NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Collaboration
Slice by Program

US agencies scramble to meet security deadline

By: Ellen Messmer, Network World (US)(09-18-2006)

Two years ago U.S. President George Bush ordered the federal government to be ready by this Oct. 27 to issue a standards-based identity card that federal employees and government contractors would use for computer and building access.

The intention of the order, known as the Homeland Security Presidential Directive 12 (HSPD-12), was to usher in a new generation of encryption-based smart cards with biometrics and photos to be used government-wide for physical and logical access.

The Personal Identity Verification (PIV) program, as it's come to be called, has federal agencies scrambling to issue PIV identity cards by the deadline, but it is unclear if they will be able to meet that goal.

For one, the US$104 million HSPD-12 services contract, awarded last month by the General Services Administration (GSA) to systems integrator BearingPoint to provide PIV enrollment services and identity cards, is up in the air.

Competitors Lockheed Martin, Xtec and Electronic Data Systems filed legal protests a week ago. When a contract is protested - a common occurrence in the world of government - the work usually stops. But not this time.

To meet the Oct. 27 deadline, the GSA - designated by the White House Office of Management & Budget (OMB) last year as the executive agent for governmentwide acquisitions of HSPD-12-related IT- is plowing on.

The GSA says BearingPoint has been instructed to go ahead as planned and open PIV enrollment centers in Washington, D.C., New York, Atlanta and Seattle.

"The whole intent is to improve the security of the U.S.," says Michel Kareis, PIV program manager at the GSA. "The GSA is setting these centers up as a shared services solution so agencies don't have to set them up on their own."

Kareis says she expects about 400,000 government employees to get their PIV cards from these services by appearing in person with proof of identity, and have their photo and fingerprints taken.

The GSA, which hopes to see the government resolve the protests against BearingPoint by the end of the month, intends to add 100 service centers in the United States, probably at government-owned facilities that it runs.

Under the OMB guidelines, federal agencies have to acquire the PIV products and services from GSA-approved lists, and high-tech contractors have been lining up seeking approval.

That process requires vendors to have products tested in government labs to see if they meet technical requirements, says Scott Price, group senior vice president in General Dynamics' IT group. General Dynamics was approved in July as an HSPD-12 system provider.

Defining the PIV technology has been no small matter. Two years is scant time to establish government standards and conformance testing of products, including smart cards, readers, biometrics, middleware and public-key encryption.

But the National Institute of Standards and Technology (NIST) has issued the necessary standard, known as the Federal Information Processing Standard 201, and lined up about a dozen labs to test FIPS 201 conformance for vendor PIV products.

These third-party test facilities include Atlan Laboratories, BKP Security Labs, BT Crytographic Module Testing Laboratory, Coact, Cybertrust's ICSA Labs and InfoGard Laboratories.

But here, too, it is down to the wire, because the labs aren't yet officially accredited. "The labs are in a probation period," says Bill MacGregor, NIST PIV program manager, about the dozen facilities undergoing the accreditation process. MacGregor says he expects the process to be finalized by the end of the month.

In the meantime, NIST is publishing prevalidation product lists that include offerings from Oberthur Card Systems, Gemalto (formerly Gemplus), ActivIdentity, SETECS, ImageWare Systems, Sagem and RSA Security. "In the middleware testing, we basically define an API for commercial products for PIV cards," MacGregor says.

Ed MacBeth, senior vice president for marketing and business development at ActivIdentity, says the NIST test-validation process has involved a "self-certification process" that entails running products - such as ActivIdentity's ActivClient, which is smart-card middleware - through testing process and procedures that NIST has published.

"It's like submitting a drug for approval by the FDA," MacBeth says. "You exhibit your results."

The NIST test regimen won't involve testing every line of code in PIV applications, because this isn't required under the FIPS 201. "FIPS 201 doesn't standardize on back-end interfaces," MacGregor points out.

The NIST PIV standard is based on the most recent ANSI card and biometrics standards. The FBI has been testing the fingerprint biometrics conformance in PIV products in FBI labs.

The whole PIV technical effort constitutes "a makeover of the marketplace," MacGregor says, adding that the government PIV push should bring interoperability to smart-card-based identity management. "Much of the biometrics products have been based on proprietary matching methods and storage methods," he points out.

The PIV cards, readers and middleware should allow for "government card portability," MacGregor says. The goal is that any PIV card that's good at one agency should be able to be used in any PIV application at another agency that's PIV-compliant to the extent that applications define themselves closely by middleware.

But will the gear be interoperable? To find out, NIST last May invited PIV product vendors to NIST headquarters in Gaithersburg, Md., to discuss their products and demonstrate how well they worked together.

About four dozen companies supplying PIV cards, enrollment and identity management systems, issuance and printing, contact readers, contactless readers and physical-access control systems, PKI and biometrics showed up.

According to MacGregor, a month-long examination left him fairly optimistic. However, he noted it did prompt NIST to release a short "interoperability definition" of two pages defining further card-to-reader recommendations.

How PIV is to connect into any legacy systems is outside the scope of the FIPS 201 standard and will have to be addressed by agencies and their vendor partners, MacGregor says.

The Department of Defense, which over several years has issued millions of its own Common Access Cards (CAC) which are not FIPS 201-compliant, won't have to meet the Oct. 27 deadline the same way other agencies must. That's because the Defense Department, along with a handful of other agencies, including the Department of Veterans Affairs (VA), has received special exemption from the OMB, though it must submit a plan for migration.

But the Defense Department is expected to add FIPS 201 support to the CAC card in order to share necessary identity data with PIV applications. "Defense Department would be the first to admit they are not compliant with FIPS 201, but they're working toward it," says Tom Greco, vice president at Cybertrust, which is providing public-key infrastructure and certificate management as part of the BearingPoint team.

Handheld reader

Some vendors are building products to support the Defense Department and FIPS 201-based cards. CoreStreet, for example, this week announced Pivman System, a handheld mobile device intended as a PIV and Defense Department card reader to be used by government personnel responding to emergencies.

"If there's a disaster or emergency, there will be a lot of people going to the scene to render help," says Phil Libin, CoreStreet's president. "The question is, who gets admittance?"

The Pivman handheld device can be used to check identity of personnel based on the holder's PIV card, with authentication provided directly through Pivman and with additional information stored in remote databases that can be accessed over a Wi-Fi or General Packet Radio Service network.

If needed, the Pivman mobile device can supply information obtained from back-end databases about the card holder based on role, such as firefighter or medical personnel. The Department of Homeland Security is said to be testing the Pivman System.

ActivIdentity, whose card-management software supports the CAC and the Government Smart Card Interoperability Standard, an earlier government standard said to be used in a half-million smart cards at the VA, views PIV as an evolution.

"PIV establishes a rigorous process for identity verification," Macbeth says. PIV also will touch the private sector, such as Northrup Grumman, because government contractors will have to use it, he points out. But it's uncertain how quickly it would be adopted by companies in the private sector not falling under the HSPD-12 mandate.

The transition from any older technologies used for physical or logical access is going to be a slow process, according to many.

"It can't all be done on Day One," MacGregor says. "There's a transition that has to occur, and it will take a long time to move from older magnetic-strip cards that some agencies use for physical access to PIV."


Read about the state of Security and Emergency Services in Canada
Learn about the Pal Initiative

Read more articles on Government wide security

More news on Canadian Government Technology

Complete coverage on Canada Inter-Government News site map

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada