Skip to content

Connector · Virtual smart card

EIDVirtual

Turn any USB key into a smart card recognized natively by Windows — no smart card reader, no middleware.

Version 2.1 · free download

Overview

EIDVirtual turns an ordinary removable device — a USB key, an SD card — into a smart card. Windows sees a smart card reader with a standard card inserted, and every application that works with smart cards works with it: logon via EIDAuthenticate or Active Directory, browsers, VPN clients, Outlook, EFS.

The emulated card is a GIDS card (Generic Identity Device Specification), the profile Windows supports natively: the minidriver that drives it ships with Windows, so there is no middleware to deploy. The certificates, private keys and PIN live in a single encrypted file bound to the device — a copy of that file on another key is not a card.

A USB key is inserted, ready to be turned into a virtual smart card.

Detailed sequence, for screen readers and when animation is reduced:

  1. A USB key is inserted.
  2. The configuration wizard initializes a GIDS card on it.
  3. A PIN is set to protect it.
  4. Verified with certutil -scinfo: Windows sees the reader and an Identity Device (Microsoft Generic Profile) card.
  5. The same USB key is recognized identically on any other PC that has the EIDVirtual driver installed — no re-initialization needed.
  6. From there, certificates can be generated, imported or requested with the Smart Card manager.
  7. It can be used for Windows smart card logon.
  8. It can be used for TLS client authentication.
  9. It can be used to sign emails (S/MIME) and to encrypt files (EFS).
See it in action

From a blank USB key to a smart card logon, in about a minute:

  1. Initialize the card with the configuration wizard
  2. Generate a certificate in the Smart Card manager
  3. Check the card with certutil -scinfo
  4. Lock the session and sign in with the USB key and its PIN
Screenshots
Initialize the card The configuration wizard creates the card on the USB key: PIN, admin key, serial number.
Manage certificates The Smart Card manager generates, imports or requests certificates from Active Directory.
Standard PIN prompt Windows asks for the PIN in its own dialog, as for any smart card.
Recognized by Windows certutil -scinfo reports an Identity Device (Microsoft Generic Profile).
Change the PIN With Ctrl+Alt+Del › Change a password, like a physical card.
A real reader driver A smart card reader and a smart card in the Device Manager.
Scriptable EIDVirtualCmd provisions, ejects and re-inserts cards from scripts.
Built-in tracing EIDVirtual Tracing shows the driver activity live, or records it across reboots.
What's new in version 2.1
Silent installation
No more “Would you like to install this device software?” prompt: the installer trusts the driver publisher first. Fully unattended deployment.
Instant insertion
A new card is available right after its initialization. Cards can be ejected and re-inserted by command, without touching the device.
Command line
EIDVirtualCmd initializes cards, imports PFX files, ejects, re-inserts and sets the device policy — from scripts and deployment tools.
Device policy
Removable devices only by default (removable media or any USB disk). The AllowNonRemovable setting accepts fixed disks.
Better device detection
The identity is read from the physical disk, with the SCSI identifiers as fallback: USB disks reporting as fixed disks are recognized.
Reliability
Insertion, removal and state changes are serialized in the reader: no conflict with certificate propagation, no spurious event log errors.
Refreshed tools
Dark mode, sortable certificate list with context menu, version in every tool, new live tracing window.
Older Windows
On Windows 7 SP1 to 8, a UMDF 1 compatibility driver is installed automatically.
Use cases

The card behaves as a physical GIDS card. While it is inserted, Windows propagates its certificates to the user's personal store, which makes them visible to browsers, Outlook, Office and every CryptoAPI / CNG application.

ScenarioWhat you need
Active Directory smart card logonA certificate enrolled with the manager's Request button, or any smart card logon template.
Standalone computer logonEIDAuthenticate and any certificate of the card — a self-signed one is fine.
TLS client authenticationA certificate with the Client Authentication usage, trusted by the server (web, VPN, Wi-Fi EAP-TLS).
Email (S/MIME) and document signatureA certificate issued for the email address or the signer.
EFS file encryptionA certificate with the Encrypting File System usage.
Development and testingNothing else: test smart card applications and PKI scenarios without buying hardware.
What's in the box
Configuration wizard
Initializes a card on a volume — PIN (4 to 16 digits), admin key, serial number — or clears it.
Smart Card manager
Lists the certificates of the card; generates self-signed ones, imports PFX files, requests certificates from an Active Directory CA, deletes.
EIDVirtualCmd new
Command-line provisioning: format, import, eject, swallow, nonremovable. Exit code 0 on success, for scripts.
EIDVirtual Tracing
Live ETW tracing of the driver and tools, or a persistent trace that also covers the boot. Traces never contain the PIN or key material.
cd "C:\Program Files\EID Virtual Smart Card"
EIDVirtualCmd format --drive F: --pin 482915 --admin-key 7E3A91C0...
EIDVirtualCmd import --pfx C:\Deploy\user.pfx --password "..." --pin 482915
Requirements
Operating system (x64)
  • Windows 11, 10, 8.1 — Windows Server 2025, 2022, 2019, 2016, 2012 R2
  • Windows 7 SP1, 8 — Windows Server 2008 R2, 2012 (UMDF 1 compatibility driver, installed automatically)
  • Administrator rights to install; none to use the card
Storage device
  • A USB key or memory card, formatted FAT32, exFAT or NTFS
  • It must report an identity (vendor, product, serial number) — almost every USB key does
  • Removable media or USB bus; fixed disks only with EIDVirtualCmd nonremovable on
Architecture & security
The card runs in the driver, not in your applications

EIDVirtual emulates the reader, and the card inside it. Applications load the Windows GIDS minidriver and exchange APDUs with the card exactly as with a physical one; the card logic — PIN verification, private key operations — runs in an isolated UMDF driver host process. A defect in the driver can at worst stop that process, never the system.

Applications use the Windows GIDS minidriver and the Smart Card service; the EIDVirtual reader and the GIDS applet — a port of the MySmartLogon GidsApplet with its cryptography on Windows CNG — run in an isolated driver host that reads the card file from the USB key. Windows — unchanged Applications logon · browser · Outlook · EFS GIDS minidriver msclmd.dll, built into Windows Smart Card service SCardSvr · APDUs, T=1 WUDFRd.sys EIDVirtual Driver host process isolated · Local Service · UMDF Virtual reader insert · eject GIDS applet port of GidsApplet Crypto & storage CNG · card file USB key EIDVirtual2.bin
The card is a single file, bound to its device

The whole card — file system, key containers, PIN and try counter, admin key — is compressed and encrypted with AES-256-GCM into EIDVirtual2.bin, at the root of the USB key. The key is derived from the identity of the physical device each time it is plugged in, and is never written anywhere: a copy of the file on another key does not decrypt, and any tampering is detected by the GCM tag.

The device identity goes through HMAC-SHA-256 to give a 256-bit key that is never stored. The card state is serialized, compressed with MSZIP and encrypted with AES-256-GCM into EIDVirtual2.bin: a 12-byte IV, the ciphertext and a 16-byte tag. Device key — computed at each insertion, never stored USB key identity vendor:product:rev:serial HMAC-SHA-256 with the product secret 256-bit key in memory only Card file — rewritten only when the card changes Card state GIDS file system RSA key containers PIN + try counter admin key XML + MSZIP AES-256-GCM new IV per write EIDVirtual2.bin IV ciphertext tag 12 B 16 B
ThreatProtectionLimit
Copy of the card to another deviceDevice-bound AES-256-GCM keySomeone able to reproduce the device identity and knowing the product secret could decrypt the file.
Use of a stolen keyPIN verified by the card, 3 attemptsA saved copy of the file restores the attempts — choose long PINs.
Key theft by an applicationKeys processed in the isolated driver host; applications only exchange APDUsAn administrator of the computer can read that process's memory.
Tampering with the card fileGCM authentication tagA tampered file is refused: the card is lost, not altered.
Card on an internal diskRemovable devices only by defaultAllowNonRemovable lifts the restriction.
A software card, not a secure chip. EIDVirtual gives a USB key the behavior of a smart card for Windows and applications, not the physical resistance of a secure element. Use a hardware token (smart card, TPM virtual smart card) when the private key must be non-exportable by design or when a FIPS 140 / Common Criteria certification is required. The functional documentation details the security model.
FAQ

No. The card answers as a GIDS card and Windows loads its own built-in GIDS minidriver. EIDVirtual itself — the reader driver and its tools — is only needed on the computers where the key is used.

No. Private keys are generated on the card or imported into it, and never leave it: there is no API to export them.

No. EIDVirtual2.bin is encrypted with a key derived from the identity of the device (vendor, product, revision, serial number). A copy on another key is ignored by the reader. A backup on the same key can be restored.

After 3 wrong PINs in a row the PIN is blocked, like on a physical card. A correct PIN resets the counter. A blocked card can be unblocked with its admin key; without it, initialize the card again (its content is lost).

RSA keys of 1024 to 4096 bits (the Smart Card manager uses 2048 bits), with PKCS#1 v1.5 and OAEP. Elliptic curve keys are not supported.

Only removable devices are accepted by default. An administrator can accept fixed disks with EIDVirtualCmd nonremovable on.

One card is inserted at a time: EIDVirtual provides one virtual reader. When several prepared keys are plugged in, the first one found is used; EIDVirtualCmd eject / swallow switches between them.

Yes. Since version 2.1 the MSI installs the driver without any prompt, and EIDVirtualCmd provisions cards from scripts.