The Physical Security Interoperability Alliance (PSIA) has released version 2.0.1 of its Public Key Open Credential (PKOC) specification, an update designed to strengthen interoperability and address implementation requirements while maintaining backward compatibility with existing PKOC deployments.
PKOC is an open, royalty-free specification for secure, interoperable credentials based on public-key cryptography. Rather than presenting a shared secret, a PKOC credential proves possession of a private key, eliminating the need to store credential secrets in readers or control panels.
According to PSIA, the approach is intended to reduce risks associated with traditional credential architectures while giving manufacturers and end users more flexibility in sourcing and deploying credentials.
The 2.0.1 update incorporates experience gained through implementation as well as application, reader and card testing. Among the changes is a new information command that allows a reader to determine a credential’s supported PKOC version, profile and message-size capability before beginning a transaction.
The specification also clarifies profile detection and version handling to provide more predictable behavior in deployments using different PKOC versions. It defines how readers should handle credentials that do not support extended Application Protocol Data Units (APDUs), allowing them to select a compatible transaction path rather than encounter failures in the field.
PSIA also updated terminology, formatting and implementation guidance throughout the specification.
“PKOC 2.0.1 reflects what we have learned from implementing and testing the specification in working applications,” said Jason Ouellette, Head of Product Management and Strategy at ELATEC and Chairman of the Board of the PSIA. “The testing confirmed that the updated specification functions properly while remaining compatible with existing PKOC cards and readers. That is important for manufacturers and end users that want to adopt stronger credential security without disrupting current implementations.”
Members of the PSIA PKOC Working Group reviewed and tested the specification using PKOC-enabled applications, physical credentials and readers from four member companies. PSIA said the testing was intended to ensure the changes addressed implementation requirements while preserving interoperability.
The update also introduces PKOC Validated mode, an optional capability intended to help organizations transition from legacy systems.
“One of the primary objectives for PKOC v 2.0.1 was to simplify the migration from legacy systems to PKOC,” said GW Habraken, Managing Director of Taglio LLC. “This release introduces PKOC Validated mode which provides optional functionality that enables Enterprises to include legacy identifiers together with the core PKOC Credential.”
PKOC supports physical and logical access control applications using both smart card and mobile credential form factors.
“PKOC was developed to give the security industry an open and interoperable alternative to proprietary credential technologies,” said David Bunzel, Executive Director of PSIA. “Version 2.0.1 strengthens the technical foundation of the specification and makes it easier for manufacturers, integrators and end users to evaluate and deploy PKOC-based solutions.”
The PKOC 2.0.1 specification is publicly available from PSIA.

