FIPS-201 Failure

By: Brian Rhodes, Published on May 28, 2012

The security market is hungry for money. With security budgets shrinking worldwide, any glimmer of untapped sales sends manufacturers and integrators scrambling. Nothing carries more impact that sweeping government regulations, and as a result, when FIPS-201 (PIV) demanded government entities reform their identity credential use, many providers jumped at the chance. Unfortunately, more than a decade later, the security industry is still waiting for race to begin.

In this update, we examine FIPS-201 intent, identify where it has gotten sidetracked, and discuss if it will ever be a significant source of security spending.

History

FIPS-201 aims to standardize physical and logical credentials into a single format:

  • Applies to over 5.7 million Federal Workers and Contractors
  • Provide official response to requirements defined in HSPD12
  • It is a joint US Department of Commerce / NIST project

When introduced, the US Government gave everyone 5 years to comply. After multiple deadline moves and delays, it still has not been universally adopted. This begs the question: "What went wrong?"

Barriers

The difficulty in pushing through FIPS-201 changes is not due to lack of awareness of the regulation itself. Rather, a host of other barriers have sidetracked adoption efforts:

  • Mass confusion understanding what FIPS-201 means: most people are waiting to be told how to be compliant.
  • Difficulty converging physical and logical identities: Getting parties to agree on compliance plans is tough.
  • Adoption required undeveloped technology: Compliant credentials and readers had to be designed first.
  • Unfunded mandates: Despite hard compliance deadlines, money was not budgeted to fund changes.
  • No enforcement beyond threats: While funding can be cut by non-compliance, real penalties are nonexistent.

Market Impact

A large integrator at PSA-TEC explained how his company geared up a major push for compliance in the government vertical, but various barriers prevented it from being a real market driver.

For example, a practical 'update' required to bring a 'legacy access control' system current to FIPS-201 standards is adopting credentials that meet ISO14443 communication standards. At the present time, this requires a type of card that mandates a 'read' range under 2 inches. In addition, FIPS-201 credential compliance requires a cryptographic 'self test' feature defined by FIPS-140. At current processing speeds, this activity takes almost a full second of continuous interface to 'read' a credential.

These requirements mean that government entities must replace all medium or long range proximity or magstripe technology readers protecting secured areas. In terms of real changes, this means a huge percentage of all installed card readers must be replaced. This does not even address the more specific data protection requirements applicable to the access control system itself, which may need to be substantially updated or forklift replaced to become compliant.

In spite of its far reaching impact, FIPS-201 compliance has not precipitated anything beyond incremental changes to most applicable access control systems. It is therefore difficult to gauge the overall effectiveness of FIPS-201. While directive's intent is smart, the case can be made that more fragmentation and confusion exist in the identity market now than before.

Future Market Driver?

The answer is: No, not it the way it was once expected. The lesson learned from this is that 'the cart cannot lead the horse'. No matter how sensitive the security market is in addressing these directives, if funding and enforcement are not concurrently made available they will be relegated into the heap of spineless legislation. Quite simply, government entities will not choose to spend money unless they are forced to or shown a tangible return on the expense. For many, FIPS-201 compliance simply becomes another check box on the '5-Year Strategic Plan' to be addressed at a later date.

Comments : PRO Members only. Login. or Join.

Related Reports

Open Access Controller Guide (Axis, HID, Isonas, Mercury) on Sep 19, 2019
In the access control market, there are many software platforms, but only a few companies that make non-proprietary door controllers. Recently,...
Directory of 68 Video Surveillance Startups on Sep 18, 2019
This directory provides a list of video surveillance startups to help you see and research what companies are new or not yet broadly known. 2019...
Fingerprints for Access Control Guide on Sep 09, 2019
Users can lose badges, but they never misplace a finger, right? The most common biometric used in access are fingerprints, and it has become one...
Assa Acquires LifeSafety Power on Sep 04, 2019
Assa Abloy is acquiring LifeSafety Power, adding to their growing collection of access control brands like Mercury, August, Pioneer Doors, and...
Mobile Access Control Guide on Aug 28, 2019
One of the biggest trends in access for the last few years has been the marriage of mobile phones and access cards. But how does this...
ZK Teco Atlas Access Control Tested on Aug 20, 2019
Who needs access specialists? China-based ZKTeco claims its newest access panel 'makes it very easy for anyone to learn and install access control...
Suprema Biometric Mass Leak Examined on Aug 19, 2019
While Suprema is rarely discussed even within the physical security market, the South Korean biometrics manufacturer made global news this past...
Biometrics Usage Statistics 2019 on Aug 13, 2019
Biometrics are commonly used in phones, but how frequently are they used for access? 150+ integrators told us how often they use biometrics,...
ProdataKey (PDK) Access Company Profile on Aug 09, 2019
Utah based ProdataKey touts low cost cloud access, wireless controllers, and no dealer required national distribution availability. But how does...
Axis Door Station A8207-VE Tested on Aug 07, 2019
Axis newest door station, the A8207-VE, claims to deliver "video surveillance, two-way communication, and access control" in a single device. But...

Most Recent Industry Reports

Open Access Controller Guide (Axis, HID, Isonas, Mercury) on Sep 19, 2019
In the access control market, there are many software platforms, but only a few companies that make non-proprietary door controllers. Recently,...
Axis Perimeter Defender Improves, Yet Worse Than Dahua and Wyze on Sep 19, 2019
While Axis Perimeter Defender analytics improved from our 2018 testing, the market has improved much faster, with much less expensive offerings...
Directory of 68 Video Surveillance Startups on Sep 18, 2019
This directory provides a list of video surveillance startups to help you see and research what companies are new or not yet broadly known. 2019...
Uniview Prime Series 4K Camera Tested on Sep 18, 2019
Is the new Uniview 'Prime' better than the more expensive existing Uniview 'Pro'? In August, IPVM tested Uniview 4K 'Pro' but members advocated...
US Army Base To Buy Banned Honeywell Surveillance on Sep 17, 2019
The U.S. Army's Fort Gordon, home to their Cyber Center of Excellence, has issued a solicitation to purchase Honeywell products that are US...
Vivotek "Neural Network-Powered Detection Engine" Analytics Tested on Sep 17, 2019
Vivotek has released "a neural network-powered detection engine", named Smart Motion Detection, claiming that "swaying vegetation, vehicles passing...
Schmode is Back, Aims To Turn Boulder AI Into Giant on Sep 16, 2019
One of the most influential and controversial executives in the past decade is back. Bryan Schmode ascended and drove the hypergrowth of Avigilon...
Manufacturers Unhappy With Weak ASIS GSX 2019 And 2020 Shift on Sep 16, 2019
Manufacturers were generally unhappy with ASIS GSX, both for weak 2019 booth traffic and a scheduling shift for the 2020 show, according to a new...
How Cobalt Robotics May Disrupt Security on Sep 13, 2019
While security robots have largely become a joke over the last few years, one organization, Cobalt Robotics, has raised $50+ million from top US...
Panasonic 4K Camera Tested (WV-S2570L) on Sep 13, 2019
Panasonic has released their latest generation 4K dome, the WV-S2570L, claiming "Extreme image quality allows evidence to be captured even under...