How an Asia-Pacific Ministry of Defence
secured its workforce
In the government defence environment, robust and adaptable digital identity solutions are paramount. Intercede and Entrust partnered with a defence advisory body in an Asia Pacific Ministry of Defence to modernise digital identity infrastructure and strengthen long-term security resilience.

The deployment in numbers
Modernising digital identity for national defence
For a national defence organisation, digital identity has to be strong, adaptable and dependable under pressure. Working alongside Entrust, Intercede partnered with a technology and infrastructure advisory body within an Asia-Pacific Ministry of Defence to modernise how the ministry issues and manages credentials across its estate.
The programme spanned multiple air-gapped environments and tens of thousands of end-user devices, and was built not just to meet today's requirements but to give the ministry the flexibility to adopt new standards and devices over an eight-year operational life. MyID CMS and MyID SecureVault sit at the centre of that framework.
The Customer faced a multifaceted challenge in their ongoing programme to refresh and update their technology infrastructure
Their existing Public Key Infrastructure (PKI) and Credential Management System (CMS), along with end-user device components, were outdated and nearing the end of their operational lifespans.
Enhanced security
There was a pressing need to support more sophisticated security mechanisms to counter evolving threats.
User experience optimisation
The organisation aimed to integrate and manage biometrics to simplify the user experience without compromising stringent security protocols.
Standards compliance
A fundamental requirement was full support for the FIPS 201 Personal Identity Verification (PIV) standard.
Transitioning PKI
A critical PKI component had reached its end-of-life, posing significant security and support risks.
Vendor independence and flexibility
The Customer sought to reduce vendor lock-in and introduce greater flexibility for future technology decisions, ensuring adaptability to emerging standards and solutions.
Fast-track deployment
The Customer required design, build and implementation of the solution within a challenging timeframe to meet their internal governance.
Intercede undertook a thorough requirement gathering session
This involved close collaboration with other vendors contributing to the solution stack, ensuring smooth integration and a joined-up approach. Scalable architecture: Using Intercede's MyID CMS, a solution architecture was deployed to support multiple air-gapped environments, managing tens of thousands of end-user devices. This architecture was designed to initially support Idemia smartcards while maintaining future scalability for a wide array of future end-user devices, including mobile platforms, USB tokens, and virtual smartcards.
Using MyID CMS
Established direct integration with a new Entrust PKI, giving a strong, modernised cryptographic foundation.
Custom applet support
The solution facilitated support for custom applets on smartcards, enabling tailored functionalities specific to the Customer's operational needs.
Enhanced end-user device security
Biometric Match-on-Card authentication was introduced to significantly enhance the user experience and security of end-user devices, providing a strong, multifactor authentication mechanism.
Secure key storage
MyID SecureVault, delivered the customer a new CA independent Key Storage solution, providing secure and managed access, generation and recovery of highly sensitive cryptographic key material. This was a critical component to maintain data integrity and confidentiality in line with the organisations strict security policies.
Our engagement with the Customer was a testament to deep collaboration. By meticulously understanding their intricate requirements and working together with their ecosystem of technology partners, we were able to create a comprehensive digital identity framework. The integration of MyID CMS and MyID SecureVault ensures not just immediate operational resilience, but also provides the foundational agility for their future security endeavours.
The organisation is currently in the process of rolling out the solution across its separate environments. This phased deployment is already enabling the identification of additional functionalities, such as secure, separate biometric storage, which will further enhance the organisation's flexibility and overall security capabilities. The full solution and end-user rollout are on track for completion, with the system intended to stay operational for at least eight years.
The platform behind the deployment
Intercede is a cybersecurity software company and the digital identity experts. For over 25 years, Intercede has helped government agencies, defence programmes, financial institutions and enterprises deploy phishing-resistant digital identities at scale.
The MyID product family, MyID CMS, MyID MFA and MyID PSM, manages millions of credentials across more than 20 countries. Vendor-neutral architecture means MyID integrates with virtually any certificate authority, hardware security module or smart card manufacturer, without organisations replacing existing infrastructure.