1. Catalogs
  2. secunet Security Networks AG
  3. Factsheet secunet eID PKI Suite
video corpo

Factsheet secunet eID PKI Suite

Factsheet secunet eID PKI Suite

Factsheet secunet eID PKI Suite

Product catalog summary
Introduction
Modern identity documents, particularly electronic identity documents (eIDs), require robust security mechanisms to protect biometric and other sensitive data. Public Key Infrastructure (PKI) is essential for ensuring data authenticity and integrity.
Specifications and Standards
The Czech Standard CSN 369791:2018 is adopted by the European Union for secure communication between eMRTDs (electronic Machine Readable Travel Documents). The International Civil Aviation Organization (ICAO) has established specifications (Document 9303) for PKI to ensure the authenticity and integrity of eID data.
PKI Components
  • ICAO PKI: Utilizes Passive Authentication to verify eID data authenticity through electronic signatures. It involves a Country Signing Certificate Authority (CSCA) as the national trust anchor and a Document Signer for document manufacturing.
  • EAC PKI: Extended Access Control (EAC) ensures only authorized entities access eID data. It requires secure communication protocols (BAC|SAC|PACE) and a valid certificate chain for Terminal Authentication.
Infrastructure and Tools
  • eID PKI Suite: secunet offers a comprehensive PKI solution tailored for eID issuance, infrastructure, and control, supporting international certificate exchange.
  • SPOC: A centralized interface for national and international certificate exchange, supporting secure communication via TLS.
  • CVCA and DVCA: Country Verifying Certification Authority and Document Verifying Certification Authority manage certificate requests and secure storage of keys and certificates.
  • TCC: Terminal Control Centre centralizes EAC and Passive Authentication for distributed readers, ensuring secure certificate and key storage.
  • C2K: Certified CA Kernel meets high security standards and is compatible with secunet's eID PKI Suite components.
Benefits and Flexibility
secunet's eID PKI Suite offers flexibility in signature components and certificate handling, supporting all relevant standards and protocols. It provides ready-to-implement solutions for various PKI requirements, ensuring secure and efficient identity document management.
Contact Information
For more information, visit secunet's website or contact them at their Essen, Germany office.
See more

Catalog excerpts

Factsheet secunet eID PKI Suite-1

Public Key Infrastructures For Modern Identity Documents

 Open the catalog to page 1
Factsheet secunet eID PKI Suite-2

With the eID PKI Suite, secunet offers its standard PKI, tailored to meet all the requirements for issuance, infrastructure and control. The design particularly focuses on the international exchange of certificates and other relevant information. Introducing electronic identity documents in most eMRTD to verify an access request all by itself de- cases means the implementation of biometric spite its computational restrictions. To get access to data in the document. Just like traditional optical eMRTDs from other countries, one has to be equipped data, this electronic data has to be secured against...

 Open the catalog to page 2
Factsheet secunet eID PKI Suite-3

SPOC ICAO-PKD Self-Service Kiosks Stationary Border Controls to be established (BAC|SAC|PACE) and access to sensitive data is granted to an Inspection System (IS) if a certificate with sufficient entitlements is available for the mechanism of Terminal Authentication. A technical infrastructure is required to provide a valid certificate chain for the entitlements. Due to their very short validity, handling of Certificate Revocation Lists (CRLs) is not necessary. The three-layered infrastructure consists of a national trust anchor (CVCA) that is connected via a centralised interface called “SPOC”...

 Open the catalog to page 3
Factsheet secunet eID PKI Suite-4

Good reasons for secunet’s eID PKI Suite secunet has developed software products in previ- ICAO PKI field such as CSCA and DS services and ous eID projects which are “ready-to-implement” components which fulfil the requirements of the EAC for your projects, too. Together with the ePassportAPI, PKI, like CVCA and DVCA services. You can choose secunet covers the important requirements re- between individual software modules for easy garding the various PKIs. The product range com- integration into your existing setup, and the complete prises software modules for application in the turn-key solution – just...

 Open the catalog to page 4
*Prices are pre-tax. They exclude delivery charges and customs duties and do not include additional charges for installation or activation options. Prices are indicative only and may vary by country, with changes to the cost of raw materials and exchange rates.