FB pixel

NIST issues new PIV standards including rules for digital IDs

 

mobile contactless access control

The U.S. government has issued a draft update to its biometric PIV card standard addressing initial identity proofing, interoperability infrastructure and other functions addressing evolving system needs.

The update also covers derived personal identity verification (PIV) credentials, which are verification credentials rendered digital for mobile devices. It details new specifications for use of derived PIV credentials.

Federal employees and contractors are required to carry this particular PIV card for logical and physical access. A PIV account stores attributes of a cardholder and enrollment data as well as information about the card itself and derived PIV credentials assigned to the account.

NIST, which published the expanded standard, added required procedures for supervised remote identity proofing, issuance and registration. Those rules set out the conditions of monitoring the proofing session, and note the necessity of biometric data collection to perform identity proofing remotely.

Its staff also created rules for front end subsystems for PIV systems, setting out requirements for cards and readers, logical data elements, cryptography and biometric records.

NIST defined card-supported authentication mechanisms as well as the mechanisms’ applicability to rules for “graduated levels of identity assurance.”

At the same time, NIST addressed interoperability protocols making it possible to use PIV systems used in other agencies.

The update is the result of a five-year review of the 15-year-old federal information processing standard 201.

A virtual, public meeting on the changes will be held December 9.

Article Topics

 |   |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Court rejects deal, reopens Clearview AI lawsuit over biometric data collection

A novel court settlement that resolved a legal complaint against the data collection practices of facial recognition provider Clearview AI…

 

Funding gap puts Sri Lanka’s digital ID project under review

The Sri Lanka Unique Digital Identity (SL-UDI) project faces a budget gap, with quotes from Indian companies surpassing the Indian…

 

Age assurance standard builds out with new draft on analysis of age check systems

Work continues to create and refine a comprehensive standard for online age assurance. Published last year, ISO/IEC 27566 is the…

 

UK government draws legal line in the sand on social media age minimum

The UK government says it is giving childhood back to the nation’s children with its new legislation restricting social media…

 

HMLR missing the net with Qualified Electronic Signatures, says UK digital ID sector

The UK’s digital identity sector is appealing to the HM Land Registry (HMLR), the government agency that registers ownership of…

 

OpenAI requires hardware-backed passkeys for trusted cyber access

OpenAI is requiring stronger account protection for users who access some of its most sensitive AI capabilities. Starting September 1,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events