PERIMETER-ZERO - Identity and Access Service
AIC’s Identity & Key Minting Service delivers Defence-grade digital trust through service-scoped tokens and cryptographic key minting — secure, auditable, and ready for enterprise or government deployment.
Category
Commercial
Client
Platform Initiative
Services
Service Design, Policy, Logging
Location
UK
Year
2025
TRL
7

Overview
AIC’s Identity & Access Service (IAS) delivers a unified, zero-trust framework for authentication, authorisation, and cross-domain access control.
Developed under Project PERIMETER-ZERO, it establishes the cryptographic foundation for Defence-grade identity assurance, combining asymmetric trust, service-scoped access, and auditable governance in one platform.
The system issues verifiable digital identities and scoped access tokens for users, applications, and workloads — allowing each to operate securely across hybrid cloud, edge, and sovereign networks.
Every identity is policy-bound, every request is cryptographically signed, and every transaction is provable.
Core Capabilities
Adaptive Identity Federation – enables inter-agency or multi-network authentication under unified zero-trust logic.
Policy-Based Access Control (PBAC) – enforces decisions using classification, context, and operational role attributes.
Cryptographic Assurance – all keys generated and validated using FIPS 140-3 compliant HSMs and ECDSA signatures.
Scoped Service Tokens – replaces static API keys with dynamic, per-service credentials that expire automatically.
Comprehensive Audit Layer – immutable event ledger for verification, revocation, and compliance reporting.
Offline & Edge Operation – validation possible in disconnected environments with deterministic key proofs.
Deployment Model
Available as a clean-cloud managed service (Azure) or deployable into private / classified networks.
Integrates with Entra ID, Auth0, and internal PKI systems.
Provides SDKs for .NET, Go, and Python, enabling secure integration with AIC or third-party platforms.
Impact
Project PERIMETER-ZERO enables governments and enterprises to standardise identity trust across environments — cloud, operational, or tactical — without exposing internal credentials or relying on third-party brokers.
It’s the identity backbone of a modern, secure digital ecosystem: one service to verify, control, and govern every transaction.
