You want to produce chip cards with certificates quickly, budget-friendly and without any problems? You don’t want to have to establish a complex PKI infrastructure? Are you looking for an effective solution to personalize chip cards that are not being activated before the users start using them? Are you currently paying a lot of money to have chip cards with individual certificates or identities produced by external partners? Do you need an out-of-the-box solution?
4smart SPACE is the perfect product for you!
Once configured by KOBIL, you will be provided with a solution for out-of-the-box card personalization that can keep it up with the big players. The functional principle is most simple and can be handled by just anyone in your team.
Blank chip cards are inserted to one side of the printer – and are turned into anonymous chip cards that contain anonymous digital certificates. As name section, the certificates merely contain the chip card’s unique serial number.
When it comes to 4smart SPACE, we rely on established and certified technologies that are also used by official certification bodies. We thus do not only provide you with a budget-friendly and efficient solution but also with a highly reliable one.
4smart SPACE perfectly replaces costly card personalization procedures. Apart from the uncomplicatedness we had on mind when we designed this solution, the two factors of reliability and mass production also played a significant role.
When you start with 4smart SPACE, your certification hierarchies can be retained. Alternatively, we will set up individual root- and subCAs for you.
You define the information you want to be part of the certificates produced.
You define the validity term for your certificates. If used for advanced signatures, this might be up to 15 years.
Produce anonymous identities the application allocates to users when they are used for the first time. This allows you to produce a stock of cards that you just have to use whenever a new card is being required. You thus won’t have to restart the card personalization line.
Frequently Asked Questions
What does it take to use 4smart SPACE?
Nothing! We will provide you with an independent and ready-to-use card personalization line comprising a card printer, chip card reader and desktop server system (tower). All you have to do is to switch it on!
Could I use 4smart SPACE to personalize just any chip card?
Theoretically you could. However, to keep the system as simple as possible and in a ready-to-use state, the standard version of 4smart SPACE only supports ATOS chip cards of version CardOS 4.4. KOBIL’s module PKCS#11 applies the file structure, which is not compatible with other file structures.
Could I connect a proprietary root-CA?
Theoretically you could. Within the scope of a project, we will gladly provide you with a respective proposal. We recommend, putting on the root-CA and subCA management executed in the set-up and thus using the roots and subs thereby generated.
Could I also equip personalized chip cards with more than one certificate?
Since the concept of 4smart SPACE is to generate anonymous certificates, it is not advisable to equip one card with two certificates. This would mean that two certificates of the chip card’s same serial number are being personalized.
Could the chip cards be equipped with a PUK?
Yes, they could. For this purpose, the individualization guide explains how to set up various PIN and PUK configurations. The most popular approach is the variant without PUK but with transport PIN that is initialized when it is first used by the user. Thereafter, the user will have to define a new, individual PIN.
The card personalization software
Ready-to-use software (no extra set-up, no configuration required)
Based on EAL3+ certified CA-components
PIN modus settings (e.g. transport PIN)
Audit-proof logging and approved security concepts
Based on international standards (e.g. RSA 2048 bit certificates)
Adjustable root- and subCA. Extendable subCAs.
Dual-control principle at implementation (2 PIN-protected chip cards to release the root-CA card for card production)
Anonymous digital user certificates
Anonymous certificates related to the chip card’s (unique) serial number
Adjustable user certificates (e.g. validity term)
Memory space for up to 4 certificates (production describes only one)