Software helps developers get started with PIV cards
The National Institute of Standards and Technology (NIST) has developed two demonstration software packages that show how Personal Identity Verification (PIV) cards can be used with Windows and Linux systems to perform logon, digital signing and verification, and other services. The demonstration software, written in C++, will assist software developers, system integrators and computer security professionals as they develop products and solutions in response to Homeland Security Presidential Directive 12 and the FIPS 201-1 standard. "We wanted to provide IT professionals with a model of one way that PIV cards can be used to support authentication to federal information systems," explains Donna Dodson, deputy director of the NIST Computer Security Division. "Our objective was not to say 'do the steps this way,' but to show an example of how you might proceed."
Homeland Security Presidential Directive 12 calls for government employees and contractors to use secure identity credentials to access federal facilities and computers. NIST worked with industry to develop the standards for the PIV cards that will be used for those purposes. Each card contains a unique number, two of the employee's biometric fingerprint templates, and cryptographic keys stored on an electronic chip embedded in the card's plastic body.
While each federal agency will implement the use of PIV cards on its own schedule, NIST computer scientists developed the software to demonstrate that PIV cards can work with common computer activities such as system logon. The typical process of keying in user name and password will be replaced with the user inserting his/her PIV card in a reader and entering a personal identification number (PIN). This secure logon could eliminate the need for passwords for other applications and could provide access to secure databases to which the user is authorized.
The PIV Crypto Service Provider (CSP) demonstrates Windows XP Logon with PIV cards. The Public Key Cryptography Standard #11 module was developed to operate in the Fedora Core 5 environment and to implement Linux Logon, signing and encrypting email (following the S/MIME standard) and Web site authentication (following the SSL/TLS standard), configured in Linux OS, Thunderbird and Firefox applications.
Source: National Institute of Standards and Technology (NIST)
Related
- The new ID cardFri, 26 Feb 2010, 10:16:18 EST
- NIST test proves 'the eyes have it' for ID verificationWed, 4 Nov 2009, 9:53:27 EST
- Cards on the table: Low-cost tool spots software security flaws during development processTue, 24 Feb 2009, 11:00:50 EST
- New NIST publications describe standards for identity credentials and authentication systemsWed, 9 Sep 2009, 12:26:06 EDT
- Researchers develop next-generation antivirus systemWed, 6 Aug 2008, 15:35:45 EDT
Other sources
- Software Helps Developers Get Started with PIV Cardsfrom PhysorgThu, 10 Jul 2008, 13:56:04 EDT
- Software Helps Developers Get Started With PIV Cardsfrom Science DailyThu, 10 Jul 2008, 12:28:10 EDT
Latest Science Newsletter
Get the latest and most popular science news articles of the week in your Inbox! It's free!Learn more about
Check out our next project, Biology.Net
Popular science news articles
- Even with defects, graphene is strongest material in the world
- Detection of the cosmic gamma ray horizon: Measures all the light in the universe since the Big Bang
- Genetic engineering alters mosquitoes' sense of smell
- Allosaurus fed more like a falcon than a crocodile, new study finds
- 'Popcorn' particle pathways promise better lithium-ion batteries
