SecureID: The evolution of mobile identity for security-critical infrastructures

In the modern working world, not only the armed forces, but also public authorities and organizations with security tasks (BOS) as well as regulated industries are facing the central challenge of increasingly mapping identities and access authorizations on the move. While traditional smartcards have formed the reliable backbone of secure digital identities for many years, they are increasingly reaching their limits and availability in everyday operations – especially in mobile use and when using modern end devices. The need to carry physical readers limits flexibility and makes the seamless digitalization of processes more difficult.

This is where SecureID comes in. As a highly secure mobile PKI (Public Key Infrastructure) wallet, the solution addresses this specific need in regulated industries such as the public sector, defense and KRITIS companies. SecureID transfers the proven security model of the physical smartcard to the smartphone in a controlled manner and combines ID, certificates and individual authorizations in a single, tamper-proof application. This transforms the mobile device into the central personal identity and access medium for both digital and physical processes.

The technological basis of the solution is strong PKI-based authentication. This enables secure access to critical IT systems, including hard disk encryption, virtual desktop infrastructures (VDI) and VPN connections. In addition to pure login, SecureID allows legally compliant digital signing of documents as well as encryption and decryption of sensitive communication(S/MIME) and files directly on the device. A key advantage is its multifunctionality: physical access and authorization scenarios can also be easily implemented using NFC (Near Field Communication). The architecture ensures strict separation of identity, device and application, which means that established security and compliance requirements are consistently maintained.

Special attention is paid to future viability and integrability. SecureID has been designed to fit seamlessly into existing PKI, IAM (Identity and Access Management) and security solutions such as SecurePIM, LANCrypt or specific specialist applications. Instead of replacing existing infrastructures at great expense, the PKI Wallet acts as a complementary extension. This approach enables authorities and companies to migrate to modern mobile identities without jeopardizing the security standards that have evolved over the years.

SecureID is backed by an alliance of market leaders and experts: SaltRock, Materna Virtual Solution and Nexus (IN Groupe) are pooling their expertise in the areas of mobile security, identity management and strategic consulting for the security-critical sector. Together, they show how practical scenarios – from public administration and state authorities to emergency organizations and critical infrastructures – can be designed securely and efficiently today.

In order to meet the highest requirements for secret protection, the entire solution is designed for use up to protection class VS-NfD (classified information – for official use only). We are actively striving to obtain a corresponding authorization for use in accordance with the strict requirements of the German Federal Office for Information Security (BSI) in order to establish SecureID as the standard for trustworthy mobile communication and identification in Germany. SecureID is therefore the answer to the question of how sovereignty and mobility – coupled with user-friendliness – can be successfully combined in a digitized security architecture.