TWIC Update to Sector Delaware Bay AMSC

Slides:



Advertisements
Similar presentations
For Joe Broghamer Philip S. Lee May 5, 2005 Implementing PIV Specifications HSPD-12 Workshop.
Advertisements

Card and Reader Overview Gerald Smith Sr. Consultant ID Technology Partners.
Current Technology and the TWIC Program Walter Hamilton Chairman, International Biometric Industry Association Sr. Consultant, Identification Technology.
1 1 A Synopsis of Federal Information Processing Standard (FIPS) 201 for Personal Identity Verification (PIV) of Federal Employees and Contractors Presentation.
Alicia Albright, Spencer Ruch, Jim Knapp, Brian Holkeboer, Anthony Santilli.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
USCG Enforcement for the Implementation of TWIC
Department of Labor HSPD-12
Cryptography Usage in TWIC (Draft v4 8Dec06)
Business Transformation Redefined | 1 PASP®ID solution for DLLR's Division of Occupational and Professional Licensing -Powered by manageID®
Computer Security Biometric authentication Based on a talk by Dr J.J. Atick, Identix, “Biometrics in the Decade of Security”, CNSS 2003.
Background Studies Division Office of Inspector General
Biometrics in New Zealand Passport issuing Border crossing System and information access Building access.
Federal Information Processing Standard (FIPS) 201, Personal Identity Verification for Federal Employees and Contractors Tim Polk May.
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
PIV Data Model Testing Ketan Mehta March 3, 2006.
Liberian Registry INTERTANKO ASSOCIATES COMMITTEE MEETING March 29, 2006.
Finalize RESTful Application Programming Interface (API) Security Recommendations Transport & Security Standards Workgroup January 28, 2014.
GSA Expo 2009 Impact of Secure Flight Program on DoD Travel Mr. George Greiling GSA Expo June 2009.
2009 Indiana Election Administrator’s Conference Statewide Voter Registration System (SVRS) Project Update December 2,
NASA Personal Identity Verification (PIV) NASA Personal Identity Verification (PIV) High Level System Overview Tice F. DeYoung, PhD 14th Fed/Ed Workshop.
May 30 th – 31 st, 2006 Sheraton Ottawa. Microsoft Certificate Lifecycle Manager Saleem Kanji Technology Solutions Professional - Windows Server Microsoft.
Biometric Access Control in TWIC Read Hardware and Card Application Specification Roger Roehr.
1 Scanner 1 June 2009 Community Visitor Management Simple Seamless Secure CapSure.
Special Publication : Interfaces for Personal Identity Verification Jim Dray NIST NPIVP Workshop March 3, 2006.
Disaster Recover Planning & Federal Information Systems Management Act Requirements December 2007 Central Maryland ISACA Chapter.
U.S. Department of Agriculture eGovernment Program July 9, 2003 eAuthentication Initiative Update for the eGovernment Working Group eGovernment Program.
28 th International Traffic Records Forum Biometrics/SmartCard Workshop 28 th International Traffic Records Forum August 4, 2002 Orlando, Florida.
LCDR Kevin Lynn, USCG Office of Port & Facility Activities (CG-5442) COHMED Conference January 26, 2010 U.S. Coast Guard Safety and Security Updates.
SunGuide SM Software Development Project End of the Year ITS Working Group Meeting December 7, 2005.
11/18/2003 Smart Card Authentication Mechanism Tim W. Baldridge, CISSP Marshall Space Flight Center Office of the Chief Information Officer.
Commercial Card Expense Reporting (CCER) The Trustees of Roanoke College An internet solution Accessed via Wells Fargo’s secure Commercial Electronic Office.
Socialsuite Training NSW SES 2 nd August, Agenda Overview & introduction to Socialsuite ~ 1 hr Review of the objectives for the project Overview.
Ketan Mehta March 3, 2006 PIV Data Model Testing Ketan Mehta March 3, 2006.
THE MALAYSIAN ELECTRONIC PASSPORT
Cyber Security Means Locking the Front Door Too: Use High-Assurance Identity Management to Control Access to the Federal Bridge.
MANAGEMENT of INFORMATION SECURITY, Fifth Edition
PCI-DSS Security Awareness
NATIONAL ACADEMIC DEPOSITORY
Microsoft Passport and Windows Hello Developer’s Guide to Windows 10 Build SDK Update Andy Wigley
Agenda Item 3: Report of the New Technologies Working Group
Opening slide.
Port Security Grant Program (PSGP)
Transportation Worker Identification Credential (TWIC)
Authentication.
Transportation Worker Identification Credential (TWIC) Next Generation (NEXGEN) Card Update for National Maritime Security Advisory Committee (NMSAC)
Transportation Worker Identification Credential
Module 8: Securing Network Traffic by Using IPSec and Certificates
Merging Security and Convenience with Seos® Credential Technology
NATIONAL ACADEMIC DEPOSITORY
TWIC Implementation Update
Biometrics Reg: AMP/HNDIT/F/F/E/2013/067.
Electronic Prescriptions for Controlled Substances
Tax Rate Redux Sue Anne Athens, CIO August 2016.
U.S. Coast Guard LCDR Brett Thompson.
Goals Introduce the Windows Server 2003 family of operating systems
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Public Key Infrastructure from the Most Trusted Name in e-Security
Installation & User Guide
NEW PRODUCT INTRODUCTION CONEKT™ Mobile Smartphone Access Control Identification Solution June 2018.
K!M SAA LOGICAL SECURITY Strong Adaptive Authentication
Group Meeting Ming Hong Tsai Date :
Module 8: Securing Network Traffic by Using IPSec and Certificates
NASA Personal Identity Verification (PIV) High Level System Overview Tice F. DeYoung, PhD 14th Fed/Ed Workshop December 14, 2006.
Module 2 OBJECTIVE 14: Compare various security mechanisms.
BCS Template Presentation February 22, 2018
The Access Challenge Multiple ID Cards Several Purposes
MyLion Registration Website | Mobile device
E-identities (and e-signatures)
Agenda Item 3: Report of the New Technologies Working Group
Presentation transcript:

TWIC Update to Sector Delaware Bay AMSC 8 June 2018

Agenda TWIC® Program Metrics TWIC® Next Generation (NexGen Physical Features) Credential Modes of Operation Canceled Card List Mobile App TWIC® Assessments Open Discussion 2

TWIC® Adjudication & Redress Metrics ~996K ENROLLMENTS ~53% Adjudicator Manual Review 2.6% PRELIMINARY DETERMINATION OF INELIGIBILITY Two-year Period January 2016 – December 2017 Approximately 53% of TWIC® enrollments are manually reviewed by adjudicators Small percentage (2.6%) of total TWIC® applicants receive a PDI Only about 1% of total applicants subject to redress process Less than 0.25% of total applicants receive waiver from TSA 0.5% WAIVERS REVIEWED 0.6% APPEALS REVIEWED 0.3% WAIVERS 0.16% WAIVERS 0.5% APPEALS APPROVED Source: TSA OIA/PMD, February 2018. 0.08% APPEALS DENIED 3

TWIC® NexGen Physical Security Enhancements TSA plans to implement physical TWIC® NexGen updates in fiscal year 2018. The NEXGEN effort is focused on enhanced card functionality, new physical security features, and changes to the Technology Infrastructure Modernization (TIM) system to realize a NexGen card. Where TWIC® is used often as a “flash pass” physical updates to deter counterfeiting were a priority of TSA. UPDATED DESIGN Enhanced card substrates Covert, overt & forensic features Color-coded expiration field Optically variable devices ENHANCED LAMINATE Holographic images Switch effect designs Letter/shaped lenses Tactility (numeric and graphic) Source: TSA OIA/PMD, September 2017. 4

TWIC® NexGen 5

TWIC® NexGen 6

TWIC® NexGen 7

TWIC® NexGen Functionalities Current Functionality (2007-2017) TWIC® NexGen Functionality (Planned) Retrieval of Fingerprint Biometrics without PIN Submission Secure Retrieval of Fingerprints/Facial Image without PIN Permits contactless use of TWIC® for all biometric card objects. Eliminates need for PIN operations (optional use). Designed for PIV/PIV-I Compatibility and Functionality Independent TWIC® and PIV Applications Enables continued direct mail issuance*, 5-year lifecycle. Permits contactless biometric user two factor authentication. Eliminates need for readers to access two (2) applications. Credential Designed for Maritime Application and Use Expanded PACS Support and Accessible Personal Information Optional support for local PACS data, i.e., E-Stickers Personal information available via 2D barcode/secure read May support use of certain information across industries Effective but Aging Security Features and Substrates Enhanced Card Platform: Features and Personalization Advanced overt, covert and forensic features. Updated production methods, formatted UUID and certificates. Incorporates Counterfeit Deterrence Best Practices Reader/Access Specifications based on Configuration of TWIC® Card TWIC® Card Backwards Compatibility Minimizes disruption of existing TWIC® implementations. Provides flexibility to vendors on support of new features. Magnetic Stripe replaced/removed for security concerns. Note: TWIC® NexGen remains in development; planned capabilities and functionality subject to change. PIV/PIV-I use of credential requires physical presence, biometric authentication and PIN selection/presentation to load/sign applications. Source: TSA OIA/PMD, September 2017.

TWIC® Modes of Operation Authentication & Identification Based on the requirements of each facility/vessel and specific threat levels, TWIC® is designed to be used in various Access Control Systems at different levels of security. 01/ 02/ STATIC IDENTIFICATION CRYTOGRAPHIC AUTHENTICATION Proximity Card Emulation Contact or Contactless Verify digital signature Identify card using unique identifier or CHUID* 1 Factor: Something you HAVE Trusted issuance by TSA No biometric authentication Authentication certificate and private key 03/ 04/ BIOMETRIC IDENTIFICATION COMBINED AUTHENTICATION 1 Factor: Something you ARE Biometric Authentication No card authentication Digital signature protects biometric templates 2 Factor: Something you ARE & HAVE Biometric Authentication Card Authentication FASC-N verified against CCL If you would like to discuss technology matters with the TSA TWIC® program, please e-mail us at TWIC-TECHNOLOGY@TSA.DHS.GOV. *FASC-N may be checked against the TWIC® Canceled Card List (CCL). Note: TWIC ® may have other modes of operation. This graphic details TSA’s planned TWIC® modes of operation. Source: TWIC® Authentication and its Use in Access Control Systems, TSA OIA/PMD, February 2018. 9

TWIC® CCL Mobile Application Physical Security Controls TSA planning to proceed with testing in Q3-FY 2018. Prototype is designed to illustrate a list verification and supplement visual inspection of the TWIC® card. The application is being designed for Android and iOS devices. Solution uses the Credential Identification Number (CIN) printed on the TWIC®: CIN compared to one list – Canceled CINs – which may be hosted in UES website and downloaded regularly. Facility/vessel users will be required to inspect TWIC® expiration date for validity (not included in canceled CIN list); behavioral prompt for facial inspection. Application and list are available to all stakeholders – no restrictions and eliminates Registration Authority. Mobile Application Phases CIN Update Updates in Seconds Sample Workflow Prompt Visual Inspection Note: Application remains in development – design, graphics and interface are subject to change. Source: TSA OIA/PMD, March 2018. 10

TWIC® Assessments Evaluations of TWIC® Controls, Fees & Maritime Use Three (3) assessments on the TWIC® program’s effectiveness at enhancing security and reducing security risks to facilities and vessels. In response to oversight recommendations and program requirements, DHS, TSA, and USCG are supporting the evaluation of the TWIC®. These assessments include analyses on: Fee Structure & Cost(s) of Vetting Use of TWIC® to address Security Risks Operational Impact(s) & Vetting Standards Assessing the Risk-Mitigation Value of TWIC® at Maritime Facilities (Ongoing – Early 2019) In response to P.L 114-278, DHS commissioned an independent assessment on TWIC® focused on the security value of the program and credentialing process. Bi-annual Review of TWIC® Fee (Ongoing – Late 2018) Based on statutory requirements and Federal guidance, TSA is conducting its bi-annual review of the TWIC® fees. Effective Internal Controls for TSA Security Threat Assessments (Completed – December 2017) TSA commissioned an independent assessment of TWIC® controls to verify that STA controls exist as well as whether TSA controls effectively mitigate TWIC® security risks. Source: TSA OIA/PMD, March 2018. 11

Discussion Questions? 12

Contact Information Please do not hesitate to contact the TSA TWIC® program with questions or for more information. Jeff Thorne TWIC® Program Analyst 571.227.4732 jeff.thorne@tsa.dhs.gov Daniel Meredith TSCC Administrative Coordinator 571.227.2299 daniel.meredith@tsa.dhs.gov