Converged (Logical and Physical) Access
IdMlogic helps Clients evaluate and implement alternative converged, logical and physical, Identity Management solutions.
A single, streamlined credential with strong two- or three-factor authentication for unified badging into facilities and access to networks, systems and applications – that’s the clear benefit of a converged access management solution.
Movement towards converged access is being driven by the Homeland Security Presidential Directive 12 (HSPD12). And as is often the case, such Federal mandates tend to drive the private sector as well.
But implementing converged access is not without its challenges. Converged access requires a unified infrastructure with interoperable standards and components, including policies, procedures and provisioning systems to handle not only initial credential distribution, but also forgotten badges / credentials, temporary credentials, temporary users, and so on. And there is often the cost of upgrading physical access control standards and environments.
On the other hand, converged access can deliver a unified, integrated access management solution that protects all your business assets, with centralized control and reporting, faster response to security emergencies, and improved regulatory compliance.
Because the ‘right’ solution for an enterprise depends on its environment, as well as on its goals and objectives, IdMlogic evaluates and recommends alternative technologies, such as:
- PKI smart card logon – a hybrid smartcard that contains both a contact-less chip used for physical access, and a contact chip for smartcard logon digital certificate.
- RFID logon – utilizing a contact-less card with the functionality of a logical authentication device.
- Biometric authentication – a portable fingerprint reader and wireless receivers for both physical and network access.
Our staff of solution architects and systems engineers can help you select and implement a converged access control solution that is right for your organization.
RFID Logon Solution Example
An RFID logon solution is based on an employee presenting his RFID (contact-less) badge to a USB external reader. The badge is an HID product using the ICLASS ™ protocol for encryption of all data transferred from and to the badge.
The reader induces an electromagnetic field near the card, and a hidden card antenna and electric mechanism transform the energy to current flow in the card. The card identifies to the reader, and the data (Card ID) is send to a card management server for authentication.
When authentication succeeds, the saved user domain password is sent back to the client and becomes the login credential to the directory.
