The ID Two Step

Officials have stopped dancing around identity verification and have take steps to implement credentialing programs

AS federal and state governments look for ways to ensure workers' identity, identification cards have come to be a hot topic. In addition to protecting physical assets -- buildings, infrastructure and other facilities -- government officials also are interested in maintaining the integrity of their computer networks.

There are two identification cards that have garnered most of the publicity in recent months -- a personal identification verification card based on FIPS 201 and the transportation workers identification credential.

There are two identification cards that have garnered most of the publicity in recent months -- a personal identification verification card based on FIPS 201 and the transportation workers identification credential.

FIPS 201 cards will affect all federal employees, up to 5 million people and an additional 2 million federal contractors. The complexity and the sheer number of cards involved will make this one of the largest security projects ever undertaken by the federal government.

The effort is the result of HSPD-12. HSPD-12 requires all federal agencies to deploy an interoperable solution for access to federal buildings and IT networks. The directive mandates that agencies must now begin to issue FIPS 201-compliant credentials. The FIPS 201 standards were set by the National Institute for Standards and Technology to address the process, use and interoperability of the PIV cards. These standards represent a major change in how the federal government will manage access control for both physical and logical assets. A common system to verify the identity of individuals has become critically important as a means to enhance security, increase government efficiency and reduce identity fraud.

The Credentialing Process
The system that the government has put into action to enhance identity verification is a process fragmented into three parts -- finding a sponsor, then a registrar and, lastly, an issuer. This process is designed to make it more difficult for any one person to falsify information, alter a card or create a credential for an inappropriate person.

Before receiving a card, every federal employee or contractor must have a sponsor. Usually, this will be a supervisor who can confirm employment and provide information regarding the employee's need for physical and logical access to federal assets. This can include restrictions on days, times or specific sites.

Next in the process is the registrar. A registrar can be an individual or group within an agency or an outside vendor approved by the government to provide the required services. It is the job of the registrar to gather pertinent data about the registrants, including information from the sponsor and from the agency's human resources department. A digital picture of the applicant will be taken, and the registrar also will digitally collect a scan of the employee's 10 fingerprints. The fingerprints will be submitted to the federal Office of Personnel Management or to the FBI to conduct a criminal background check.

Once the background check is successfully completed, the issuer will complete the process. Again, the issuer can be an internal agency group or an outside vendor. The first step is to verify, via fingerprints, the identity of the intended card recipient. The issuer then will add a Java applet to a card, as well as a bar code and employee photo. At this point, the card is ready to print. The cards are layered with designs, hidden text, holograms and other information to discourage duplication or counterfeiting.

Once issued a PIV card, employees are required to swipe the card through a reader to access their office, and then swipe the card again, while placing a finger on a biometric reader to authenticate their identity and gain access to the agency computer system.

A Government-Wide Installment
As people leave government employment, human resources departments can immediately deactivate identity cards, rendering them useless. Also, as new employees are hired, human resources can notify a sponsor to begin the registration process.

A number of vendors, including systems integrators, plan to offer partial or end-to-end solutions for card registration on an agency or office-by-office basis. In order to qualify for the job, a vendor must submit its solution or products to NIST for testing and review. The General Services Administration has said it attempts to promote interagency cooperation. For example, two or more agencies sharing the same building will be encouraged to share the same registration solution to potentially save paperwork, time and money.

While plans for the new identification card have recently gained widespread attention in the media, a survey released in mid-June by a consulting firm for government procurement and contracting found nearly half of federal IT security executives did not have a plan in place to meet the deadline. One reason is the lack of funds in the federal budget earmarked to pay for this ambitious program.

However, HSPD-12 addresses a serious issue. Some agencies have already begun pilot programs to implement HSPD-12. And it is anticipated that most agencies used discretionary funds to begin pilot projects prior to the Oct. 27 deadline.

The nation's ports also are looking to enhance security procedures through the proposed TWIC card, which will be issued to each of the 750,000 truck drivers, longshoremen and railway employees who access docks and shipyards on a regular basis. In late 2002, Congress ordered the administration to develop a tamper-proof photo identification card for port and other transportation workers. All individuals with unescorted access to secure areas of port facilities would be required to carry this identification card. The first cards were expected to be issued in August 2004. According to Congressional investigators, however, bureaucratic delays and poor planning slowed development of the card.

The Right Direction
The first cards, costing workers $149 each and valid for five years, are just now being issued. Companies may agree to cover the cost to their workers and the cost of card readers. Installation and maintenance costs will be taken on by the companies and ports employing the credentialing products.

Before TWIC cards are issued, the government will conduct a background check of each worker that will include a review of criminal records, terrorist watch lists, immigration status and warrants. Shipyards and terminals will be expected to update their criminal lists from the FBI on a daily or weekly basis, depending upon the facility's rated threat level. In addition, much like PIV cards, employees will have their fingerprints digitally embedded into the TWIC.

Once a shipyard or port worker receives a card, he or she will walk or drive up to an access gate, swipe his or her card through a reader and place a finger on a biometric reader. The readers will verify that the fingerprint matches that embedded in the TWIC. A similar procedure will be required each time that a worker passes through a gate.

While FIPS 201 and TWIC may not yet be perfect, the two are a start in the right direction. Government-conducted background checks and biometrically-embedded smart cards will help ensure that the person seeking access to a port terminal, federal office building or network computer is the person he or she claims to be.

This article originally appeared in the December 2006 issue of Security Products, pg. 70.

Featured

  • Allegion, Comfort Technologies Implement Mobile Credentials at the Artisan Apartment Homes in Florida

    Artisan Apartment Homes, a luxury apartment complex in Dunedin, Florida, recently transitioned from mechanical keys to electronic locks and centralized system software with support from Allegion US, a leading provider of security solutions, technology and services, and Florida-based Comfort Technologies, which specializes in deploying multifamily access control, IoT devices and software management solutions. Read Now

  • Mall of America Deploys AI-Powered Analytics to Enhance Parking Intelligence

    Mall of America®, the largest shopping and entertainment complex in North America, announced an expansion of its ongoing partnership with Axis Communications to deploy cutting-edge car-counting video analytics across more than a dozen locations. With this expansion, Mall of America (MOA) has boosted operational efficiency, improved safety and security, and enabled more informed decision-making around employee scheduling and streamlining transportation for large events. Read Now

  • Security Industry Association Launches New “askSIA” AI Tool

    The Security Industry Association (SIA) has unveiled a brand-new SIA member benefit – askSIA, a conversational AI agent designed to help users get the most out of their SIA membership, easily access SIA resources and find the latest information on SIA’s training and courses, reports and publications, events, certification offerings and more. SIA members can easily find askSIA by visiting the SIA homepage or looking for the askSIA icon in the top left of webpages. Read Now

    • Industry Events
  • Industry Embraces Mobile Access, Biometrics and AI

    A combination of evolving workplace dynamics, technology innovation and new user expectations is changing how people enter and interact with physical spaces. Access control is at the heart of these changes. Combined with biometrics and AI, mobile access control has become increasingly crucial for deploying entry solutions that are seamless, secure and adaptive to user needs. Read Now

  • Sustainable Video Solution Delivered for Landmark City of London Office Development

    An advanced, end-to-end video solution from IDIS, with a focus on reducing waste and costs, has helped a major office development in the City of London align its security with sustainability objectives. Read Now

New Products

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”