Identity and Access IDGo Secure (ISE) for Android Didier Bonnet April 2015
s are a Priority for Enterprises 2 Forrester, December 2011 Mobile Enterprise, December 2014
Main Requirements Addressed 3 BYOD Same mobile device for professional and private usages Mobility Access to s anywhere, anytime Security Mobile devices are more exposed than PCs Standard Compatibility with existing servers and Outlook
Mobile OS Market Share Evolution in Q3 2014Q
Adoption of the OS by the Enterprises Footer, 20xx-xx-xx 5 Mobile Enterprise, December 2014
6 Secure Elements Now and Future MicroSD UICC TEE eSE Badge via contact reader As of today: 10 Million Gemalto smartcard active users 20 Million 3 rd party smartcard active users Next 2 years: Prototypes in progress Badge via NFC Semi- detached credentials Embedded credentials Smart card on a stick Badge via Bluetooth reader Detached credentials In years: Next generation of handsets BYOD/ mobile desktop will increase needs for Secure Elements Secure Element adoption over the time
IDGo 800 Middleware and SDK 7 NFC driver USB OTG (*) driver PKI Crypto Layer API Test tools OTP API 3 rd party client applications Middleware SDK IDPrime Secure Elements TEE (*) PC-SC like API (*) OTG: On-The-Go = USB Master TEE: Trusted Execution Environment BlueTooth driver Other Secure Elements Other APIs
Supported Readers and Tokens on Android 8 USB On-The-Go port (= USB Master ) or BlueTooth USB Female – Micro USB adaptor or cable BHXT and Feitian readers USB tokens & IDBridge K3000 PC-Link readers Micro USB cable
IDGo Secure Native applications: Native clients are not designed with security in mind: s and attached documents are in clear text Encrypted or signed s cannot be read User credentials can be easily discovered IDGo Secure features: Encryption of s and User credentials Digital signature Strong authentication of the user 12
Value Proposition For enterprises and governments who want to secure their s, IDGo Secure is a state-of-the-art application for Android that signs, encrypts and decrypts the professional s based on Extended ActiveSync (EAS) and S/MIME protocols. Thanks to the IDGo 800 middleware, it addresses all the Gemalto hardware Secure Elements and benefits from their unequaled security level. 10 For BYOD environments, IDGo Secure also manages the private s following the standard public POP3, SMTP and IMAP4 protocols.
ISE Security Features S/MIME signature and encryption Encryption algorithms: 3DES, AES256, RSA Signature algorithms: MD5, SHA1, SHA256, SHA512, RSA 11 Gemalto middleware and Secure Elements IDGo 800 for Android and associated readers: USB, NFC, BLE, µSD IDPrime MD,.NET and PIV PKI applets SSL / TLS communication with the server
More Features and Benefits Microsoft Exchange ActiveSync (EAS) protocol Synchronization of Contacts and Calendar Push or periodical synchronization, SSL / TLS communication Compliant with Outlook, Thunderbird and other standard apps S/MIME signature and encryption Crypto algorithms: 3DES, AES256, RSA, MD5, SHA1, SHA256, SHA512 PKI certificates management Local validation with the CA, revocation by CRL Certificates retrieved from validated s, (multi) LDAP and EAS server POP3, IMAP4 and SMTP protocols for BYOD usage Multi accounts, mailboxes and folders, combined mailbox HTML or plain text format, Group and Search s, Remote Wipe, Root detection 12
What is Exchange ActiveSync? EASEAS is a communication protocol that synchronizes s, calendars, contacts and tasks between servers and mobile client applications It also provides some Mobile Device Management (MDM) features and security policy controls It is based on XML and HTTP(S) protocols More details… EAS is licensed by Microsoft is the main provider of EAS compliant servers EAS is supported by Windows Phone, Android, iOS, BB, Gmail, Google Apps, Office 365, Lotus Notes 13
What is S/MIME? Secure / Multipurpose Internet Mail Extensions Standard protocol based on X509 PKI certificates Described by several specifications: RFC 3851, 5751, 5652 Present version is S/MIME v3.2 Insures compatibility between the various applications and servers Main applications Outlook, Mozilla Thunderbird, MacOS Mail, Gmail, OWA Main server: Microsoft Exchange Active Sync (EAS) 14 S/MIME specifies the Digital Signature and encryption / decryption
S/MIME Signature more details more details 15 Note: The signed s can be sent in clear or opaque (base64 encoded) format. Opaque format prevents the risk of wrong signature verification due to some automatic conversion of the text, but requires a S/MIME compliant app.
S/MIME Encryption and Decryption more details more details 16
Basic Operations 17 edition Input mailbox
Wide Settings Capabilities 18
More details on our webpagewebpage 19
Thank you!