Athena Smartcard Solutions June 2009 Smart Card Technology and Security Leaders About Athena General • Corporate HQ in Tokyo, Japan • R&D & Sales centers in Japan, US & Israel The Technology What we develop, manufacture and sell: Cryptographic Java & Native - Smart Card operating systems Uniquely designed for PKI – ID Specific Government & Corporate ID versions PKI Middleware Most advanced in the industry, innovative architecture, secure, cross platform Windows/Linux/Mac OS X Smart card readers and tokens Over 15 designs including USB/Serial Desktop, Keyboard, Motorized, Token, SDMicro, Biometric Athena’s Product Family •ASECard Crypto & ASECard Crypto Duo • • • • • • • • 36,72 or 144KByte Cryptographic Smart Card- RSA (2048), Innovative Memory Management Advanced security techniques FIPS 140-2 Level 3, FIPS 201/PIV and CC EAL4+ Biometrics MOC Windows/Linux/Mac OS X Contact or Dual Interface ICAO specs, PKI •IDProtect & IDProtect Duo • • • • • Java Card 2.2.2 and Global Platform 2.1.1 compliant Multi-application platform supporting cryptographic and PKI applications, such as Biometrics MOC Cryptography supported - RSA (2048), AES (256), SEED, DES, 3DES, SHA-256, MD5 Available in different form factors, such as USB, SDMicro. Dual interface solution providing a ISO 14443 interface Main Advantages Athena products integrate seamlessly with standard market technologies Athena is the first company to introduce a combined physical and logical access smartcard lifecycle management system through our Unified Badge family of products. Athena CMS and smart cards have been deployed in the largest Financial institutions in complex physical/logical access scenarios including biometric MOC. The Athena solution is the only one where security related settings such as pin complexity rules, pin validity and timing data are enforced on the card itself. Certificates and keys on Athena cards can be used through CAPI/PKCS#11/MiniDriver no matter through which cryptographic interface, CMS or ILM, and Platform (Windows/Linux) they were generated. Cryptographic Middleware •CAPI and PKCS#11 PKI Middleware • Main features: • User PIN options: •Regular PIN, Biometric PIN •PIN AND Biometric (i.e. 3 factor authentication) •PIN OR Biometric (i.e. either PIN or fingerprint used to authenticate the card holder). Admin PIN options: •Challenge Response, 3DES key. • Various certificate propagation options (e.g. remove certificates from store if card is removed; keep for x days if not used etc.) • PINs are never sent to the card in plain, sent in challenge response process under the cover. Keys are always sent encrypted (RSA encryption) to the card. • Common CAPI and PKCS#11 objects (objects in a CAPI container are accessible to PKCS#11applications as well). • Protected PIN entry (in S/W). •Microsoft BaseCSP for ILM • Certified for all Windows platforms incl. Windows 7 • Member "Logo Ready" early adopter program for V6 smart card minidrivers. Athena Java IDProtect •IDProtect flexible design offers: • Rapid porting onto leading silicon manufacturers • IO interface options (ISO 7816, ISO 14443, USB, SD) • Compliance to the latest industry standards –Java CardTM 2.2.2 –GlobalPlatform 2.1.1 • A focus on cryptography –DES and 3DES –SHA-1 and SHA-256 –RSA (up to 2048) –AES (up to 256) –ECC • Easy integration of 3rd party applications • Performance and code size optimisation Smart Card Readers ASEDrive IIIe Smart Card Reader and Tokens USB, Serial, Keyboard USB Biometric Smart Card Keyboard Contactless Reader Smart Card Keyboard Token Special Features on all Readers Flash Upgradeable EMV Microsoft Logo Made in Japan Landing contacts Athena CMS Athena Card Management System •Complete card life cycle management •Badging and Photo ID •Local and Remote Unlock of PINs •Support for any LDAP, CA •Workflow and role based •Easily localized into any language •Various issuance models •Biometric support •Contactless support •Back office/IDM integration – SAP, Tivoli, iPlanet Athena CMS PKI Certificates Contactless Chip SSO/Passwords Barcode & Magnetic Swipe encoding Logical Access Controls Biometric credentials Flexible Role Definition Selected customers Europe Banking Telecom Manufacturing Corporate Government USA Israeli Government ID Card Athena IDProtect Duo • Java Card 2.2.2 and Global Platform 2.1.1 compliant. • Advanced Athena Laser PKI applet. • Precise Biometrics MOC. • Cryptography supported - RSA (2048), AES (256), SEED, DES, 3DES, SHA-256, MD5. • Dual interface. • Contactless ISO 14443 Type B interface for physical access control. • Security features – Holographic lamination – UV – Microtext. • Durable card body material blend with high temperature resistance. Israeli Government ID Card IDMS PKI Bio Visual card properties Card Lifecycle Management System Smartcard structure Physical access Control Athena IDProtect RA Thank You