Skip to content

Security Expertise

Deep-level Windows security engineering — from smart card drivers to Active Directory protocol internals.

Active Directory Replication

We are the worldwide experts on AD replication techniques including DCSync and DCShadow. Whether you need to replicate credential data in trust-less environments or harden against such attacks, we have deep hands-on experience.

Smart Card Driver Development

CSP, OpenSC driver, or Windows minidriver — delivered at fixed price with full compliance with Microsoft's test suite and optional auto-deployment via Microsoft Update.

Windows Authentication Hooks

Credential Providers, GINA DLLs, SSP/AP packages, Kernel SSPs, NegoEx extensions, password filters, ISAPI filters — we build the deepest authentication integrations Windows supports.

Smart card driver & integration

Integrating smart cards — especially EIDs compliant with ISO 7816-15 / PKCS#15 — is difficult because most vendors ship drivers with subtle, hard-to-reproduce bugs. Common failures include user-context caching, incompatibility with system accounts, silent-context breakage, broken container enumeration, and Microsoft Update incompatibility.

Developing a CSP, an OpenSC driver, or a minidriver requires specialized skills — these components can be loaded into Windows security kernels, and errors are often silent and difficult to diagnose.

Where a smart card driver runs in Windows The Windows smart card stack, from logon and applications down to the card. Logon, LSASS, the Certificate Propagation service, user applications and Windows Update all load the same card minidriver, and each layer has its own failure modes: silent contexts, PIN caching, concurrent transactions, card removal, reader quirks and card profile parsing. The domain controller adds certificate mapping, the NTAuth store and revocation checks. WHO LOADS YOUR DRIVER WINDOWS SMART CARD STACK WHAT CAN GO WRONG Logon & applications Winlogon · LogonUI · user apps CryptoAPI · CNG CAPI2 · NCrypt Base CSP · Smart Card KSP basecsp.dll · scksp.dll Card minidriver the vendor DLL — where the bugs live WinSCard API winscard.dll Smart Card service SCardSvr · resource manager Reader driver CCID · PC/SC Smart card APDUs · ISO 7816-4 Logon UI & credential providers before any user session exists LSASS · Kerberos PKINIT SYSTEM account · a crash = reboot Certificate Propagation service reads the card at every insertion User applications Outlook, browsers, VPN · user context Plug and Play · Windows Update installs the driver from the ATR 1 Silent contexts no PIN prompt allowed: fail cleanly 2 PIN & container caching shared across processes and sessions 3 Concurrent transactions several callers, a single card 4 Card removed or reset in the middle of a logon 5 Reader quirks timing, extended APDUs, CCID bugs 6 Card profile parsing ISO 7816-15 / PKCS#15 variants Domain controller too: certificate mapping · NTAuth store · CRL / OCSP checked by the KDC
One driver, loaded by many processes in very different contexts — each one a new way to fail, often silently.

My Smart Logon has built numerous production smart card drivers — including the OpenPGP minidriver and the EIDVirtual minidriver — and has contributed patches to the OpenSC project.

Fixed-price packages available. We offer competitive, high-quality smart card driver development — fully compliant with Microsoft tests and ready for Microsoft Update auto-deployment. Contact us to discuss your project.

Windows authentication hooks
Common Sign-On to SSO

We build web server plugins — including IIS ISAPI filters — that rewrite NTLM authentication messages on the fly, bridging untrusted corporate domains seamlessly.

Password synchronization

Custom password filter libraries running on domain controllers — synchronizing passwords across Windows, Unix, and custom identity stores, including direct SAM database access.

Custom authentication protocols

Credential Providers, GINA DLLs, SSP/APs, Kernel SSPs, NegoEx packages — for any device or protocol, including smart card and hardware token integration. See EIDAuthenticate as a proof of our depth.