FIPS 201 News
Audio from August 25 IAB meeting online now
The August meeting of the influential Government Smart Card Interagency Advisory Board (IAB) was recently held in Washington D.C. FIPS201.com was on hand to cover the event and has provided, as a service to the IAB and the smart card community, an audio recording of the presentations. Click on the link below to access a list of audio and accompanying PowerPoint slides (in pdf format).
Government Smart Card Interagency Advisory Board (IAB) Meeting
Opening Remarks
Tim Baldridge, NASAMP3: click here
Digital Identity in the States: Advancing an Interoperable National Framework
Doug Robinson, NASCIOPDF: click here
Due to technical difficulties no audio is available for this presentation.
PIV Card test suite
Tim Polk/ David Cooper, NISTPDF: click here
MP3: click here
Understanding the implementation requirements of SHA 256
Tim Polk, NISTPDF: click here
Due to technical difficulties no audio is available for this presentation.
Update Special Publications supporting FIPS 201
Bill Macgregor, NISTPDF: click here
Due to technical difficulties no audio is available for this presentation.
Understanding the differences in PIV, PIV-I, PIV-C
Tim Baldridge, NASAPDF: click here
Due to technical difficulties no audio is available for this presentation.
Closing Remarks
Tim Baldridge, NASADue to technical difficulties no audio is available for this presentation.
New Schlage smart credential readers unveiled
Ingersoll Rand Security Technologies announced the availability of a new line of Schlage contactless smart credential readers - operating on 13.56 MHz frequency – and designed to address the industry’s current requirements while providing a foundation and scalability for future applications.
The new Schlage contactless smart credential readers provide improved security and support all applicable ISO 14443 and 15693 standards. They leverage MIFARE DESFire EV1 technology, and are encrypted with AES 128-bit diversified keys and include mutual authentication and a message authentication code (MAC) to ensure that data is safe.
The new Schlage readers, when used with new Schlage smart credentials, provide a baud rate transfer of up to 848 kbps between the credential and reader. These readers also come standard as FIPS 201/ PIV II compliant readers, ready to be used in government applications:
The SXF2200 Mid-Range Contactless Smart Credential Reader is ideal, with its provided read range, for mounting on single gang U.S. electrical boxes.
The SXF2210 Mid-Range Contactless Smart Credential Reader is for higher security applications where two factor (card and/or pin number) authentications are desirable.
SecuGen releases biometric scanner and card reader in-one solution
SecuGen, a developer of biometric technology solutions, has announced the availability of its SecuGen iD-USB SC/PIV, a USB-connectible device that is capable of scanning fingerprints and smart cards and is FIPS 201/PIV compliant.
SecuGen is targeting its new offering at the large number of government and commercial projects that require both biometric and smart card capabilities in the solutions they choose. The new unit is now listed on the General Services Administration’s FIPS 201 Approved Products List.
Some of the aspects of the new device that SecuGen is touting include its compliance with different standards.
Its optical fingerprint sensor is certified to meet the FBI’s Image Quality Specifications. Additionally, the reader comes with drivers Windows, Linux and various embedded operating systems allowing for more choice from end users of what to use as the computer to run the device.
Audio from July 28 IAB meeting online now
The July meeting of the influential Government Smart Card Interagency Advisory Board (IAB) was recently held in Washington D.C. FIPS201.com was on hand to cover the event and has provided, as a service to the IAB and the smart card community, an audio recording of the presentations. Click on the link below to access a list of audio and accompanying PowerPoint slides (in pdf format).
Government Smart Card Interagency Advisory Board (IAB) Meeting
Opening Remarks
Tim Baldridge, NASAMP3: click here
Research Collaboration in the Cloud: How NCI and Research Partners Are Improving Business Processes using Digital Identities
Sherry Ansher, NIH/NCI and Cindy Cullen, CTO Safe Bio-PharmaPDF: click here
MP3: click here
Minimum Standards for Proof and Verification of Personal Identity
Graham Whitehead, NAPSOPDF: click here
MP3: click here
The status and future plans for the GSA Shared Service
Steve Duncan, MSO DirectorPDF: click here
MP3: click here
The ICAM Return on Investment (ROI) WG
Tim Gaines, ICAM ChairPDF: click here
MP3: click here
Proposed Federal Profile for SAML 2.0 for LOA 1 through 4
Tim Baldridge, FICAM AWGPDF: click here
MP3: click here
Planned changes to the Federal PKI
Judy Spencer, FICAM Co-ChairPDF: click here
MP3: click here
TSCP Implementation Pilots to demonstrate NTSIC Goals & Objectives
Keith WardPDF: click here
MP3: click here
Closing Remarks
Tim Baldridge, NASAMP3: click here
Feds schedule PIV information sharing day
In order to share information about various deployments and uses of PIV credentials there will be an information sharing day for federal officials on Aug. 4. The purpose of the ICAM Information Sharing Day is to provide an forum for agencies to understand and share information related to implementation activities being taken by early adopters of ICAM programs.
The goal of the event is to share stories and information about early ICAM adopters and minimize the learning curve for other agencies. The information sharing day is sponsored by the CIO Council/ISIMC and USDA.
The ICAM Information Sharing Day will take place at the Jefferson Auditorium at the U.S. Department of Agriculture located at 14th and Independence Sts NW, in Washington, DC on Aug. 4, from 9:00 am till 4:00 pm.
More information about the event can be found here.
DOJ taps Hirsch for ID systems
Hirsch Electronics announced the award of $4 million in orders to supply U.S. Department of Justice agencies with Hirsch security systems. The majority of the revenue associated with the orders was recognized within the second quarter 2010. Notice of the awards was first made public by the General Services Administration pursuant to Federal disclosure regulations.
Hirsch supplies solutions for security management and access control to a number of federal agencies. In particular, U.S. government customers rely on Hirsch to provide solutions that help them address growing threats and comply with new standards.
Aware announces supplying of biometric technology to government agency
Aware Inc. has announced it has supplied a major U.S. government agency with client and server-based software products for the personal identity verification (PIV) employee credentialing system implemented by IT services firm Jacob & Sundstrom.
The solution Aware has sent is their Universal Registration Client (URC) and their Biometric Services Platform (BioSP) which through working together are to provide enterprise-wide enrollment of employees into the PIV system as well as offering centralized data structuring and workflow for the issuance of the employee credentials.
In the system provided to the agency, the URC will handle enrollment and capture of biometric information such as facial images, digital signatures and fingerprint scans as well as scans of an employees I9 form. After an employee is enrolled, the BioSP provides card-based password access control to whichever systems the agency decides as well as processes any data sent from the URC system.
GSA releases info request for PIV
The General services Administration is seeking information from vendors relating to Personal Identity Verification (PIV) services.
The GSA wants to review different PIV scenarios for 2011 and beyond. This includes government furnished systems managed by an integration contractor, government-owned and operated services, contractor-owned-and-operated services, or some combination of the three.
The deadline for responding to the information request is July 28. The document can be found here.
VA facility deploys Codebench
Codebench Inc. announced that the Department of Veterans Affairs Financial Services Center in Austin, Texas has deployed Codebench’s PIVCheck Plus and Certificate Manager software to check and authenticate Personal Identity Verification cards for employees at its new facility.
By deploying Codebench’s PIVCheck Plus Software, in conjunction with the Software House C•CURE 800/8000 physical access control system, the VA’s Financial Services Center is using the PIV card as a single card access control solution facility-wide. Card holders use the PIV ID card to gain access into the building and verify privileges once inside the facility.
The Financial Services Center is running a pilot on using the PIV card to log onto their computers. Results thus far are excellent, and they expect full implementation of systems access using the PIV card by December 2010.
Codebench’s PIVCheck Plus software has been used to read, validate, authenticate and then register each cardholder’s PIV card into the C•CURE 800/8000 database without any manual data entry. Codebench’s PIVCheck Certificate Manager is a PC-based application that, after registration, re-validates imported cardholder certificates on a periodic basis. It checks the revocation status of the card, enabling the system to revoke access privileges on the spot.
Systems integrator Tech Systems Inc., Duluth, Ga., installed the system for the Veterans Affairs Financial Services Center, a facility that opened in Austin in 2009.
PIVCheck provides three-factor authentication, managing the acquisition of cardholder data from a smart card and performing off-card biometric matching. The software uses an asymmetric key authentication scheme to identify forged or cloned cards. Digital certificates may be verified by querying the issuer’s validation authority or an OCSP/SCVP responder. PIVCheck is FIPS 201-certified in several of the NIST SP 800-116 categories, including PIV Authentication System and Caching Status Proxy.
Audio from June 29 IAB meeting online now
The June meeting of the influential Government Smart Card Interagency Advisory Board (IAB) was recently held in Washington D.C. FIPS201.com was on hand to cover the event and has provided, as a service to the IAB and the smart card community, an audio recording of the presentations. Click on the link below to access a list of audio and accompanying PowerPoint slides (in pdf format).
Government Smart Card Interagency Advisory Board (IAB) Meeting
Opening Remarks
Tim Baldridge, NASAMP3: click here
ABA Working Group Update
Tom SmedinghoffPDF: click here
MP3: click here
GSA ICAM Implementation
Bill Erwin, GSAPDF: click here
MP3: click here
Status Update: Technical Transition Working Group (TTWG)
Karyn Higa Smith, DHSPDF: click here
MP3: click here
DCTC Taxicab Smart Meter Solution/DC PIV-I Update
Stephan Papadopulos, DC GovernmentPDF: click here
MP3: click here
NIST SP 800-131 Discussion
Alan Roginsky, NISTPDF: click here
MP3: click here
Closing Remarks
Tim Baldridge, NASAMP3: click here
Government Smart Card Interagency Advisory Board (IAB) Breakout Session
Moving Forward - Part “B”
FIPS 201-2, ICAM part “B” and PIV–I
This is a continuation of the April 1st breakout session and contains current status and topics to enable industry to create the best possible solutions.
ICAM Part “B”, FIPS 201-2 and SP800-116 are triggering significant investment in product procurement as well as system development. This timely and important session includes presentations from Smart Card Alliance Physical Access Council, Deloitte, OCFW, ID Technology Partners and Security Industry Association, SIA.
Relevant topics include what is on the horizon for FIPS 201 PIV–I, ICAM Part B, PIV–I Identity beyond the Federal enterprise and an open forum discussion on how to best consolidate these functions to an operational solution:
Short Introduction (Lars Suneborn, Hirsch Electronics and Chair of the Physical Access Council)
FIPS 201-2 Summary of submitted comments and suggestions (Lars Suneborn, Hirsch Electronics)
ICAM Part “B”–the objective and status of ICAM Part “B” (Shelly Hartsook, Deloitte)
PDF: click hereThe Impact of ICAM on Enterprise infrastructure and applications (Sal D’Agostino, IDmachines)
PDF: click herePACS in the ICAM era–Authentication mechanisms using secure, contactless Card-to PACS communication (Gilles Lisimaque, IDTP)
PDF: click hereOSIPS integration standards (Steve Van Till, SIA)
PDF: click herePIV–I Deployment in the ICAM environment: State level deployment of trusted identity credentials (Bob Donelson- Organizational Change, Future Workplace, OCFW)
PDF: click hereBirds-of-a-Feather Discussion: Additional deployment opportunities for secure ID credentials at State and private enterprises
From 4:00PM to 5:30PM, the PIV-I WP Project WG have a room available for an in-person working session at the American Institute of Architects (AIA) building.
NOTE: The CSCIP/Government smart card industry certification exam will be administered immediately after this session at 4:15PM.
The Legal Challenges of Federated Identity
This session will provide an overview of the legal issues that need to be addressed in a federated identity model, ranging from liability risk to privacy, and models for addressing those issues. It will include an interactive discussion and Q & A.
Session Chair: Tom Smedinghoff

