IdExchange 1.9.1

Derived Credential Support - Overview

The IdExchange Derived Credential Platform (DCP) enables the issuance of additional credentials to an existing cardholder through a secure and streamlined workflow. With IdExchange, the credential delivery process is drastically simplified by allowing the cardholder to use their existing credential they received issued after undergoing the identity proofing process, as a way to digitally prove they have already been verified. By using their previously issued credential as proof they have been verified, there is no need to perform the identity proofing process again to receive additional credentials. They simply login with their existing credential and can request additional credentials for hardware MFA tokens, mobile devices, or other devices requiring MFA credentials.

Capabilities

  • External Identity issuer integration to provide the ability to Import the cardholder's primary credential via API submission or manual card read.

  • Multi-phase device registration and identity verification to enforce credential issuance security controls.

  • YubiKey lifecycle management; ability to fully program and manage a YubiKey device.

  • Ability to issue both PKI certificates and FIDO credentials.

  • Automated certificate and employment status monitoring.

  • Detailed reports and dashboards to monitor performance.

  • Web interface to provide easy to understand wizards to issue new credentials.

Benefits

With IdExchange, organizations can quickly augment their MFA credentialing capabilities to use the latest technologies and provide additional MFA options for their workforce. IdExchange provides a way to conveniently and securely issue alternate credentials by leveraging the user's existing PKI based smart ID badge.


Independently work with different identity providers

IdExchange can independently consume primary credentials from different issuers to allow organizations to issued derived credentials even if unable to directly connect to the issuer.

Multiple issuance models

Credentials can be issued in many ways to support the business needs of the organization:  1) face to face in a traditional ID badge office, 2) self service where the card holder performs the encoding without any assistance, 3) secure bulk mode where a security official programs the device and distributes it to the card holder.

Credential Synchronization

Credentials derived from the primary credential can be automatically revoked of the primary credential is revoked. IdExchange enables the derived credentials to be synchronized with the primary credential. 

Practical installation

IdExchange uses standard Microsoft technologies such as Internet Information Systems (IIS) and Microsoft SQL making it easy to install and operate with general technical knowledge.



Derived Credential Issuance Aligned with NIST 800-157 and NIST 800-79

Security Management and Data Protection

End to end Encryption: Data at rest and in transit is encrypted using the strongest cryptographic ciphers and require mutually authenticated sessions for all system interactions. Hardware security module (HSM) is supported for additional controls.

Privacy Notifications: Privacy notification screens can be customized to meet organization messaging needs to ensure the appropriate privacy notification is seen and accepted by the system users.

Auditing: All identity proofing and credentialing lifecycle events are tracked and made available through a wide array of pre-designed reports. For custom auditing needs, the auditing API is available as well as a configuration guide to link an external security information and event management system.

Record Expungement: All traces of subscriber information are removed when an authorized official offboards a subscriber. When the subscriber is to be removed, the system deletes all the user’s information and internal data security keys to completely remove all subscriber data from the system.

Infrastructure

Issue different types of derived credentials: Utilize the NIST 800-157 identity proofing workflow to easily issue different types of derived credentials from different credentialing providers. Easily configure a PIV Derived certificate authority to be used in the issuance of hardware based derived credentials.

Automate Revocation and Employment status checking: Automatically check the subscriber’s primary credential status and then revoke their associated derived credentials if the primary credential has been revoked.

Issuance and Maintenance Processes

Easily onboard Subscriber verification: The system can securely register any PIV credential using standard protocols to enable the subscriber to login and verify their identity in accordance with NIST 800-147.

Chain of Trust:  Easily register and verify different mobile devices, hardware keys, or other derived credential security containers using Mobile Device Management systems, API, or manual data input.

Termination Flow: Synchronize all credential statuses for a subscriber by automatically terminating derived credential if the primary credential is terminated.

Name change: Securely refresh derived credential information when subscriber’s primary credential information changes.