SIA Releases Offers Recommendation For Use Of Biometrics In E-Verify Program

The Security Industry Association recently released recommendations for use of biometrics with the federal government’s E-Verify employment verification program.

Security Industry Association members believe implementation of a biometric component to the E-Verify program should reflect the following principles to protect individual privacy and prevent identity theft:

1. Use biometrics to bind an individual to a credential associated with an identity based on presented biometric data and identity documents, which will be associated with a vetted Social Security Number. This will authenticate E-Verify transactions and create trusted audit trails respecting access to privacy data.

  • Provides high assurance that the individual subsequently authenticating is the same person who enrolled.
  • Provides non-repudiation of E-Verify transaction records, including who accessed specific data by date and time.

2. Use biometric authentication of the applicant, post-enrollment, with each subsequent verification of application for employment.

  • Ensures job applicant is associated with only one Social Security number.
  • Confirms individual presenting a Social Security number for employment or identification is the same person who originally enrolled with the Social Security number.
  • Alerts if the live biometrics submitted don’t match the templates stored on the smart card carrier. This can trigger additional adjudication procedures to investigate why two different individuals are associated with a single Social Security number or other I9 identity documents.
  • Deters identity theft for citizens while providing legal aliens with a means to validate their work status.

3. Avoid unnecessary distribution of biometric data by encoding biometric data to a smart card for possession by the person associated with the data. A terminal that performs a 1-to-1 match of a person’s live sample to the smart card data will be used for real-time authentication.

  • Allows the applicant to authorize how the biometric data is used.
  • Prevents unauthorized access to an applicant’s biometric data.
  • Provides a mechanism for the person to possess their biometric data and limit alternative instances to the enrollment database.
  • Protects citizen against identity theft.

4. Allow solutions including a 1-to-1 match with the smart card as a ‘personal vault,’ where an encrypted fingerprint or template is securely stored.

  • Locks sensitive data stored on the card (example: Social Security number) against access so it is not retrievable except after successful match to the card-holder.
  • Removes the need for biometric data ever to be extracted from the card, thereby allowing the smart card to lock it away from any fraudulent retrieval or copy. This will also ensure that the biometric data cannot be used for forensic investigation purposes.

5. E-Verify-sanctioned functions must include controlled distribution of biometric terminals to enable reporting of lost or stolen cards at easily accessible locations (such as the local U.S. Post Office).

  • Provides a value-add function to the card making it more useful and attractive to card holders.
  • Delivers assurances that the E-Verify data is not used for criminal investigation purposes.

6. Biometric data collected at initial enrollment must be stored in an encrypted database. Strong consideration should be given to establishing separate databases that secure the biometric from other personally identifiable information.

7. Utilize the experience and application expertise of industry and, in particular, the Security Industry Association to guide the implementation of biometrics in E-Verify applications.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3