FIPS-201 Failure

By: Brian Rhodes, Published on May 28, 2012

The security market is hungry for money. With security budgets shrinking worldwide, any glimmer of untapped sales sends manufacturers and integrators scrambling. Nothing carries more impact that sweeping government regulations, and as a result, when FIPS-201 (PIV) demanded government entities reform their identity credential use, many providers jumped at the chance. Unfortunately, more than a decade later, the security industry is still waiting for race to begin.

In this update, we examine FIPS-201 intent, identify where it has gotten sidetracked, and discuss if it will ever be a significant source of security spending.

History

FIPS-201 aims to standardize physical and logical credentials into a single format:

  • Applies to over 5.7 million Federal Workers and Contractors
  • Provide official response to requirements defined in HSPD12
  • It is a joint US Department of Commerce / NIST project

When introduced, the US Government gave everyone 5 years to comply. After multiple deadline moves and delays [link no longer available], it still has not been universally adopted [link no longer available]. This begs the question: "What went wrong?"

Barriers

The difficulty in pushing through FIPS-201 changes is not due to lack of awareness of the regulation itself. Rather, a host of other barriers have sidetracked adoption efforts:

  • Mass confusion understanding what FIPS-201 means: most people are waiting to be told how to be compliant.
  • Difficulty converging physical and logical identities: Getting parties to agree on compliance plans is tough.
  • Adoption required undeveloped technology: Compliant credentials and readers had to be designed first.
  • Unfunded mandates: Despite hard compliance deadlines, money was not budgeted to fund changes.
  • No enforcement beyond threats: While funding can be cut by non-compliance, real penalties are nonexistent.

Market Impact

A large integrator at PSA-TEC explained how his company geared up a major push for compliance in the government vertical, but various barriers prevented it from being a real market driver.

For example, a practical 'update' required to bring a 'legacy access control' system current to FIPS-201 standards is adopting credentials that meet ISO14443 communication standards. At the present time, this requires a type of card that mandates a 'read' range under 2 inches. In addition, FIPS-201 credential compliance requires a cryptographic 'self test' feature defined by FIPS-140. At current processing speeds, this activity takes almost a full second of continuous interface to 'read' a credential.

These requirements mean that government entities must replace all medium or long range proximity or magstripe technology readers protecting secured areas. In terms of real changes, this means a huge percentage of all installed card readers must be replaced. This does not even address the more specific data protection requirements applicable to the access control system itself, which may need to be substantially updated or forklift replaced to become compliant.

In spite of its far reaching impact, FIPS-201 compliance has not precipitated anything beyond incremental changes to most applicable access control systems. It is therefore difficult to gauge the overall effectiveness of FIPS-201. While directive's intent is smart, the case can be made that more fragmentation and confusion exist in the identity market now than before.

Future Market Driver?

The answer is: No, not it the way it was once expected. The lesson learned from this is that 'the cart cannot lead the horse'. No matter how sensitive the security market is in addressing these directives, if funding and enforcement are not concurrently made available they will be relegated into the heap of spineless legislation. Quite simply, government entities will not choose to spend money unless they are forced to or shown a tangible return on the expense. For many, FIPS-201 compliance simply becomes another check box on the '5-Year Strategic Plan' to be addressed at a later date.

Comments : PRO Members only. Login. or Join.

Related Reports

Hikvision DS 2nd Gen Intercom Tested on Dec 12, 2019
With its newest IP intercom, Hikvision proclaims users can 'get full control over an entrance' regardless of where it is installed, home or office...
Access Startup Multi-Mount Aims To Streamline Reader Installs on Dec 03, 2019
Startup Multi-Mount claims it makes installing access readers 'Fast', 'Secure,' and fit 'any size frame.' The company states its bracket 'fits most...
Directory of Access Reader Manufacturers on Nov 27, 2019
Credential Readers are one of the most visible and noticeable parts of access systems, but installers often stick with only the brand they always...
Top 2020 Trend - AI Analytics on Nov 22, 2019
170+ Integrators answered: What do you think will be the top industry trend in 2020? Why? For the 4th year in a row, AI/video analytics was...
Glass Doors and Access Control Tutorial on Nov 21, 2019
One of the biggest access challenges are locking and securing glass doors. Unlike wood or steel doors that can be modified to work with...
ISC East 2019 Show Report on Nov 21, 2019
IPVM has finished in New York City covering both days of the ISC East 2019 show. Here is a 6+ minute general walkthrough: Inside this report,...
Avigilon H4 Intercom Tested on Nov 20, 2019
Avigilon is well-known for video surveillance and access, but how well does the company's intercom work? We purchased and tested Avigilon's H4...
Top Manufacturers Gaining and Losing 2019 on Nov 18, 2019
2019 has been an explosive year for video surveillance, with the world's two largest manufacturers, Dahua and Hikvision, being sanctioned for human...
The Access Control Codes Guide: IBC, NFPA 72, 80 & 101 on Nov 07, 2019
For access, there is one basic maxim: Life safety above all else. But how do you know if all applicable codes are being followed? While the...
100+ Companies Profile Directory on Nov 06, 2019
While IPVM covers the largest companies in the industry regularly (like Axis, Dahua, Hikvision, etc.), IPVM strives to do a profile post on each...

Most Recent Industry Reports

ADT CEO Not Worried About DIY: "2 Discrete Markets" on Dec 13, 2019
ADT's CEO is not worried about DIY, characterizing DIY and ADT's DIFY as "2 discrete markets" at the Imperial Capital Security Investor's...
Hikvision CEO Alleged Illegal Activities Investigated on Dec 13, 2019
Hikvision's CEO Hu Yangzhong is under investigation for suspected illegal activities, according to the PRC's securities regulator. This has become...
Video Surveillance 101 Course Opened on Dec 12, 2019
IPVM is adding a Video Surveillance 101 course, designed to help those new to the industry to quickly understand the most important terms,...
Verkada Notification Outage on Dec 12, 2019
Verkada is suffering an event notification outage and analytic search failures. Inside, we examine what the issues are, what Verkada told IPVM...
Hikvision DS 2nd Gen Intercom Tested on Dec 12, 2019
With its newest IP intercom, Hikvision proclaims users can 'get full control over an entrance' regardless of where it is installed, home or office...
Honeywell 30 Series Cameras Tested Vs Dahua and Hikvision on Dec 11, 2019
Honeywell has infamously OEMed Dahua and Hikvision for years, but now they have introduced an NDAA-compliant line, the 30 Series, claiming "lower...
"Good Market, Bad Business Models" - Residential Security on Dec 11, 2019
Industry banker John Mack, at his company's annual event, took aim squarely at the problems in the residential security...
IP Camera Browser Support: Who's Broken / Who Works on Dec 10, 2019
For many years, IP cameras depended on ActiveX control, whose security flaws have been known for more than a decade. The good news is that this is...
Acquisitions - Winners and Losers on Dec 10, 2019
Most major manufacturers have been acquired over the last decade. But which have been good deals or not? In this report, we analyze the...
IP Camera Installability Shootout 2019 - Avigilon, Axis, Bosch, Dahua, Hanwha, Hikvision, Uniview, Vivotek on Dec 09, 2019
What are the best and worst cameras to install? Which manufacturers make it the hardest or easiest to install their cameras? We tested 35 total...