Innovative Projects Topped with YubiKing Crowns

Break out the trumpets. Lower the drawbridge. The YubiKings are here to claim their thrones!

Today, Yubico is announcing the three winners of the months-long YubiKing contest, designed to discover who had mad enough skills to build the most innovative, creative and compelling solution around the YubiKey.

We received and evaluated a pile of fantastic entries. It was hard to cut them to a reasonable number before deciding on the three winning teams, each of which had incorporated a number of Yubico and open source elements into their YubiKing projects.

Congratulations to the leaders and team members of the victorious projects:

Each team will receive a $3,000 prize and special-edition etched “YubiKing” keys. YubiKing etched YubiKey

And we need to have a well-deserved virtual cheer for all those who took their best ideas and spent time working them into tangible solutions over the past months.

YubiKing Buckell and his team of four added support for YubiKey protocols ­— OTP, OATH and FIDO’s U2F — to the two versions of their MFAStack platform, that include two-factor authentication (2FA) support, IdP capabilities, and standards-based single sign-on. The YubiKey supports two-factor authentication to access the admin console, and a Yubico OTP is also used to approve changes to user settings, such as revoking keys.

But it’s the integration with U2F that gives users private key cryptography capabilities. In essence, it is strong authentication to protect an end-user’s single sign-on account. Buckell’s development team also included Nikola Bursac, Dominik Trupčević, Marko Bencek and Domagoj Paljug.

YubiKing Qvist and his teammate, Michael Bisbjerg, built CSIS Enrollment Station, an application that lets IT departments easily deploy and manage certificates and YubiKeys (PIV support, enrollment, pin reset, revocation) on behalf of Microsoft Windows users. This was not possible previously because the YubiKey does not have native write support with Microsoft’s Base Smart Card Crypto Provider. So the team used Yubico’s PIV tool and a YubiKey PIV library .dll to generate a private key directly on the YubiKey and then generate a Certificate Signing Request. The request is read by their program as PKCS#7 and then packaged in a Certificate Management Message over CMS (CMC). The package is then sent to the Windows Certificate Authority. For good measure, Qvist and his team added the ability to generate a Pin Unlock Code and management keys by interfacing with Yubico HSM’s random number generator.

Not to be outdone, YubiKing Schürmann and his teammate, Vincent Breitmoser, went mobile with OpenKeychain for Android, which provides OpenPGP encryption, decryption and digital signatures to protect messages on an Android smartphone. Schürmann’s team added support for the OpenPGP feature of YubiKey NEO and its Near Field Communication (NFC) option. By separating the key mechanism from the device, OpenKeychain dramatically increases the security of the device. The application integrates with K-9 Mail and Conversations.

Thank you, everyone, for the wonderful submissions and for contributing to a successful contest. Don’t forget to look up Yubico at the Black Hat conference next month in Las Vegas at Booth #964. We can talk a little YubiKing.

See you next year!

Talk to our teamTalk to our team

Share this article:


  • Introducing new features for Yubico Authenticator for iOSWe’re excited to share the new features now available for Yubico Authenticator for iOS in the latest app update on the App Store. Many of these improvements aim to address frequently requested features from our customers, while providing additional new functionalities for a seamless authentication experience on iOS.  With increased interest in going passwordless and […]Read moreiOSYubico Authenticator
  • Platform independent digital identity for all Many are understandably concerned that the great invention called the Internet, initially created by researchers for sharing information, has become a major threat to democracy, security and trust. The majority of these challenges are caused by stolen, misused or fake identities. To mitigate these risks, some claim that we have to choose between security, usability […]Read moreDigital IdentityEUDIFounderStina Ehrensvard
  • Q&A with Yubico’s CEO: Our move to the main Nasdaq market in StockholmAs 2024 draws to a close, it’s the perfect time to reflect on the incredible journey we’ve had this year and how it has shaped where we stand today as a company. To mark this moment, I sat down with our CEO, Mattias Danielsson, to look back on the milestones and achievements of 2024—culminating in […]Read moreCEOMattias Danielsson
  • Exploring DORA: A look at the next major EU mandateFinancial institutions have historically managed operational risk using capital allocation, but under EU Regulation 2022/2554 – also known as the Digital Operational Resilience Act (DORA) – the financial sector and associated entities in the European Economic Area (EEA) must also soon follow new rules. These new rules focus on the protection, detection, containment, and the […]Read moreDORAEU