Hardware Token
What is Hardware Token?
Hardware TokenPhysical device that stores cryptographic secrets and performs authentication operations, used as a possession factor in multi-factor authentication.
A hardware token is a tamper-resistant physical device that generates or holds credentials used to prove identity. Examples include FIDO2 security keys (YubiKey, Google Titan, SoloKey), OATH TOTP/HOTP fobs, PIV/CAC smartcards, and chip-based EMV payment cards. They are stronger than passwords or app-based TOTP because the private key never leaves the secure element, and modern FIDO2/WebAuthn keys cryptographically bind each assertion to the site origin — so a credential phished on a look-alike domain is simply unusable, which is why FIDO2 is the reference for "phishing-resistant MFA."
Hardware does not make a token infallible. The 2011 breach of RSA exposed SecurID seed records, enabling downstream intrusions at defense contractors. The ROCA flaw (CVE-2017-15361) in Infineon's RSA key generation weakened keys on YubiKey 4 and many smartcards. Most recently, EUCLEAK (CVE-2024-45678, NinjaLab 2024) recovered ECDSA keys from YubiKey 5 devices with firmware below 5.7.0 via an electromagnetic side channel in the Infineon library — though the attack needs physical access and device disassembly. Practical risk is dominated by loss, theft and supply-chain tampering, so enrollment, attestation, inventory and prompt revocation matter as much as the cryptography.
flowchart TD
U[User at login] --> S[Server sends challenge]
S --> T[Hardware token]
T --> P{User presence + PIN/biometric}
P -->|verified| K[Sign challenge with origin-bound private key]
K --> V[Server verifies with public key]
V --> A[Access granted]
P -->|failed| D[Denied]● Examples
- 01
Issuing FIDO2 hardware tokens to all administrators to meet phishing-resistant MFA requirements.
- 02
Using a PIV smartcard plus PIN for federal-government login per HSPD-12 and NIST 800-157.
● Frequently asked questions
What is Hardware Token?
Physical device that stores cryptographic secrets and performs authentication operations, used as a possession factor in multi-factor authentication. It belongs to the Cryptography category of cybersecurity.
What does Hardware Token mean?
Physical device that stores cryptographic secrets and performs authentication operations, used as a possession factor in multi-factor authentication.
How do you defend against Hardware Token?
Defences for Hardware Token typically combine technical controls and operational practices, as detailed in the full definition above.