| Army
Information Assurance CAC/PKI Division—HSPD-12
Maden
Technologies has been instrumental in deploying identity verification
functions across the US Army. The current technologies, smart cards,
and PKI allow for strong authentication and digital encryption and
signature capabilities for Army applications and transactions. The
essential security services Maden Technologies provides include:
confidentiality, data integrity, identification, authentication,
and non-repudiation.
In
support of the Army’s functional proponent for CAC and PKI
implementation, Maden Technologies develops policy, shapes guidance,
and coordinates across DoD. We deliver the centralized management
and oversight necessary to ensure that DoD smart card and PKI products
are evaluated, integrated, procured, fielded, and supported in a
cost effective and timely manner.
We
supported CAC/PKI hardware and software fielding to the Army’s
800,000-seat enterprise and trained 8,000 IT professionals on implementation
and use. In anticipation of the “forgotten personal identification
number (PIN)”, we developed, integrated, and deployed an augmented
infrastructure solution named CAC PIN Reset, or CPR. The solution
allows PINs to be reset to the lowest organizational level, reducing
losses in labor and productivity of Army personnel. Maden Technologies
conducted interoperability and backward compatibility for all CAC/PKI
hardware and software, ensuring the Army’s investment in smart
card technology was protected and would not require replacement
due to changing card platforms or software. We currently manage
the Army Registration Authority (RA) for human PKI certificates
and provide key recovery services to Army PKI subscribers.
With
the issuance of HSPD-12 in August of 2004, we analyzed standards,
published policy, and lead the Army’s implementation of logical
access. Our implementation includes user provisioning to automate
the migration of existing user accounts to smart card-compliant
accounts and web-based distance learning—both exponentially
minimize the cost and “touch” effort of transitioning
to enterprise CAC logon. Additionally, we participate in DoD-level
working groups and forums to help shape the direction of HSPD-12
implementation throughout the Army enterprise. Once complete, the
Army’s capability will meet HSPD-12requirements.
Our
analysts and engineers concurrently support the Army’s enterprise
implementation of Online Certificate Status Protocol (OCSP), a technology
required as part of HSPD-12’s Personal Identity Verification
(PIV). While this capability supports logical access, it is vital
for any electronic transaction performing a real-time check of a
user’s PKI certificate. The Army will leverage this technology
for other CAC/PKI opportunities such as enterprise implementation
of digital signature.
|