Download - Cloud PIV Authentication and Authorization Demo

Transcript
Page 1: Cloud PIV Authentication and Authorization Demo

Cloud PIV Authentication and Authorization Demo

PIV Card

User Workstation

Central Security Server

In order to use Cloud Authentication and Authorization system, user needs PIV cardand smart card reader

Cloud Authentication and AuthorizationSystem comprises Central Security Serverand Portal Security Server. Portal Web Server is behind Portal Security Server. User needs Cloud Login Client on his/her workstation.

Portal Security Server

Web / PortalServer

Page 2: Cloud PIV Authentication and Authorization Demo

Cloud PIV Authentication and Authorization Demo

PIV Card

User Workstation

Cloud Login Client is installed on a User Workstationand can be activated using its icon on the desktop.

Page 3: Cloud PIV Authentication and Authorization Demo

Cloud PIV Authentication and Authorization Demo

PIV Card

User Workstation

Central Security Server

Cloud Login Client displays login panel.Several Central Security Servers are already pre-configured and the one to perform initial authentication is selected. User enters his/her smart card PIN.

Page 4: Cloud PIV Authentication and Authorization Demo

Cloud PIV Authentication and Authorization Demo

PIV Card

User Workstation

Central Security Server

Cloud Login Client opens PIV card, reads PIV Authentication Certificate and sends it to the Central Security Server. The Server performs strong authentication challenge/responseprotocol with the PIV card and when successfully completed issues SAML ticket.

SAMLTicket

AuthenticationCertificate

Page 5: Cloud PIV Authentication and Authorization Demo

Cloud PIV Authentication and Authorization Demo

User Workstation

Central Security Server

Next, Internet Explorer is automatically startedand directed to the Portal Security Server.

PIV Card

SAMLTicket

Portal Security Server

Web / PortalServer

Page 6: Cloud PIV Authentication and Authorization Demo

Cloud PIV Authentication and Authorization Demo

User Workstation

Central Security Server

Portal Security Server fetches SAML ticket and uses it for single sign-on authentication.When completed, it displays success message.

PIV Card

SAMLTicket

Portal Security Server

Web / PortalServer

Page 7: Cloud PIV Authentication and Authorization Demo

Cloud PIV Authentication and Authorization Demo

User Workstation

Portal Security Server Web / Portal

Server

After that, Portal Security Server re-directs user’s request to the Web Portal, which displaysits home page. Accessing Portal’s pages isalso controlled by the Portal Security Server.

PIV Card

SAMLTicket