STRONG IDENTITY & ATTESTATION

Turn strong identity into an enforceable trust decision.

SYNRION x.ID connects verified primary identities, controlled secondary identities, authentic hardware and independent policy. Trust is granted only when the required proofs succeed together.

CONTROLLED TARGET STATE TRUST GRANTED
01 · Problem

Identity, hardware and policy are checked in isolation.

A known person, an authentic device and a valid policy are different signals. When they are verified separately, the final trust decision remains difficult to enforce and explain.

02 · Control

The required proofs form one technical decision.

x.ID binds verified identity, authentic hardware and independent policy enforcement. Separation of duties and technical four-eyes control become part of the decision instead of a later manual check.

TECHNICAL CONTROL

Verify every required trust signal together.

x.ID is designed around a clear gate: trust is not assumed from a single attribute but granted when all required proofs are present.

01

Identity bound

Connect verified primary identity, controlled secondary identities and assigned roles.

02

Hardware attested

Include PIV and FIDO attestation, authentic hardware and the bound cryptographic key.

03

Policy enforced

Apply independent policies, separation of duties and technical four-eyes control to the decision.

FEATURES AT A GLANCE

Identity, hardware and policy become one defensible decision.

x.ID evaluates the required trust signals together. The checklist separates identity verification, hardware, platform access and integration into clear groups.

01

Identity & policy enforcement

Trust is granted only when identity, role and independent rules are satisfied together.

  • Available Verified primary identity

    Keep the accountable person as the starting point for every further identity and authorization decision.

  • Available Multiple secondary identities and roles

    Assign additional identities and roles without losing the connection to the primary identity.

  • Available Independent policy enforcement

    Enforce approval conditions technically instead of relying on the target system or a single signal.

  • Available Automated technical four-eyes principle

    Apply separation of duties and required independent verification as part of the trust decision.

02

Yubico YubiKey, hardware tokens and attestation

Authentic hardware and bound keys are evaluated together with identity.

  • Available Up to 23 secondary identities on one YubiKey

    Depending on cryptographic algorithms and hardware version, manage up to 23 secondary identities on one hardware security key. This reduces token demand and cost, especially in multi-tier and multi-domain environments.

  • Available PIV attestation

    Include hardware authenticity and the origin of the bound key as trust signals.

  • Available FIDO and passkeys

    Connect phishing-resistant FIDO and passkey use cases with strong device and identity assignment.

  • Available Pre-register FIDO2 keys in Microsoft Entra ID

    Use a portal to assign hardware keys unambiguously to a primary identity before issue and manage their lifecycle under control.

  • Available Thales SafeNet eToken and Nitrokey

    Connect the Thales SafeNet eToken Fusion Series, Nitrokey 3 and Nitrokey HSM 2 to the same identity, attestation and policy model.

  • Coming soon Swissbit iShield Key 2

    Integration of the Swissbit iShield Key 2 Series is planned as the next extension of the supported hardware-token portfolio.

  • Available YubiKey and PKI management for BSI-oriented controls

    Connect YubiKey, PIV and FIDO attestation, certificate lifecycle and policy evidence in the SYNRION control loop. This helps organizations implement their own cryptographic and identity requirements in line with BSI guidance; conformity assessment remains the organization’s responsibility.

03

Platforms & access

Strong identity remains consistent across operating systems and infrastructure tiers.

  • Available Windows certificate authentication

    Connect certificate-based Windows authentication with verified identity, hardware and policy assignment.

  • Available Linux certificate authentication

    Support certificate-based authentication for Linux use cases with the same trust decision.

  • Available Agent and agentless

    Work with a connected local client or without an additional agent according to the target system.

  • Available Multi-tier and multi-forest

    Relate identities and policies across separated tiers and multiple directory structures.

04

Directories & interfaces

Existing identity sources and external systems remain part of the operating model.

  • Available Multiple CAs

    Connect multiple certification authorities to one identity and approval model.

  • Available LDAP and Microsoft Entra ID

    Correlate users, computers and directory information from existing identity sources.

  • Available Control the LDAP certificate store and SKI store

    Discover and verify certificate and key assignments in connected directory stores and bring them into the same controlled lifecycle.

  • Available gMSA and mTLS-secured outposts

    Operate outposts with gMSA service accounts and protect their communication with mTLS. Hardware-protected keys are recommended for the gMSA service accounts.

  • Available OIDC-based authentication

    Use OIDC for secure authentication and the correlation of identities and assets.

  • Available API for external systems

    Connect external systems to SYNRION or integrate x.ID data and decisions into existing processes.

OPERATING CONTEXT

Where strong identity must be demonstrable.

Use x.ID when access or authorization depends on more than a user account and every trust signal must be technically connected.

01

Primary and secondary identities

Relate verified identities and roles without losing the accountable primary identity.

02

PIV and FIDO attestation

Bring authentic hardware and bound keys into the same decision as identity and policy.

03

Independent policy control

Make approval conditions and separation of duties enforceable rather than implicit.

COMPLEMENTARY TO x.ID

SYNRION x.CASEone DUO

A complementary x.ID offering for selected strong-identity use cases. x.CASEone DUO remains subordinate to x.ID and is considered only where the concrete identity workflow requires it.

Discuss the identity use case

THE NEXT CONTROLLED STEP

Define which proofs must be true before trust is granted.

We map the identity, hardware and policy signals that matter in your environment and turn them into a concrete x.ID use case.

Discuss an x.ID use case