The Credential Conundrum

 

Connecting state and local government leaders

<b>DHS Special Report</b> | Agencies are developing a broad mix of credentialing programs to deal with an equally broad range of threats.

Which is better: a complex credential and identity management system with multiple technologies and standards, or a streamlined, one-size-fits-all approach? How about the trade-offs of speed versus security?Disputes over which technology standards should become the norm for identity management programs, or whether the existing menagerie of standards should be retained, have inflamed privacy disputes and spurred industry rivalries.Today, the federal government has multiple identification and credential programs designed to combat terrorism (see box), mostly run by different agencies using different technologies, security standards and processes.It's the best possible solution to protect privacy and improve security, said Kathy Kraninger, director of the Homeland Security Department's Screening Coordination Office.Officials at SCO now are working to sort the various identity management and credential programs into three categories, and identify the preferred standards and technologies for each group, Kraninger said.DHS' technology leadership originally created SCO to consolidate all DHS identity and credential programs into a central organization. But the office has evolved as a support organization for several credential and identity management programs run by other agencies and departments.The technologies used in the various credential programs have raised standards-based issues that enmesh security, funding and legislative mandates, she said.For example, the federal Real ID law, which effectively mandates a secure biometric driver's license that will also serve as proof of citizenship or legal residence, brings together several such issues.Under the proposed Real ID implementation regulations, the licenses themselves would carry biographic data using a nonsecure, two-dimensional bar code.Most states now use the two-dimensional bar code technology, which complies with PDF, a machine-readable technology pattern developed by Symbol Technologies.The PDF-417 bar codes can be read using a commercially available scanner.DHS has acknowledged that the bar code standard's lack of security poses challenges for states as motor vehicle departments roll out their Real ID credentials and the related back-end systems. Similar issues have arisen regarding the data storage standards that apply to the People Access Security Service, or PASS, card program. That joint State Department and DHS program is preparing to issue wallet-size documents that citizens will be able to use to re-enter the country via land ports after trips to Western Hemisphere countries.The program forms an element of State's Western Hemisphere Travel Initiative, a policy to require returning citizens to show secure biometric credentials, such as passports, when they re-enter the country.Citizens have been required to show a passport when re-entering this country from countries in the Western Hemisphere via an airport or cruise ship since Jan. 1.The PASS program is developing a card-format 'passport-lite' for use when re-entering via land borders.State and DHS launched the PASS card project as a cheaper, more convenient alternative to passports that would be especially helpful to residents of border areas who cross into Canada and Mexico frequently.The PASS card program has faced brickbats from lawmakers in both the House and Senate who charge that it will be a costly burden on border region residents. The Real ID program has prompted a campaign to convince state legislatures to condemn the federal requirement.State and DHS, meanwhile, have launched a pilot to test whether Real ID driver's licenses issued by Washington state could also meet the requirements to function as PASS cards.That pilot brings two standards arenas into collision: those used now to issue driver's licenses and the stricter document security standards used by State to prevent passport forgery.Opponents of the Real ID card program have vociferously denounced the technology standards involved as a threat to citizens' privacy rights.'The Real ID is unworkable because it's fundamentally flawed,' said attorney and privacy technology specialist Melissa Ngo, senior counsel and director of the identification and surveillance project at the Electronic Privacy Information Center.'The Real ID wants to be the one ID for everything,' said Ngo, who argued that the purpose behind the new credential standard is to create a single national identity card, which could then be an easy target for terrorists.Privacy activist Jim Dempsey, policy director at the Washington-based Center for Democracy and Technology, sees potential security issues with the radio frequency identification (RFID) technology standard proposed for the PASS cards.Information on an RFID card can be read from a distance, 'making it more likely that data can be acquired for unauthorized purposes,' he said.Dempsey also condemned DHS' proposed use of the PDF-417 standard for Real ID driver's licenses.'The Real ID card can be scanned by commercial entities and essentially used to track individuals and compile information about them,' Dempsey said.Funding is another issue preventing identification and credential programs from being as secure as they could be, said Steve Cooper, former DHS chief information officer.'In some cases, there is not enough money in one fell swoop to put a secure credentialing program in place,' Cooper said.The American Red Cross, where Cooper currently is CIO, is not able to fully be a part of DHS' credential programs because the nonprofit organization lacks the funds, he said.Stephen Price-Francis, vice president of business development at LaserCard, the Mountain View, Calif.-based contractor producing Mexican laser visas and U.S. green cards used by noncitizens, said the lack of a uniform standard and technology infrastructure undermines credential security.'While a number of machine-readable technologies are discussed for the border and security environments, the practical reality today is that most ID documents are inspected visually by human beings,' Price-Francis said. The existing crazy-quilt standard framework will remain 'until a ubiquitous infrastructure for automatic document authentication exists,' he said.Other groups representing industry interests see technology standardization as a way to improve security and lower costs.The Smart Card Alliance strongly advocates using smart cards instead of RFID technology for identification and credentialing of human beings, said the organization's executive director, Randy Vanderhoof.Smart cards have a limited range from which their data can be accessed, and data on the cards can be secured from eavesdropping via an encryption technique known as Basic Access Control.State adopted smart cards and Basic Access Control for the electronic passports it now is distributing to citizens.The e-passports use the International Standards Organization 1443 standard that Vanderhoof's group advocates for all federal identification management programs, including the PASS card and Real ID driver's licenses.'Having one group of citizens with electronic passports using one security credential and having the rest of the citizens being less secure with an entirely different [PASS or Real ID] technology platform doesn't live up to protecting citizens,' Vanderhoof said.'In addition, using two different types of technologies for identification and credentialing creates a double standard and two different technology platforms to support at the border,' he said.'We are working very hard to educate the DHS and the [Customs and Border Protection] about the error in their present selection' of using RFID for identity management and credential programs, said Neville Pattinson, vice president of government affairs and standards at Gemalto North America.But Kraninger sees serious security issues with using only a single technology standard. 'We should not, for privacy issues, try to bring [information] into one national ID card system. If you choose one way to operate, then you are driving to a universal ID card,' she said.For each identity management program, DHS determines what personal information would be included, and what business processes and physical features the card would need. From that, it decides on technologies and standards, Kraninger said.

A Stacked Deck

Federal agencies have no fewer than 22 electronic credentialing programs in use, in testing or in the planning stages. For details on the programs, go to GCN.com/787.


Citizenship and Immigration Services

Employee eligibility verification system

DHS/SSA information-sharing database

Mexican laser visas


Coast Guard

Merchant Mariner's Document (MMD)


Customs and Border Protection

Customs-Trade Partnership Against Terrorism (C-TPAT)

NEXUS

Free and Secure Trade (FAST)

Secure Electronic Network for Travelers Rapid Inspection (SENTRI)


Federal Aviation Administration

Airmen Certification


Homeland Security Department

Real ID

U.S. Visit

Enhanced driver's licenses

Homeland Security Presidential Directive-12


Social Security Administration

Fraud-resistant Social Security cards


State Department

Passport Card (PASS Card)

E-Passport National Security Exit Entry

Registration System (NSEERS)

Student and Exchange Visitor Information System (SEVIS)

Z-Visa


Transportation Security Administration

Transportation Worker Identification Credential Program Registered Traveler

Hazardous Materials Endorsement Threat Assessment Program (HAZMAT)

Secure Flight

Other stories in this report focus on cross-agency homeland security technology standards in border technology, identity management and credential programs, fusion centers and the multibillion-dollar Integrated Wireless Network program to build a nationwide law enforcement radio network for voice and data.

In each area, the potential for efficiencies and mission improvements from common technology standards force federal information technology manages to make thorny choices involving missing standards, immature standards and the relative merits of settling on one or several systems to deal with specific problems.

'We should not, for privacy issues, try to bring [information] into one national ID card system. If you choose one way to operate, then you are driving to a universal ID card.' ' Kathy Kraninger, DHS' Screening Coordination Office













Mix of issues








































































NEXT STORY: IT challenges meet at the border

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.