Identity and Access IDPrime MD 8840 and IDCore 8030 MicroSD cards Didier Bonnet April 2015
MicroSD Slots Deployment As of today, MicroSD cards are compatible with most of the Android and Windows platforms, but not the iOS ones
Secure MicroSD Cards Range MicroSD cards embedding the same secure chip as the IDPrime MD cards IDPrime MD 8840 – 8GB or 16GB = PKI enabled IDCore 8030 – 8GB or 16GB = Pure Java platform Use Cases All PKI and OTP use cases Android, Windows 7/8 and Linux Supported by IDGo Secure Email, IDProve 300 and any other 3rd party application based on IDGo 800 for PCs or Mobiles Value proposition Form factor: Small size and semi detachable Can be personalized on PCs using standard Card Management Systems (CMS) Flash memory for personal or professional usages Well suited for low volumes / short term projects, OR for projects requiring Flash memory
IDCore 8030 Features Secure MicroSD equipped with 8 or 16 GB Flash memory Compliant with the SD Association specifications and the ASSD protocol Java platform compliant with Java Card v2.2.2 and Global Platform v2.1.1 Secure chip EAL5+ certified, memory size of 80 KB (standard) or 160 KB (option) Support of all the most recent cryptographic algorithms including RSA 2048 and Elliptic Curves High security level certifications on request: FIPS140-2 Level 3 or Common Criteria EAL5+ Gemalto Java applets in option: OTP-OATH, MPCOS Drivers for Android, Windows 7 / 8.x, Linux and BlackBerry OS More details
IDPrime MD 8840 Features More details Secure MicroSD equipped with 8 or 16 GB Flash memory Compliant with the SD Association specifications and the ASSD protocol PKI applet: Same features as the Gemalto IDPrime MD smart cards Support of all the most recent cryptographic algorithms including RSA 2048 and Elliptic Curves Certification Common Criteria EAL5+ / PP SSCD for Qualified Signature or FIPS 140-2 Level 3. FIPS140-2 Level 3 certification on request. OTP- OATH applet in standard, MPCOS applet in option Easy connection to a Windows PC through a PC/SC driver Supported by the IDGo 800 middleware on Android and Windows 7 / 8.x Linux on request More details
Main Features IDCore 8030 IDPrime 8840 Secure MicroSD equipped with 8 or 16 GB Flash memory Java platform OS compliant with Java Card v2.2.2 and Global Platform v2.1.1 Compliant with the SD Association specifications and the ASSD protocol Support of all the recent cryptographic algorithms including RSA 2048 and Elliptic Curve Certification: CC EAL5+ & PP SSCD for Qualified Signature On request On going FIPS140-2 Level 3 OTP-OATH applet Option PC/SC emulation driver for Windows 7 / 8 Driver for Linux Libraries Driver for Android IDGo800
Packaging and Marking Specifications Packaging specifications Standard : MicroSD stuck in a white ISO format plastic card 80 units per box Option: JEDEC 4 x 16 units trays Marking specifications Standard: Gemalto logo Option: Customisation of the marking, Q > 10 KU, 2.5 K€ fee Option: Customisation of the ISO plastic card, Q > 1 KU, 2.5 K€ fee
Sales Conditions IDPrime MD 8840 – 8 GB available on the BtoB webstore Q = 1400 units available in stock Product sold through the Direct and Indirect Channels Beside the webstore, MoQ = 3 KU Standard delivery time = 10 weeks Usually requires the IDGo 800 for Android middleware Please refer to the IDGo 800 Legal process Please contact the Gemalto TCs for demonstrations IDGo 800 for Android architecture
More Details on our Webpage
Common Features with the IDPrime MD cards range
IDPrime cards positioning statement Gemalto helps organizations protect and manage their logical, physical, and cloud-based data assets. Our strong multi-factor authentication solutions support a range of form factors and authentication methods providing the highest level of protection. IDPrime Minidriver enabled PKI Cards
Minidriver enabled PKI cards IDPrime family IDPrime Minidriver enabled PKI cards A common set of features Product Features IDPrime .NET 510 IDPrime .NET 5500 IDPrime MD 3810 IDPrime MD 830 IDPrime MD 3840 IDPrime MD 840 Base CSP PKCS#11 RSA On board PIN Policy Multi PIN support Biometry support Dual interface (contact / contactless & NFC support) FIPS 140 -2 Level 3 certif. (platform + PKI applet) FIPS 140-2 Level 2 certif (platform + PKI , OTP & MPCOS app) CC EAL5+ / Javacard & CC EAL5+ / PP SSCD (Java+applet) Elliptic Curves OTP OATH option MPCOS applet option
Minidriver enabled PKI cards IDPrime family IDPrime Minidriver enabled PKI cards Other features Product Features IDPrime .NET 510 IDPrime .NET 5500 IDPrime MD 3810 IDPrime MD 830 IDPrime MD 3840 IDPrime MD 840 Dynamic profile update Secure Key injection (Windows) Option (Dec 14) RSA OAEP algo RSA PSS algo PIN Policy SSO Option (Dec14) Option (Feb 15) ICP Brazil certification Option (Q2 15) Dedicated Signature PIN for CC certified (Sign only) keys Dedicated PUK to unblock the Signature PIN Mifare Classic emulation Hybrid Option DESFire emulation Legic Advant compatibility PAC options
Value Proposition: IDPrime MD as Corporate Badge Enterprises, Universities & Governments who need to secure the access to their data, network & cloud-based assets from both PCs and mobile devices The IDPrime MD offers all the services of a smart card based Corporate Badge plus the full compatibility with the NFC interface of smartphones and tablets. IDPrime MD allows card holders to securely and easily access all their applications whatever their location. The IDPrime MD, associated with the IDGo 800 middleware suite, is the only Corporate Badge operating on any OS, Plug & Play under Windows, and via NFC with mobile devices. WE TARGET THE SOLUTION BENEFITS DIFFERENTIATOR 14
IDPrime MD key benefits 1/2 Plug & Play PKI smart cards Native support on Windows up to 8.1 IDGo 800 middleware suite: Minidriver, PKCS#11, Credential Provider, tools Ready for Mobile Security Dual interface capability ISO 14443 and NFC compliant) Security level even beyond Digital Signature regulations FIPS 140-2 Level 3 CC EAL5+ / PP SSCD Various form factors and authentication methods Contact / dual / hybrid smartcard or token Both PKI and OTP authentication are available
IDPrime MD key benefits 2/2 Enhanced cryptographic support PKI services with both RSA and Elliptic curves E-purse option with MPCOS applet Flexible security policy Extended on-board PIN Policy Optional Microsoft Secure Key Injection service Wide eco-system integration
Digital Signature regulations IDPrime MD security level is even beyond requirements for Digital Signature regulations FIPS140-2 Level 3 certified OS and PKI applet IDPrime MD 830 FIPS 140-2 Level 2 is required by US regulations CC EAL5+ / PPSSCD certified OS and PKI applet IDPrime MD 840 and IDPrime MD 3840 CC EAL4+ / PPSSCD required by European Digital Signature law All the IDPrime MD card chips are certified CC EAL5+ or EAL6+ All IDPrime MD cards embed the most advanced security countermeasures 17
Enhanced cryptography IDPrime MD is ready for the future, since it supports all the crypto. algorithms for immediate and future deployments IDPrime MD supports both RSA and Elliptic Curves RSA up to 2048, RSA OAEP & PSS Elliptic Curves up to P-521 SHA1, SHA 256, SHA-384, SHA-512 AES up to 256, 3DES ECC (Elliptic Curves) computation is faster than RSA Apart for signature verification – which is not performed by the card anyway Improved performances are becoming important with large key lengths
Various authentication methods PKI authentication PIN based Multi PIN option OTP authentication OATH standard Event based Batch, Self or Live provisioning With or without PIN entry (same PIN as PKI) Proposed as an option 19
Optelio Contactless MicroSD card
Dual Secure Element running contactless applets Optelio Contactless Micro SD A contactless MicroSD card with an integrated antenna, turning any handset into a contactless MIFARE Classic, MIFARE + and DESFire EV1 card Dual Secure Element running contactless applets Active contactless front end and specific RF antenna architecture to boost RF performance: A unique Gemalto design. A technological breakthrough The result of Gemalto’s unique RF and hardware integration expertise.
Marking specifications Standard marking 2 Marking customization: On request 22
Value Proposition for Enterprises For Physical Access Control and private epurse use cases Makes any mobile phone equipped with a MicroSD slot ready to use
Qualified Android handsets – Oct 2014 24
Thank you!