Skip to main content
Home > Solutions > Solutions by Use Case > Mobile Identity PKI on Every Smartphone

Mobile Identity
PKI on Every Smartphone

Deploy MyID® for mobile-first credential programmes, issuing derived PKI credentials to iOS and Android devices, managing mobile MFA and supporting BYOD and government-issued device programmes.

Key Capabilities

What this deployment model delivers

iOS and Android derived credentials

MyID issues X.509 PKI certificates to iOS and Android devices, with keys held in the device's hardware-backed secure key store so they cannot be exported. Each credential is derived from a primary PIV card or smart card, so no new identity proofing is required.

NIST SP 800-157 compliant

MyID's mobile derived credential implementation meets NIST SP 800-157 and 800-157r1 requirements for PIV-Derived credentials. Compliant for US federal mobile access programmes under OMB M-19-17.

Remote enrolment

Remote workers verify their identity from anywhere using document scan, NFC chip reading and biometric liveness detection, then collect their mobile credential through the MyID Identity Agent app. No in-person visit is required for LOA-3 derived credentials.

Lifecycle management from CMS

Mobile credentials are managed through the same MyID CMS admin console as smart cards and USB tokens. Renewal, suspension and leavers revocation are consistent across all credential types.

Architecture components

Identity verification document scan, NFC, liveness
Mobile app MyID Identity Agent (iOS and Android) for credential collection and activation
TEE / Secure Enclave device hardware-backed key store
MyID CMS Central lifecycle management, issue, renew, revoke mobile credentials
MDM Integration Works alongside Intune, Jamf and other MDM platforms
System requirements

Detailed platform requirements

Full server, operating system, database, HSM and client requirements for every MyID deployment are maintained in the Technical Overview, alongside the architecture and API detail.

View the Technical Overview →
Context

Mobile identity, derived credentials for the smartphone-first workforce

Derived credentials bring hardware-grade identity assurance to smartphones and tablets. A physical PIV card is used to verify identity and derive a credential onto the mobile device, the derived credential is issued under NIST SP800-157 at LOA-3, or at LOA-4 where in-person biometric authentication is performed, and can be used for logical access, VPN, email signing and mobile applications. PIV-D and NIPR/SIPR mobile access scenarios are supported. MyID handles the full derived credential lifecycle, initial derivation, renewal, and revocation, integrated with your existing PKI infrastructure.

PIV-D
Compliant derived credential profile
iOS & Android
Both platforms supported
SP800-157
Derived credential specification compliance
Same assurance
Derived credential = original PIV assurance level
Frequently Asked Questions

Common questions

Need something specific? Contact our team →

A derived credential is a PKI certificate issued to a mobile device that is derived from an existing primary credential (typically a PIV smart card) without requiring full re-identity proofing. The derivation process verifies the primary credential before issuing to the mobile device. NIST SP 800-157 defines the technical requirements for derived PIV credentials.

Derived credential issuance work without an MDM. However, an MDM (Intune, Jamf, SOTI) is recommended for enterprise deployment to manage app distribution, device compliance policy and certificate profile deployment. MyID integrates with major MDM platforms.

iOS 14 and later (Secure Enclave key binding). Android 9 and later with StrongBox or TEE (Trusted Execution Environment) support. Specific device compatibility is tested against the MyID app, refer to the current compatibility matrix in our support documentation.

Deployment · Mobile Identity

PKI authentication on every device your workforce uses.

MyID mobile derived credentials give iOS and Android users hardware-bound PKI authentication, the same assurance level as a smart card, with the convenience of a smartphone.