PIV Gateway™ CA|Cloud-based private certificate authority

Private CA for X.509 certificates / platform certificates

What is PIV Gateway™ CA?

PIV Gateway™ CA is a cloud-based private certificate authority solution that supports X.509 certificate issuance as well as platform certificate issuance.
PIV Gateway™ CA enables the construction of an authentication infrastructure equivalent to AAL3 (Authenticator Assurance Level 3), making it possible to secure an organization's network and systems while reducing operating costs.

PIV Gateway™ CA also supports the issuance of platform certificates. Platform certificates can be used to verify the authenticity and traceability of devices and improve supply chain reliability. This is the world's first commercial certification authority to support platform certificates. (According to our own research as of February 29, 2024)

Features

Platform certificate support

PIV Gateway™ CA supports the issuance of platform certificates.

Platform certificates are certificates that vouch for a computer's configuration as standardized by the Trusted Computing Group and include information such as model name, serial number, and hardware bill of materials for the device. Platform certificates can be used to detect counterfeit or altered devices and components, as well as unexpected changes.

FIPS 140-2 certified HSM (Hardware Security Module)

PIV Gateway™ CA uses a FIPS 140-2 Level 3 certified, tamper-resistant HSM to securely generate and manage the keys needed to create certificates.

FedRAMP / ISMAP registered infrastructure

PIV Gateway™ CA operates on trusted cloud services registered with FedRAMP and ISMAP.

High cost performance and scalability

PIV Gateway™ CA is a private certification authority using a cloud environment. It does not require expensive HSM server costs or personnel resources to build and operate and offers better cost performance and scalability due to being a cloud service.

An on-premises version with the same functionality as the cloud environment is also available.

Use Cases

Establishment of a secure authentication infrastructure that does not use IDs and passwords

Many cyber attackers exploit system and operational flaws related to authentication and authorization, exemplified by ID/password grabbing and spoofing to accomplish their objectives.

Creating a secure authentication infrastructure using certificates not only greatly reduces the risk of cyber attacks, but also reduces the cost of managing account IDs and passwords and improves user convenience.

Verification of device authenticity and configuration status

The platform certificate issued by the PIV Gateway™ CA contains information such as model name, serial number, and hardware bill of materials (H-BOM) for the device.

The H-BOM contains information on various components such as CPU, memory, SSD, hard disks, NICs, firmware and OS, etc., allowing for verification of device authenticity and the ability to detect counterfeit devices, counterfeit internal components, replacement of components or unauthorized configuration changes.

Responding to the U.S. government's push to strengthen supply chain security

In recent years, the U.S. government has been promoting enhanced supply chain security through TPMs and platform certificates, with an emphasis on ensuring device authenticity, integrity, and traceability.*1

Platform certificates issued by PIV Gateway™ CAs enable the traceability and verification of authenticity, and integrity of computers and their various modifications since leaving the factory, meeting U.S. government requirements. *1 Promotion of the US Government

Pricing

Certificate Authority

1 CA 450 USD / Monthly

Certificate Issuance(X.509)

Number of certificates issued RSA ECC
1 - 1,000 1 USD / 1 credential 1 USD / 1 credential
1,001 - 10,000 0.75 USD / 1 credential 0.75 USD / 1 credential
10,001 - 50,000 0.35 USD / 1 credential 0.35 USD / 1 credential
50,001 - 100,000 0.05 USD / 1 credential 0.05 USD / 1 credential
100,001 - 200,000 0.025 USD / 1 credential 0.025 USD / 1 credential
200,001 - 0.0125 USD / 1 credential 0.0125 USD / 1 credential
Key management system HSM FIPS 140-2 Level3 HSM FIPS 140-2 Level3
RSA
ECC
Number of certificates issued Price
1 - 1,000 1 USD / 1 credential
1,001 - 10,000 0.75 USD / 1 credential
10,001 - 50,000 0.35 USD / 1 credential
50,001 - 100,000 0.05 USD / 1 credential
100,001 - 200,000 0.025 USD / 1 credential
200,001 - 0.0125 USD / 1 credential
Key management system HSM FIPS 140-2 Level3
Number of certificates issued Price
1 - 1,000 1 USD / 1
1,001 - 10,000 0.75 USD / 1 credential
10,001 - 50,000 0.35 USD / 1 credential
50,001 - 100,000 0.05 USD / 1 credential
100,001 - 200,000 0.025 USD / 1 credential
200,001 - 0.0125 USD / 1 credential
Key management system HSM FIPS 140-2 Level3

Option:OCSP

Per Certificate Authority 0.06 USD / 月
10,000 OCSP requests RSA 2048 type 1 USD
10,000 OCSP requests RSA 3072, 4096, ECC P256 P384 type 2 USD

Line up

PIV Gateway™ CA is the world's first cloud-based private CA solution that supports issuance of platform certificates in addition to X.509 certificates.
An authentication infrastructure equivalent to AAL3 can be built, and verification of the authenticity and traceability of devices using platform certificates is possible.

A password-less multi-factor authentication infrastructure equivalent to AAL3 that uses hardware tokens and digital certificates.
Compatible with RFC9334, OpenID Connect, etc., and works with PIV Gateway™ CA to realize integrated management of authentication and authorization for users and devices easily and inexpensively.

PIV Gateway™ Chronos is a highly available and accurate NTP time server that provides highly accurate time synchronisation even under GNSS spoofing and jamming attacks.

PIV Gateway™ CA is the world's first cloud-based private CA solution that supports issuance of platform certificates in addition to X.509 certificates.
An authentication infrastructure equivalent to AAL3 can be built, and verification of the authenticity and traceability of devices using platform certificates is possible.

Consult with our specialists for your security needs.

Cyber Defense Institute's core value drive us to provide top-notch cyber security services and ensuring a secure digital environment for our clients.
Trust us with every aspect of your security strategy, from inception to execution.
For confidential inquiries, we also accept requests via email at cdiprivacy(at)protonmail.com.
Please consider using this option if necessary. ※ (at)should be replaced with @.