Xerox Xerox Secure Access Unified ID System Support & Software Administrator's Guide

Page of 50
Secure Access Overview
Xerox Secure Access Administration Guide
17
The core server components communicate on designated ports. Each component “listens” on a specific 
port for information or requests from the other components. Refer to 
a complete list of port assignments per component. 
Core Authentication Server (CAS)
The Core Authentication Server (CAS) houses the database that contains all user and MFP device data. 
Every Secure Access installation requires a pre-installed database. The CAS uses the database instance 
to create an accounts database that contains all user information, and all device information. See 
System Requirements in the Installation Guide for information about supported databases.
Device Control Engine (DCE)
The Device Control Engine (DCE) handles all communication with the MFP devices. When a user wants 
to use the copy, scan, or fax functionality on a MFP, they must first trigger the card reader. A swipe or 
proximity read initiates an access request.
The Authentication Device forwards the login request to the DCE, which then contacts the CAS to 
verify the user account data associated with the card. This process is depicted in Figure 4 and 5.
Figure 3-4: User Authentication Workflow
2. Authentication Request 
Generated
3. Forward Request
Authentication 
Device
6. Send Unlock 
Request to MFP
DCE
CAS
4. Verify User
5. User Verified
1. User triggers card reader
MFP
Ethernet
Serial Cable
Ethernet CAP Protocol
Card 
Reader