Client Certificate Solutions - Providing Standards Based User Authentication for Web Portals, Remote Access (SSL VPNs) and Secure Messaging
The opportunities inherent in securing applications for remote access, messaging and paperless
transactions are within reach. Costs are low. Deployment is fast. And the technology can be employed in
every
government organisations, University or public sector body.
True Credentials is the first second-generation enterprise security service. A second-generation security
(PKI) service is one that is fully managed (i.e. outsourced) including authentication of recipients, requires
no complex software at the enterprise, enables quick and easy deployment of client certificates for applications, and involves
very low initial investment making it possible to apply security to one application at a time in priority
(ROI) order. True Credentials delivers real value in the following areas of security:
- Secure Network Access (SSL VPNs)
True Credentials issues end users with a client certificate which can be used to provide a two way secure tunnel that authenticates user to server and server to user before allowing access through a 128 bit encrypted secure "tunnel". SSL VPNs are already supported by popular browsers and require no additional client software like traditional VPNs.
True Credentials can also be used for user authentication to web portals, like the UK Government Gateway (see case study). Once a user has been issued with a client certificate, they can be authenticated to specific web sites or resources, and depending on the policies in place be granted access.
- Secure Messaging (S/MIME)
Secure messaging is about
making sure only the intended recipients of your message can read it. All modern
email clients support signing and encrypting messages to keep communication private and confidential by using client certificates issued through True Credentials. With a certificate installed,
email clients and servers continue to work unaltered but emails remain private, secure and integral.
Public Sector Drivers
E-Government is central to the modernisation of the UK Government. The Priority Service & National Strategy transformation outcomes for local e-government in December 2005 has been defined to have 100% e-enablement of Government services by 2005. Strong and managable security will play an increasingly important role in meeting the public sector requirements for the transition of services online.
GeoTrust is focused on assisting all levels of Government bodies, no matter what the size of the project, in e-enabling their services.
|