PIV ATTESTATION & SELF-SERVICE

A YubiKey is lost while travelling. The controlled identity lifecycle continues.

The old device is blocked, replacement hardware is verified and new credentials are issued to the accountable identity. Self-service accelerates the process without turning trust into an unchecked shortcut.

VALUE IN 30 SECONDS

Fast recovery without lowering the trust level.

01

Remove old trust first

The lost key and affected credentials are blocked through an explicit lifecycle action.

02

Verify replacement hardware

PIV attestation and policy check whether the new key provides the required hardware evidence.

03

Rebind the identity

New credentials are issued to the verified person and application context, not copied blindly from the lost device.

RECOVERY WITHOUT AN UNCONTROLLED EXCEPTION

How can self-service remain secure when replacement must be fast?

Self-service is safe only when it shortens waiting time while the required proofs remain intact. SYNRION x.ID separates loss response, hardware verification, identity approval and credential reissue.

  1. 01

    Report the device as lost

    The user or service desk starts a defined loss process. The affected key becomes an explicit risk instead of remaining an unknown absence.

  2. 02

    Block the old credentials

    Revoke or disable the affected PIV and FIDO2 use cases according to policy before a replacement becomes trusted.

  3. 03

    Obtain supported replacement hardware

    A replacement YubiKey can be obtained through the organization’s approved path or an allowed emergency process while travelling.

  4. 04

    Verify PIV attestation

    The portal evaluates whether the new key and generated PIV key material provide the required hardware-backed evidence.

  5. 05

    Approve the accountable identity

    Authentication, identity assignment and independent policy decide whether the person may bind the replacement key.

  6. 06

    Issue new credentials and resume work

    Fresh PIV certificates and approved FIDO2 registrations are created for the replacement. The old and new lifecycle records stay distinguishable.

THE ARCHITECTURE AT A GLANCE

A fast replacement process remains trustworthy because loss, hardware proof, identity approval and new credential issue are separate controlled states.

Recovery path from a reported lost YubiKey through blocking, replacement hardware attestation, identity approval and controlled credential reissue.
A fast replacement process remains trustworthy because loss, hardware proof, identity approval and new credential issue are separate controlled states.

TECHNICAL DEPTH

What attestation proves—and what it does not.

Attestation strengthens the hardware statement. The complete trust decision still needs identity, authorization, policy and lifecycle context.

Hardware-backed key generation
PIV attestation can provide signed evidence that a supported key pair was generated in the security key. This is different from importing an externally generated private key.
Identity proofing
Attestation does not identify the person holding the key. The primary identity and approval process remain separate mandatory signals.
Controlled self-service
The user can initiate and complete permitted steps through a portal, but policy determines the allowed device, required evidence, approvers and target credentials.
Reissue instead of key copying
A non-exportable private key is not moved from the lost device. New key material and credentials are issued, while old trust is removed and the relationship remains traceable.

EVIDENCE & BOUNDARIES

The recovery result remains auditable.

A successful replacement is more than “the user can log in again”. It must show why the new key was accepted and what happened to the old one.

Available

Old and new hardware remain distinct

The loss record, removed trust, replacement key and new credentials do not collapse into one device history.

Available

Policy remains enforceable

Device class, attestation, identity and optional independent approval are evaluated before enrolment succeeds.

Available

Emergency paths remain controlled

A faster process can be defined for travel or operational urgency without bypassing the required trust evidence.

Available

AD and Entra are reconciled

Old and new certificates, SKI mappings and FIDO2 registrations remain distinguishable in their respective target systems.

View the official Works with YubiKey entry

THE NEXT CONTROLLED STEP

Test the loss scenario before it becomes an emergency.

We will walk through blocking, attestation, identity approval and credential reissue with the controls your organization requires.

Request an x.ID demo