IHS Inc. The Source for Critical Information and Insight
Electronics |  Change  

Go
 
 

NIST Describes Standards for Identity Credentials, Authentication Systems

October 12, 2009 // Published as a news service by IHS

  
Document Management Tools
IHS Standards Expert is an online service providing access to documents from top standards bodies, including ASTM, ISO, ANSI, IEC, DIN, BSI and 100s more.

Features include customized collections, flexible search options, watch lists, advanced navigation and alerts.

To learn more, and for a free quote, please complete the form below.
IHS Standards Expert
First Name:

Last Name:

Email Address:
The National Institute of Standards and Technology (NIST) issued Use of ISO/IEC 24727 and Special Publication 800-73-3, which describe new capabilities for authentication systems using smart cards or other personal security devices within and outside federal government applications.

Use of ISO/IEC 24727 describes the NIST-led international standard, ISO/IEC 24727, which defines a general-purpose identity application programming interface (API).

Special Publication 800-73-3 is a draft publication on refinements to the personal identity verification (PIV) specification.

NIST developed specifications for PIV cards required for the government under Homeland Security Presidential Directive 12.

These smart cards have embedded chips that hold information and biometric data, such as specific types of patterns in fingerprints called minutiae, along with a unique identifying number.

Experts said the goal is to develop methods that allow each worker to have a PIV card that works with PIV equipment at all government agencies and with all card-reader equipment regardless of the manufacturer.

Because of the interest in using secure identity credentials like PIV cards for multiple applications beyond the federal workplace, NIST developed ISO/IEC 24727 - Identification cards - Integrated circuit card programming interfaces - that provides a set of authentication protocols and services common to identity management frameworks.

The NIST report, Use of ISO/IEC 24727 is an introduction to that standard. It describes the standard's general purpose identity application programming interface, the "Service Access Layer Interface for Identity," which allows cards and readers to communicate and operate with applications.

The report also describes a proof-of-concept experiment demonstrating that existing PIV cards and readers can work interoperably with ISO/IEC 24727. The applications tested included logging on to Windows or Linux systems, signing and encrypting e-mail and performing web authentications.

NIST researchers are also working to improve PIV components and provide guidelines that the private sector and municipalities can use with a similar smart ID card.

They drafted an update to an earlier publication that contains the technical specifications for interfacing with the PIV card to retrieve and use identity credentials.

Special Publication 800-73-3, Interfaces for Personal Identity Verification, provides specifications for PIV-interoperable and PIV-compatible cards issued by nonfederal issuers, which may be used with the federal PIV system.

It also provides specifications designed to ease implementation, facilitate interoperability and ensure performance of PIV applications in the federal workplace.

The publication specifies a PIV data model, card edge interface and application programming interface. The report also provides editorial changes to clarify information in the earlier version.

Source: National Institute of Standards and Technology (NIST).


ELECTRONICS & TELECOMMUNICATIONS NEWS
November 18, 2009
Internet Directory Moves Toward Internationalized Domain Names
The Internet Corporation for Assigned Names and Numbers (ICANN), which manages the Internet's core address directory, announced on Nov. 16 that ... more
November 13, 2009
Canada, U.S., Mexico Publish Compact Fluorescent Lamp Standard
The Canadian Standards Association (CSA) teamed with Underwriters Laboratories (UL) Inc. and Mexico's National Association of Standardization ... more
November 9, 2009
Agreement Reached on Far-Reaching EU Telecoms Reform Package
The European Parliament (EP) and European Council of Ministers reached agreement on Nov. 5 regarding the long-anticipated telecoms reform legislation ... more
November 5, 2009
ITU Approves G.hn Standard for Wired Home Networks
The International Telecommunication Union (ITU) approved G.hn, a technical standard for home networking systems and applications. ... more
October 30, 2009
EC Proposes New Uses for Spectrum Freed Up by Digital TV Switch
On Oct. 28, the European Commission (EC) set out plans for a coordinated distribution of newly available radio spectrum to encourage investment ... more
Show All..