FIPS 201
ComplianceFederal Information Processing Standard 201 -- the US government standard specifying PIV card requirements including physical form factor, electrical interface, data model, and cryptographic algorithms for federal employee identity cards.
What Is FIPS 201?
FIPS 201FIPS 201ComplianceUS federal standard defining PIVPIVIdentityUS federal identity card standard.Click to view → smart card specifications.Click to view → (Federal Information Processing Standard 201) is the US government standard that defines the requirements for Personal Identity Verification (PIV) smart cards used by federal employees and contractors. Published by NIST and mandated by Homeland Security Presidential Directive 12 (HSPD-12), FIPS 201 specifies the card's physical form factor, chip interface, data model, cryptographic algorithms, biometric storage, and lifecycle management procedures.
The current version, FIPS 201-3 (2022), governs over 5 million active PIV cards across US federal agencies and serves as the reference architecture for derived credentials on mobile devices.
What FIPS 201 Covers
The standard addresses every aspect of a federal identity smart card:
| Area | Specification |
|---|---|
| Physical card | ISO 7810 ID-1, contact + contactless interfaces |
| Chip interface | ISO 7816 contact, ISO 14443 Type A/B contactless |
| Data model | NIST SP 800-73 (card application, data containers) |
| Cryptography | NIST SP 800-78 (RSA 2048+, ECC P-256/P-384) |
| Biometrics | Fingerprint templates, facial image, iris (optional) |
| Key management | On-card key generation, PIV Auth, Digital Signature, Key Management, Card Auth keys |
| Lifecycle | Issuance, maintenance, termination procedures |
PIV Data Containers
A PIV card stores multiple data objects, each accessible through standard APDU commands:
- CHUID (Card Holder Unique Identifier) -- FASC-N, UUID, and digital signature. Readable without PIN for contactless physical access.
- PIV Auth Certificate -- X.509 certificate for general authentication (login, VPN). Requires PIN to use the private key.
- Digital Signature Certificate -- for signing emails and documents. PIN required per use.
- Fingerprint Templates -- biometric templates for Match-On-Card or off-card comparison.
- Facial Image -- JPEG photo for visual verification.
Relationship to Other Standards
FIPS 201 references and builds upon several companion standards:
- FIPS 140 -- the PIV card's cryptographic module must be FIPS 140FIPS 140ComplianceUS government cryptographic module security standard.Click to view →-2 Level 2 or higher certified.
- Common Criteria -- PIV card chips typically hold EAL 4+ certification.
- NIST SP 800-73 -- defines the PIV card application programming interface and data model.
- NIST SP 800-76 -- biometric data specifications for PIV cards.
The PIV card and CAC (Common Access Card) share significant technical overlap, with CACCACIdentityUS DoD identification smart card.Click to view → being the DoD-specific implementation aligned with PIV standards.
Related Content
TEE vs Secure Element
Security…SESP, separate die Enterprise PIV No Yes NIST SP 800-73, FIPS 201 GlobalPlatform and TEE API GlobalPlatform defines APIs for…
OpenSC and Open-Source Smart Card Tools
Programming…Drivers Driver Cards Supported card-piv US PIV (FIPS 201), CAC card-openpgp OpenPGP Card v2/v3 card-cac US DoD…
Smart Card Access Control Systems
Industry Applications…v2 / iCLASS High PKI-based, cloud provisioning PIV / CAC FIPS 201 Very high RSA/ECC certificates, biometric optional LEAF…
FIPS 140 for Smart Card Products
Compliance…Card Deployments U.S. federal identity programmes — PIV (FIPS 201), CAC , and logical access tokens — mandate FIPS 140 Level…
Häufig gestellte Fragen
The smart card glossary is a comprehensive reference of technical terms, acronyms, and concepts used in smart card technology. It covers protocols (APDU, T=0, T=1), security (Common Criteria, EAL, HSM), hardware (SE, EEPROM, contact pad), and applications (EMV, ePassport, eSIM). It serves developers, product managers, and engineers.
Yes. SmartCardFYI provides glossary definitions in 15 languages including English, Korean, Japanese, Chinese, Spanish, Portuguese, Hindi, Arabic, French, Russian, German, Turkish, Vietnamese, Indonesian, and Thai.