CASE STUDY – Implementation of OpenTrust® PKI (Public Key Infrastructure) system in
Al Hilal Bank, Abu Dhabi, UAE

Mr. Kenan Begovic, Information Security Officer at Al Hilal Bank, at the time of implementation:
„I am personally very satisfied. I am particularly impressed by the quality of the people who came to implement the system. I have also heard some people who work for me unofficially saying to their colleagues how impressed they were by the quality. The whole implementation was definitely one of the smoothest projects we had ever had at the bank. We hope to have an opportunity to continue with our cooperation in some future projects.
RECRO-NET is a serious company and we trust them completely.“
Customer profile
Customer: Al Hilal Bank, Abu Dhabi government-owned bank, largest UAE Islamic bank in share capital
Industry: Islamic banking service provider
Size: 14 branches in UAE, first Islamic bank in Kazahstan, cca 1.000 employees
Details: A perfect example of an accelerated business development in the Emirates: founded by Abu Dhabi government in June 2008, with an authorized capital of 4 billion AED. After having established 14 branches in the UAE within a span of 18 months, business had been expanded in Kazakhstan. Plans include opening of two new banks in Europe.
Business need
In the beginning, the Bank required in-house bank employee identification and authorisation. Moreover, cell phone identification inside corporate network over the wireless had been required, as well as identification and authentication services for remote users via VPN access.
Another opportunity is in planning phase - a specific concept for field employees, which includes carrying tablet PCs and instead of a traditional interview with the Customer over the table, transfer of business meeting to another place, e.g. a coffee bar, with the ability to do everything required over the wireless and the mobile device.
Objectives
Following objectives were set out:
-
Secure customer authentication
-
Introduce digital signature into business communication,
-
Offer new services with the use of wireless technology,
-
Improve communication security with Bank’s Kazakhstan branch office.
-
Solution
One of the basic ideas was to outsource the implementation. As an emerging bank, internal IT team did not have enough resources to do everything on their own.
RECRO-NET's proposal was recognized as optimal due to the short implementation time and the lowest total costs of ownership.
The implementation included the PKI software package of the French company OpenTrust.
The project duration was three months in total, whereas installation, training and integration with the current system proceeded in two phases, 10 days each, with two RECRO-NET engineers on the spot. It took approximately 40 man-days, which accounted for field installation and implementation at the Customer’s premises; administration and daily system maintenance are remotely operated from Zagreb.
In comparison with other IT projects, one of the specific characteristics of the PKI project is the training held initially, at the beginning of the project. PKI is not a product, but a combination of technology, security policies, administrative procedures and staff. It is very important to have users understand the PKI technology in detail before its implementation to be able to make decisions about the PKI system design and configuration together with consultants, and to integrate it with the current working procedures.
After the training, together with RECRO-NET consultants, users prepared all the parameters required for the PKI system configuration. Testbed configuration had been set up in RECRO-NET premises, where throughout testing of all user scenarios took place. Owing to good preparation, the installation was fast and smooth. The largest amount of time was spent on the integration with the current IT system components and accreditation testing.
Management of installed PKI system is handled remotely by RECRO-NET administrators.
Benefits
Following benefits have been reached with RECRO-NET solution:
-
full integration into existing Customer IT infrastructure,
-
total cost of ownership lower than for other solutions,
-
short implementation time,
-
extendible scalability and performance in order to meet the future expansion of the system.
All of the Customer's project objectives were met, with a wide span of new possibilities readily waiting for deployment, based on mature technology, trustworthy software solution and reliable business partner.