- New
The Swissbit iShield Key 2 Series is the second generation of professional hardware authentication keys designed to protect user accounts, corporate systems, applications, cloud services, and – in selected variants – physical access control.
Swissbit iShield Key 2 Series – FIDO2 / NFC Hardware Security Key
The Swissbit iShield Key 2 Series is the second generation of professional hardware authentication keys designed to protect user accounts, corporate systems, applications, cloud services, and – in selected variants – physical access control.
The device supports the latest FIDO2 / CTAP 2.1 standard and WebAuthn, enabling secure passwordless login and phishing-resistant Multi-Factor Authentication (MFA). All models are equipped with a USB-A or USB-C interface and NFC wireless communication.
The iShield Key 2 can store up to 300 passkeys, or access keys used by modern passwordless authentication systems. Physical confirmation of operations is achieved by touching the sensor located on the device. For mobile devices, authentication is possible by holding the key near an NFC reader.
The enhanced iShield Key 2 Pro also supports HOTP, TOTP, static password storage, and PIV (Personal Identity Verification) smart card functionality. This allows a single physical token to be used for system logins, VPNs, Active Directory, certificate authentication, encryption, and digital signatures, among other functions.
Selected versions of the iShield Key 2 can also integrate digital authentication with physical access control systems thanks to support for MIFARE DESFire EV3, HID Seos, and LEGIC advant/neon. FIPS 140-3 Level 3 compliant variants and models supporting Enterprise Attestation are also available, designed primarily for organizations, public administrations, and environments with heightened security requirements.
The iShield Key 2 devices are water and dust resistant to an IP68 rating, feature a durable construction, a multicolor LED, and a keyhole for attaching the key to a lanyard or key fob.
Key Features
FIDO2 Hardware Authentication Key
FIDO2 / CTAP 2.1
WebAuthn
FIDO U2F / CTAP1
Phishing-resistant authentication
Passwordless login support
MFA support (Multi-Factor Authentication)
Storage for up to 300 passkeys
USB-A or USB-C interface
NFC in all variants
Physical confirmation of operations via touch sensor
Tap-and-go NFC authentication
Remote firmware and device app update capability
Compatible with Windows, macOS, Linux, ChromeOS, Android, iOS, and iPadOS
Compatible with popular services supporting FIDO2/WebAuthn, including: Microsoft, Google, Amazon/AWS, and Salesforce
Rugged design
IP68 protection
Multicolor RGB LED
Digital authentication and physical access control integration
Optional MIFARE DESFire EV3 support
Optional HID SEO support
Optional LEGIC advant/neon support
Optional FIPS 140-3 Level 3
Optional Enterprise Attestation
iShield Key 2 Pro – Additional Features
The iShield Key 2 Pro variant offers additional authentication and cryptography mechanisms:
HOTP – HMAC-based One-Time Password
TOTP – Time-based One-Time Password
Static passwords
Up to 42 configurable HOTP / TOTP / Password slots
Ability to assign two functions to short and long touches of the sensor
PIV – Personal Identity Verification
Smart card support
OpenSC compatibility
X.509 certificate authentication
Can be used to log into Windows/Active Directory environments
Can be used in solutions using BitLocker and certificate authentication.
Models and Variants
The family is based on two functional models:
iShield Key 2 FIDO2 – FIDO2 / CTAP 2.1, WebAuthn, and U2F
iShield Key 2 Pro – FIDO2, plus HOTP, TOTP, static passwords, and PIV.
Each basic model is available in the following versions:
USB-A + NFC
USB-C + NFC
Functional variants are also available:
iShield Key 2 FIDO2
iShield Key 2 Pro
iShield Key 2 FIDO2 MIFARE
iShield Key 2 Pro MIFARE
iShield Key 2 FIDO2 FIPS
iShield Key 2 Pro FIPS
HID Seos variants
LEGIC advant/neon variants
Enterprise Attestation variants
Variants combining FIPS with HID Seos or LEGIC
Enterprise versions are also available in various functional configurations.
MIFARE DESFire EV3 enables the same device to be used as a digital token and an identifier in physical access control systems. Selected HID Seos and LEGIC variants support similar applications.
Software
Standard FIDO2/WebAuthn authentication does not require dedicated Swissbit software running continuously. The key works with an operating system, browser, or application that supports the FIDO2/WebAuthn standard.
For device configuration and management, the manufacturer provides free software:
Swissbit iShield Key Manager – iKM
iShield Key Manager CLI – iKMcli, a command-line tool.
For iShield Key 2 devices, iShield Key Manager / iKMcli version 1.7.4 or later is required.
iShield Key Manager is available for:
Windows
macOS
Linux.
The program allows you to:
Configure FIDO2 functions
Set and change PINs
Manage saved passkeys
Configure HOTP
Configure TOTP
Configure static passwords
Manage PIV functions
Check the serial number
Check the device firmware version.
For PIV functions and some smart card scenarios, additional components may be required, such as the OpenSC Minidriver / iShield PIV Module, depending on the operating system and usage.
Technical Specifications
Manufacturer and Country of Origin
Manufacturer: Swissbit AG
Manufacturer's Headquarters: Bronschhofen, Switzerland
iShield Key 2 production country: Germany
Swissbit production location: Berlin, Germany
Made in Germany.
Technical Specifications
Device Type: Hardware Authentication Token / Hardware Security Key
Generation: iShield Key 2
Wired Interface: USB 2.0
Connector: USB-A or USB-C, depending on the model
Wireless Interface: NFC
Authentication Standard: FIDO2
Protocol: CTAP 2.1
Backward Compatibility: FIDO U2F / CTAP1
WebAuthn Support: Yes
Number of Stored Passkeys: Up to 300
User Attendance Function: Touch Sensor
Mobile Authentication: NFC
Device Type: FIDO2 HID Device / CCID Smartcard, depending on the function
Security Controller: NXP P71D600
System: JCOP 4.5
Flash Memory: 600 KB
RSA: 2048 / 3072 / 4096 bit
ECDSA: 224 / 256 / 384 / 512 bit
AES: 128 / 192 / 256 bit
HMAC: SHA-1, SHA-256, SHA-384, SHA-512
Housing color: black, RAL 9005
Indication: multicolor RGB LED with double-sided backlight
Protection rating: IP68
Operating temperature: -25°C to +70°C
Storage temperature: -25°C to +85°C
USB supply voltage: 5 V ±10%
Current consumption during initialization: approx. 30 mA
Current consumption in idle mode: approx. 19.5 mA
Weight: approx. 5 g
Width: 16 mm
Thickness: max. 5.2 mm
MTBF at 25°C: over 4,000,000 hours
Regulatory compliance includes: CE, FCC, UKCA, RoHS, REACH, WEEE, and TAA environmental and immunity tests include MIL-STD-810H and select IEC and JESD standards.
Supported Operating Systems
Windows 10
Windows 11
macOS
Linux
ChromeOS
Android
iOS
iPadOS.
Supported Browsers
Google Chrome
Microsoft Edge
Mozilla Firefox
Apple Safari.