Enroll users with public-key mobile access credentials
Sentry Interactive’s mobile credentials are built on Public Key Infrastructure (PKI) and support specifications like the Public Key Open Credential (PKOC) to ensure the best security standards, open interoperability, and flexibility in deployments being hardware agnostic.
Public/Private Key Generation and Storage
When the Sentry Interactive app, or any third-party app using the SDK, is first initialised on an iOS or Android device, a unique public/private key pair is generated after the user registers an account.
The private key is stored in the smartphone’s secure enclave, the secure enclave is a secure storage location used by Apple and Google to store the users wallet details and is unlocked by the users biometrics and password.
The public key, attached to the user’s account is sent to the Sentry Interactive cloud securely over an TLS connection, with TLS pinning to prevent man in the middle attacks.
Reading the Smart Access Tile and communication with cloud
When the Sentry Interactive app detects a tile via NFC or QR code scan, the Universal unique identifier on the tile is recognised by the app and sent up to the Sentry Interactive cloud.
The cloud will then respond with lock details for the UUID which is cached by the app to speed up the unlock process for that specific tile and door in the future.
The Lock UUID is then combined with certificates, current time, and a unique UUID. This group, known as the unlock request, is then signed using our private key from the secure enclave, and sent to the Sentry Interactive cloud.
The cloud will firstly authenticate the time, then it will check if it contains a unique UUID that hasn’t been seen before, and finally will check if the user has privilege, if this is all successful the request is forwarded on.
Cloud-to-cloud and on-premise integration
For a cloud-to-cloud integration, the unlock request is sent to the third-party cloud service to be processed and to be accepted or denied.
For an on-premise integration using the Sentry Interactive SDK or Doordeck Fusion the same details are sent from the cloud over a TLS connection, with added security, one of them being and TLS pinning to the server with fusion installed and the decision is made by fusion that is installed on the server.
If accepted the request will be sent from the cloud or the on-premise access control system that will make the final decision to establish the privilege of the user and then send a signal to unlock the door.
*When you integrate with Sentry Interactive’s software, Sentry Interactive does not make the access decision, the access controller continues to make that access decision and establishes the privilege of the user. We validate and authenticate a credential, but the decision to open isn’t ours. We simply send a request to the controller or on-prem host to open a specific door, by a specific user, at a specific time.
Mass enroll open standard credentials
Public Key Open Credentials (PKOC) are now able to be deployed at scale with new mass enrollment capabilities enabled via Sentry Interactive’s SDK. This new enrollment capability ensures that PKOC is not just interoperable, it is operationally scalable.
Sentry Interactive's SDK integration enables:
- Rapid mass enrollment of employees, contractors, and visitors.
- Secure provisioning of credentials to mobile devices.
- Automated credential lifecycle management.
- Seamless integration with enterprise identity systems.
- Simplified deployment across multi-site global organizations.
Sentry Interactive and Public Key Open Credential (PKOC)
Learn more in an article exploring how the Sentry Interactive SDK is enabling mass enrollment of PKOC credentials for enterprises.
Find out about the benefits of mass enrollment capabilities of Public Key Open Credentials (PKOC) for enterprises.
Find out what PKOC is and how it is shaping the future of open standard credentials that deliver the highest security levels.
Mass enroll users with PKOC credentials today
By integrating our SDK, you will have the ability to enroll users at scale with mobile credentials that follow PKOC specification. Embrace the future of open standard credentials today.
Connect with a member of our team within 24 hours.
Get a system audit for integration.
Deploy and activate mobile credentials within days.