The Unifyia Platform
The Unifyia Platform is a next-generation identity and credential management solution that serves as a comprehensive and centralized hub. It is designed to streamline identity management tasks for administrators, operators, and end users, all governed by role-based access privileges.
Unifyia Platform Features
| FEATURES | DESCRIPTION AND BENEFITS |
|---|---|
| CLOUD-NATIVE MICROSERVICES-BASED, MULTI-TENANT ARCHITECTURE | ·The Unifyia platform is cloud-native and employs a microservices architecture, providing a comprehensive and modern solution for identity and authentication services. |
| ·It features a multi-tenant architecture, allowing for the easy addition of new tenants, reducing deployment and maintenance costs, and enhancing security. | |
| API-BASED ARCHITECTURE | ·Delivers a consistent integration experience across existing applications and services. Secure, tokenized APIs offer backend functionality, allowing developers to create modular and reusable application ecosystems. |
| API GATEWAY | ·JWT/API Token Validation: Verifies security tokens with the authentication and authorization service using the tenant identifier. |
| ·Authentication Analytics: Logs user authentication outcomes for analytical purposes. | |
| ·Service Routing: Utilizes a routing service to direct or connect to internal services based on the resource path following successful authentication and authorization. | |
| ·Credential Management: Provides dedicated endpoints for the issuance and management of credentials. |
| PASSWORDLESS MULTI-FACTOR AUTHENTICATION | Password Elimination: Replace traditional passwords with unphishable, frictionless verified credential authentication across the enterprise. | | Unified Credential Experience: Utilize a single credential for a seamless authentication experience, with support for multi-factor authentication (MFA) using various identity types. | | Certificate-based Authentication (CBA) | | Personal Identity Verification (PIV) | | Passkeys (FIDO2) | | Push Verify PKI with Unifyia ID Wallet | | OTP with Unifyia ID Wallet | | Derived Credentials | | | | SINGLE SIGN-ON (SSO), IDENTITY FEDERATION, & IDENTITY BROKERING | Zero Trust and Passwordless Compatibility: Seamlessly integrate zero trust and passwordless authentication using industry standards, complemented by pre-built adapters and connectors. | | Federated Identities for SSO: Centralize login to multiple applications with a unified interface and credential using OpenID Connect or SAML protocols, enhancing compliance, operational efficiency, and credential management. | | Identity Brokering: Authenticate across multiple external identity providers and applications with a unified authentication layer using OpenID Connect or SAML protocols. | | User Attribute Management: Aggregate and map user attributes, roles, and groups from various sources, including external identity repositories and attribute services. | | Directory Integration and Access Control: Manage identities from any directory and enforce attribute-based access policies. | | Elastic Scalability: Achieve high-performance, cost-effective identity infrastructure with elastic scaling capabilities. | LEGACY DIRECTORY INTEGRATIONS | Seamlessly integrate with various directories to synchronize and centrally manage users and groups, including: | | | ·Microsoft Active Directory(AD) | | | ·LDAPv3 | | SUPPORTED PROTOCOLS FOR IDENTITY, USER FEDERATION, AND USER PROVISIONING | Integrate and manage user and identity data from multiple external sources, such as databases or directory services, within a single identity management system using the below protocols: | | | ·OpenID Connect | | | ·OAuth 2.0 | | | ·SAML 2.0 | | | ·SCIM 2.0 | | ADMINISTRATION | Role-based Access Control (RBAC): To define and enforce access policies based on users' roles and responsibilities. | | Comprehensive Administration: Administer organizations, Passkey(FIDO) policies, groups, device profiles, identity visual designs, workflows, notification providers, notifications, users, identities, and credentials from a single portal. | | Customizable Branding: Personalize branding and notifications. | | Flexible Identity Configuration: Easily set up and manage multiple identity types for diverse user groups. | | Authenticator Enrollment and Management: Enroll and manage a variety of authenticators to ensure seamless access to applications. |
| | Workflows: Customizable workflows for user onboarding, offboarding, enrollment, issuance, lifecycle, and other identity-related processes to ensure that organizations can adapt the platform to their specific use cases. | | Sponsorship: Manage user onboarding for enrollment and identity issuance. | | ID Proofing: Configure in-person, supervised identity proofing with the approved I9 documents in compliance with NIST SP 800-63A. | | Data and Biometric Enrollment: Facilitate the enrollment of data and biometric information, including face, fingerprint, and iris recognition with NIST SP 800-63A and FIPS 201-3. | | Certificate Policies: Configure and integrate certificate authorities (CAs) to manage the issuance of certificates from multiple CAs in compliance with FIPS 201-3. | | Configure Identity Activation Policies: Configure the PIV identity activation policies. | | Adjudication: Configure adjudication policies before the issuance of PIV identities in compliance with FIPS 201-3. | | Configure Policies for DPIV/DFIDO: Configure policies to issue DPIV/DFIDO leveraging existing PIV ID of trusted partners in compliance with FIPS 201-3. | | Mobile Identities: Configure the issuance of mobile digital identities in compliance with the FIPS 201-3. | | Authentication: Configure authentication policies in compliance with NIST SP 800-638 standard. | | Notifications: Configure email and SMS notification services and manage the predefined notification templates.
| Data Integrity and Authenticity: Sign the data written to the smart cards/security keys/mobile device containers using a content signing certificate. | |
|---|---|
| SPONSORSHIP & ENROLLMENT | A flexible user data and biometric enrollment process for enterprises and PIV issuance, compliant with NIST SP 800-63-4 guidelines, ensuring secure and reliable identity verification. |
| IDENTITY CREDENTIAL ISSUANCE AND LIFECYCLE MANAGEMENT | Identity Issuance: Simplify the issuance of identities through streamlined group and device workflows. |
| Supported Authenticators: Includes PIV, FIDO2.1 smart cards/security keys, and mobile app-based authenticators using the Unifyia ID Wallet. | |
| Supported Identity Credentials: Features Visual ID, PIV, Passkeys (FIDO2.1), Passkeys (FIDO2) on Behalf of Identity Providers (Entra / Okta), Derived PIV, Derived FIDO, push with PKI (X509 certificate) via Unifyia ID Wallet, push verify with Unifyia ID Wallet, OTP with Unifyia ID Wallet, FIDO2.1 with Unifyia ID Wallet, and verifiable credentials (QR Code). | |
| PIV Derived Credentials: Utilize existing PIV credentials to issue DPIV/DFIDO credentials for trusted partners. | |
| Lifecycle Actions: Manage various actions including certificate renewal, suspension, activation, reactivation, revocation, PIN reset, PIN reset with PUK, PUK display, incident reporting, PIN change, and removal. | |
| MONITORING | Reports and Analytics: Customers can effortlessly generate detailed reports to monitor user activities and events, aiding in the detection of security threats and ensuring policy compliance. |
| INTEGRATIONS | Unifyia is fully vendor-agnostic. Below is a list of third-party application integrations and supported technologies. |
Server OS Support
• AWS Linux 2.0
• Red Hat Enterprise Linux 8, 9.3, and 9.4 versions
• Rocky Linux 8.9 version
• Ubuntu 22.04
• General support for current and previous versions of the above OS.
Client OS Support
• Windows
• macOS
Biometrics Verification and Duplication
• Amazon Rekognition
• Neurotechnology MegaMatcher ABIS
Smart Cards and Security Keys
• ID-One PIV 2.4 + FIDO2.1 on Cosmo V8.2
• IDEMIA:
• ID-One PIV 2.4 on Cosmo V8.2
• OpenJDK 17
• No Java is required on client workstations.
Server Java Version
• ID-One PIV 2.4 on Cosmo V8.1
• Entrust CA Gateway
• PrimeKey
• Signature
• Signotec Sigma
• PrimeKey
• Thales: Gemalto SafeNet IDPrime PIV v3.0
• EJBCA
• Unifyia ID Wallet - iOS and Android
• WidePoint-ORC PIV SSP
• Bitbucket
• Microsoft CA
Supported Browsers
• Microsoft Edge Chromium
• Google Chrome
• Docker
• DevOps Tools
Certificate Authorities
• Signotec Sigma
• Zabbix
Monitoring & Metrics
• HID FARGO® HDP6600
Card Printer & Encoder:
• Prometheus
• Google Chrome
• Matica XID8600
• Magicard Rio Pro 360
• Grafana
Application/Web Servers
• NGINX 1.20.0
• Node.js: 16.16.0 and higher
• Wildfly: Version 11 and higher
Identity Brokering and User Federation
• AWS v2 CloudHSM
• Thales Luna Network HSM 7
• Microsoft Azure AD, Okta, Ping
• Identity, Jump Cloud
Supported HSMs
• Amazon RDS for PostgreSQL 15.1
• Utimaco CryptoServer Gen 2
• Thales Luna Network HSM 7
Databases
• Oracle 19c
• ZTPass PIV 2.0 on NXP P71D600
• ZTPASS:
• Yubico: Yubikey 5, 5.7, YubiKey FIPS, YubiKey Bio
• Giesecke & Devrient (G&D): Sm@rtCafé Expert StarSign® FIPS 2017.0, 8.0
• ZTPass - ZTPass PIV 2.0 + FIDO2.1 on NXP P71D600
Fingerprint
• Integrated Biometrics - FIVE-O, Watson Mini, Columbo
• SecuGen Hamster Pro 20
• HID Guardian 100
Iris
• CMITech BMT-20
• EF-45
Photo
• Webcam/Camera with live streaming option (e.g., Sony ZV-1F)
Document Scanners
• Webcam
• EPSON V600 Photo Scanner
Card Readers
• PCSC Card Readers - Contact and Contactless
• ACS ACR122U NFC Contactless Smart Card Reader
• ACS ACR39U-U1 Smart Card Reader
• SecuGen Hamster Pro Duo SC/PIV