Power LogOn:

Certificate-Based Offline Authentication (COA)

 

Authenticate to offline networks without online

revocation list access.

Use existing certificates to access offline networks

UEI: X4CCM6HULMX6
CAGE: 5AU22
DUNS: 829366660

Introducing

Power LogOn:

Your Complete Cyber Authentication Solution

 

There is no other commercial off-the-shelf (COTS) product that can do all that Power LogOn COA does.

– U.S. Air Force Project Manager

 

How can Power LogOn help you?

Power LogOn COA solution provides secure verification and login authentication onto disconnected or intermittently connected networks that cannot access online certificate authority servers or revocation lists, using your existing digital certificate enabled credentials (CAC/PIV/CIV and others).

Currently used within the US government on air-gapped networks. Power LogOn COA works out-of-the-box with most digital certificates to facilitate secure authentication, authorization, verification, and non-repudiation for Windows login. Enables distributed authentication for tactical units under Degraded, Delayed, Intermittent and Limited (DDIL) conditions.

Flexible and Scalable

Power LogOn COA supports a wide range of certificate-based credentials and technologies, and ensures compliance with government standards and regulations, with minimal infrastructure changes. 

Power LogOn COA doesn’t replace your digital certificate architecture or require new certificates, it adds additional functionality and flexibility to existing certificates when accessing government or commercial networks that are disconnected from any network for Security, Degraded, Delayed, Intermittent and Limited (DDIL) conditions. With strong encryption, centralized IT control, and compatibility across platforms, Power LogOn COA is a scalable solution providing both convenience and robust protection.

Power LogOn COA has passed compliance review by third-party pen testers (NIST approved Network Security Inc.), and STIGs self-evaluation approved by United States Air Force.

Secure, Automated Offline Logins

Power LogOn COA streamlines verifiable certificate-based offline MFA authentication access management by automating logins across disconnected or intermittently connected workstations, while enhancing both convenience and security.

With strong encryption and administrative tools, Power LogOn COA ensures comprehensive protection while simplifying IT security by utilizing existing credential infrastructure.

 

  • Zero Trust authentication
  • Works side-by-side with digital certificates
  • Doesn’t replace existing credential digital certificates
  • Provides Username & Password to the Windows Authentication process
  • Uses existing credentials, certificate, and PIN for true MFA
 
Zero Trust Authentication Methods

Power LogOn creates zero trust by using government cybersecurity standards, regulations, and best practices to authenticate and verify user against approved revocation lists without network connectivity.

  • Possession (Something you have, i.e. credential), 
  • Knowledge (Something you know, i.e. PIN), 
  • Digital certificates public and private key,
  • Encryption Keys, 
  • CUID (Chip Unique Identifier)

 

 

 

IT Centralized Password Management

 

Ideally suited for computer workstations isolated from an organization’s network that require certificate-based multi-factor authentication.

 

  • Works with any credential with a valid X509 certificate.
  • Does not require any additional hardware infrastructure.
  • FIPS 140-2 verified, FIPS 201, HIPAA, CJIS, NIST 800-171 & 800-63b-AAL3 Compliant
  • Self-evaluated STIGs review accepted by USAF 
  • Scalable and adaptable for organizations of any size

 

 

~
Multi-Factor Authentication

According to Microsoft, MFA blocks 99.9% of attack vectors.

True multi-factor authentication (MFA) is essential for enhancing security by requiring users to verify their identity through multiple forms of validation, such as something they know (password), something they have (security token), and/or something they are (biometrics).

By adding these layers of protection, MFA greatly reduces the risk of unauthorized access, minimizing threats from compromised credentials and bolstering overall cybersecurity defenses.

System Requirements

Power LogOn is compatible with Windows operating systems, supports major cloud platforms, and requires minimal client computer resources, making it a highly scalable solution.

Primary Application: Identity management, multi-factor authentication, and enterprise security

Secondary Application: Strong passwords, safeguards against many hacker techniques

Operating System: Windows 11, Windows 10 (32/64-bit), and earlier versions

Servers: Win Server 2022, 2019, 2016, and earlier versions and SQL Server 2022, 2019, 2016, 2014, and earlier

Server RAM: at least 4GB for small installations, 8+GB for installation over 50 users

Virtual Server: Recommended

Client computer hard drive space: 70GB

Clouds: AWS, Azure, Google, or any private cloud supporting Virtual Machine

Web Browsers: Auto launch IE, Edge, Firefox, and Chrome browsers

Certificate-based Offline

Authentication Features

Government COA Customers

  • US Air Force

Advantages and Benefits

Cybersecurity authentication goes beyond simply generating strong passwords based on length, character types, randomness, and change frequency for secure digital identity. By adopting many of the security principles used to safeguard digital certificate keys and zero trust architecture, passwords can achieve a commensurate level of security.

 

  • Federal identity management compliant
  • Compliant with FIPS 140-2 and NIST 201.
  • Works with existing issued government contact or contactless CAC/PIV/CIV credentials.
  • No data on the government credential is added or modified.
  • No rebadging or re-certifications required.
  • Employees no longer need to know, type, generate, or manage passwords.
  • Secures the logs into their federal approved identity providers (IdP)
  • PIN and/or biometric protection enhances security.
  • Implements a work-from-anywhere architecture.
  • Wrong PIN lockout prevents unauthorized access.
  • Recognizes unregistered credentials to prevent misuse.
  • Password Configurator ensures compliance with IT policies.
  • The Password Generator prevents employees from overriding IT-configured settings.
  • Passwords can be up to 500 characters in length.
  • Configurable password options include upper case, lower case, numeric, and special characters.
  • Passwords can be automatically changed by IT without user involvement.
  • Unlimited number of accounts can be stored in LDAP directories.
  • Change Password Reminder ensures timely password updates.

Security

Power LogOn enhances federated cybersecurity by using advanced encryption methods, unique usernames and passwords for each site, and non-typed passwords to guard against common cyber threats like keyloggers, social engineering, and phishing. Additionally, it provides customizable actions upon card removal and ensures encrypted password backups for secure data recovery.

 

  • Password data is encrypted using AES-256, SHA-256, hash salting, SSL, and challenge/response for maximum security
  • Self-analyzed and reviewed by USAF for STIGs compliance 
  • No data is added or modified to a CAC/PIV/CIV credential.
  • Users don’t know or type passwords, protecting against common attack methods like social engineering, keyloggers, password sharing, and “over-the-shoulder” attacks
  • Each site has a unique username and password, enhancing account security
  • Card removal triggers your choice of security actions: user network log off, computer lockdown, shutdown, or custom options
  • Password data backup files are encrypted
  • Session key negotiation for secure communication between devices
  • Account addresses are verified before autofill, guarding against spam, phishing, and pharming
  • Email protections further safeguard against cyberattacks
  • Password length configurable up to 500 alphanumeric characters
  • PIN length configurable between 4 to 20 alphanumeric characters

Compliance

Power LogOn meets stringent federated cybersecurity standards, ensuring compliance across local, state, federal and tribal governments. Its comprehensive approach protects agencies by adhering to government-specific regulations, safeguarding sensitive data, and supporting cybersecurity requirements.

 

  • FIPS 140-2 Verified by InfoGard
  • FIPS 201 compliance by NIST– no data is added or changed on existing government credentials
  • DoD STIGs compliance (U.S. Air Force reviewed)
  • DFARS NIST 800-171 compliance
  • NIST 800-63b AAL-3 compliance
  • NIST 800-53
  • CJIS compliance
  • IRS 1076 Security Guidelines compliance
  • HIPAA and HITECH compliance
  • Insurance companies’ cybersecurity requirements

PSC

  • DA10
  • DJ10
  • 7A20
  • 7A21
  • 7C20
  • 7C21

Convenience

Combining multiple functions onto a single CAC/PIV/CIV ID badge streamlines security management, making it easier to identify and address vulnerabilities quickly. Employees don’t carry multiple credentials and tokens—such as a physical access badge, a network access token, and a smartphone for SMS. With a single credential, the risk of a cyber vulnerability—the losing, misplacing, or forgetting increases with each additional device—is significantly reduced.

Power LogOn’s convenience ensures that end users follow security policies by integrating various card technologies—RFID, mag stripe, custom graphics, barcodes, and more—into a single access ID badge. This allows IT and HR to issue and manage just one credential, simplifying administration and reducing costs.

  • Enhances security through secure Identity, Credential, and Access Management (ICAM) 
  • Streamlines security by consolidating both physical and cyber access onto a single card
  • Leverages your existing CAC/PIV/CIV ID credential, simplifying integration
  • In most installations, no need for re-issuance or re-badging, saving time and resources
  • Enables password management with existing CAC/PIV/CIV badges, reducing the need for additional credentials
  • Supports non-proprietary card compatibility for greater flexibility
  • Compatible with a wide range of credential technologies, including Prox, RFID, NFC, Contact Smartcards, magnetic stripe, and more
  • Reduces administrative complexity and costs while maintaining robust security standards
  • Third-party software API integration
  • LDAP directories supported
  • Store multiple account access
  • Add, view, edit, and delete cardholders
  • Event logging for security and tracking records
  • Supports terminal services
  • Online time and attendance tracking
  • Security monitoring features
  • Database importing and exporting capabilities

Fast, Easy, and Affordable

Power LogOn streamlines the implementation of secure access management by utilizing existing credentials and offering flexible licensing options, making it both cost-effective and easy to deploy.

With features that enhance both user convenience and IT control, it ensures robust security without requiring additional hardware or complex infrastructure changes.

  • Leverages existing physical access credentials, eliminating the need for rebadging or re-issuance
  • Employees simply present their credential and enter a unique PIN, automating the logon process without typing usernames or passwords
  • Provides perpetual license options for full ownership with no renewal or subscription fees
  • Subscription licenses to lower annual costs based on volume and organizational needs
  • No need for centralized enrollment stations, making deployment simpler and faster
  • Employees can self-enroll into the system, reducing the administrative burden
  • Installs in about one hour
  • Works seamlessly with the same credential at the office, offsite, and at home
  • Ensures data is backed up and recoverable if credentials are lost or stolen
  • Temporary credentials can be issued within minutes, maintaining operational continuity
  • Open architecture supports non-proprietary cards and smartcard readers
  • No backend server modifications or additional hardware purchases required
  • Allows users to store personal accounts without IT having access to the passwords
  • Security settings are configured and locked by IT, preventing employees from altering them
  • Power LogOn evaluation kit available with a 90-day money-back guarantee for thorough testing

Availability

Power LogOn is available through a network of approved GSA and SEWP contract holder resellers and distributors. If you’re interested in testing or implementing Power LogOn Government, reach out to your IT reseller. If they are not an authorized reseller, they can contact us to become one.