Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Securing Access Through a Multi-Purpose Credential and Digital ID
1. Securing Access through a Multi-Purpose
Credential and Digital ID
ForgeRock Identity Relationship
Management Summit
June 4, 2014
2. • Stephan Papadopulos, Managing
Director, The Triage Group
• Washington, DC-based Woman-
Owned Business
• Healthcare and Emergency
Response IT and Business
Consulting Firm
• ForgeRock Systems Integration
Partner with deep Identity and
Access Management experience
Introduction
2
PAPADOPULOS,
STEPHAN
4. • The DC One Card is designed to
give cardholders convenient access
to DC government facilities,
resources and programs
• Provides immediate benefits by
incorporating WMATA SmarTrip®
capabilities
• Reduces citywide credentialing
inefficiencies and reduces costs
• Establishes single trusted identity for
DC stakeholders
• Consolidates Constituent Touch
Points
DC One Card Overview
4
5. DC One Card Program
Physical and Digital Credentials
5
Citizens have multiple
ID Cards
Citizens have multiple
online identities Objectives
• Convenience
• Physical and Digital
ID Consolidation
• Improved
Constituent
Relationships
• Security
• Cost Savings
• Fraud Reduction
• Improved Access
DC One ID
Username:
Password:
DCPS Google Apps Login
@dcpsk12.edu
Connect using your DC One ID
or
6. How it Works
6
Physical Credential Features Online Digital Identity Features
Single digital identity can be used to
access multiple online systems –
eliminating users to remember numerous
passwords
12-digit barcode
number ties to
individual and
can be easily
read with a
basic scanner
Embedded
chips can be
used to control
physical access
to facilities and
transit
The PIV-I with
Smart Chip
secures access
to high risk
systems and
facilities
Mag Stripe for future
banking use DC One ID
Username:
Password:
Connect using your DC One ID
or
8. 8
somagee8456@student.k12.dc.us
DCPS Google Apps Login
@student.k12.dc.us
Connect using your DC One ID
or
forgot username?
DCPS Google Apps Login
@dcpsk12.edu
Connect using your DC One ID
or
How it Works
Federated Identity for SSO
13. Case Study: Entitlements
• Access
Policies
Set in
OpenAM
• IdM
Manages
PIV-I
Issuance
• PIV
Registered
After
Issuance
14. Case Study: Enrollment Kiosk
• Authenticates
and Validates
Visitor Credential
• Matches Card
Data to
Entitlement
Policy
15. Case Study: Lobby Entry
• Reads,
Authenticates
and Validates PIV
Credential
• Sends XACML
Access and
Attribute Request
to OpenAM
• Opens Turnstile
on Permit
Decision
16. 16
Deanwood
Customer Service Center
One Judiciary Square
Customer Service Center
Wilson
Customer Service Center
DCPS Secondary Schools
(DCPS Student and Staff DC One
Cards Only)
Ever in Washington, DC
Get a DC One Card, they’re Free!