Infineon Serves up Security IC Supporting USB and NFC Connectivity
The new SECORA ID Key S USB security solution supports FIDO2 and PKI through hardware and near field interfaces.
Infineon recently announced the SECORA ID Key S USB, a Java Card-based access security system in package (SiP). The chip is designed for passwordless security authentication through serial USB, USB key, and NFC hardware configurations. Common applications include USB security key fobs, hardware built-in passkeys, certificate-based authentication, physical access authentication, software rights management, and crypto wallet security.

The new 4 mm × 4 mm SiP SECORA ID Key S USB
Infineon created the SiP as a part of a larger solution so customers can focus on customization and integration rather than ground-up security design. The solution includes the SECORA chip with on-board Java operating system, development tools and a configurator. SECORA comes in a 4x4mm system in package (SiP) to allow for compact application designs. It is powered by an Arm SecureCore SLC38 security controller CPU and a 48 MHz Arm Cortex M0 USB serial bridge CPU.
Key Features
The chip communicates with the outside world via USB 2.0, IEC14443/IEC18092 passive mode NFC, or the Infineon CAPSENSE capacitive/inductive sensing technology. Data crosses over via credit card ID (CCID), human interface client to authenticator protocol (CTAP HID), or secure channel protocol (SP02/SC03).
The SecureCore SLC38 crypto controller is a 32-bit Arm core solid flash processor designed around cryptographic security. In SECORA, it operates at 100 MHz and comes with 250kB of user non-volatile memory (NVM) and 7,392 bytes of free user RAM. NVM can be increased by 64kB if the included ISO files system is removed.
Asymmetric cryptography modes include ECC up to 521 bits and RSA up to 4096 bits. Symmetric security delivers AES up to 256 bits and DES up to 192 bits. More information is available in the SECORA ID Key S USB product brief.
Keeping The World Secure
Security risk comes in many forms these days. The new Infineon chip is directly targeting phishing attacks and user authentication, two of the greatest points of vulnerability, with FIDO2-certified Level 3+ and CTAP 2.1 compliance.

SECORA-based security in action
Fast identity online 2 (FIDO2) and public key infrastructure (PKI) work together but on different layers. PKI is the private/public key backbone. It consists of a pair of large unique prime numbers, one is public and used to encrypt messages coming back to the owner. The private key never leaves the owner’s equipment and is used to securely decrypt the message. PKI also utilizes certificate authorities to ensure key ownership.
FIDO2 utilizes PKI for authentication and message validation. One of the key features of FIDO2 is targeted at phishing emails. It prevents logins on faked websites by refusing to authenticate – even if a user with FIDO2 goes to a fake site and attempts to log in, FIDO2 will not allow it.
FIDO2 Level 3+ and CTAP 2.1 are the highest security levels under the standard. They add resistance to phishing and sophisticated hardware/software attacks.
Development and Deployment
Java Card is an MCU hosted Java platform designed to speed the development of secure software on small systems. It utilizes Java Card Virtual Machine (JCVM) and the Java Card runtime environment (JCRE) for security applet execution. The physical layer (PHY) of SECORA follows the Java Card ISO 7816 and GlobalPlatform standards for interoperability.
Java Card, as implemented in SECORA is suitable for a wide variety of consumer applications, government, and enterprise applications. Its security levels make it acceptable for stringent uses such as enterprise multifactor authentication (MFA), electronic voting and tax reporting, national identification documents, and other systems where high-security authentication is required.
JVCM and JCRE differ from standard Java in a number of ways to better accommodate security and device portability. Some wrapper classes and float and double primitives are eliminated due to limited processing power of typical MCUs. It uses a persistent memory model for objects to allow power off data retention. Other differences improve security for the devices.
Infineon ID Key S USB engineering samples are available now. Volume production is planned for September 2026.
All images used courtesy of Infineon.