KeyekID Structure

Keyek Universal Identity

Universal Identity:

The Keyek ID provided by Keyek serves as a universal digital identity that can be used across various systems and platforms.

Complex Relationship Structure:

The relationship between a user, their assigned Keyek Card(s), and the systems the Keyek Card can authenticate is multifaceted. Keyek supports a flexible many-to-many-to-many relationships model, offering granular control at each step.

Device and Platform Flexibility:

  • Keyek Cards are not tied to a single device, system, or platform.

  • A user can use a single Keyek Card to access multiple accounts and

  • Multiple Keyek Card users can log into the same device.

ID Generation in Bureau of ID (BoID):
When a user is created in the Keyek system, a VeroID is generated in the Bureau of ID (BolD), which acts as a central hub for consolidating identities from other systems. This allows users to access any application integrated with Keyek using their Keyek Card and PIN.

image-20241009-015517.png Keyek ID Core Elements

The core elements to the structure of the VeroID and the relationship between them is explained below:

A Customer manages their Keyek instance and determines who can become an End User.

  • Keyek Cards are supplied to the Customer for allocation to End Users. Keyek Cards can exist without being assigned to any user, making them available for future assignment.

    • A Keyek Card can only be assigned to one user at a time.

    • A User can have multiple Keyek Cards assigned to them simultaneously.

  • Applications can be made available to a Customer’s Instance.

    • The Customer Administrator can assign these applications to individual Users.
      Examples of such applications include Active Directory or FIDO2.

    • Each Application can have multiple Resources.

      • Resources contain data linked to a user's account and can be assigned to multiple Keyek Cards.

Keyek Customer Instance Concept.png
Keyek Customer Instance Concept