{"id":30719,"date":"2020-07-30T14:25:18","date_gmt":"2020-07-30T12:25:18","guid":{"rendered":"https:\/\/2023.oneclick-cloud.com\/blog\/uncategorized\/the-oneclick-platform-integrates-bundesdruckereis-identity-and-rights-management-fides-for-the-provision-of-digital-workspaces\/"},"modified":"2023-08-04T11:36:47","modified_gmt":"2023-08-04T09:36:47","slug":"oneclick-integrates-fides","status":"publish","type":"post","link":"https:\/\/one2.sem-webagentur.de\/en\/blog\/products\/oneclick-integrates-fides\/","title":{"rendered":"The oneclick\u2122 platform integrates Bundesdruckerei&#8217;s identity and rights management FIDES for the provision of digital workspaces"},"content":{"rendered":"<p><strong>Users of oneclick\u2122 and FIDES gain self-determination over their data by means of digital authorization chains.<\/strong><\/p>\n<p>Classical identity and rights management systems do not sufficiently meet the users&#8217; need for data sovereignty and security. This is why Bundesdruckerei&#8217;s innovation laboratory has developed a revolutionary approach with FIDES which anchors individual data sovereignty in the basic technology. At the core of FIDES identity and rights management are linked authorizations, so-called ID chains, which are based on block chain technology. The idea behind it: With FIDES, the user alone has control over his digital authorizations, such as access to his personal data. Authorizations can be passed on to others or withdrawn again. The central point is the right of self-determination of the individual user to decide at any time and with sovereignty about his data and its transfer.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20867 size-large\" title=\"Permissions in FIDES\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/berechtigung-1.png\" alt=\"Permissions in FIDES\" width=\"1024\" height=\"389\" \/><\/p>\n<h2>Meeting high requirements of data protection<\/h2>\n<p>With the concept of ID-Chains, FIDES provides a consistently user-friendly answer to increased expectations of data protection and security, which meets the high requirements of the general data protection regulation of the European Union. This stipulates, among other things, the right to be forgotten and the privacy-by-design approach to the processing of personal data. With these demands, a public block chain, for example, encounters problems. Information stored in the chain cannot be deleted there and can be viewed by the participants in the block chain.<\/p>\n<p><img decoding=\"async\" class=\"img-blog aligncenter wp-image-20893 size-large\" title=\"FIDES: ID chain\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/id_chain_EN-1.png\" alt=\"FIDES: ID chain\" width=\"1024\" height=\"334\" \/><\/p>\n<h2>Compliance conform and traceable<\/h2>\n<p>With FIDES, every user can only see what he or she has permissions for. Within the system he has no way of finding out what other identities and authorisations are available. The consequence: Everyone sees only what he is allowed to see. Data sovereignty is solely held by those to whom the data belongs in a professional or personal sense. Due to the clear assignment of rights, there is a clear responsibility for each right. The system logs all rights and identities. It also documents every delegation of authorizations and all accesses. This guarantees the integrity of the user data, transparency and security against manipulation. A user can track what happens to his rights at any time. Particularly during audits, controllers can always trace who has accessed which data or systems when and with which authorizations and where these authorizations originate. A transaction history in the form of a timeline is regularly saved by the system.<\/p>\n<p><img decoding=\"async\" class=\"img-blog aligncenter wp-image-20897 size-large\" title=\"Block chain of FIDES\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/blockchain_EN-1.png\" alt=\"Block chain of FIDES\" width=\"1024\" height=\"662\" \/><\/p>\n<h2>The &#8220;Business Chain&#8221; for enterprise customers and other organizations<\/h2>\n<p>&#8220;With oneclick\u2122 we have found a partner to apply FIDES as a business chain in the corporate environment,&#8221; says Dr. Manfred Paeschke, Chief Visionary Officer of Bundesdruckerei.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20881\" title=\"Dr. Manfred Paeschke\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/Manfred-Paeschke-1.png\" alt=\"Dr. Manfred Paeschke\" width=\"180\" height=\"180\" \/><\/p>\n<p>&#8220;In conjunction with the oneclick\u2122 platform, our FIDES concept enables efficient and secure allocation and maintenance of rights for access to all applications, data and other company resources. Thanks to FIDES, a new employee can obtain all important authorizations directly from the team leader or a responsible colleague. FIDES gives those responsible in the organization the design authority and the technical tools to distribute and maintain their respective rights. Each owner of rights as well as each delegating instance in the chain takes responsibility for ensuring that only those identities that actually need authorization are given it. If, for example, a person&#8217;s area of responsibility changes, the rights that are no longer needed are immediately withdrawn.<\/p>\n<h2>Security is the top priority at oneclick\u2122<\/h2>\n<p>The oneclick\u2122 platform, winner of the renowned eco and Enterprise Workspace Awards, among others, is based on IT security best practices for application provisioning, namely the principles of a <a href=\"https:\/\/one2.sem-webagentur.de\/en\/cloud-dmz-zero-trust-security\/\" target=\"_blank\" rel=\"noopener noreferrer\">Zero Trust Architecture<\/a> (ZTA).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-18671\" title=\"Zero Trust Network\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/zero_trust_network-1.png\" alt=\"Zero Trust Network\" width=\"751\" height=\"502\" \/><\/p>\n<p>Each access to dedicated company resources is individually authenticated and the trust status is continuously checked. Unauthorized sideways movements in a company network or within larger and distributed hybrid structures are reliably prevented. oneclick\u2122 bears the Trusted Cloud Label as a trustworthy cloud service. A review conducted by Capgemini on behalf of the Federal Ministry of Economics and Energy confirms that oneclick\u2122 meets all requirements in terms of transparency, security, quality and legal conformity. In addition, oneclick is an active member of TeleTrust, the largest competence association for IT security in Germany and Europe.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20873 size-full\" title=\"eco award, Enterprise Workspace Award, Trusted Cloud, Teletrust\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/logos-1.jpg\" alt=\"eco award, Enterprise Workspace Award, Trusted Cloud, Teletrust\" width=\"650\" height=\"150\" \/><\/p>\n<h2>From &#8220;Zero Trust&#8221; to &#8220;Zero Knowledge&#8221;<\/h2>\n<p>&#8220;With our digital workspaces in the browser, we connect users in a secure way with all company applications and data&#8221;, says Dominik Birgelen, CEO of oneclick AG.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-15313\" title=\"Dominik Birgelen\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/DominikBirgelen@2x-1.png\" alt=\"Dominik Birgelen\" width=\"180\" height=\"180\" \/><\/p>\n<p>&#8220;As a central orchestration platform, oneclick\u2122, for example, enables remote access to on-premises environments, automates the provision of cloud infrastructure via interfaces, and authenticates users to assigned SaaS applications. We at oneclick pursue two paradigms: Consumerization of IT and Democratization of Innovation. FIDES supports us in both goals by focusing on the individual user. But we go one step further: through the use of the FIDES pseudonymization service, no personal data is stored recognizably in oneclick\u2122 and our Zero Trust architecture is supplemented by a Zero Knowledge approach. From a visionary point of view, thanks to the integration of FIDES, we are moving beyond the already supported Bring-your-own-Device (BYOD) towards Bring-your-own-Application and even one step further thought towards Bring-your-own-Data. With oneclick\u2122 and FIDES, companies and administrators now have the opportunity to position themselves as absolute leaders in the field of data protection and thus achieve competitive advantages&#8221;.<\/p>\n<h2>Control over the system but not over user-related data<\/h2>\n<p>A company is free to decide where the identity management system of FIDES is operated. It can be operated in Bundesdruckerei&#8217;s data center, at oneclick\u2122 or in the company&#8217;s own data center. In each scenario, the data is encrypted using Bundesdruckerei&#8217;s highly secure algorithms. The solution differs fundamentally from classic identity management systems in which the administrator assigns specific roles and rights to each identity. Particularly in larger organizations, it is often no longer possible to trace which rights a selected person had or has at a certain point in time.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20895 size-large\" title=\"Assignement of rights in FIDES\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/rights-1.png\" alt=\"Assignement of rights in FIDES\" width=\"1024\" height=\"152\" \/><\/p>\n<p>In addition, the administrator often does not learn about changes in personnel or responsibilities in time. In the worst case, employees can access the data of a department even though they left it months ago. While in most existing systems an administrator has all file permissions, with FIDES the rights are assigned to the respective responsibilities. This means that the administrator still has control over the system but no longer over the user-related data.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20903 size-large\" title=\"oneclick\u2122 + FIDES\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/Fides_flowcart_veticalEN-1.png\" alt=\"oneclick\u2122 + FIDES\" width=\"1024\" height=\"930\" \/><\/p>\n<h2>Simplified operation and simultaneous cleanup of the Active Directory<\/h2>\n<p>Managing an enterprise Active Directory can quickly become a complex task for larger and distributed enterprise structures. Now, users are created clearly and easily in FIDES and the Active Directory is operated via a connector. At the same time, the customer&#8217;s Active Directory is tidied up, because FIDES immediately recognizes all redundancies and conflicts that have accumulated over time during the setup, for example by assigning users to several groups with overlapping rights. FIDES plays back such inconsistencies to the administrator so that he can clean up the Active Directory. It is also possible to synchronize with multiple systems, for example, by combining an Active Directory and SAP.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20899\" title=\"Login with FIDES\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/Login_2020-1.png\" alt=\"Login with FIDES\" width=\"700\" height=\"417\" \/><\/p>\n<h2>Unique: A secure Unified Workspace for Active Directory management and access to all applications and data<\/h2>\n<p>The combination of oneclick\u2122 and FIDES makes it possible for the first time to manage both the administration of the entire Active Directory and the access to applications and data via a uniform interface in the browser. With the FIDES app in the oneclick\u2122 workspace, every user can manage and delegate his Active Directory authorizations. All applications necessary for everyday work can also be opened and operated directly via the oneclick\u2122 Workspace. Data is shared across applications via the so-called Hybrid Drive using state-of-the-art streaming technology without the data leaving the defined storage location. There is no need to install additional client or server services.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20886\" title=\"FIDES in oneclick\u2122\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/Desk-mit-Sidebar-1.jpg\" alt=\"FIDES in oneclick\u2122\" width=\"700\" height=\"394\" \/><\/p>\n<h2>Secure authentication and Single Sign-On<\/h2>\n<p>In order to work with oneclick\u2122 and the FIDES identity and rights management, users only have to log in to the platform once. The basis for access is a trustworthy identity provider, who creates and confirms identities. The oneclick\u2122 platform and FIDES support the OpenID Connect standard. A rights owner can define different trust levels for certain rights. For example, access to less critical documents may only require the entry of a password, or a second or third factor may be requested for particularly sensitive information.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20877\" title=\"Passpol\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/passpol-1.png\" alt=\"Passpol\" width=\"250\" height=\"68\" \/><\/p>\n<h2>Easy handling of strong passwords<\/h2>\n<p>In order to make strong passwords easy to handle, the partners rely on PASSPOL, a patented, graphical multi-factor authentication, which is a fast, convenient and highly secure alternative for textual passwords, PINs or biometric methods. Personalizable images, which also serve as cryptographic key files, are moved in a specific order on a matrix. This sequence, in combination with the correct images, serves for verification, is very easy to remember and almost unforgettable. PASSPOL makes use of three proven psychological phenomena: the Pictorial Superiority Effect, the Dual Code Effect and the high memorability of movement patterns.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"img-blog aligncenter wp-image-20879\" title=\"Bundesdruckerei\" src=\"https:\/\/one2.sem-webagentur.de\/wp-content\/uploads\/2023\/08\/Bundesdruckerei_logo-1.png\" alt=\"Bundesdruckerei\" width=\"250\" height=\"137\" \/><\/p>\n<h3>About Bundesdruckerei<\/h3>\n<p>Bundesdruckerei GmbH is a leading German high-tech security company. Its products and services are &#8220;Made in Germany&#8221; and are based on the secure identification of persons and institutions. As a federal security company, the company paves the way to a secure digital future. More information can be found at <a href=\"http:\/\/www.bundesdruckerei.de\" target=\"_blank\" rel=\"noopener noreferrer\">www.bundesdruckerei.de<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>Image sources:<\/p>\n<ul>\n<li>Bundesdruckerei (2018): White paper: From the Almighty Administrator to the Self-determined User. Online: https:\/\/www.bundesdruckerei.de\/en\/whitepaper\/download\/2835\/Whitepaper-Fides.pdf<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Users of the oneclick\u2122 platform and FIDES gain self-determination over their data by means of digital authorization chains.<\/p>\n","protected":false},"author":3,"featured_media":30745,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[51],"tags":[61],"class_list":["post-30719","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-products","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/posts\/30719","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/comments?post=30719"}],"version-history":[{"count":1,"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/posts\/30719\/revisions"}],"predecessor-version":[{"id":30744,"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/posts\/30719\/revisions\/30744"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/media\/30745"}],"wp:attachment":[{"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/media?parent=30719"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/categories?post=30719"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one2.sem-webagentur.de\/en\/wp-json\/wp\/v2\/tags?post=30719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}