San Francisco International Airport

Slides:



Advertisements
Similar presentations
Conducting your own Data Life Cycle Audit
Advertisements

HiPath SIcurity Card Manager Smartcard Management and Personalization System Sales Presentation.
EzScoreboard.com A Fully Integrated Administration Service.
What’s New in Fireware XTM
For Joe Broghamer Philip S. Lee May 5, 2005 Implementing PIV Specifications HSPD-12 Workshop.
June 27, 2005 Preparing your Implementation Plan.
© 2006 IBM Corporation Tivoli Identity Manager Express Tivoli Access Manager for Enterprise Single Sign-On (Product Demonstrations) Tivoli Live! – 15 June.
Pilot Instructor Currency
1 System Engineers Toolbox 1 Compliance Automation, Inc. INCOSE: NM Enchantment Chapter By Cheryl Hill August 12, 2009.
My AmeriCorps AmeriCorps National Programs Member Enrollment Presentation developed for the Corporation for National and Community Service by the eGrants.
Implementation of a Validated Statistical Computing Environment Presented by Jeff Schumack, Associate Director – Drug Development Information September.
National Infrastructure – Citizen’s Account
Module N° 7 – Introduction to SMS
E-Child Care Time and Attendance Tracking System December 17, 2010 Department of Human Services, Division of Family Development 1.
Addition Facts
An Institutionally Secure Integrated Data Environment (INSIDE) By University of St Andrews & University of Durham Original Aims –the development of a sustainable.
NexSentry Imaging Solutions
WELCOME Keyscans Access Control KIMA SECURITY INC.
Insert image here © SPEC-Soft SAVINGS AND EXPERTISE FOR YOUR PLANT PFS-Suite Life-cycle Tools For Process Automation PFS-Suite TM.
Narita International Airport Corporation All Rights Reserved. Yoshihiro Ozawa Planning Department Narita International Airport Corporation 21 April 2005.
1 The smart card slot! Sara Eyre Head of IT Customer Services Or how to produce an attendance monitoring system using the access.
Current Technology and the TWIC Program Walter Hamilton Chairman, International Biometric Industry Association Sr. Consultant, Identification Technology.
Residents’ register service under the Ministry of the Interior
2014/6/2 Giga-Tms 1 The latest Biometric Technology.
Improving SOX Remediation Through Automated Testing of Internal Controls November 4, 2005.
12 November 2002Digital Identity Forum – London Biometrics and ID Bill Perry Independent Consultant Phone:
MediTract Contract Management Software
“The Honeywell Web-based Corrective Action Solution”
Airport Security – Post 9/11
Presented to: By: Date: Federal Aviation Administration Safety Management System (SMS) at Airports : Principles APEC TPT-WG AEG-SAF Jim White, Deputy Director.
Because IDENTITY Matters.. AIRPORT Public, Press Political Concerns Public, Press Political Concerns No fences or gates.
LeadManager™- Internet Marketing Lead Management Solution May, 2009.
© 2013 Jones and Bartlett Learning, LLC, an Ascend Learning Company All rights reserved. Fundamentals of Information Systems Security.
Brian Epley, VA PIV Program Manager
These presentation slides are designed as content for AP Change Makers building their own internal presentations on the subject of Accounts Payable Automation.
The Human Resources Management and Payroll Cycle
- 1 - Defense Security Service Background: During the Fall of 2012 Defense Security Service will be integrating ISFD with the Identity Management (IdM)
AFCEA TechNet Europe Identity and Authentication Management Systems for Access Control Security IDENTITY MANAGEMENT Good Afternoon! Since Yesterday we.
User Security for e-Post Applications Dr Chandana Gamage University of Moratuwa.
Your Complete Solutions Provider™
1 Traveling? Don’t Forget OIE! A global OIE rollout case study.
The Federation for Identity and Cross-Credentialing Systems (FiXs) FiXs ® - Federated and Secure Identity Management in Operation Implementing.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
Department of Labor HSPD-12
e-Solutions for Access Control, CCTV, Attendance Monitoring, Personal Identification, Building Management and Fire Detection SECURITY & SAFETY IS ONE.
Computer Security Biometric authentication Based on a talk by Dr J.J. Atick, Identix, “Biometrics in the Decade of Security”, CNSS 2003.
1 Automatic Border Passage at Amsterdam Airport Schiphol ACM ICPC, November 16th 2002 Art de Blaauw, manager projects.
Integrated Security Solution Ingersoll Rand. Insert Footer 2.
1 Preview of the self service airport R edesign P assenger P rocess (RPP) Club of Amsterdam, 1 Maart 2006.
Enterprise Physical Access Control System (ePACS) Overview Briefing
Basics of Access Control A new & exciting world.
1J. M. Kizza - Ethical And Social Issues Module 16: Biometrics Introduction and Definitions Introduction and Definitions The Biometrics Authentication.
Module 14: Biometrics Introduction and Definitions The Biometrics Authentication Process Biometric System Components The Future of Biometrics J. M. Kizza.
© 2008 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Automates Infrastructure Outsourcing.
Lenel OnGuard and Bioscrypt V-Smart
AGENDA Welcome and introductions Brief introduction to PSI Mobile Technical Overview Demonstration Q and A Next Actions.
Solution Overview for NIPDEC- CDAP July 15, 2005.
PIV 1 Ketan Mehta May 5, 2005.
BioLynx™... Ensuring Employees are paid for actual time worked and Facilities’ access is audited and controlled.
28 th International Traffic Records Forum Biometrics/SmartCard Workshop 28 th International Traffic Records Forum August 4, 2002 Orlando, Florida.
COAG AUSTRALIA The Prime Minister, Premiers and Chief Ministers signed the IGA at the COAG meeting on 13 April The key objectives of the Strategy,
Health Plan Solutions Stephanie Rose ECMp, PAHM Insurance Industry Account Manager.
Supplier Kickoff Presentation Presented by Computer Aid, Inc.
A Fully-integrated Timekeeping Solution Through PlatinumPay Xpress.
TXF 4998 PROJEK ILMIAH Title: An efficient framework of distribution and collaboration in Electronic Document Management System (EDMS) Name: Norlaele bt.
Commercial Card Expense Reporting (CCER) The Trustees of Roanoke College An internet solution Accessed via Wells Fargo’s secure Commercial Electronic Office.
Identity and Access Management
WALLA WALLA REGIONAL AIRPORT
SAFE Suite of Applications
Carrier Qualifications & On-Boarding
Presentation transcript:

San Francisco International Airport Access Control and Biometrics Case Study Kim Dickie, Asst Deputy Airport Director, - Aviation Security

Background Access Control System (ACS) MDI and Ingersoll Rand Hand Geometry installed 1991 Serve 20,000 airport ID badged employees Terminal 2 Renovation Project New domestic terminal w/ 14 gates Select a new ACS and Biometric system Identify need for migration plan for all terminal facilities Smart Card Technology Comply with new industry standards Terminal closed since 2000. Opening in January 2011. No impact to opening date. Opportunity to identify new ACS and Biometric, SMART CARD. Completed an upgrade from an 0S2 to a Windows version, very challenging. No longer service needs of airport.

ACS and Biometric System - Current Approximately 1500 airfield access portals ACS Card Reader transactions —over 200,000 / day 200+ access portals equipped with Card/ Hand Geometry Readers Hand Geometry Reader transactions —can exceed 35,000 / day Deployed at all Airport controlled access portals leading directly to the Secured Area

Access Control System - Current Turnstile Vestibule, Card Reader/Hand Geometry, Access Portal

Biometric Technology – Current How it works…………… Over 90 distinct hand measurements taken including: Length Width Thickness Surface area 3-D image acquired 9 byte template is generated

Biometric Technology - Current Hand Geometry Facts Easy to use Low failure to enroll rate 2 out of 70,000 Fast verification 2 – 3 second average Low false rejection rate—.1% probability an authorized user is rejected Hand Geometry Reader reliability — greater than 99.9%

Biometric Technology - Future Lumidigm™ fingerprint readers to replace infrared hand geometry readers Multispectral imaging technology used to collect fingerprint information from below the surface of the skin Avoids conventional fingerprint reader pitfalls: Worn fingertips Overly moist or dry skin Soft press against reader Susceptibility to fraudulent, artificial fingertips

Access Control System - Future ACS system – Lenel OnGuard HID iClass Elite “contactless” Card Fingerprint, Hand Geometry, Mag stripe, proximity card Space for a contact chip

Airport Badging/Credentialing Process – Current

CA DOJ Pre-Enroll Forms & Pre-Checks CHRC Manual Setup Enroll Time for completion Not Controlled by Airport - CA DOJ CHRC Manual Setup Enroll Fingerprinting Manual Verification – inconsistent return rate – 3 places to check for approval “No-Fly” List Manual Setup Airport Security Training Conduct Document Archiving Manual Filing Badging & Card Issuance Manual Results End Enroll Audit Manual Audit Reports FORMS AND PRE CHEKCS – Paper intensive process. First integration phase - In 2007 migrated majority of databases into a single database developed locally by a consultant called SAO database. Second integration phase - We were able to integrate the Identix LiveScan to the SAO database. When individual’s fingerprints and information are captured, populate the SAO database automatically. Third integration phase – audit of physical metal keys during re-badging process, eliminate auditing as a separate process. FINGERPRINTING - In 2009, the Badging Office started conducting the CAL DOJ fingerprint submission. Previously, airport employee would have to go to downtown in the city to conduct this step of the background check in addition to the required TSA CHRC/STA. Badging Office was capturing two sets of fingerprints for the background check. SECURITY TRAINING – In 2008, migrated from a video to CBT platform. Currently, still a separate database maintaining all training records for both safety/security classes. BADGING AND CARD ISSUANCE – Paper process for filing all documents. Conducting Annual ID Audit as a manual process that takes months to complete. PACS – Access is selected by badging clerk. Manual Physical Access Privileges Physical Access Manual Data Reconciliation Provision

Airport Badging/Credentialing Process – Future

Badging, Card, Key, Issuance Automate Data Input Capture Fingerprints “No-Fly” & “Selectee” list CHRC Background Check Upload & Verification CA DOJ Web Paper Forms Pre-Enroll Airport Security Training Document Archiving Conduct Automate Doc Mgmt Automate Training Registration Badging, Card, Key, Issuance End Enroll Automate Result Upload However by Automating the Processes:  Reduce decision time. Improve processing time. Operational efficiency. Higher level of Security. Capability to create new rules. WEB PAPER FORMS - Forms will be printed w/ a barcode, signed by employer, and when employee goes to Badging Office, the bar code will be used by the clerk to populate the database. Creating a web portal for Authorized Signers to access the start the process. Automated process for access requests and is pre-determined by position. FINGERPRINTS - The enrollment record containing the biometric and biographic information for vetting required by federal agencies via BASIC concept. Information (like fingerprints, driver’s license, passport information, etc.), are captured and stored, in an electronic format on a centralized document management system, and mbedded in the enrollment software. Capture all biographic and biometric information for both TSA and City background process (CAL DOJ). SECURITY TRAINING - Automate Training requirements by sending a URL to the Authorized Signatory validating completion of training prior to credential issuance. Identify all training requirements to obtain ID badge. Re-enforces policy of required training before issuance of ID. BADGE ISSUANCE – All prior steps completed, wSAFE will allow clerk to issue ID Badge to employee. Continue to capture Fingerprint and Hand Geometry biometric. Issue new HID iClass Elite card w/ mag stripe and contactless chip. PACS – SAFE boards both MDI and Lenel OnGuard at same time. Privleges are the same. Two ID numbers, Unique identifer on front and an airport number on back of card.   Audit Automate Data Reconciliation Automate Audit Reports Physical Access Privileges Provision Automate Provisioning & Role-based Access Privileges

Identity Management System (IDMS) External Processes AAAE/TSC (BASIC, CATSA) No-Fly Physical Security Documents PACS Biometrics Smartcard Third Parties Background Check/ No-fly List Vetting Credential Check Vehicle/Parking Access Control Biometric, Smart Cards Document Mgmt Be prepared to modify their processes and adjust to new regulations, policies and technology and to adhere to the BASIC concept of operations when finalized . By deploying the Airport IDMS system, the airport is positioned to adjust and change to all processes recommended by AAAE and the BASIC task force. Rules based system allowing to create requirements. Manage Identities w/ airport policy. Added Safety/Security Enforcement Program, for example three citations, you lose your privileges, all agencies involved in Enforcement Program (Operations, Communications) would have ability to view history. Identify when an employee may lose privileges based on number of infractions. Position airport to be able to participate in new initiatives, BASIC pilot, PKI applications, etc. Have left room on new HID card to add a contact chip. Eventually, E-Form will be authenticated by Authorized Signatory using PKI and barcode and printing of application goes away and is replaced w/ all electronic transactions IDMS solution connects siloed systems into a common framework

IDMS – Automated Workflow E-Form Credential Application Eliminates duplicate data entry Streamlines manual enrollment of biographic data Badge creation is only allowed when: STA & CA DOJ is approved Role-based badge template selection Twice Daily – SAFE is looking for STA Setup alert for company-authorized designee, Deactivate Card within 48 hours Automatic Notification Process Creates Authorized Signatory or Employer correspondence Automated Compliance of TSA regulations Audit process Authorized designee training mandatory SAFE Applies Pre-Defined Rules Other Policies that SFIA is using their IdM application to facilitate and automate include things like: 1. E-FORM Employers are responsible for the data entry for new employees through the entry into a web form that produces a barcode form. The barcode form that the employee submits to the Credentialing Office will auto populate the database, so as to alleviate fat-finger errors and labor hours. Steamlines manual enrollment 2. BADGE CREATION IS ONLY ALLOWED WHEN: Ensures compliance w/ background checks being completed prior to being able to issue a badge. +++++++SAFE is checking twice daily to see if background checks have been approved. This still a manual process of checking for the return but now the credentialing officer merely checks off in SAFE and it triggers notifications to the actual badge creation office to go ahead and issue a badge. 3. Badge creation is only allowed once all background checks and approvals have been checked off within the system. Also, role based template selection makes it easy for a badging officer to determine the proper template as it is preselected by SAFE based upon identity attributes during the enrollment process. This ensures NO credentials are issued without complying. 4. SAFE monitors all cards, keys and passes that are provisioned to each individual so that if the individual is terminated there is a Failure to Return flag raised and communicated to the proper authorities to ensure outstanding cards and keys are returned. Notication sent to employere (Authorized ) 5. Automatic revocation of access privileges based upon expiration date, training expiration and infraction record. 6. Alerts are sent to employers and Airport Security for lack of badge use in 90 days. 7. Multiple employers per identity – assigning a unique Person Id # to each employee for life, so that when they leave and if they come back their UID remains constant and their history can be traced.

BASIC Pilot Program SFO to BASIC : XML Web Services - HTTP, SOAP 1.1 Phase 1 – Biographic information completed 5-15 Day Exercise (Design, Test, Deploy) Initial round of integration testing complete Testing conducted remotely Phase 2 – Biometric and Biographic in work Integrate SAFE to Identix LiveScan – Fall 2009 Allow SFO to connect to BASIC SAFE had passed the integration testing with BASIC and will conduct Biographic data exchange and STA security assessment, but are waiting for BASIC to get a “green light” on conducting the CHRC so we can exchange biometric.

Lessons learned so far…….. Identify IDMS requirements and opportunities Phased approach - operational pilot •        Create integration for Lenel to airports CAD system, Integraph. Was identified later in the process and ultimately became a critical path item. Public Dispatch managed by another department. •        Created an operational test room, capability to also conduct acceptance test and training for clerks. •       Work closely to identify network path multiple interfaces Clearly define your current processes to identify potential cost savings Evaluate Network system to identify requirements Perform ROI - Metrics