CAH
Paraview builds a centralized identity management platform for Capital Airport Holding to achieve seamless access management, enhanced security, and streamlined user experience.
Overview
Industry
Transportation
Business Nature
Aviation Industry
Company Size
> 70000 Employees
Services Required
IAM
The Problem
- Lack of Centralized Identity Management: The client requires a secure and centralized platform to manage the identities of employees, partners, suppliers, and other users, with support for multi-factor authentication methods like passwords and SMS codes.
- Limited Access Efficiency: Users currently needed to log in separately to each system or application, leading to a fragmented and time-consuming user experience.
- Inadequate Security Auditing: The lacks of comprehensive logging of user access and activities created difficulties for security audits and regulatory compliance.
- Integration Challenges: Former business systems and applications were not integrated with each other, and there was limited support for standard protocols such as OAuth, LDAP, and SAML, complicating seamless operations.
- Heavy IT Workload: Routine user support requests, such as password resets and account unlocks, relied heavily on the IT department due to the absence of self-service options.
Our Solution
- Unified Identity Management: Developed a centralized identity management platform to unify all user identity information. The platform supports various authentication methods, ranging from password-based to multi-factor authentication, to enhance overall system security.
- Single Sign-On (SSO): A centralized SSO authentication center is provided, enabling users to log in once to access multiple systems and applications. The SSO solution seamlessly integrates with all existing business systems, delivering a streamlined and efficient user experience.
- Strengthened Security: Robust security measures are implemented, such as encrypted transmission, data encryption, and intrusion detection, with regular security audits and penetration testing to identify and resolve vulnerabilities promptly.
- Audit and Compliance: Comprehensive logging of user access and activities ensures complete audit trails. Reporting and analysis tools are integrated to support security audits and compliance checks.
- Integration Capability: Standard interfaces and protocols (e.g., LDAP, SAML, OAuth) are used to enable seamless integration with existing business systems and applications.
- User Self-Service: Paraview develops a user-friendly self-service portal for the client to enhance its user experience, offering functions like password reset and account unlocking, reducing the workload on the IT department.
- Data Migration: A detailed data migration plan is devised to securely and completely transfer user data from the existing system to the new platform, ensuring the consistency and integrity of all data.
Achievements
- Unified Identity Implementation: Standardized user naming conventions and globally consolidated user identifiers and password policies, achieving a cohesive "one person, one account, one identity" framework.
- Centralized Identity Data Storage: Integrated with the mobile operations control system to synchronize permissions data and established an LDAP enterprise directory for secure and centralized data storage of identity information.
- Comprehensive User Management: Effectively managed over 70,000 users identities, utilized an event streaming platform to seamlessly administer account permissions across key systems, including cloud management platforms, finance and reporting, IT security, and operational logging.
- Enhanced User Experience: Streamlined account and password management with added self-service functions, significantly improving user experience.
- Standardized Application Management: Established unified application integration guidelines, enabling centralized and efficient management of user accounts across all applications.
More Case Studies
Ready to Embrace a Safe and Efficient Digital World?
Contact us and Let’s discuss how Paraview can secure your identity and API assets.