Remove old trust first
The lost key and affected credentials are blocked through an explicit lifecycle action.
Enterprise PKI · Digital Trust Engineering
PIV ATTESTATION & SELF-SERVICE
The old device is blocked, replacement hardware is verified and new credentials are issued to the accountable identity. Self-service accelerates the process without turning trust into an unchecked shortcut.
VALUE IN 30 SECONDS
The lost key and affected credentials are blocked through an explicit lifecycle action.
PIV attestation and policy check whether the new key provides the required hardware evidence.
New credentials are issued to the verified person and application context, not copied blindly from the lost device.
RECOVERY WITHOUT AN UNCONTROLLED EXCEPTION
Self-service is safe only when it shortens waiting time while the required proofs remain intact. SYNRION x.ID separates loss response, hardware verification, identity approval and credential reissue.
The user or service desk starts a defined loss process. The affected key becomes an explicit risk instead of remaining an unknown absence.
Revoke or disable the affected PIV and FIDO2 use cases according to policy before a replacement becomes trusted.
A replacement YubiKey can be obtained through the organization’s approved path or an allowed emergency process while travelling.
The portal evaluates whether the new key and generated PIV key material provide the required hardware-backed evidence.
Authentication, identity assignment and independent policy decide whether the person may bind the replacement key.
Fresh PIV certificates and approved FIDO2 registrations are created for the replacement. The old and new lifecycle records stay distinguishable.
THE ARCHITECTURE AT A GLANCE
TECHNICAL DEPTH
Attestation strengthens the hardware statement. The complete trust decision still needs identity, authorization, policy and lifecycle context.
EVIDENCE & BOUNDARIES
A successful replacement is more than “the user can log in again”. It must show why the new key was accepted and what happened to the old one.
The loss record, removed trust, replacement key and new credentials do not collapse into one device history.
Device class, attestation, identity and optional independent approval are evaluated before enrolment succeeds.
A faster process can be defined for travel or operational urgency without bypassing the required trust evidence.
Old and new certificates, SKI mappings and FIDO2 registrations remain distinguishable in their respective target systems.
RELATED PRODUCT
SYNRION x.ID combines verified primary identities, authentic hardware and independent policy enforcement into one reliable trust decision.
THE NEXT CONTROLLED STEP
We will walk through blocking, attestation, identity approval and credential reissue with the controls your organization requires.