public-private partnerships

Card Overload

Government directives can help private sector determine which access control cards best fit their needs

Government directives were designed to help enhance security, increase government efficiency, reduce identity fraud and protect personal privacy by establishing a government-wide standard for secure and reliable forms of identification issued by the federal government to its personnel.

You can use these directives to help those in the private sector to be better informed. With computer hackers stealing millions of electronic records every year, many Fortune 1,000 companies are trying to secure their networks through the use of public key infrastructure. As such, many are turning to HSPD-12.

The Federal Government

As a result of Sept. 11, 2001, in August 2004, President George W. Bush issued HSPD-12, which established the policy for common identification standards for all federal employees and contractors who require routine or regular scheduled access to federal facilities.

The directive developed a common identification standard that ensures people are who they say they are, so government facilities and sensitive information stored in networks and within physical facilities remain protected. To achieve a higher protection level, HSPD-12 requires agencies to issue smart-card technologies to all federal employees and contractors for access to buildings, facilities and computer networks. In addition, HSPD-12 directed the development of federal information processing standards to define systems to achieve a common identification credential. In accordance with HSPD-12, the FIPS 201 standard, the personal identity verification of federal employees and contractors, establishes the technical requirements for the identity credential that is issued based on sound criteria for verifying a person's identity. It ensures the credential is strongly resistant to identity fraud, tampering, counterfeiting and terrorist exploitation and can be rapidly authenticated electronically.

Following this presidential directive, standards have arisen to drive major changes in card technologies. For example, FIPS 201 defines the PIV and platform interoperability. FIPS 140 defines the requirements and standards for cryptographic modules, which include both hardware and software components for security. Finally, NIST 800-116 defines the use of PIV cards within a physical access control system. From these standards have come other programs, like TWIC, CAC (Department of Defense), FRAC (first responders) and PIV-I (interoperable) for government subcontractors and PIV-C (PIV compatible) for private companies that want to use the card as an employee badge.

A new type of card was developed to support both contactless physical access and contact logical access, commonly referred to as a dual interface card. Both interfaces, contact and contactless, are connected to the same processor chip, providing common security and cost efficiency. For physical access control, the cards can support MIFARE or DESFire emulation and, with the addition of a Prox inlay, also can support legacy proximity technologies.

While MIFARE and DESFire are not used within a PIV deployment, the open and interoperable architecture of the technologies aligns perfectly with the non-proprietary strategy behind HSPD-12.

Public key infrastructure is a set of policies, processes, server platforms, software and workstations used for the purpose of administering certificates and public-private key pairs, including the ability to issue, maintain and revoke public key certificates As a result of HSPD-12, the government has launched major PIV programs to comply with this directive, including TWIC, Department of Veterans Affairs Personal Identity Verification system and GSA USAccess. It also includes two forms of ID: physical access and computer access using the PIN within the card.

The General Services Administration's Office of Governmentwide Policy has been appointed as the Federal PKI Management Authority to manage the design and development, and implement and operate the Production FPKIA.

Homeland Security-trusted Traveler Program

The purpose of the card is to verify your identity by matching the information stored in the card with the information you provided during your enrollment process.

The National Institute of Standards and Technology has issued specific guidance on the implementation and application of physical access control with PIV cards. This guidance is known as SP800-116 and requires the specific use of the strong authentication and other features of the PIV credential for every access control system. The requirements of SP800-116 represent the use of advanced credential and individual identity authentication that is outside of the scope of most existing access control readers and require PKI processing that transcends the operational capabilities of most PACS infrastructure.

A few companies have developed products specifically to meet and exceed the requirements of FIPS201 and SP800-116 and now offer a complete solution in compliance with these standards and directives.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • ISC West 2024 is a Rousing Success

    The 2024 ISC West security tradeshow marked a pivotal moment in the industry, showcasing cutting-edge technology and innovative solutions to address evolving security challenges. Exhibitors left the event with a profound sense of satisfaction, as they witnessed a high level of engagement from attendees and forged valuable connections with potential clients and partners. Read Now

    • Industry Events
    • ISC West
  • Live From ISC West: Day 2

    What a great show ISC West 2024 has been so far. The second day on Thursday was as busy or even more hectic than the first. Remember to keep tabs on our Live From ISC West page for news and updates from the show floor at the Sands Expo, because there’s more news coming out than anyone could be expected to keep track of. Read Now

    • Industry Events
    • ISC West
  • A Unique Perspective on ISC West 2024

    Navigating a tradeshow post-knee surgery can be quite the endeavor, but utilizing an electric scooter adds an interesting twist to the experience. While it may initially feel like a limitation, it actually provides a unique perspective on traversing through the bustling crowds and expansive exhibition halls. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3