Page tree
Skip to end of metadata
Go to start of metadata

3.8 - Nexus PRIME consists of these applications:

The program package Nexus PRIME has the following basic architecture:

  • J2EE/Java-based server
  • SQL database, connected to the application server
  • User Interface:
    • Designer: Rich client framework (based on Java) for rendering the user interface
    • Explorer: HTML5 client or Java web start application
    • Tenant: HTML5 client
    • USSP: HTML5 framework

Nexus PRIME architecture

PRIME architecture overview


For more information on the supported systems and versions, see 3.8 - PRIME requirements and interoperability

Corporate directory

The LDAP connector enables searching and reading identity information from an LDAP directory, such as Active Directory. User authentication with directory-stored password and group-based role assignment are also supported. 

Alternatively, PRIME can connect to different HR systems, typically via CSV file import/export.

Certificate authority

Through the PKI connectors, Nexus PRIME PKI applications can request, renew, and revoke certificates from/in a certificate authority (CA). The PKI connector delivers the certificate template names that are made available by the CA for use. These templates are mapped to Nexus PRIME certificate types. Multiple CA connections are possible.

Smart cards and software tokens can contain any number of certificates that may be issued by different CAs.

Physical access control systems (PACS)

Through PACS connectors, it is possible to read access profile information from the PACS as well as to provision and de-provision ID cards and entitlements (profile assignment) in PACS systems. The PACS connector may be based on CSV file (asynchronous) or WebServices (synchronous) interfaces.


All configuration and run time data is stored in an SQL database.

PRIME Web server

Includes the PRIME components, that is, PRIME Explorer, PRIME Designer etc.

Registration client

Identity assurance, data, image and signature capturing.

Production client

Card printing and encoding, batch production.


Support, invalidation, temporary PIN, card reset.


Request, approval, invalidation.

User Self-Services

Request, image capturing, PIN reset, renewal, etc.

Nexus PRIME architecture, details