Smart Employee ID for Government
For organizations seeking to deploy a single and secure intelligent ID badge
allowing employees, contractors and partners to access government facilities
and IT resources, ActivIdentity provides a Smart Employee ID solution
that enables secure access, communications and transactions while reducing
administration costs and improving user convenience.
The ActivIdentity Smart Employee ID smart card functions as a photo ID and a
proximity badge for facility access, as well as an IT security device for digital
identification and authentication. The Smart Employee ID solution is much more than
a multi-function smart card: it is a solution that allows organizations to converge
user identification and improve facility and IT security by integrating processes and
back-end systems. The result is a single card for each person across facility and IT
domains, providing increased security and accountability.
Why move from existing solutions?
Passwords
- Passwords are insecure: A password can be used by anyone who knows it, there is no way to be sure
that password-authenticated users are really who they say they are.
- Passwords are expensive: Resetting forgotten passwords is one of the most common help desk requests
and represents a major IT support cost for organizations.
- Passwords are inconvenient: End-users typically choose weak passwords to make them easier to remember,
or write them down on sticky notes “hidden” in trivial locations.
Tokens
- Limited functionality: One-time password tokens are limited to authentication to IT systems. A smart
card or USB token can also be used for secure communications and transactions, for physical access to facilities,
and many other applications.
- Limited usability: Users read the one time password from the token display and then type it on their
workstation keyboard. This is time consuming, and leads to errors. A smart card or USB token only requires
the user to insert the device and type in a simple PIN code.
Business Benefits
- Risk mitigation: In today's world, a security or privacy breach can result in grave
consequences, especially for government agencies who handle sensitive information. ActivIdentity Smart
Employee ID solutions reduce the risk of such events by enabling strong proof of identity and secure
access to information.
- Accountability: When a security incident occurs, the organization must be able to identify
the individuals who broke the rules. Strong proof of identity and tight integration between security audits are
the keys to providing legally enforceable proof of any access to facilities, IT systems and information.
- Cost reduction: Most organizations have separate processes and systems for issuance of
facility access badges, identity cards and IT security tokens. This results in high cost and increased security
risk. With the ActivIdentity Smart Employee ID solution, smart cards can be used interoperably for all identity
and access control needs throughout the organization - increasing security and reducing operating costs.
- Productivity: In a typical government agency, users login with user names and static
passwords multiple times per day. With smart card authentication, the login experience is fast with an
ATM-like experience (insert your card and type your PIN).
- Employee education: Frustrated users tend to work around security policies to make logging
into computers easier. With ActivIdentity Smart Employee ID solutions, convenience and security are tied together.
For example, the card is required to access facilities, so employees must take their card with them when leaving
their office and the card removal automatically locks the screen and the application.
- Organizational efficiency: As recent regulations have increased the accountability of
executives, many organizations are merging their facility and IT security teams into a single
organization. ActivIdentity Smart Employee ID solution enables alignment of processes and technology to reinforce
these efforts.
Technical benefits
- Field-proven – ActivIdentity Smart Employee ID solutions are used by many
government agencies around the world including the U.S. DoD, Veterans Affair and Department of Interior,
as well as Singapore Defense (DSTA).
- Security across IT infrastructures – Enable multi-factor security with smart
cards across the IT infrastructure, including secure remote access, secure workstation and network access,
secure application access (single sign on) as well as secure information such as signed and encrypted e-mail,
documents and files and secure transactions.
- Ease of deployment – Most government agencies can deploy the ActivIdentity
solution without the need for custom integration work, since it comes pre-integrated with leading vendors
of Smart Cards, Certificate Authorities (CA), Directories, Identity Management Systems (IDMS), and Physical
Access Control Systems (PACS).
- Extensible and open – Public APIs and SDKs allow easy integration with more
environments such as additional IDMS, CA and PACS vendors that may not be pre-integrated. Open
standards-based architecture allows integration with virtually any third party system or application.
- Future-proof – ActivIDT Card Management System (CMS) allows organizations to
quickly deploy smart cards to address immediate needs, and to update the cards post-issuance securely in
the field. ActivClient® middleware shields organizations from the headaches of evolving interoperability
standards by providing transparent support for multiple generations of specifications including U.S. DoD CAC,
GSC-IS 2.1 and PIV, and will continue to evolve to support new standards.
- A name you can trust – With over a decade of domain expertise, a broad patent
portfolio and an extensive investment in ongoing research and development, ActivIdentity develops all its
software products internally and ensures that its solutions continue to provide the industry leading security,
usability, and interoperability that government agencies require.
Standards Support
- GlobalPlatform / OpenPlatform
- Java CardT
- FIPS 201 / PIV certified cards and applications
- FIPS 140-2 certified cards and applications
- FIPS 140-2 certified Hardware Security Modules
- LDAP 3.0 directory services
- SSL 3.0 communications
- Section 508 accessibility requirements
- A variety of Public Key Infrastructure standards including PKCS#7, PKCS#10, PKCS#11, X509, CRMF / CMMF / CRM
- U.S. DoD CAC
- U.S. DoD GSC-IS
ActivIdentity products used in this solution
Case Study
Nissan Europe drives security with ActivIdentity Smart Employee ID