Online and Digital Identification, Securing Web 2.0, PKI and Digital Certificates

The 'key' to PIV-I, FICAM, FIPS 201 and trusted identities

Wednesday, September 8, 2010

Any security solution is only as good as the keys it uses. Keys and key management are crucial factors in the level of assurance and trust that a system can provide. Keys are both metal and digital, this discussion focuses primarily on digital keys.

Key management requires technology, policy and procedure. The key management component of physical access control is expanding and needs upgrading. At present physical access control systems typically manage a small number of user keys–company ID and common symmetric key.


In some cases users have defined specific keys and access rights for sectors on memory smart cards. In some of these cases there is a expiration date on the keys. Typically the access control vendor or system integrator holds the keys in escrow.

Key management in a PIV-I context introduces the use of digital certificates and their associated private and public keys–asymmetric keys/cryptographic vs. the solely symmetric, or single shared key.

There are also hybrids which use both, for example, creation of a session key, or a combination of asymmetric and symmetric authentication factors being used by a system. This does not replace the key management requirements described above but can add, change or eliminate aspects.

The best practices for management of cryptographic keys are well covered in the literature. This involves much more than the mathematics of cryptography.

References and guidance include National Information Assurance Acquisition Policy 2003 in addition to the special publications from the National Institute of Standards Key Management that include Draft Special Publication 800-130, A Framework for Designing Cryptographic Key Management Systems, Draft Special Publication 800-131, Recommendation for the Transitioning of Cryptographic Algorithms and Key Sizes, Special Publication 800-56 Parts A & B and 800-57 Parts 1, 2, 3.

Best practice requires a focus on education for employees, contractors, vendors and integrators. Specific new curriculum, leveraging the above documents, should be developed and integrated into vendor and system documentation and training to address this.

All of these practices are relevant in a PIV-I or FICAM context and need to be a consideration of next generation logical and physical access control systems and their deployment. Key management requires roles and system of record data stores.

Organizations should look to see if they have these in place and consider:

  • Establishing role of key custodian(s)
  • Defining individual and enterprise key archives
  • Performing enterprise key census
  • Defining policy for key life-cycle management
  • Ability to work with latest, and evolving, keys sizes and algorithms

 [end] 

Neurotechnology announced that it has developed three versions of embedded solutions for Android-powered devices such as smart phones and tablets.

Specifically, Neurotechnology has ported its VeriFinger Embedded software development kit (SDK), which authenticates user identities via fingerprints, VeriLook Embedded SDK, which authenticates user identities via facial recognition, and MegaMatcher Embedded SDK, which authenticates user identities via both fingerprints and facial recognition. A version that utilizes iris recognition also is in the works.

read more »

By Salvatore D’Agostino, CSCIP, IDmachines

2012 promises to continue to advance the case for and the solutions to address the need for trusted interoperable, privacy-enhancing digital identities.

read more »

By Colin Soutar, Director of Identity and Privacy Assurance, CSC

In the past, the term “credential” was used solely to refer to a dedicated physical entity that intertwined an individual’s identity with a specific entitlement, for example a passport or driver’s license.

read more »

Gordon Hannah, Principal, Deloitte & Touche LLP

Our cyber world has grown and spread rapidly. It enables us to do our jobs faster and more efficiently and gives us unprecedented access to information, whether we’re in the office or on the go.

read more »

Be first to comment...
Comment on this article

Your full name and URL will be displayed with your comment.

Your email is not shown or shared, and is used only for your Gravatar image.




characters left.