Ceedo Enterprise for SafeNet

Ceedo Enterprise running on SafeNet’s eToken NG-FLASH enables driverless smart card-based PKI operations for applications running from the Ceedo workspace on any host PC.
With Ceedo Enterprise, users can take their applications on the eToken NG-FLASH token, and run them on any host PC, enabling plug-'n'-play secure access to banking transactions, strong certificate-based authentication to Outlook Web Access (OWA), and email signing using S/MIME.
A user simply plugs the Ceedo-enabled eToken NG-FLASH USB token into any host PC. User applications installed on the token execute from the device memory. Smart card-based PKI operations are accessible through the portable eToken PKI Client also running from the eToken NG-FLASH. When the device is disconnected from the host PC, all user data is removed from memory and no trace is left behind.
Ceedo’s Workspace utilizes the host PC’s operating system and hardware resources (e.g. Internet connection, printer) without altering the host PC itself. It is robust, non-intrusive, requires no special expertise from users, and runs on any Windows PC alongside existing applications.
SafeNet's eToken NG-FLASH is an enterprise solution with full central management capabilities. All provisioning/de-provisioning of user credentials is performed through eToken Token Management System (TMS). On the Workspace and application front, Ceedo’s Workbench allows administrators to change use policies, to update, remove or install new software applications, apply patches and perform other operations on workspaces in the field, securely and over the web.
Solution Features:
- Smart card-based PKI operations with no need for host installation
- User applications running directly from the token in a sandboxed environment
- Strong hardware-based encryption of the flash memory
- Highly secure smart card chip
- On-board RSA 1024-bit and 2048-bit key generation and authentication
- Support for standard cryptographic APIs including PKCS#11 and CAPI
- Certifications: FIPS 140-2 Level 2 (full device); Common Criteria EAL4/EAL5 (smart card chip and OS)
- Fully portable, self-contained solution: PKI and virtual workspace
- Sandboxed environment ensures that temporary files and cookies are not left behind on the PC when the eToken device is unplugged
- Secure storage of user credentials, keys and sensitive information inside the eToken smart card chip, away from the hostile PC environment
- High security – Private keys are never exposed outside the eToken device
- Two-factor authentication – requires both the eToken itself and the eToken password
- No special reader needed for the smart card chip

