Bruhn Freeman Advanced Solutions

Bruhn Freeman

Advanced Solutions

Home · Our Work · // PROJECT 025 · Security · Identity · PKI
// PROJECT 025 · Security · Identity · PKI

Enterprise Smart-Card Single Sign-On & PKI

Single sign-on across a PC, a VPN, a webmail login, and the door to the building — all off one smart card — was not an off-the-shelf capability in the early 2000s. We designed and built it for a federal agency, years ahead of when enterprise SSO became common practice.

PKIJava Smart CardsEnterprise SSOIBM Tivoli IAMCA eTrust IAMFIPS / GSC-ISBiometric Enrollment
Industry
Federal Government
Scale
Enterprise-wide identity program
Status
Prototype delivered under compressed timeline
// Problem

The challenge

Federal identity-assurance standards were pushing agencies toward one strong credential per person — but no existing product tied a single smart card to sign-on across a PC, a VPN, webmail encryption and signing, and a building door. Each system still held its own separate notion of who a person was.

// Solution

What we built

Designed and built a prototype enterprise identity platform on ISO 7816 Java smart cards.

  • Single sign-on to Windows PC login, VPN, and web applications from one smart card
  • PKI-based email encryption and digital signing tied to the same credential
  • Integrated IBM Tivoli and CA eTrust identity and access management as the enterprise IAM backbone
  • Biometric (fingerprint and hand-geometry) enrollment stations feeding the same credential-issuance workflow
  • Contactless physical-access integration so the same card opened doors
  • Delivered against FISMA, HIPAA and GSC-IS/FIPS compliance requirements on a compressed federal timeline
// Architecture

How it works

One enrollment event provisions a Java smart card with a PKI certificate, a biometric template reference, and physical-access credentials. From that point, the card is the single factor presented to a PC login prompt, a VPN client, a webmail client's signing/encryption layer, or a badge reader — all validated against one IAM backbone rather than four separate systems each holding their own notion of identity.

// Outcome

Results

  • One credential replaced what would otherwise have been separate logins for PC, VPN, email, and building access
  • Delivered enterprise SSO and PKI patterns years before they became standard enterprise practice
  • Met federal compliance requirements (FISMA, HIPAA, GSC-IS) under a compressed delivery timeline
// Have a similar problem?

Let's talk about what you need built.

Custom-engineered solutions — no generic platforms, no compromises.

Start a Project →