Ramanuj Banerjee Director Technical Consultancy. ActivCard, Inc. Headquartered in Fremont, CA Headquartered in Fremont, CA Over 12 years of experience.

Slides:



Advertisements
Similar presentations
HCQ P MEDICARES HEALTH CARE QUALITY IMPROVEMENT PROGRAM QualityNet Exchange Dennis Stricker Director, Information Systems Group Office of Clinical Standards.
Advertisements

Agenda 2 factor authentication Smart cards Virtual smart cards FIM CM
End Slide Format DO NOT place photos or additional text boxes on this slide. An ASSA ABLOY Group brand PROPRIETARY INFORMATION. © 2013 HID Global Corporation/ASSA.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
The Italian Academic Community’s Electronic Voting System Pierluigi Bonetti Lisbon, May 2000.
SPD1 Improving Security and Access to Network with Smart Badge Eril Pasaribu CISA,CISSP Security Consultant.
SECURITY IN E-COMMERCE VARNA FREE UNIVERSITY Prof. Teodora Bakardjieva.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
PKI Implementation in the Real World
United States DoD Public Key Infrastructure: Deploying the PKI Token
Department of Labor HSPD-12
1 1 Secure Medical Information Exchange (MIX ™ ) System Sead Muftic SETECS Medical Technologies SETECS MIXSystem SETECS ® MIX ™
August 2004 Providing Industry-wide Security and Identity Management Solutions.
Department of Defense Biometrics Management Office 1 Department of Defense (DoD) Common Access Card (CAC) and Biometrics Integration (CBI) Overview
CLXMGCS.ppt Why Smart Cards System Overview Card Architecture Why CardLogix Smart Cards Overview FY 2001.
Increased Security, while protecting Privacy ? True or False ? Christer Bergman, President and CEO, Precise Biometrics.
E-banking.
Figure 1: SDR / MExE Download Framework SDR Framework Network Server Gateway MExE Download + Verification Using MExE Repository (Java sandbox) MExE Applet.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
Polytechnic University of Tirana Faculty of Information Technology Computer Engineering Department Identification of on-line users and Digital Signature.
Brooks Evans – CISSP-ISSEP, Security+ IT Security Officer Arkansas Department of Human Services.
UNCLASS DoD Public Key Infrastructure LCDR Tom Winnenberg DISA API1 Chief Engineer 25 April 2002.
Athena Smartcard Solutions June 2009 Smart Card Technology and Security Leaders.
Certificate and Key Storage Tokens and Software
Virginia Tech Overview of Tech Secure Enterprise Technology Initiatives e-Provisioning Group Frank Galligan Fed/Ed.
Dr. John P. Abraham Professor UTPA.  Particularly attacks university computers  Primarily originating from Korea, China, India, Japan, Iran and Taiwan.
Deploying a Certification Authority for Networks Security Prof. Dr. VICTOR-VALERIU PATRICIU Cdor.Prof. Dr. AUREL SERB Computer Engineering Department Military.
Mobile Identity and Mobile Authentication (mobile e-signature) Valdis Janovs Sales Director Lattelecom Technology SIA.
12 th XBRL International Conference National Tax Agency JAPAN.
Terminal Services in Windows Server ® 2008 Infrastructure Planning and Design.
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
Deploying PKI Inside Microsoft The experience of Microsoft in deploying its own corporate PKI Published: December 2003.
Digital Certificates Made Easy Sam Lutgring Director of Informational Technology Services Calhoun Intermediate School District.
The Windows NT ® 5.0 Public Key Infrastructure Charlie Chase Program Manager Windows NT Security Microsoft Corporation.
1 Personal Digital Certificates at Virginia Tech: Who Are You? Mary Dunker Internet-2 December 4, 2006
Johnson & Johnson’s Public Key Infrastructure Bob Stahl
1 NOAA CVS Training Guide. Background NOAA employees and contractors began receiving new badges in April, 2008, known as Common Access Cards (CACs). These.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
1 EAP and EAI Alignment: FiXs Pilot Project December 14, 2005 David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Module 9: Fundamentals of Securing Network Communication.
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
Security Overview  System protection requirements areas  Types of information protection  Information Architecture dimensions  Public Key Infrastructure.
1 7 th CACR Information Workshop Vulnerabilities of Multi- Application Systems April 25, 2001 MAXIMUS.
® Gradient Technologies, Inc. Inter-Cell Interworking Access Control Across the Boundary Open Group Members Meeting Sand Diego, CA USA April 1998 Brian.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
One Platform, One Solution: eToken TMS 5.1 Customer Presentation November 2009.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
The Distribution Online Vending Pilot Project Demo Testing Certificate Management Kennedy P Subramoney 23 July 2004.
PKI and the U.S. Federal E- Authentication Architecture Peter Alterman, Ph.D. Assistant CIO for e-Authentication National Institutes of Health Internet2.
Identity Management Working Group 2006 Member Meeting Tempe, AZ Barry Ribbeck Rice University.
28 th International Traffic Records Forum Biometrics/SmartCard Workshop 28 th International Traffic Records Forum August 4, 2002 Orlando, Florida.
SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.
How to Deploy and Get the Most Out of Tokens Paul Caskey PKI Deployment Forum 2008.
Belgian EID Card 15/12/2004 Derette Willy eID program manager.
Chapter 4 - X.509 Authentication TE-405 Network Security and Management Fall Dr. Faisal Kakar
Review of ASP/SAS benefits and Web-based Concepts.
Module 3 Planning for Active Directory®
Copyright Statement Copyright Robert J. Brentrup This work is the intellectual property of the author. Permission is granted for this material to.
Securing Online Banking By Ben White CS 591. Who Federal Financial Institutions Examination Council What To authenticate the identity of retail and commercial.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Presented by: Defense Manpower Data Center Access Card Office
Online Security Myths & Challenges HIGHER COLLEGES OF TECHNOLOGY Abeer Nijmeh Account Manager April 14, 2002.
LEARNING AREA 1 : INFORMATION AND COMMUNICATION TECHNOLOGY PRIVACY AUTHENTICATION VERIFICATION.
Electronic Banking & Security Electronic Banking & Security.
The Federal E-Authentication Initiative David Temoshok Director, Identity Policy GSA Office of Governmentwide Policy February 12, 2004 The E-Authentication.
Summary Physical Access & Time and Attendance PC/Network Access
Secure Enterprise Technology Initiatives e-Provisioning Group
35 years of business with Security and Cloud solutions
HIMSS National Conference New Orleans Convention Center
Federating and PKI: Case Studies Paul Hill, MIT
Presentation transcript:

Ramanuj Banerjee Director Technical Consultancy

ActivCard, Inc. Headquartered in Fremont, CA Headquartered in Fremont, CA Over 12 years of experience with smart card technology Over 12 years of experience with smart card technology Seasoned management team Seasoned management team Public Company (Nasdaq:ACTI Easdaq:ACTI) with $300 million in cash Public Company (Nasdaq:ACTI Easdaq:ACTI) with $300 million in cash Sold 300,000 ActivCard Gold licenses in 2000 Sold 300,000 ActivCard Gold licenses in 2000 Over 100 installed ActivCard Gold customer sites Over 100 installed ActivCard Gold customer sites

Reference Customers Defense Manpower Data Center (DMDC) – 4.3 million users Defense Manpower Data Center (DMDC) – 4.3 million users Citigroup / Citibank – undetermined millions of users Citigroup / Citibank – undetermined millions of users Sun Microsystems, Inc. – 45,000 users Sun Microsystems, Inc. – 45,000 users DataCard, Inc. – 3,000 users DataCard, Inc. – 3,000 users Barclays Bank – United Kingdom – 4,000 users Barclays Bank – United Kingdom – 4,000 users ForeningsSparbanken – Sweden – 1.2 million users ForeningsSparbanken – Sweden – 1.2 million users NTT – Japan – 5,000 users NTT – Japan – 5,000 users HP – 100,000 users HP – 100,000 users

The “ATM User Experience” + PIN = Jane Johnson 06/03 No Jane Johnson 06/03 No ATM

Internet The “ATM User Experience” for the Internet + PIN = Jane Johnson 06/03 No Jane Johnson 06/03 No Network Service

ActivCard’s role User Terminal Network Server Service GovernmentHealthcareBankingFinanceCorporateEntertainment Issuance & Enrollment OfficeBranchCustomerHomeHotelAirportMobile Post-issuance Management Add, Delete, Modify Digital Identity

LegacySystemsCertificateAuthorityBuildingAccess FinancialServices E-businessServices Where is ActivCard Software? The Mgt Console The Server The Card Java Card WpSC MultOS Cryptoflex The Terminal

Citibank and ActivCard Citibank has licensed ActivCard software Citibank has licensed ActivCard software Citibank delivers “Turn-key” service Citibank delivers “Turn-key” service Multi-application smart card as new corporate badge Multi-application smart card as new corporate badge –Financial Application – Travel & Expense Card, ePurse, purchase card –Physical Access Control –Logical Access –Demographic and Loyalty Applications –Open Platform Card –Card Lifecycle Management Johnson Jane 12345

Picture ID BuildingAccess Remote Access Token DigitalCertificates Passwords No Common Infrastructure Digital Identity – Sun Microsystems NT Login jjohnson ihate SAP jjohnson x4Lo19b C. Schwab jjohnson echo2 Finance jjo echo1 w Jane Johnson S E C U R ID

Johnson Jane Consolidation Digital Identity – Sun Microsystems NT Login jjohnson ihate SAP jjohnson x4Lo19b C. Schwab jjohnson echo2 Finance jjo echo1 w RP C INCORPORATED John Johnson S E C U R ID NT Login jjohnson ihate SAP jjohnson x4Lo19b C. Schwab jjohnson echo2 Finance jjo echo1 w RPCRPC INCORPORATED John Johnson S E C U R ID w NT Login jjohnson ihate SAP jjohnson x4Lo19b C. Schwab jjohnson echo2 Finance jjo echo1 Jane Johnson S E C U R ID

Service Provider Example Federated Smart Card Management Service Provider Customer Domain Login Virtual Private Networking with portal manager approval Certificate Authority

Usage - $1.5 Billion GSA Contract Active Duty U.S. Navy Johnson, Jane Marie Social Security NumberDate of Birth JAN09 Issue DateExpiration Date 1999SEP032003SEP01 Pay GradeGeneva Conv. Cat. LTCOLVI Rank A1 Geneva Conventions Identification Card DMDC New Process ApplicationsNew Process Applications Single Sign OnSingle Sign On Room for new applets post-issuanceRoom for new applets post-issuance SAMPLE

Department of Defense Example Federated Smart Card Management DOD Service Branches

Deploying 4.3 million Cards The GSA Common Access Card (CAC) Program PIN Mgt AppletPIN Mgt Applet Generic Container AppletGeneric Container Applet –Employee ID –Benefits –External Benefits –Healthcare –Utility PKI AppletPKI Applet –Three Key Pairs/Certificates Space for Departmental AppletsSpace for Departmental Applets Active Duty U.S. Navy Johnson, Jane Marie Social Security NumberDate of Birth JAN09 Issue DateExpiration Date 1999SEP032003SEP01 Pay GradeGeneva Conv. Cat. LTCOLVI Rank A1 Geneva Conventions Identification Card DMDC SAMPLE

Defense Manpower Data Center (DMDC) DEERS ID Badge PayHRMedical 23 million records on Oracle Active Duty U.S. Navy Johnson, Jane Marie Social Security NumberDate of Birth JAN09 Issue DateExpiration Date 1999SEP032003SEP01 Pay GradeGeneva Conv. Cat. LTCOLVI Rank A1 Geneva Conventions Identification Card DMDC SAMPLE

Real-time Distributed Issuing DEERS 1900 RAPIDS STATIONS

Rapids Issuance Terminal

Technical Walkthrough

Distributed Issuing DEERS Issuance Portal https Server HSM HSM HSM HSM Netscape Cert Server DISA / National Security Agency RAPIDS Station ActivCard Gold Monterey, CA 23 Million Records Chambersburg, PA

Verification Officer Authentication to DEERS DEERS Netscape Cert Server National Security Agency HSM HSM HSM HSM RAPIDS Station Issuance Portal https Server ActivCard Gold

SSL v3 Session to DEERS DEERS Netscape Cert Server National Security Agency HSM HSM HSM HSM RAPIDS Station Issuance Portal https Server SSL v3 ActivCard Gold

SSL v2 Session with Issuance Portal DEERS Netscape Cert Server National Security Agency HSM HSM HSM HSM RAPIDS Station Issuance Portal https Server SSL v3 SSL v2 ActivCard Gold

VO Authenticates to NSA DEERS Netscape Cert Server National Security Agency HSM HSM HSM HSM RAPIDS Station Issuance Portal https Server SSL v3 SSL v2 SSL v3 ActivCard Gold

OP Secure Channel to New Card DEERS Netscape Cert Server National Security Agency HSM HSM HSM HSM RAPIDS Station Issuance Portal https Server SSL v3 SSL v2 SSL v3 OP Secure Channel ActivCard Gold Pipe also used post-issuance for card update – Unique to ActivCard

Card Application Managers (CAMs) DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) ID Generic Container PKI SSL v3 SSL v2 SSL v3 OP Secure Channel ActivCard Gold

Create Card Applets - ID DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 SSL v3 ActivCard Gold Generic Container

Create Card Applets – Generic Containers DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 SSL v3 ActivCard Gold Generic Container

Create Card Applets - PKI DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 SSL v3 ActivCard Gold Generic Container

Instantiate ID Applet DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 SSL v3 ActivCard Gold Generic Container

Instantiate Generic Container Applet DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 SSL v3 ActivCard Gold Generic Container

Instantiate PKI Applet DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 SSL v3 ActivCard Gold Generic Container

SSL v2 Profile, Parameters, PIN Data DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 ActivCard Gold Generic Container

SSL v2 Generic Container Data DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 ActivCard Gold Generic Container

Encryption Key DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 SSL v3 ActivCard Gold Generic Container

First Signature Key DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 ActivCard Gold Generic Container SSL v3

Second Signature Key DEERS Netscape Cert Server National Security Agency RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Card Application Managers (CAMs) IDPKI SSL v3 SSL v2 ActivCard Gold Generic Container SSL v3

Print Card DEERS RAPIDS Station Issuance Portal https Server HSM HSM HSM HSM Active Duty U.S. Navy Johnson, Jane Marie Social Security NumberDate of Birth JAN09 Issue DateExpiration Date 1999SEP032003SEP01 Pay GradeGeneva Conv. Cat. LTCOLVI Rank A1 Geneva Conventions Identification Card DMDC Netscape Cert Server National Security Agency ActivCard Gold SAMPLE

Conclusion User Terminal Network Server Service GovernmentHealthcareBankingFinanceCorporateEntertainment Issuance & Enrollment OfficeBranchCustomerHomeHotelAirportMobile Post-issuance Management Add, Delete, Modify Digital Identity

Questions ? ? ?