried on a mobile device for use where a card reader isn’t practical. Because it is issued from the same IDMS that issued the card, the derived credential shares the card’s identity proofing, lifecycle, and audit trail.

On that basis the phone can stand in for the card across a federal workflow — PIV-authenticated logon and digital signing, physical access, and a presentable digital ID — hardware-bound in the Secure Enclave and PIN-protected, issued and governed from the IDMS.

Built on standards, not proprietary cryptography

IDMS Mobile Credential is built from published, independently reviewed standards.

NIST FIPS 201 / SP 800-73 · PIV

Smart-card credential model — slots, certificates, and the card-edge commands the phone answers.

NIST SP 800-157 · Derived PIV

Mobile derived credential — a PIV-derived identity carried on a device.

NIST FIPS 204 · ML-DSA

Post-quantum signatures — ML-DSA-87 credentials issued and used live.

RSA-2048 · ECDSA P-256

Classical algorithms — for compatibility with existing PKI.

ISO/IEC 18013-5 · mDOC

Verifiable credential format — issuer-signed, device-bound, offline-verifiable.

HID Origo / Seos

Mobile physical access — the door credential in the phone’s secure element.

Noise Protocol · Encrypted BLE

Secure device-to-computer link — a paired, encrypted Bluetooth channel for logon.

Apple Secure Enclave

Hardware key isolation — private keys generated in, and never leaving, the chip. IDMS Mobile Credential runs on iPhone.

Plain-language glossary

PIV credential

The government smart-card standard for identity — here, emulated by the phone.

Derived PIV credential

A PIV credential carried on a mobile device instead of a card (NIST SP 800-157).

IDMS

Identity Management System — the central authority that registers devices and issues credentials. Here that is IdExchange, the CyberArmed platform HID licenses as PIV IDMS.

Post-quantum (ML-DSA)

A signature algorithm designed to resist future quantum computers (FIPS 204).

Secure Enclave

A tamper-resistant chip in the iPhone that stores keys the rest of the phone can’t read.

Phishing-resistant MFA

Authentication with no shared secret or code to steal — a certificate proves identity.

PACS / mobile access

Physical Access Control — the door-reader credential (HID Origo / Seos).

mDOC

The ISO/IEC 18013-5 container format for a signed, device-bound verifiable credential. The standard is best known for mobile driver’s licenses; IDMS Mobile Credential uses the same certified format to carry an employer-issued identity credential.

Ready to see IDMS Mobile Credential in action?

Schedule a walkthrough and watch a phone enroll, receive a post-quantum PIV certificate, unlock a door, and sign a live authentication challenge — end to end.