Smart Card Talk a Quarterly Newsletter for Members and Friends of the Smart Card Alliance May 2016
Total Page:16
File Type:pdf, Size:1020Kb
Smart Card Talk A quarterly newsletter for members and friends of the Smart Card Alliance May 2016 In This Issue: ② Executive Director Letter >> A Message From the ③ Latin America Letter >> Executive Director ④ Profile >> It’s been a few months since I’ve talked about the government ⑥ Feature Article >> market, and with our 2016 Government Conference coming ⑩ Council Reports >> up in a few weeks, I’ve turned my attention to the government security marketplace. I hope you’ll join us for Securing Federal Identity 2016, which On the Web: will be held on June 6th at the Ronald Reagan International Alliance in the News >> Trade Center Building in Washington, DC. This issue of the newsletter also features updates on Alliance Councils, a profile Members in the News >> of our newest Internet of Things (IoT) Security Council, new members and CSCIP and CSEIP recipients. Sincerely, Smart Card Alliance Events Randy Vanderhoof SECURING Executive Director, Smart Card Alliance FEDERAL IDENTITY2016 06.06.16 RONALD REAGAN BUILDING GOVERNMENT EVENT WASHINGTON, D.C. Click to Read Letter ... SecuringFederalID.com Securing Federal Identity 2016 June 6, 2016 Ronald Reagan Building Washington, D.C. GlobalPlatform TEE Conference 2016 Call for Papers – Speakers are invited to participate in the world’s only dedicated trusted execution environ- ment (TEE) conference: Next Generation Mobile Feature Article: Profile: Security for Today and Tomorrow Conference, Smart Card Technology and the Internet of Things which will take place in October 2016 in Santa FIDO Protocols Security Council Clara, CA. Today, the FIDO Alliance is working to pro- In the spring issue of 2016, Smart Card Talk vide simpler, stronger authentication to re- spoke with Executive Director Randy Van- duce reliance on usernames and passwords, derhoof about the organization’s new Inter- which are susceptible to a wide range of at- net of Things (IoT) Security Council, which OCTOBER 19-20 CHICAGO, IL tacks. This month’s article provides an over- was formed to develop and promote best view of the FIDO authentication standards practices and provide educational resources Security of Things Conference and describes how smart card technology on implementing secure IoT architectures October 19-20, 2016 can enhance the security of FIDO protocol by using embedded security and privacy. Hilton Rosemont Chicago O’Hare implementations. Chicago, Illinois Click to Read More … Click to Read More … A Look at the Government Security Marketplace Dear Members and Friends of the credentials for administrators with access privileges to the most Alliance, secure systems so that breaches of personal information, like last year’s OPM data breach, will not be repeated. In this month’s letter to our Smart Card Alliance organization mem- What I heard during the preparation is that infrastructure interop- bers, I turn my attention to our gov- erability remains the “devil in the details” for faster adoption, par- ernment security marketplace. It has ticularly with mobile credentials. When most of the federal enter- been a few months since I’ve talked prise mobile infrastructure was built on the Blackberry operating about the government market; much system platform, development and testing could be concentrated attention instead has gone into the on a few smart phone models and a common mobile management complex payments industry migra- system approach. However, now there are Apple and Android and tion to EMV chip cards and our ef- Windows devices, and still some Blackberry devices, that need to forts in forming the new IoT Security be supported, with multiple mobile operating system revision lev- Council. But we have our annual Government Conference com- els running on multiple smart phone devices. Developing a testing ing up in a few weeks, so I think it would be wise to share some program to validate all of the use cases to meet the identity man- insights into the Alliance efforts in education, industry collabora- agement and authentication requirements for encryption services tion, and training that is supporting government use of HSPD-12 and mobile access to remote networks will be challenging, as de- based PIV credentials. mand for such services is increasing. The 2016 Government Conference event, Securing Federal Iden- I learned that the biggest challenge to using PIV credentials for tity 2016, will be held on June 6th at the Ronald Reagan Interna- two-factor authentication in government IT networks is that fed- tional Trade Center Building in Washington, DC. The event has eral CIOs need to evaluate all of the existing IT services that rely undergone a complete make-over from previous years. What we on Windows log-in and legacy system access rules before develop- came to realize is that, more than anything, most people wanted to ing a solution that will replace current approaches with the certif- learn about the new identity management and security programs icate-based PIV smart card credential. Likewise, those IT systems that are coming, rather than look back on past successes and exist- in need of strong two-factor authentication lack uniform means ing standards and policies for using chip-enabled PIV credentials of access, run on different types of PC platforms and mainframe for physical access for the federal market. servers, and require the addition of a smart card reader at every access point to leverage the two-factor authentication the PIV cre- In the past, we held a three-day event at the Washington Conven- dential provides over weaker and more easily compromised user tion Center with over 75 speakers and multiple tracks covering names and passwords. executive director’s corner executive director’s every aspect of identity, security, biometrics, and healthcare. It was costly for industry participants to attend and for government It is the challenge for technology providers and standards groups to workers to devote three days from their schedules to sit through all work with their government customers to come up with the solu- of the tracks and talk with scores of exhibitors. tions that work across this wide array of infrastructure conditions. I am confident that our Smart Card Alliance members will lever- The Securing Federal Identity 2016 event is a one-day, highly-fo- age their experience with commercial clients and overseas markets cused and high-energy event that will concentrate on how federal to find the solutions that meet these challenges and adapt to the agencies are using PIV and PIV-I credentials as strong, two-factor changing hardware and software needs of our federal enterprise authentication devices to secure federal networks. It will also focus customers. If you are interested in the government identity man- on how federal programs are extending the usage of the PIV cre- agement and access security markets, you should definitely plan dential’s identity management and authentication capabilities to on attending the June 6th Securing Federal Identity 2016 event. mobile devices through the use of derived credentials. The agenda features a select group of mostly federal government speakers, and Thank you for your continued support. we will have room for a small group of government security indus- try exhibitors who will highlight the present capabilities and the Sincerely, future direction of the government’s efforts to replace user names and passwords on desktops and mobile devices and use PIV-based authentication to log into Microsoft Windows-based network sys- tems and legacy systems for all federal agencies. Randy Vanderhoof In preparing for this event, I worked closely with our federal and Executive Director, Smart Card Alliance industry contacts. Doing so, I learned of the renewed commit- [email protected] ment to further adoption of the PIV card to replace weaker log-in 2 Smart Card Talk latin america corner Transformation Moves Forward Dear Members and Friends of the cultures within their institutions. They are rewarded by the market Smart Card Alliance Latin America and their employees, and are viewed as important icons of society, (SCALA), wisdom, knowledge, innovation, riches, efficiency, and collabo- ration. They offer their customers the tools to accomplish a high Today we find ourselves in the middle level of existence while connecting the world with services and of a digital transformation, where it solutions. Some examples are Google, Samsung, Apple, Facebook, seems that services, processes, com- WhatsApp, YouTube, Netflix, Skype, Uber and Amazon. panies, and governments are chang- ing their core businesses to serve the In this context and to promote this digital transformation, we have needs of a population that demands created The Digital Tour – Americas, organized in collaboration transparency, efficiency, speed, con- with the Banking Association of Panama (ABP). We also have sup- venience, and personal attention, all port from the Latin American and Caribbean Council for Civil of which can only be provided through a digital medium. The Registration, Identity, and Vital Statistics (CLARCIEV), the Latin transformation process has not been equitable for all. American Security Association (ALAS), the Panamanian Public Health Society (SPSP), the National Bureau of Science, Technol- It wasn’t too long ago that I remember a period when tablets, cell ogy, and Innovation (SENACYT), the Public Registry of Panama phones, and other digital means of customer service didn’t exist. (RPP), and the Panamanian Association of Company Executives I still recall all of the processes that were completed in person, on (APEDE), among others. These organizations are focused on the paper, signed and handwritten; that created long lines in public implementation of systems that facilitate interaction with their cli- institutions such as banks; that resulted in office file cabinets filled ents/citizens and at the same time remain at the forefront of tech- to the top and lost paperwork; and that required return trips to nology advances. resolve a small but vital procedure such as getting a letter notarized or adding extra postage stamps.