TSA TWIC Program Operational Considerations and One Manufacturer s TWIC Pilot Experience

Similar documents
Transportation Worker Identification Credential (TWIC) Program Briefing

TWIC Reader Acquisition Cost Estimates

Application & Benefits of TWIC Readers. Walter Hamilton Vice Chairman, IBIA & Senior Consultant, ID Technology Partners

1667 K Street, NW Suite 700 Washington, DC 20006

Transportation Worker Identification Credential: Leveraging New Technologies to Integrate Access Control Readers with High Security Standards AC02

June 20, Transportation Worker Identification Credential Reader; Notice of Proposed Rulemaking RIN 1625-AB21

Fourchon Launch Services, LLC Dock and Vessel Security Guidelines. Dock and Vessel Security Guidelines

Transportation Worker Identification Credential (TWIC) Program Briefing

The Role of the South Carolina State Port Authority Police Dept. August 2009

Transportation Worker Identification Credential (TWIC) Program. American Association of Port Authorities 2013 Security Seminar July 17, 2013

Template Document for the Interim Final Rule 33 CFR

IN THE FAST MOVING WORLD OF AVIATION YOU CAN RELY ON AC2000 AIRPORT; A POWERFUL ACCESS CONTROL AND SECURITY MANAGEMENT SYSTEM AC2000 AIRPORT

United States House of Representatives. Committee on Homeland Security, Subcommittee on Border and Maritime Security

AWR 144: Port and Vessel Security for Public Safety and Maritime Personnel Introduction

Subj: CH-2 to 03-03, IMPLEMENTATION GUIDANCE FOR THE REGULATIONS MANDATED BY THE MARITIME TRANSPORTATION SECURITY ACT OF 2002 (MTSA) FOR FACILITIES

Subj: CH-2 to 03-03, IMPLEMENTATION GUIDANCE FOR THE REGULATIONS MANDATED BY THE MARITIME TRANSPORTATION SECURITY ACT OF 2002 (MTSA) FOR FACILITIES

Wednesday, May 14. Track D Security & Access Control

Statement of Richard Smith, Westar Marine Services On behalf of The American Waterways Operators

Hamilton Port Authority Security Guidelines

ITS Canada 2016 Conference

Card Tech / Secure Tech November 19, 2002

Questions and Answers about the Proposed Use of RFID for U.S. Border Crossing Documents

Entry Station. Lane Entry Station. LE Station

Introduction to Homeland Security

EMV Terminology Guide

Case Study: NYK Logistics

Identiv Credentials. Ordering Guide for Cisco. June 2016

Time Clocks for Employee Attendance Tracking. InfoTronics, Inc. Farmington Hills, MI

Transportation Worker Identification Credential (TWIC)

Homeland Security Presidential Directive (HSPD-12) Product and Service Components

New project for: message specification for ro-ro cargo

Utah Transit Authority. Utah Transit Authority Electronic Fare Collection Full System Deployment

AGORA Final Conference, Frankfurt Some Numbers

RFP #2514S016 System Requirements PEC Scoring Metrics Matrix - ATTACHMENT #14

BULK LIQUID FACILITY INSPECTION JOB AID

Cards on the table! Bernd Filsinger Payment Technology Services Lead Client Support Services, Europe region

AC2000 LITE; A POWERFUL, FEATURE RICH ACCESS CONTROL AND SECURITY MANAGEMENT SYSTEM FOR SMALL TO MEDIUM SIZED SITES AC2000 LITE

ECSG (Vol Ref. 8.A01.00) SEPA CARDS STANDARDISATION (SCS) VOLUME. Payments and Cash Withdrawals with Cards in SEPA

The Future of Airport Information Technology (IT) Presentation to, ACI-NA Airport Board Members and Commissioners Conference April 28, 2009

TONNAGE OVERSUPPLY & COMPLIANCE COSTS PAGE 10 NAMEPA 5 YEARS OF BUILDING BRIDGES PAGE 14 JONES ACT DEBATE IN PUERTO RICO PAGE 24

DELIVERY INSTRUCTION FOR VEHICLE (BALTIMORE)

For Purchase & Installation call: Biometric Enabled Access and T&A Solutions. License# EF

Access Control. StarWatch SMS - Core System Capabilities

Physical and Logical Identity Management: The Good, the Bad and the Ugly. Carolyn Loew The Boeing Company

First Data Merchant Solutions EFTPOS. 8006L2-3CR Integrated PIN Pad. User Guide

Identity Management. ID management for people and objects

ADDITIONAL FUNDING AND AGREEMENTS (5)

EMV Chip Cards. Table of Contents GENERAL BACKGROUND GENERAL FAQ FREQUENTLY ASKED QUESTIONS GENERAL BACKGROUND...1 GENERAL FAQ MERCHANT FAQ...

Is Your Organization Ready for the EMV Challenge?

Flexible Scalable Complete. Sustainable Future Maximum Investment

access to the world s markets. The National Conference of State Legislatures (NCSL) recognizes

Flexible Scalable Complete. Sustainable Future Maximum Investment

Card Payment acceptance at Common Use positions at airports

Company Introduction. Electronic Trade Solutions Ltd

Tuesday, May 13 Track D Security & Access Control

Virginia s Long-Range Multimodal Transportation Plan SECURITY. Prepared for: Office of Intermodal Planning and Investment October 2009

KEY MANAGEMENT SOLUTIONS

Best Practices on Project Implementation

FACILITY SECURITY PLAN (FSP) REVIEW CHECKLIST

Semi-Integrated EMV Payment Solution

Controlled Access Pharmaceutical Dispensers 24/7 Controlled Access True Inventory Visibility Real Time Reporting

Truck entrance/exit complex: Driver procedure

Gate Innovations & Technologies for Improving Throughput, Efficiency and Security. AAPA Annual Convention 2009 Information Technology Award

Smart credentials. Enabling today s and tomorrow s digital identities.

Properly Securing. Terra Industries

PayPass Mag Stripe Vendor Testing Process (Cards & Devices)

EMV Frequently Asked Questions for Merchants May, 2015

FERRIBY MARINE SHIP SECURITY ASSESSMENT AUDIT CHECKLIST

Frequently Asked Questions for Merchants May, 2015

Smart credentials. Enabling today s and tomorrow s digital identities.

How to Plan, Procure & Deploy a PIV-Enabled PACS

Proactive Approaches. To Minimize. Supply Chain Security. Breaches in the Rail, Air, Ocean and Land Environment

RFID AS A TOOL FOR SAFETY, SECURITY, PRIVACY AND CONVENIENCE FOR INTELLIGENT TRANSPORT SYSTEMS

X Infotech Banking. Software solutions for smart card issuance

Winter 2019 Network Updates. Webinar Presentation January 29, 2019

Electronic I-9 Documentation Guardian Electronic I-9 and E-Verify Compliance with 8 CFR 274a.2

POSITION DESCRIPTION

Brisbane Container Terminals. Receival / Delivery Processes. June 2016

!"#$"%& National ID Cards Today and Beyond: Streamlining the Delivery of Multi-Technology ID Solutions

Target, the third largest retailer in the U.S., suffered a

SecurWave. Integrated security system for high-risk remote surveillance sites

eid Meets Credit Cards and Biometrics: The Next Stage of Convergence Adam Ross Sales Manager eid Solutions EMEA, cv cryptovision GmbH

A brand new cash recycler makes a real difference in your total cost of ownership

Secure and Transparent Cargo Supply Chain: Enabling Chain-of-Custody with Economical and Privacy Respecting Biometrics, and Blockchain Technology

INVESTOR PRESENTATION DNB TMT CONFERENCE

Research Activities. RFID and Wireless Technologies for Transportation Industry

Using RFID for Customs Control on Transit Containers

Best practices of digital technology application in transport facilitation and logistics

II. IMPORT FLOW FOR RO-RO (PORT KLANG)

X Infotech Government

Testing & Certification Terminology

Vehicle Booking System User Guide Lyttelton Container Terminal

THE STATE OF PHYSICAL ACCESS CONTROL: IMPACT ON THE ENTERPRISE

SOP USCG PERMITTNG OF EXPLOSIVES TRANSFER

A Review of RFID ISO Standards & CEN TC225 Developments. Paul Chartier Principal, Praxis Consultants Chair, CEN TC225 RFID Ad Hoc October 2007

Terminal Information Handbook

IFSF V2 of POS/FEP and Host/Host

PIN Issuance & Management

GAME TO SYSTEM (G2S) VERSUS SLOT ACCOUNTING SYSTEM (SAS)

Maritime Energy Transport Regulatory Overview and Status

Transcription:

TSA TWIC Program Operational Considerations and One Manufacturer s TWIC Pilot Experience

TSA TWIC Program Topics Covered Overview of latest Notice of Public Rulemaking Operational Considerations of TWIC Implementation Interesting Lessons Learned One Reader Manufacturers Experience

Coast Guard Notice of Proposed Public Rulemaking Released March 27, 2009 Risk Based Approach Based on maximum consequence of a terrorist attack; impact on nation s health, economy, and security Three categories, high (A), medium (B), low (C) - Category A: vessels carrying more than 1000 passengers, vessels carrying dangerous cargoes, towing vessels - Category B: vessels carrying 500 to 1000 passengers, vessels carrying hazardous flammable or combustible material, towing vessels - Category C: vessels carrying less than 500 passengers, vessels carrying nonhazardous cargoes, offshore supply vessels, towing vessels, and offshore drilling units 1

Coast Guard Notice of Proposed Public Rulemaking Risk Category Marsec 1 Marsec 2 Marsec 3 A More than 1000 passengers CDCs Biometric Match to Card Hotlist Check- Update weekly Card Authentication Certificate Check Hotlist Check Update daily Hotlist Check Update daily B 500-1000 passengers HAZ MAT, Crude Oil Once a month random Biometric Match to Card Hotlist Check- Update weekly Card Authentication Certificate Check Biometric Match to card Hotlist Check Update daily Biometric Match to card Hotlist Check Update daily C Less than 500 passengers Non-HAZ MAT, Visual inspection of Card Check Security Features Expiration Date Check CG random spot checks No Change No Change 2

TSA TWIC Program Operational Considerations The biggest challenge for customers: TWIC Card interfaces provide access to different data elements on the Card 3

TSA TWIC Program Operational Considerations The biggest challenge for customers: Understanding how to read the TWIC card to get the data needed Cardholder Picture is only available through contact read of card and PIN entry Biometric authentication requires access to encrypted template via contactless interface and access to TPK (TWIC Privacy Keys) - How is the TPK made available to the TWIC reader? Biometric authentication requires access to the TWIC Privacy Keys (TPK) available only from magnetic stripe or a contact read of card (no PIN) 4

TSA TWIC Program Operational Considerations Integrating TWIC Card into Existing PACS Define TWIC card registration in the existing PACS system - Hotlist check during card registration Consider other systems that use existing PACS ID, do they need the TWIC card PACS ID? How is the TWIC Card going to be read at the gate, on the dock? Driver for this decision is TCP/IP connectivity 5

TSA TWIC Program Operational Considerations TCP Connectivity Contactless + Biometric Sensor + Hotlist Check Contact + Biometric Sensor + Hotlist Check No TCP Connectivity Manual load of Hotlist Check Contactless + Biometric Sensor + Magnetic Stripe Reader Contact + Biometric Sensor 6

TWIC Pilot Program Port of Brownsville Overview 12 Outdoor Biometric TWIC Readers in Operation Locations range from Dock, Truck Lanes, Car Lanes, to Coal Yard Port of Brownsville selected because of its harsh environment: Extreme temperatures and humidity Dusty, grimy environment Prime Contractor with Two Subs performing the installation 7

TWIC Pilot Program Port of Brownsville Lessons Learned Prime contractors and sub-contractors did not have TWIC cards early on Didn t understand TWIC Card is not a touch and go card - When read TWIC card is passing 27,000 bits or more of data; prox card only passes 26 bits of data Didn t understand the FIPS201 TWIC card rules - What data has to be read from the card, what is stored for future access what is always read from the card in real time - What data must the TWIC reader access to perform required functions 8

TWIC Pilot Program Port of Brownsville Lessons Learned Conflicting messages from Local Coast Guard and TSA TWIC Team - this has now been addressed in the HomePort TWIC FAQs CG: TWIC cardholders must enter PIN to authenticate to card TSA TWIC Team: TWIC cardholders do not need to know PIN for registration of TWIC card into PACS TWIC Reader Specifications do not and were not meant to address operational considerations PACS registration of TWIC card should require a hotlist check Non networked fixed readers are not required to check a TWIC card against the Hotlist Functional Specification Conformance Tests (F-SCT) underway Major goals: identify inconsistencies and vague specifications, validate the test protocol 9