The challenge
Federal identity-assurance standards were pushing agencies toward one strong credential per person — but no existing product tied a single smart card to sign-on across a PC, a VPN, webmail encryption and signing, and a building door. Each system still held its own separate notion of who a person was.
What we built
Designed and built a prototype enterprise identity platform on ISO 7816 Java smart cards.
- Single sign-on to Windows PC login, VPN, and web applications from one smart card
- PKI-based email encryption and digital signing tied to the same credential
- Integrated IBM Tivoli and CA eTrust identity and access management as the enterprise IAM backbone
- Biometric (fingerprint and hand-geometry) enrollment stations feeding the same credential-issuance workflow
- Contactless physical-access integration so the same card opened doors
- Delivered against FISMA, HIPAA and GSC-IS/FIPS compliance requirements on a compressed federal timeline
How it works
One enrollment event provisions a Java smart card with a PKI certificate, a biometric template reference, and physical-access credentials. From that point, the card is the single factor presented to a PC login prompt, a VPN client, a webmail client's signing/encryption layer, or a badge reader — all validated against one IAM backbone rather than four separate systems each holding their own notion of identity.
Results
- One credential replaced what would otherwise have been separate logins for PC, VPN, email, and building access
- Delivered enterprise SSO and PKI patterns years before they became standard enterprise practice
- Met federal compliance requirements (FISMA, HIPAA, GSC-IS) under a compressed delivery timeline
Let's talk about what you need built.
Custom-engineered solutions — no generic platforms, no compromises.
Start a Project →