Secure Credential Interoperability and PKOC

Objective

The objective of the Secure Credential Interoperability (SCI) initiative is to define requirements for an open specification that provides an interoperable access credential. Unlike PIV, this specification, the Public Key Open Credential (PKOC), does not rely on the Public Key Infrastructure (PKI) for issuing and managing digital certificates. Instead, the private key of the credential is stored only on the card/device itself, maximizing system security. Initially, PKOC supported mobile credentials but has expanded to include smart cards. PKOC readers are compatible with both Wiegand and OSDP panels, minimizing the need for panel replacements.

The SCI working group has identified relevant existing and emerging standards in the physical security industry and is working to enhance them to meet industry requirements for secure mobile credentials. The PSIA is actively collaborating with vendors, consultants, integrators, and customers to encourage adoption. Additionally, the group will review and vet specifications to ensure they meet the objective of being open and interoperable.

What is PKOC?   

Everything you wanted to know!

A whitepaper written by Ed Chandler and Jason Ouellette

Working Documents

PKOC v2.0.1 is published as a transport-independent Core Specification plus a Transport Profile for each link technology. The Core defines everything common to every transport; each profile defines only the wire binding for its link. An implementation conforms to the Core plus at least one profile — the Core alone has no wire format, and a profile alone is incomplete

PKOC Core Specification 2.0.1 — Approved August 13, 2026

The transport-independent foundation for all PKOC implementations. Defines the credential model, the cryptographic baseline (ECDSA on NIST P-256), key encodings, derivation of the PKOC Credential and PKOC Derived Identifier, the PKOC-CVC attestation certificate, the credential registration and trust-anchor provisioning process, and the requirements common to every Credential and Reader. Read this first; both profiles below reference it rather than repeating it.

PKOC NFC Transport Profile 2.0.1 — Approved August 13, 2026

Binds the Core to contactless smart cards over ISO/IEC 14443. Defines the PKOC application, the APDU command set, and three card profiles — SE V1, SE V2, and EV-P — together with Standard Mode and the optional Validated Mode, in which a Reader validates a card-bound PKOC-CVC against an Issuer Key. Credential derivation, cryptography, and the certificate format come from the Core. Supersedes the PKOC NFC Card Specification v1.1; the SE V1 profile is the v1.1 protocol unchanged, so existing v1.1 cards and readers remain conformant without modification.

PKOC BLE Transport Profile 2.0.1 — Approved August 13, 2026

Binds the Core to mobile credentials over Bluetooth Low Energy. Defines the PKOC GATT service, TLV framing and fragmentation, and two transmission flows: an ECDHE flow with Perfect Forward Secrecy and AES-CCM encryption, and a simpler un-obfuscated flow. Adds per-reader signing keys with Site Issuer-signed Reader Certificates, which is the BLE realization of the Core’s Validated trust model — here the Reader is authenticated to the credential, rather than the credential to the Reader as in NFC. Credential derivation and cryptography come from the Core. Supersedes PKOC BLE v3.1.2; the wire protocol is unchanged and byte-compatible.

PKOC over OSDP Specification 1.63- Approved Mar 22, 2024

Carries PKOC credential data from Reader to panel over OSDP. Independent of the card or mobile transport, and not yet re-issued under the 2.0.1 Core structure.

 

Contact us

Address

65 Washington Street, Suite 170
Santa Clara, CA 95050

Email

Phone

1.650-938-6945

Get in touch