Home » Products » FIDO2 range » Winkeo2J-A FIDO2
Security key FIDO2

Winkeo2J-A FIDO2

The Winkeo2J-A FIDO2 is NEOWAVE’s new generation of USB Type-A security keys designed to provide strong authentication, for both web and cloud environments​. Compatible with the FIDO2 (CTAP 2.1) and FIDO U2F standards and FIDO2 L2 certified, it ensures the highest level of protection against phishing and password theft, while remaining simple and quick to use. It is also officially listed by the French Digital Health Agency (ANS) as an electronic identification means (eID means) compatible with Pro Santé Connect, meeting the security requirements of the most demanding environments.

The Winkeo2J-A FIDO2 features a more modern and streamlined design, perfectly aligned with the brand’s other products. Its new, more intuitive rear button offers improved ergonomics and a smoother everyday user experience. By effectively protecting your access against phishing attacks or password theft, the Winkeo2J-A FIDO2 key combines security, modernity, and ease of use.

NEOWAVE Cybersecurity Made in Europe
Winkeo2-A FIDO2 de NEOWAVE certifiée FIDO L1
Winkeo2-A FIDO2 de NEOWAVE certifiée FIDO L1

USB-A security key compatible with FIDO2 (CTAP 2.1)

Credential generation, management and storage inside the smart card

Ease of use

(no software installation on the client workstation)

Anti-Phishing protection

(in order to replace vulnerable SMS solutions)

Winkeo2J-A FIDO2 is a Type-A security USB key manufactured in Europe. It is compatible with the FIDO2 (CTAP 2.1) and FIDO U2F standards defined by the FIDO Alliance (Fast Identity Online) and is FIDO2 L2 certified. It is also officially listed by the French Digital Health Agency (Agence du Numérique en Santé – ANS) as an electronic identification means (eID means) compatible with Pro Santé Connect, demonstrating its compliance with the security requirements of the most demanding healthcare environments.

The FIDO protocol is based on an asymmetric cryptography architecture using a public/private key pair, with the private key always securely stored on the Winkeo2J-A FIDO2 security key. The FIDO2 standard enables secure passwordless authentication. Simply insert the Winkeo2J-A FIDO2 into your computer and enter your PIN to authenticate and sign in. The security key therefore provides a secure and convenient replacement for traditional passwords. In addition, it incorporates a Common Criteria EAL6+ certified secure component, ensuring robust protection of cryptographic secrets.

The Winkeo2J-A FIDO2 is compatible with Windows 10/11 and Microsoft Entra ID. It also supports the FIDO U2F standard, enabling two-factor authentication (2FA) for a wide range of online services, including social media platforms, webmail services, e-commerce websites, and online banking. 

The FIDO protocol ensures strong and secure authentication, protecting online accounts against phishing attacks.

The Winkeo2J-A FIDO2 provides users with a high-quality authentication solution, delivering maximum protection against phishing and password theft while simplifying secure access to digital services.

 

Features

Interface(s)

USB-A 2.0 HID

Certifications

  • Java Card™ smart card (micro-SIM format) certified Common Criteria EAL6+
  • FIDO2 L2 certification
  • “Cybersecurity Made in Europe” label
  • ANS-listed product, compatible with Pro Santé Connect

Wide compatibility

• Windows 10/11 with Microsoft Entra ID and over 250 online services such as Gmail, Paypal, OVH, WordPress, Dropbox
• Identity federations such as Evidian, Ilex, Okta, Ping Identity

Supported operating systems and browsers

Operating Systems: Windows, Mac OS and Linux
Browsers: Chrome, Edge, Firefox, Safari

FIDO2.1 features

• credProtect
• hmac-secret
• Resident keys (rk) – Detectable credential
– Maximum number limited by an available persistent memory (200 to 512 bytes per credential)
• User PIN, PIN 1 and PIN 2 protocols
– PIN length between 4 Unicode characters and 63 bytes
– PIN try limit set to 8. After 8 unsuccessful tries, the authenticator must be reset.
– No default value
– Management of specific PIN policies
• Customization options:
– credBlob
– largeBlobKey
– noMcGaPermissionsWithClientPin
– largeBlobs
– minPinLength
– pinUvAuthToken
– ep – Enterprise Attestation
– authnrCfg
– credMgmt
– setMinPINLength
– makeCredUvNotRqd
– alwaysUv

Supported signature-algorithm

ECC P-256 (secp256r1)

Associated optional services

Graphical customization: logo, photo, name, unique number…

Size / Weight

• Length 43.8 mm / width 18 mm / height 9.76 mm
• Weight: 6 g

I would like more information on the NEOWAVE offer