* Government ID card documents, standards could help companies
Government reports and projects may sometimes seem to be abstruse and expensive uses of taxpayer resources with limited relevance for the private sector. However, much of the work published for free access by state and federal authorities actually has value for any organization, especially larger ones facing problems similar to those of the government services. Luckily, documents created for governments are generally in the public domain, meaning that anyone can use them for constructive purposes.
The federal government has recently established standards for identifying government employees and contractors. Federal Information Processing Standard (FIPS) 201 was issued in February. It currently defines standards for smart card design, the details of biometric-data acquisition, and guidelines for the cryptographic components of the system. Much of the project information is useful for network administrators looking at shifting away from password-based identification and authentication (I&A).
The project overview states that “a comprehensive set of guidelines, recommendations, reference implementations, and conformance tests has been identified as being needed to: implement and use the [personal identity verification, or PIV] system; protect the personal privacy of all subscribers of the PIV system; authenticate identity source documents to obtain the correct legal name of the person applying for a PIV ‘card’; electronically obtain and store required biometric data (e.g., fingerprints, facial images) from the PIV system subscriber; create a PIV ‘card’ that is ‘personalized’ with data needed by the PIV system to later grant access to the subscriber to Federal facilities and information systems; assure appropriate levels of security for all applicable Federal applications; and provide interoperability among Federal organizations using the standards.”
In addition to the special publications available explaining the major elements of the PIV system, the most interesting resources available on the overview site are the presentation materials:
https://csrc.nist.gov/piv-project/workshop-Jan19-2005/presentations.html
There was a public meeting Jan. 19 that included the following talks whose slides and papers are available online as PDF handouts:
* Ari Schwartz, associate director of the Center for Democracy and Technology, spoke on “Privacy and Other Policy Issues in Common ID for Federal Employees and Contractors.” One of his key points was that “technical standards are being set before policy framework.” He also provided a list of useful privacy-policy resources.
* Pam Dixon, executive director of the World Privacy Forum, spoke on “The New Federal ID Card: Privacy Implications.” She warned that the use of a single unique card identification number for all federal employees and contractors would be “subject to [the] same pressures and abuses as [Social Security Numbers].”
* Amitai Etzioni, founder and director of The Communitarian Network, emphasized the value of difficult-to-counterfeit IDs. “There is no right to have a false ID,” he wrote in his two-page summary, and enumerated many cases of security failures due to counterfeit identification documents.
* Robert Atkinson, vice president and director of the Technology and New Economy Project at the Progressive Policy Institute, dismissed privacy concerns about the new cards and encouraged use of the government cards for many other purposes such as access to the rail system and for opening hotel rooms. He dismissed other speakers’ concerns over tracking employees carrying the new cards by writing, “An employer has a right to know where employees are during work hours.”
Several other papers presented that day have valuable information for anyone interested in privacy and identification technology. I hope that the issues raised will be helpful for private-sector readers interested in establishing their own token-based I&A projects.




