Transportation Worker Identification Credential (TWIC) Steve Parsons Deputy Program Manager, TWIC July 27, 2005

Similar documents
Office of Transportation Vetting and Credentialing. Transportation Worker Identification Credential (TWIC)

Using the Prototype TWIC for Access A System Integrator Perspective

Interagency Advisory Board Meeting Agenda, February 2, 2009

TWIC Transportation Worker Identification Credential. Overview

Strategies for the Implementation of PIV I Secure Identity Credentials

TWIC Update to Sector Delaware Bay AMSC 8 June 2018

000027

Physical Access Control Systems and FIPS 201

Interagency Advisory Board HSPD-12 Insights: Past, Present and Future. Carol Bales Office of Management and Budget December 2, 2008

Interagency Advisory Board Meeting Agenda, Wednesday, May 23, 2012

Multiple Credential formats & PACS Lars R. Suneborn, Director - Government Program, HIRSCH Electronics Corporation

Credentialing Project Technical Architecture

Biometric Use Case Models for Personal Identity Verification

Next Generation Physical Access Control Systems A Smart Card Alliance Educational Institute Workshop

Unified PACS with PKI Authentication, to Assist US Government Agencies in Compliance with NIST SP (HSPD 12) in a Trusted FICAM Platform

Securing Federal Government Facilities A Primer on the Why, What and How of PIV Systems and PACS

IMPLEMENTING AN HSPD-12 SOLUTION

Revision 2 of FIPS 201 and its Associated Special Publications

Next Generation Physical Access Control Systems A Smart Card Alliance Educational Institute Workshop

Single Secure Credential to Access Facilities and IT Resources

Interagency Advisory Board Meeting Agenda, Wednesday, February 27, 2013

TWIC / CAC Wiegand 58 bit format

Paul A. Karger

TWIC Program Overview for the Smart Cards in Government Conference March 10, 2004

(PIV-I) Trusted ID across States, Counties, Cities and Businesses in the US

FIPS and NIST Special Publications Update. Smart Card Alliance Webinar November 6, 2013

DHS ID & CREDENTIALING INITIATIVE IPT MEETING

Leveraging HSPD-12 to Meet E-authentication E

FiXs - Federated and Secure Identity Management in Operation

TWIC Readers What to Expect

Secure Solutions. EntryPointTM Access Readers TrustPointTM Access Readers EntryPointTM Single-Door System PIV-I Compatible Cards Accessories

Using PIV Technology Outside the US Government

Will Federated Cross Credentialing Solutions Accelerate Adoption of Smart Card Based Identity Solutions?

TWIC Reader Technology Phase

To be covered: S&T Intro TTWG. Research/Pilots. Scope Goals Report

Considerations for the Migration of Existing Physical Access Control Systems to Achieve FIPS 201 Compatibility

CREDENTSYS CARD FAMILY

Physical Access Control Systems and FIPS 201 Physical Access Council Smart Card Alliance December 2005

June 17, The NPRM does not satisfy Congressional intent

Smart Card Alliance Comments and Considerations on Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance

PIV Data Model Test Guidelines

Helping Meet the OMB Directive

Version 3.4 December 01,

Guidelines for the Use of PIV Credentials in Facility Access

Smart Cards and Authentication. Jose Diaz Director, Technical and Strategic Business Development Thales Information Systems Security

How to Plan, Procure & Deploy a PIV-Enabled PACS

EU Passport Specification

ITU-T SG 17 Q10/17. Trust Elevation Frameworks

TWIC Reader Hardware And Card Application Specification May 30, 2008

Match On Card MINEX 2

Technical Implementation Guidance: Smart Card Enabled Physical Access Control Systems Draft Version 2.3E

Policy on Standardization of Airport Access Security 14.May.2008

National Transportation Worker ID Card (TWIC) Credentialing Direct Action Group Functional Requirements DRAFT

PKI is Alive and Well: The Symantec Managed PKI Service

Module 5: Smart Card Usage Models Identity, Security and Access Control

Emergency Response Official Credentials: An Approach to Attain Trust in Credentials across Multiple Jurisdictions for Disaster Response and Recovery

State of the Industry and Councils Reports. Access Control Council

DoD & FiXs : Identity Superiority

Federated Access. Identity & Privacy Protection

MAESON MAHERRY. 3 Factor Authentication and what it means to business. Date: 21/10/2013

FPKIPA CPWG Antecedent, In-Person Task Group

DoD Common Access Card Convergence of Technology Access/E-Commerce/Biometrics

LDS2 Concept and Overview: Exploring Possibilities in Travel Border Clearance

I N F O R M A T I O N S E C U R I T Y

Interagency Advisory Board Meeting Agenda, Wednesday, June 29, 2011

Mandate. Delivery. with evolving. Management and credentials. Government Federal Identity. and. Compliance. using. pivclasss replace.

Biometrics. Overview of Authentication

Certification Authority

An Overview of Draft SP Derived PIV Credentials and Draft NISTIR 7981 Mobile, PIV, and Authentication

Keith Ward Northrop Grumman IT Smart Card Security Solutions June 04, 2002

Identity Management as a Service

IAB Minutes Page 1 of 6 April 18, 2006

Interagency Advisory Board Meeting Agenda, February 2, 2009

HITPC Stage 3 Request for Comments Smart Card Alliance Comments January, 14, 2013

The Leader in Unified Access and Intrusion

Strong Authentication for Physical Access using Mobile Devices

g6 Authentication Platform

Unlocking The CHUID. Practical Considerations and Lessons Learned for PIV Deployments. Eric Hildre 07/18/2006

GLOBALPLATFORM CASE STUDY. Overview. Development of the Solution. The Standard for Smart Card Infrastructure

About MagTek. PIN Entry & Management

Smart Cards and Biometrics in Privacy- Sensitive Secure Personal Identification Systems

Sphinx Feature List. Summary. Windows Logon Features. Card-secured logon to Windows. End-user managed Windows logon data

I N F O R M A T I O N S E C U R I T Y

Interfaces for Personal Identity Verification Part 1: PIV Card Application Namespace, Data Model and Representation

Verifying emrtd Security Controls

Interagency Advisory Board Meeting Agenda, April 27, 2011

Lecture 9 User Authentication

There is an increasing desire and need to combine the logical access and physical access functions of major organizations.

PKI-An Operational Perspective. NANOG 38 ARIN XVIII October 10, 2006

Interagency Advisory Board (IAB) Meeting. August 09, 2005

FICAM in Brief: A Smart Card Alliance Summary of the Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance

PIN Entry & Management

TWIC or TWEAK The Transportation Worker Identification Credential:

TWIC Operational Biometric Solution. Presented by Terry Wheeler

Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance

DFARS Requirements for Defense Contractors Must Be Satisfied by DECEMBER 31, 2017

Interagency Advisory Board Meeting Agenda, Tuesday, November 1, 2011

Strategies for the Implementation of PIV I Secure Identity Credentials

Corporate Commitment to Excellence

IDCore. Flexible, Trusted Open Platform. financial services & retail. Government. telecommunications. transport. Alexandra Miller

Transcription:

Transportation Worker Identification Credential (TWIC) Steve Parsons Deputy Program Manager, TWIC July 27, 2005

Who Am I? How do you know? 2

TWIC Program Vision A high-assurance identity credential that is trusted and used across all transportation modes for unescorted physical access to secure areas and logical (cyber) access to systems. Goals Improve security Enhance commerce Protect personal privacy 3

TWIC Priorities Strong focus on identity assertion Establish and maintain the integrity of the chain of trust for identity management Bind: cardholder-credential-biometric-threat assessment-valid issuer If it s printed on the card, it s on the chip(s) Drive excellence in use of biometrics for physical access solutions ICAO/ANSI/ISO standard photograph ANSI standard fingerprint minutia ANSI standard fingerprint pattern ANSI standard IRIS 4

Prototype An original type, form, or instance serving as a basis or standard for later stages. An original, full-scale, and usually working model of a new product or new version of an existing product. An early, typical example. Source: Dictionary.com (Copyright 2005, Lexico Publishing Group, LLC. All rights reserved). 5

TWIC Phase III: Issuance Locations 6

Prototype Phase Workflow 7

Lessons Learned Functional Technical Programmatic 8

Functional - Trusted Agents - Enhance identity vetting - Standard Operating Procedures essential - Adjudication requirements - Sponsorship - User Acceptance / Functional Qualification Testing 9

Technical Technical standards / specifications / guidelines Maximize Commercial Off The Shelf (COTS) components Biometrics Standards Conforming products Alternatives Common topology Document Security Alliance Physical Access Control System (PACS) Integration Readers Infrastructure readiness Legacy Cardholder Conversion 10

Programmatic - Personnel transition/turnover - MOAs - GFE/P must be ready - Independent Verification / Validation (IV&V) - Privacy (independent assessment) - Volunteer participants - Physical presence / frequent communication - Plan for system demos and presentations - Conformance to HSPD-12 glad we did 11

TWIC Process Employee 2 Enrollment Centers Employers 1 3 Identity Management System (IDMS) 6 4 Database Queries 1:n 1:n biometric biometric search search Name-Based Name-Based Terrorist-Focused Terrorist-Focused Risk Risk Assessment Assessment 5 * Future CHRC Card Production Facility 8 Employee 7 Local Facilities Numbers Indicate Workflow Order 12

Summary TWIC is a high-assurance identity credential ( above the line ) TWIC was used as reference model during development of FIPS 201 (implements HSPD-12) Scalable - able to serve multiple communities of interest Local facilities grant/deny access (i.e., below the line ) Biometrics can help protect personal privacy / improve security Reliance on open, standards-based technologies improve opportunities for interoperability 13

For additional information Look at the TWIC Website at: http://www.tsa.gov/public (click on Industry Partners ) AND E-mail the TWIC Program at Credentialing@dhs.gov 14

Prototype Credential TWIC = secure and reliable form of identification Contactless Chip Magnetic stripe with FASC-N* *Federal Agency Smart Credential Number Integrated Circuit Chip (ICC) Linear 1D Barcode PDF-417 with Name, GUID* *Global Unique ID 16

Overt Security Features 17

Covert Security Feature Ultraviolet Image 18

Contact Chip Data Model Card information General information Issuer ID Issuance Counter Issue Date Expiration Date Card Type Issuer Identity Assertion Cardholder Unique ID (CHUID) - PACS Reference biometric Security object FASC-N GUID First name Middle name Last name Digital Photograph Operational biometric directory PKI Signature PKI Encryption Operational biometric 1 Operational biometric 2... Hash table Issuer public key information Issuer asymmetric signature CBEFF headers ANSI standard left index fingerprint template ANSI standard right index fingerprint template Additional post issuance information... Training/Qualifications Killer apps (e.g., First Responders, Armed LEOs) Mandatory issuer controlled data Post issuance optional 19

Contactless Chip Data Model Issuer ID Issuance Counter Issue Date Expiration Date First name Middle name Last name FASC-N GUID All containers use CBEFF Card type Issuer Identity Assertion Card information General information Cardholder Unique ID (CHUID) - PACS Reference biometric Security object Digital photograph - ANSI/ICAO standard Both index fingerprints - ANSI standard minutia Both index fingerprints - ANSI standard pattern Hash table Current solution = DESfire Training/Qualifications Killer apps Issuer public key information Issuer asymmetric signature Mandatory issuer controlled data Post issuance optional 20

HSPD-12: Secure and Reliable Forms of Identification Issued based on sound criteria for verifying an individual employee's identity Strongly resistant to identity fraud, tampering, counterfeiting, and terrorist exploitation Can be rapidly authenticated electronically Issued only by providers whose reliability has been established by an official accreditation process. 21

TWIC Kiosk Provides: - Pre-enrollment and printing locator/appt. card - Any other web-based functionality (e.g. card status, lost card reporting, etc.)

Mobile Enrollment Workstation