and other
physical access control systems equip-
ment manufacturers. This guidance
reflects current U.S. Government techni-
cal requirements and has been approved
by the Government Smart Card
InteragencyAdvisory Board (GSC-IAB).
The guideline correctly states that the
key to credibility, non-repudiation and
reciprocity in a government-wide creden-
tial program is defining and accepting a
unique number assigned to a single indi-
vidual. To achieve this, the guideline
specified the FederalAgency Smart
Credential Number (FASC-N) to replace
the SEIWG-012 definition, which has
been in use for more than 10 years. The
FASC-N will be the primary identifica-
tion string used on all government issued
credentials.
The FASC-N, a very robust and for-
ward thinking definition (read "lots of
bytes"), was created to ensure legacy
compatibility with existing systems based
on the SEIWG-012 definition.
The specification also cover what chip
technology can be used and provides the
command set for use with physical
access control. In short, it adequately
specifies how to build interoperable read-
ers and the card-reader security level.
Thecurrentguidelines,however,donot
fullyspecifyreaderstoaccesstheentire
controlpaneloutput.TheFASC-Nistoo
largeformanyaccesscontrolpanelsto
supportitsfulloutputbecausearangeof
assuranceprofiles–low,medium,and
high–areassociatedwiththeextensible
datamodelonFASC
cards.
These assurance profiles provide for
increasing the integrity of the transaction
between the card and the reader, but put
significantly greater demands on readers
and access control panels than was tradi-
tionally required.
Wisely, the government working
groups have left this issue to the industry
to resolve, with the goal of extending the
standard over time as the best solutions
emerge. NIST will be releasing a new
specification in February 2005 to comply
with HSPD#12. This is an extremely
aggressive schedule for developing an
entirely new specification and I believe
they will look to the GSC and Technical
Implementation Document for guidance
to create this new specification.A few
ambiguities do exist in these specifica-
tions today and this new spec will help
clear things up and make it easier to
achieve a truly interoperable system.
Four months after the release of the
specification, each government agency is
to have a program or plan in place for
compliance. Four months after that, they
are required to start implementing the
plan. Although there is no government
funding for this initiative, each agency is
asked to find the funds to comply. This
should be a very interesting time.
One thing is certain, new access con-
trol readers will require a great deal of
flexibility from reader manufacturers to
achieve interoperability. This is particu-
larly true in the near term, where the
only sensible way to achieve interoper-
ability will be to support several upstream
options for communicating out of the
reader to the access panels.
Over time, these older products will
give way to a new generation of open,
flexible access panels. These new sys-
tems will consist of open architecture,
and will include options for handling the
full capabilities of the FASC-N identifier,
stronger encryption and
advanced network com-
munications capabilities.
The consensus of both
industry and govern-
ment stakeholders is
that the standards and
guidelines that are in
place today are suffi-
ciently detailed to
support develop-
ment and imple-
mentation of physical
access control readers and cards.
The FASC-N definition provides a
long range, extensible foundation.At
the same time, the guidelines are flexi-
ble in defining how readers and
panels communicate. This
practical approach positions
government organizations
to gradually evolve to new
access control card and system technol-
ogy. Going too far would create an
unworkable situation in the short term
by discouraging organizations from con-
tinuing to use existing panels and sys-
tems, thereby making it economically
infeasible to migrate. Over time, stan-
dards will move higher up the system
chain as best practices for reader to
access panels emerge.