Asymmetric encryption is the latest security model being used to protect mobile and physical access credentials. Made up of a public/private key pair, asymmetric credentials retain robust security measures due to the private key being stored and never leaving the smartphone device’s secure element. At the same time they offer open standards and interoperability with disparate systems and applications, thanks to the public key and its ability to be shared to verify identity and authenticate a user, without the fear of it being compromised as a result of replay attacks, man in the middle attacks, or credential spoofing. These security vulnerabilities are common with symmetric encrypted credentials, where there is only one shared key.
Until now, asymmetric mobile and physical credentials had to be provisioned to users one by one, making practical deployment for enterprises with large numbers of users, spanning across multiple locations very difficult and not worth it. The operational headache and use of resources for this led many enterprises to settle for symmetric encrypted credential solutions provided by a single vendor.
Recent developments by Sentry Interactive to their Software Development Kit (SDK), that they provide to access control OEMs, reader manufacturers, identity and access management platforms and other cloud managed software providers, offers a new mass enrollment service for public-key credentials. This now allows enterprises to provision asymmetric credentials based on specifications like Public Key Open Credential (PKOC), on a large scale, across multiple locations, via a centralized cloud management platform. Enterprises can now enroll users at scale with open standard, asymmetric credentials that can work with a combination of different access control systems and reader hardware. This will mean they can now follow the highest access credential security, compliance and regulatory standards, lowering the risk of unauthorized access, data breaches, and human error.
Benefits of asymmetric access credential mass enrollment for enterprises
Improved user experience:
- Users can be enrolled remotely with asymmetric credentials, there’s no need to wait in a queue to be enrolled manually.
- Users have the choice to use mobile or physical asymmetric credentials.
- Administration staff time is saved with remote mass enrollment capabilities, allowing them to maximize output in other areas.
Enhanced security and compliance:
- Risk of security breaches as a result of replay attacks, man in the middle attacks, or credential spoofing are significantly reduced using access credentials secured with asymmetric cryptography.
- Sentry Interactive’s SDK integrates and synchronizes seamlessly with existing enterprise systems ensuring robust compliance standards.
Centralized management:
- Instead of managing individual users separately, companies can control everything from one place.
- Enterprises can operate with quicker and simpler administration and less facilities management or IT credential management workload.
Scalability:
- Asymmetric credentials can be deployed quickly across multiple locations as easily as one.
- If an enterprise decides to introduce a different system or readers, asymmetric credentials will still work, they won’t have to be re-issued.
How to implement
By embedding Sentry Interactive’s SDK into their access control ecosystem, enterprises will unlock the ability to start mass enrolling asymmetric mobile credentials to their users. Asymmetric physical credentials can also be issued and enrolled to run alongside mobile credentials as another option of access.
The future of access credentialing has arrived
Adoption of asymmetric credentials for access control can now scale. Organizations can now deploy and manage open standard public-key credentials across thousands of users, devices, and locations remotely from a centralized platform that have the ability to work with systems and hardware from multiple vendors. A true step forward for enterprise access security.
If you are an enterprise looking to start deploying asymmetric credentials across your locations, get in touch to find out more about our mass enrollment feature and how it can be integrated into your access control ecosystem.