To provide organizations without a mobile device management system the ability to issue derived credentials using the NIST procedures, the IDMS provides a credentialing API that enables full device registration and certificate lifecycle management.
-
Customer ID Manager System: The term “ID Manager System” is generic and refers to any system the customer wants to designate to interact with the IDMS and mobile device.
-
Mobile App: The software on the mobile that will generate the keys, format the CSR, interact with the customer ID manager system and then install the certificate.
-
IDMS: This is the system that will manage the device requests, interact with the certificate authority to generate the certificates, and respond with the certificate. Furthermore, this system will control the security of the PIV card to device linkage.
-
Workstation: The cardholder will need to be able to access an internet browser with their PIV credential to log in and create a credential request.
System Flow
*Note: The term device ID refers to any value that will uniquely identify the mobile device in the IDMS. The device ID can be generated by the MDM or mobile software.
Cardholder credential request: The cardholder will authenticate with their PIV credential and create a request for a given device. This information will be sent to the Id Manager.
User registration: The Id Manager System will retrieve the user information and send the information to the IDMS.
Device registration: The Id Manager system will send the user’s device ID and certificate authority information to the IDMS. This will enable the user to create a credential request for a specific device id. Additionally, the IDMS will be able to verify the device ID belongs to the correct person before issuing the certificate.
Cardholder derived credential application: The Id Manager will forward the certificate and request from Step 1 to the IDMS.
The IDMS will respond with a temporary passcode that will be used to authenticate the user/device.
Device credential request: The cardholder will use their iPhone app to create a certificate request. This process will send the device ID, temporary code, and certificate signing request to the ID manager which will then route to the IDMS for certificate fulfilment.
Certificate generated: The ID manager system will forward the certificate request package to the IDMS. The IDMS will then interact with the Certificate Authority to process the CSR and create the certificate. The completed certificate will be sent back to the ID manager system.
Certificate installed: The ID manager system will respond to the iPhone with the certificate. The iPhone software will then install the certificate and send back an acknowledgement signed with the keys associated with the certificate that was just delivered.