ActivID Batch Management System
High volume PIV issuance
For organizations deploying large quantities of Personal Identity Verification (PIV) smart cards in centralized high-volume card production facilities, ActivID™ Batch Management System (BMS) extends ActivID™ Card Management System (CMS) by enabling communication with a card production facility for personalization and encoding of PIV smart cards.
Key Features
Batch Management
- Retrieve PIV card production requests from ActivID CMS.
- Select requests based on configurable search criteria to create batch orders.
- Exchange information with the card production facility that produces the cards.
- Update ActivID CMS to enable lifecycle management of the smart cards.
- Communicate with multiple card production facilities and multiple delivery sites.
- Complete tracking of batch orders throughout their lifecycle via unique identifiers.
Configurable issuance process
- Activation mode: cards are produced in blocked state by the card production facility for later activation with ActivID CMS.
- Non-Activation mode: cards are produced by the card production facility ready to be used by the end-user.
Administration and configuration
- Configurable GUI displays all selected PIV data
- Configurable search criteria for creation of batch orders
Security
- Ability to encrypt and sign batch order files
- Secure communications with remote systems via SSL.
- Administrator authentication with smart card based PKI.
- Full tamper-evident audit logs all activities for reporting.
API
- Full set of Application Programming Interfaces (APIs) for system integrators to develop their own application or user interface.
Benefits
Reduced Issuance Time
Separating card production from card issuance reduces the issuance time to a verification of the user identity and activation of the card (optional). No need for time-consuming personalization and encoding of the card while the end-user is waiting.
Lower Production Costs
Production of smart cards in a high volume personalization and encoding facility reduces the cost through usage of specialized equipment and optimized processes.
Standards Compliance
ActivID BMS and ActivID CMS enable issuance of PIV cards in compliance with the FIPS 201 Standards. The data format used by ActivID BMS for information exchange with Card Production Facilities is compliant with the U.S. Department of Defense (DoD)Pre-Issuance Requirements (PIR).
Security
ActivID BMS protects data confidentiality and integrity through signature and encryption of PIV data exchanged with the Card Production Facility. ActivID BMS and ActivID CMS use ActivIdentity technology adopted by U.S. DoD to issue over 10 million Common Access Cards to military personnel.
Technical Specifications
Server operating systems
- Microsoft® Windows® 2003 Server
Client Operating System
Web Server
- Microsoft Internet Information Services
Database
Directory
- Critical Path Directory Server
- CA eTrust™ Directory
- IBM® Tivoli® Directory Server
- Microsoft Windows Server 2003 Active Directory
- Novell® eDirectory™
- Siemens HiPath Slcurity DirX
- Sun Java System Directory Server
Certificate authorities (PKI)
- Cybertrust UniCERT™
- Entrust® Authority™
- Microsoft Windows Server 2003 Certificate Services
- VeriSign® Managed PKI
Identity Management and User Provisioning
- CA eTrust Admin
- DaonEngine™
- IBM Tivoli Identity Manager
- Intellisoft FIPSICE™
- IWS™ PIV Management Application
- Lenel IdentityDefender®
- Novell Identity Manager
- Sun Java System Identity Manager
- Viisage PROOF™
Card Production Facilities
- Oberthur Card Systems
- Any Card Production Facility supporting the U.S. DoD Pre-Issuance Requirements v4.2.1.
Smart Cards
- Oberthur Card Systems PIV EP
- Oberthur Card Systems ID-One Cosmo
Contact ActivIdentity for latest smart card support list.
Hardware security modules
- AEP™ Keyper
- nCipher™ nShield
- nCipher™ netHSM
- SafeNet Luna® PCM
- SafeNet Luna RA
Smart card readers
- ActivIdentity Readers
- Dell® Readers
- Gemalto® (Gemplus®) GemPC™
- HP® Readers
- OmniKey® CardMan™
- SCM Microsystems® SCR
Compliance with standards
- ActivID BMS and ActivID CMS can be used to issue smart cards in compliance with FIPS 201 / PIV.
- LDAP 3.0
- Secure Socket Layer (SSL)
- GlobalPlatform/OpenPlatform
- Java Card™ 2.1 and 2.2
- FIPS 140-2 certified cards and
- applications support
- FIPS 201/PIV certified cards and
- applications support
- FIPS 140-2 certified HSM support
Please check with ActivIdentity for latest supported versions or devices and any known restrictions.