- New
NEOWAVE QSCD is a family of hardware security solutions utilizing smart cards and a Public Key Infrastructure (PKI). The products are designed for strong user authentication, secure digital certificate storage, Windows login, data encryption, SSO, VPN, and electronic signature support.
NEOWAVE QSCD – PKI Keys and Cards for Strong Authentication and Electronic Signatures
NEOWAVE QSCD is a family of hardware security solutions utilizing smart cards and a Public Key Infrastructure (PKI). The products are designed for strong user authentication, secure digital certificate storage, Windows login, data encryption, SSO, VPN, and electronic signature support.
QSCD stands for Qualified Signature Creation Device. Products in this series utilize a certified Java Card component and PKI solutions compliant with QSCD/eIDAS requirements. They also enable centralized access rights management, user registration, and temporary or permanent revocation of logical and – in appropriate variants – physical rights.
The family is intended for businesses, public administration, healthcare, critical infrastructure operators, local government units, and certification authorities, among others.
Key Features of the QSCD Family
Strong User Authentication
Digital Certificate-Based Authentication
PKI Certificate Storage
Windows Login Using a Certificate
Electronic Signature
QSCD Application Support
Data Encryption
Single Sign-On Support
VPN Support
Interoperability with Directory Services
PKI Certificate Generation
Device Registration and User Association
Temporary or Permanent Revocation of Permissions
Central Access Rights Management
PIN-Protected Credential Storage
Device or Card Personalization
Available Models
NEOWAVE Winkeo2J-A QSCD
Hardware PKI/QSCD token with USB-A connector. The device includes an integrated smart card, eliminating the need for an external card reader.
Type: Hardware PKI/QSCD token
Interface: USB-A PC/SC
Integrated Java Card in micro-SIM format
Common Criteria: EAL6+
QSCD / eIDAS: Yes
Cybersecurity Made in Europe: Yes
Middleware: SafeSign Identity Client
Operating Systems: Windows, macOS, Linux
Length: 43.8 mm
Width: 18 mm
Thickness: 9.76 mm
Weight: 6 g
Applications: Windows login, PKI, SSO, VPN, encryption, electronic signature.
NEOWAVE Winkeo2J-C QSCD
Functionally similar to the Winkeo2J-A, equipped with a modern USB-C connector.
Type: PKI/QSCD hardware token
Interface: USB-C PC/SC
Integrated Java Card in micro-SIM format
Common Criteria: EAL6+
QSCD / eIDAS: Yes
Cybersecurity Made in Europe: Yes
Middleware: SafeSign Identity Client
Operating systems: Windows, macOS, Linux
Length: 39.7 mm
Width: 18 mm
Thickness: 8.25 mm
Weight: 5 g
Applications: PKI, login, SSO, VPN, encryption, and electronic signature.
NEOWAVE Badgeo QSCD
A smart card designed primarily for certificate authentication and PKI/QSCD applications. Type: Contactless PKI/QSCD Smart Card
Interface: ISO 7816
Format: ID-1
Java Card: Yes
Common Criteria: EAL6+
QSCD / eIDAS: Yes
Middleware: AET SafeSign Identity Client
Software Interfaces: CSP / KSP / PKCS#11
Systems: Windows, macOS, Linux
Browsers: Edge, Firefox, Chrome, Safari
Length: 85.6 mm
Width: 54 mm
Thickness: 0.76 mm
Weight: 5 g
A compatible ISO 7816 / PC/SC smart card reader is required for use with a computer.
NEOWAVE Badgeo HYB QSCD
A hybrid card variant combining PKI/QSCD functions with physical access technologies.
Type: Contactless and contactless smart card
Contact interface: ISO 7816
Contactless/NFC interface: Available
Contactless technologies depending on configuration: MIFARE, DESFire EV2/EV3, ISO 15693, 125 kHz
Logical application: PKI, authentication, signature, SSO, VPN, encryption
Physical application: Access control
Common Criteria: EAL6+
Middleware: SafeSign Identity Client
Card format: ID-1
Dimensions: approx. 85.6 x 54 x 0.76 mm
Weight: approx. 5 g. The manufacturer lists the Badgeo HYB QSCD as a contactless and contactless/NFC variant of the QSCD family.
Software Required for Operation
Unlike basic FIDO2 keys, the QSCD family requires middleware to utilize PKI functionality on the computer.
Required middleware: AET SafeSign Identity Client
Supported cryptographic interfaces: CSP, KSP, and PKCS#11
CSP – Cryptographic Service Provider, a cryptographic interface used by, among others, via the Microsoft environment
KSP – Key Storage Provider, a key management mechanism in the Microsoft Cryptography API: Next Generation
PKCS#11 – a standard interface that allows applications to use keys and certificates stored on a cryptographic device
Operating system: Windows, macOS, or Linux
An additional certificate-using application may be required, such as an electronic signature program, VPN client, SSO solution, encryption software, or PKI system
Winkeo2J-A and Winkeo2J-C have an integrated smart card interface and do not require a separate card reader
Badgeo QSCD requires a suitable contactless card reader
Badgeo HYB QSCD can work with appropriate contactless and contactless infrastructure, depending on the application.
Manufacturer and Country of Origin
Manufacturer: NEOWAVE
Manufacturer's Country: France
Manufacturer's Headquarters: Gardanne, France
Country of Design and Production: France
Manufacturer Declares: 100% Made in France
Design: France
Production: France
Product Family: NEOWAVE QSCD
Segment: Identity Security / PKI / Strong Authentication / Electronic Signature
Product Designation: Cybersecurity Made in Europe
The products utilize Common Criteria EAL6+ certified smart card components.
Technical Specifications – Common Features
Technology: Smart Card / Java Card
Component Certification: Common Criteria EAL6+
PKI Support: Yes
QSCD Support: Yes
QSCD / eIDAS Certification: Yes – for appropriate applets/products specified by the manufacturer
Middleware: AET SafeSign Identity Client
Middleware Programming Interfaces: CSP / KSP / PKCS#11
Supported Operating Systems: Windows, macOS, Linux
Supported Browsers: Microsoft Edge, Mozilla Firefox, Google Chrome, Apple Safari
Strong Authentication Support: Yes
User Directory Support: Yes
PKI Support: Yes
SSO Support: Yes
VPN Support: Yes
Encryption Support: Yes
Electronic Signature Support: Yes
Supported QSCD Cryptographic Algorithms
RSA 2048 bit
RSA 3072 bit
RSA 4096 bit
ECC NIST P-256 / SECG secp256r1
ECC NIST P-384 / SECG secp384r1
ECC NIST P-521 / SECG secp521r1.
PIN / PUK Security
PIN support: yes
PIN length: 5 to 15 bytes
Maximum number of incorrect PIN attempts: 3
PUK support: yes
PUK length: 5 to 15 bytes
Maximum number of incorrect PUK attempts: 3.
Compatibility with IT Infrastructure
The official NEOWAVE documentation for Badgeo QSCD lists, among others:
Microsoft Active Directory
LDAP
Microsoft PKI
Evidian
CertEurope
Certinomis
PrimeKey
Microsoft VPN
Cisco
Juniper
Check Point
TheGreenBow
IBM
Evidian
Oracle
Systancia
Prim'X
Sophos
card and token management systems.