Centralized Authentication Gateway CAG360 for SME

Slides:



Advertisements
Similar presentations
Digital Certificate Installation & User Guide For Class-2 Certificates.
Advertisements

Installation & User Guide
Cloud PIV Authentication and Authorization Demo PIV Card User Workstation Central Security Server In order to use Cloud Authentication and Authorization.
Digital Certificate Installation & User Guide For Class-2 Certificates.
WPKI available technology diagram and the business model
PKI Administration Using EJBCA and OpenCA
WAP Public Key Infrastructure CSCI – Independent Study Fall 2002 Jaleel Syed Presentation No 5.
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
Product and Technology News Georg Bommer, Inter-Networking AG (Switzerland)
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
EASY LOGISTICS CENTER - the TURNTABLE for information, documents and processes EASY LOGISTICS CENTER DOCUMENTS SHOP CONTENT COMMUNITY MODULES EASY ENTERPRISE.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Alcatel Identity Server Alcatel SEL AG. Alcatel Identity Server — 2 All rights reserved © 2004, Alcatel What is an Identity Provider?  
 Proxy Servers are software that act as intermediaries between client and servers on the Internet.  They help users on private networks get information.
TrustPort Public Key Infrastructure. Keep It Secure Table of contents  Security of electronic communications  Using asymmetric cryptography.
For Sage MIP Fund Accounting
INTRODUCTION Why Signatures? A uthenticates who created a document Adds formality and finality In many cases, required by law or rule Digital Signatures.
X.509 Certificate management in.Net By, Vishnu Kamisetty
Wolfgang Schneider NSI: A Client-Server-Model for PKI Services.
May 30 th – 31 st, 2006 Sheraton Ottawa. Microsoft Certificate Lifecycle Manager Saleem Kanji Technology Solutions Professional - Windows Server Microsoft.
1 Card Scanning Solutions SigniShell CSSN – Card Scanning Solutions THE ULTIMATE SIGNATURE CAPTURE & AUTHENTICATION SOLUTION.
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
Cisco Confidential © 2010 Cisco and/or its affiliates. All rights reserved. 1 SAN Certificate in Unity Connection Presenter Name: Bhawna Goel.
PETS – Power Exchange Trading Software Power Exchange Trading Software for Online Bidding, Billing and much more.
© GlobalSign. A GMO Internet Inc group company. Authentication. Security. Trust. Code Signing Distributing trustworthy software over the Internet.
| | Tel: | | Computer Training & Personal Development Microsoft Office PowerPoint 2007 Expert.
PCT-SAFE and e-Services developments Webinar September 7/
Registration Processing for the Wireless Internet Ian Gordon Director, Market Development Entrust Technologies.
Gregorio Martínez Pérez University of Murcia PROVIDING SECURITY TO UNIVERSITY ENVIRONMENT COMMUNICATIONS.
SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.
Case Study.  Client needed to build data collection agents for various mobile platform  This needs to be integrated with the existing J2ee server 
Norwegian e-health infrastructure based on XML, ebXML and PKI Øyvind Gjørven Rikstrygdeverket (RTV)/ National Insurance Administration.
Belgian EID Card 15/12/2004 Derette Willy eID program manager.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
What is this “thing”?  Basically it is a website where you would be able to collaborate with the group in a safe and private environment through a powerful.
Adviser Panel. Go to All DD Track Advisers: Click “Advisor Login”
28/09/20161 PKI and card issuance EJBCA.org SignServer.org Tomas Gustavsson
© Software602 a.s. SOFTWARE Zdenek Metodej Zalis Martin Vondrous Ondrej Malek.
Digital Signature Certificate and Its Advantages Visit Our Site:
CLOUDENTIFY.
Mobile Security for QlikView
Secure Cloud Based Listening Devices
Setting and Upload Products
CENTRALIZED AUTHENTICATION SERVICES THROUGH MOBILE PHONE
Training Objectives About D2F Download Installation Configuration
Where the security and convenience meet
Mobile Security for QlikView
5/12/2018 3:54 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
ESign Aashutosh.
Single Sign-On Led by Terrice McClain, Jen Paulin, & Leighton Wingerd
DIGITAL SIGNATURE SERVICE
HMA Identity Management Status
How to Check if a site's connection is secure ?
Installation & User Guide
IBM Certified WAS 8.5 Administrator
Using SSL – Secure Socket Layer
Secure Enterprise Technology Initiatives e-Provisioning Group
E-Government Government Gateway Overview.
DIGITAL SIGNATURE CERTIFICATE SERVICE PROVIDER IN NOIDA DIGITAL CERTIFICATE.
Rapid Connect® Getting Started
کاربرد گواهی الکترونیکی در سیستمهای کاربردی (امضای دیجیتال)
Digital Signatures and Forms
Enabling paperless workflows through digital signatures
Public Key Infrastructure from the Most Trusted Name in e-Security
RKL Remote key loading.
Installation & User Guide
Automated Bulk Signing Solution
E-Lock ProSigner ProSigner means “Professional Signer” signifying the software that can apply legally enforceable Advanced electronic signatures to electronic.
Digital Signature Certificate- Common Signer Manual
National Trust Platform
Presentation transcript:

Centralized Authentication Gateway CAG360 for SME

CONTENTS I CAG Introduction II Signer Management System Validator Management System III IV Authentication Agent & SDK BackOffice Portal V VI EJBCA As Private CA For Banks

CAG360 INTRODUCTION TOTAL PKI/OTP SOLUTION FOR BANKING AND SECURITIES

Functional Structure Signer Management System Validator Management System BackOffice Portal CAG360 Authentication Agent & SDK

Signer Management System PDFSigner XML Signer CMSSigner (CAPICOM compliant) Office Signer TPM Performance for SME: 40 TPS, if using HSM, the performance is higher

Signer Management System AOpen DEX9235 from Taiwanese company already installed CentOS 6 TPM: Trusted Platform Module from Infineon chipset SLB9660 that applying to NIST FIPS 140/2 Level 3. Stored up to 680 RSA key pairs Capacity up to 40 TPS (Transaction Per Second)

Signer Management System Supports Wireless PKI (wPKI) and 2nd token wPKI 2nd token Content Layouts 2nd Token is supported for both Android and iOS devices. Bring the best flexibility to customers with the highest security

Signer Management System HTTP Post (Webpage) SOAP Web Services Supports two methods for signing

Functional Structure Signer Management System Validator Management System BackOffice Portal CAG360 Authentication Agent & SDK

Validator Management System PDFValidator OfficeValidator XMLValidator OTP (Hardware/SMS/Email) CapicomValidator Fido Validate signed documents automatically before auditor manually do that Validate signed documents automatically before auditor manually do that

Validator Management System Sign request Do signing OTP/Fido Authentication Supports Two Factor Authentication (2FA) for centralized signing by using OTP/Fido. Detail workflow for centralized signing worker that hybrid integrated OTP authentication 1. Officer staff should go to the CGI page (so-called CAG360 Signer Page), and submit the corresponding credential consisted of username/password 2. The staff should use one of following worker for appling the signing request - PDFSigner for signing the pdf file, our signing worker can create the signed pdf file with invisible/visible signature, it depends on the existing configuration that already applied on the corresponding worker - OOXMLSigner for siging the MS Office file (MS Word, MS Excel, MS Access, MS Power Point ....) , our worker can create the signed file even for MS Office 2003 or later - ODFSigner for signing the Open Office file - XMLSigner for signing the XML file comprised of XMLDSig or XaDES - CMSSigner for signing the String and create the CAPICOM compliant string 3. Once staff choose and browse file, the CAG360 will send the OTP passcode, it maybe is OTP SMS or OTP Email 4. After the OTP passcode is validated, the signed file will be downloaded over the Signer Page, the staff will use this signed file for their own purpose, maybe it will be sent by email, eOffice or so on ....

Validator Management System Detail workflow for centralized signing worker that hybrid integrated OTP authentication 1. Officer staff should go to the CGI page (so-called CAG360 Signer Page), and submit the corresponding credential consisted of username/password 2. The staff should use one of following worker for appling the signing request - PDFSigner for signing the pdf file, our signing worker can create the signed pdf file with invisible/visible signature, it depends on the existing configuration that already applied on the corresponding worker - OOXMLSigner for siging the MS Office file (MS Word, MS Excel, MS Access, MS Power Point ....), our worker can create the signed file even for MS Office 2003 or later - ODFSigner for signing the Open Office file - XMLSigner for signing the XML file comprised of XMLDSig or XaDES - CMSSigner for signing the String and create the CAPICOM compliant string 3. Once staff choose and browse file, the CAG360 will send the OTP passcode, it maybe is OTP SMS or OTP Email 4. After the OTP passcode is validated, the signed file will be downloaded over the Signer Page, the staff will use this signed file for their own purpose, maybe it will be sent by email, eOffice or so on ....

Functional Structure Signer Management System Validator Management System BackOffice Portal CAG360 Authentication Agent & SDK

Authentication Agent & SDK Java C# Content Layouts Sample client is available in Java & C#

Functional Structure Signer Management System Validator Management System BackOffice Portal CAG360 Authentication Agent & SDK

BackOffice Portal It also provides token operations such as initializing, blocking, unblocking...

EJBCA As Private CA For Banks Integrated EJBCA into CAG360 and supported: OCSP CRL LDAP In case of the banks want to build their own private CA, we can support EJBCA which is integrated into CAG360

Our Advantages This is the cost-effective solution with fully integrated variety authentication/validator methods 1 It is suitable for SME with the easy to integration, the cheaper budget, the totally support from security expert 2 We connected all of Certification Authority service providers such as VNPT-CA, FPT-CA, SAFE-CA.... 3

Contact Us MINH THONG CARD SOLUTIONS CO., LTD Address: 16/2 Ter Dinh Tien Hoang, Da Kao Ward, 1st District , Ho Chi Minh City Website: www.tomicalab.com Hotline :19006884 Email : sales@tomicalab.com

Thank You!