SlideShare a Scribd company logo
1 of 14
PIV Data Model Testing Ketan Mehta [email_address] March 3, 2006
Agenda ,[object Object],[object Object],[object Object],[object Object]
PIV Test Environment PIV Client Application Programming Interface PIV Card Command Calls Card Reader Driver Card Reader PIV Card Application PIV Data Model PIV Card Command Interface PIV MIDDLEWARE (SP 800-73) Host PC Smart Card Reader PIV CARD (FIPS 201,  SP 800-73,  SP 800-76,  SP 800-78) Test Toolkit Application
Agenda ,[object Object],[object Object],[object Object],[object Object]
Inputs Process Outputs Derived Test Requirements & Test Assertions Lab Testing: Conformance to  SP 800-73 NIST Test Guidance  —  SP 800-85 Lab Activity SP 800-85A PIV Test Methodology PIV Data Model  Testing* Agency Activity** SP 800-85B * Conformance to FIPS 201, SP 800-76, and SP 800-78 ** The process is currently being defined FIPS 201 SP 800-73 SP 800-76 SP 800-78 Test Results NPIVP Certificate Self-certification
Agenda ,[object Object],[object Object],[object Object],[object Object]
Test Areas ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
PIV Client Application Programming Interface PIV Card Command Calls Card Reader Driver Card Reader PIV Card Application PIV Card Command Interface PIV  MIDDLEWARE Agency / System Integrator Smart Card Reader PIV CARD (SP 800-73 Conformant) Test Toolkit Application ,[object Object],[object Object],[object Object],[object Object],Data Under Test SP 800-85B – PIV Biometrics Testing PIV Data Model
Enrollment Process Face Templating Fingerprint Templating CBEFF Header Generation PIV-Specific Enrollment Procedures Verification Process Fingerprint Matching Documentation  (Fingerprint and Facial Acquisition, Equipment, Procedures) - Quality dependent  on the MINEX04 test results - External to PIV testing Tested through  SP 800-85B - Dependent on the policy requirements and procedural steps - External to PIV Testing Integrated  PIV Biometrics  Process Format Validation Human Inspection Performance Tests SP 800-85B – Biometric Data Conformance
Test Toolkit Application Card Reader Driver Card Reader PIV Card Application PIV Card Command Interface Agency / System Integrator Smart Card Reader Data Under Test Certificate Profile Conformance Algorithm Conformance Signature Conformance PIV Card SP 800-85B – PIV PKI Testing PIV Data Model
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],SP 800-85B  —  Cryptographic Objects Conformance …Signature Conformance
[object Object],[object Object],SP 800-85B  —  Cryptographic Objects Conformance …Certificate Conformance
[object Object],SP 800-85B  —  BER-TLV Format Conformance
Tentative Schedule ,[object Object],[object Object]

More Related Content

Similar to Nist piv data model testing

The Rise of New Industries & How to Seize Those Opportunities at ArabNet Riya...
The Rise of New Industries & How to Seize Those Opportunities at ArabNet Riya...The Rise of New Industries & How to Seize Those Opportunities at ArabNet Riya...
The Rise of New Industries & How to Seize Those Opportunities at ArabNet Riya...ArabNet ME
 
Digital%20 signatures%20overview
Digital%20 signatures%20overviewDigital%20 signatures%20overview
Digital%20 signatures%20overviewrajesh123
 
Automated Low Level Requirements Testing for DO-178C
Automated Low Level Requirements Testing for DO-178CAutomated Low Level Requirements Testing for DO-178C
Automated Low Level Requirements Testing for DO-178CQA Systems
 
ICAM - Demo Architecture review
ICAM - Demo Architecture reviewICAM - Demo Architecture review
ICAM - Demo Architecture reviewRamesh Nagappan
 
Gateway/APIC security
Gateway/APIC securityGateway/APIC security
Gateway/APIC securityShiu-Fun Poon
 
QR Code and Transport Layer Security For Licensing Documents Verification- Ir...
QR Code and Transport Layer Security For Licensing Documents Verification- Ir...QR Code and Transport Layer Security For Licensing Documents Verification- Ir...
QR Code and Transport Layer Security For Licensing Documents Verification- Ir...irawan afrianto
 
Lads Tech Company Profile V4.0
Lads Tech Company Profile V4.0Lads Tech Company Profile V4.0
Lads Tech Company Profile V4.0Resident Meer
 
Neumann 24727 B10.12 Update 20091029 AM R3
Neumann 24727 B10.12 Update 20091029 AM R3Neumann 24727 B10.12 Update 20091029 AM R3
Neumann 24727 B10.12 Update 20091029 AM R3Agile Set, LLC
 
IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 Rob Akershoek
 
Overview fips2012 workshop presentations
Overview fips2012 workshop presentationsOverview fips2012 workshop presentations
Overview fips2012 workshop presentationspuffyduffduff
 
2022 APIsecure_Shift Left API Security - The Right Way
2022 APIsecure_Shift Left API Security - The Right Way2022 APIsecure_Shift Left API Security - The Right Way
2022 APIsecure_Shift Left API Security - The Right WayAPIsecure_ Official
 
Performance Testing Technical Meeting (http://managingperformancetesting.blog...
Performance Testing Technical Meeting (http://managingperformancetesting.blog...Performance Testing Technical Meeting (http://managingperformancetesting.blog...
Performance Testing Technical Meeting (http://managingperformancetesting.blog...akbollinger
 
Cardholder authentication for the piv dig sig key nist ir-7863
Cardholder authentication for the piv dig sig key nist ir-7863Cardholder authentication for the piv dig sig key nist ir-7863
Cardholder authentication for the piv dig sig key nist ir-7863RepentSinner
 
Computer system validation
Computer system validationComputer system validation
Computer system validationNitor Infotech
 
Application Visibility and Experience through Flexible Netflow
Application Visibility and Experience through Flexible NetflowApplication Visibility and Experience through Flexible Netflow
Application Visibility and Experience through Flexible NetflowCisco DevNet
 
Webinar: Be DevOps Ready with Testing 20170628 0656 1
Webinar: Be DevOps Ready with Testing 20170628 0656 1Webinar: Be DevOps Ready with Testing 20170628 0656 1
Webinar: Be DevOps Ready with Testing 20170628 0656 1JK Tech
 

Similar to Nist piv data model testing (20)

The Rise of New Industries & How to Seize Those Opportunities at ArabNet Riya...
The Rise of New Industries & How to Seize Those Opportunities at ArabNet Riya...The Rise of New Industries & How to Seize Those Opportunities at ArabNet Riya...
The Rise of New Industries & How to Seize Those Opportunities at ArabNet Riya...
 
Digital%20 signatures%20overview
Digital%20 signatures%20overviewDigital%20 signatures%20overview
Digital%20 signatures%20overview
 
Automated Low Level Requirements Testing for DO-178C
Automated Low Level Requirements Testing for DO-178CAutomated Low Level Requirements Testing for DO-178C
Automated Low Level Requirements Testing for DO-178C
 
ICAM - Demo Architecture review
ICAM - Demo Architecture reviewICAM - Demo Architecture review
ICAM - Demo Architecture review
 
Gateway/APIC security
Gateway/APIC securityGateway/APIC security
Gateway/APIC security
 
QR Code and Transport Layer Security For Licensing Documents Verification- Ir...
QR Code and Transport Layer Security For Licensing Documents Verification- Ir...QR Code and Transport Layer Security For Licensing Documents Verification- Ir...
QR Code and Transport Layer Security For Licensing Documents Verification- Ir...
 
Lads Tech Company Profile V4.0
Lads Tech Company Profile V4.0Lads Tech Company Profile V4.0
Lads Tech Company Profile V4.0
 
Neumann 24727 B10.12 Update 20091029 AM R3
Neumann 24727 B10.12 Update 20091029 AM R3Neumann 24727 B10.12 Update 20091029 AM R3
Neumann 24727 B10.12 Update 20091029 AM R3
 
IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022
 
Overview fips2012 workshop presentations
Overview fips2012 workshop presentationsOverview fips2012 workshop presentations
Overview fips2012 workshop presentations
 
2022 APIsecure_Shift Left API Security - The Right Way
2022 APIsecure_Shift Left API Security - The Right Way2022 APIsecure_Shift Left API Security - The Right Way
2022 APIsecure_Shift Left API Security - The Right Way
 
Performance Testing Technical Meeting (http://managingperformancetesting.blog...
Performance Testing Technical Meeting (http://managingperformancetesting.blog...Performance Testing Technical Meeting (http://managingperformancetesting.blog...
Performance Testing Technical Meeting (http://managingperformancetesting.blog...
 
13_CES_DO-178B.pdf
13_CES_DO-178B.pdf13_CES_DO-178B.pdf
13_CES_DO-178B.pdf
 
EPCPROMAN-brochure.pdf
EPCPROMAN-brochure.pdfEPCPROMAN-brochure.pdf
EPCPROMAN-brochure.pdf
 
Cardholder authentication for the piv dig sig key nist ir-7863
Cardholder authentication for the piv dig sig key nist ir-7863Cardholder authentication for the piv dig sig key nist ir-7863
Cardholder authentication for the piv dig sig key nist ir-7863
 
SiPCPE-108-1
SiPCPE-108-1SiPCPE-108-1
SiPCPE-108-1
 
Avi solution2
Avi solution2Avi solution2
Avi solution2
 
Computer system validation
Computer system validationComputer system validation
Computer system validation
 
Application Visibility and Experience through Flexible Netflow
Application Visibility and Experience through Flexible NetflowApplication Visibility and Experience through Flexible Netflow
Application Visibility and Experience through Flexible Netflow
 
Webinar: Be DevOps Ready with Testing 20170628 0656 1
Webinar: Be DevOps Ready with Testing 20170628 0656 1Webinar: Be DevOps Ready with Testing 20170628 0656 1
Webinar: Be DevOps Ready with Testing 20170628 0656 1
 

More from Kaye Beach

North america toll interoperability ati aamva e z p ass ibtta
North america toll interoperability ati aamva e z p ass ibttaNorth america toll interoperability ati aamva e z p ass ibtta
North america toll interoperability ati aamva e z p ass ibttaKaye Beach
 
Nlets implementation of xml candle aamva
Nlets implementation of xml candle aamvaNlets implementation of xml candle aamva
Nlets implementation of xml candle aamvaKaye Beach
 
Ky fusion center
Ky fusion centerKy fusion center
Ky fusion centerKaye Beach
 
Iclei programmesreport-14june2009-090626152055-phpapp02
Iclei programmesreport-14june2009-090626152055-phpapp02Iclei programmesreport-14june2009-090626152055-phpapp02
Iclei programmesreport-14june2009-090626152055-phpapp02Kaye Beach
 
Intelligence warfighter summit 16 dec09-institutionalizing-agility-keeping-i...
Intelligence warfighter summit  16 dec09-institutionalizing-agility-keeping-i...Intelligence warfighter summit  16 dec09-institutionalizing-agility-keeping-i...
Intelligence warfighter summit 16 dec09-institutionalizing-agility-keeping-i...Kaye Beach
 
Rapid reaction technology 2009 irregular warfare
Rapid reaction technology 2009 irregular warfareRapid reaction technology 2009 irregular warfare
Rapid reaction technology 2009 irregular warfareKaye Beach
 
Sensor nets the business of surveillance
Sensor nets the business of surveillanceSensor nets the business of surveillance
Sensor nets the business of surveillanceKaye Beach
 
New sensor technologies mems wireless texas
New sensor technologies  mems wireless texasNew sensor technologies  mems wireless texas
New sensor technologies mems wireless texasKaye Beach
 
GISAC GA Information Sharing and Analysis Ceneter
GISAC GA Information Sharing and Analysis CeneterGISAC GA Information Sharing and Analysis Ceneter
GISAC GA Information Sharing and Analysis CeneterKaye Beach
 
State CIO health it 2010
State CIO health it 2010State CIO health it 2010
State CIO health it 2010Kaye Beach
 
Ise enterprise architecture and common standards program
Ise enterprise architecture and common standards programIse enterprise architecture and common standards program
Ise enterprise architecture and common standards programKaye Beach
 
Robotics in future warfare 09 finkelstein
Robotics in future warfare 09 finkelsteinRobotics in future warfare 09 finkelstein
Robotics in future warfare 09 finkelsteinKaye Beach
 
NORAD NORTHCOM Experimentation Activities Key Results 2007
NORAD NORTHCOM Experimentation Activities Key Results 2007NORAD NORTHCOM Experimentation Activities Key Results 2007
NORAD NORTHCOM Experimentation Activities Key Results 2007Kaye Beach
 
Rapid reaction technology 2009 irregular warfare
Rapid reaction technology 2009 irregular warfareRapid reaction technology 2009 irregular warfare
Rapid reaction technology 2009 irregular warfareKaye Beach
 
IARPA automated low level analysis and description of diverse intelligence vi...
IARPA automated low level analysis and description of diverse intelligence vi...IARPA automated low level analysis and description of diverse intelligence vi...
IARPA automated low level analysis and description of diverse intelligence vi...Kaye Beach
 
Darpa minds eye program Industry Day Announcement
Darpa minds eye program Industry Day AnnouncementDarpa minds eye program Industry Day Announcement
Darpa minds eye program Industry Day AnnouncementKaye Beach
 
Controlled unclassified information
Controlled unclassified informationControlled unclassified information
Controlled unclassified informationKaye Beach
 
CUI briefing II
CUI briefing IICUI briefing II
CUI briefing IIKaye Beach
 
Office for state and local government coordination-and preparedness 2004
Office for state and local government coordination-and preparedness 2004Office for state and local government coordination-and preparedness 2004
Office for state and local government coordination-and preparedness 2004Kaye Beach
 

More from Kaye Beach (20)

North america toll interoperability ati aamva e z p ass ibtta
North america toll interoperability ati aamva e z p ass ibttaNorth america toll interoperability ati aamva e z p ass ibtta
North america toll interoperability ati aamva e z p ass ibtta
 
Nlets implementation of xml candle aamva
Nlets implementation of xml candle aamvaNlets implementation of xml candle aamva
Nlets implementation of xml candle aamva
 
N dex
N dex N dex
N dex
 
Ky fusion center
Ky fusion centerKy fusion center
Ky fusion center
 
Iclei programmesreport-14june2009-090626152055-phpapp02
Iclei programmesreport-14june2009-090626152055-phpapp02Iclei programmesreport-14june2009-090626152055-phpapp02
Iclei programmesreport-14june2009-090626152055-phpapp02
 
Intelligence warfighter summit 16 dec09-institutionalizing-agility-keeping-i...
Intelligence warfighter summit  16 dec09-institutionalizing-agility-keeping-i...Intelligence warfighter summit  16 dec09-institutionalizing-agility-keeping-i...
Intelligence warfighter summit 16 dec09-institutionalizing-agility-keeping-i...
 
Rapid reaction technology 2009 irregular warfare
Rapid reaction technology 2009 irregular warfareRapid reaction technology 2009 irregular warfare
Rapid reaction technology 2009 irregular warfare
 
Sensor nets the business of surveillance
Sensor nets the business of surveillanceSensor nets the business of surveillance
Sensor nets the business of surveillance
 
New sensor technologies mems wireless texas
New sensor technologies  mems wireless texasNew sensor technologies  mems wireless texas
New sensor technologies mems wireless texas
 
GISAC GA Information Sharing and Analysis Ceneter
GISAC GA Information Sharing and Analysis CeneterGISAC GA Information Sharing and Analysis Ceneter
GISAC GA Information Sharing and Analysis Ceneter
 
State CIO health it 2010
State CIO health it 2010State CIO health it 2010
State CIO health it 2010
 
Ise enterprise architecture and common standards program
Ise enterprise architecture and common standards programIse enterprise architecture and common standards program
Ise enterprise architecture and common standards program
 
Robotics in future warfare 09 finkelstein
Robotics in future warfare 09 finkelsteinRobotics in future warfare 09 finkelstein
Robotics in future warfare 09 finkelstein
 
NORAD NORTHCOM Experimentation Activities Key Results 2007
NORAD NORTHCOM Experimentation Activities Key Results 2007NORAD NORTHCOM Experimentation Activities Key Results 2007
NORAD NORTHCOM Experimentation Activities Key Results 2007
 
Rapid reaction technology 2009 irregular warfare
Rapid reaction technology 2009 irregular warfareRapid reaction technology 2009 irregular warfare
Rapid reaction technology 2009 irregular warfare
 
IARPA automated low level analysis and description of diverse intelligence vi...
IARPA automated low level analysis and description of diverse intelligence vi...IARPA automated low level analysis and description of diverse intelligence vi...
IARPA automated low level analysis and description of diverse intelligence vi...
 
Darpa minds eye program Industry Day Announcement
Darpa minds eye program Industry Day AnnouncementDarpa minds eye program Industry Day Announcement
Darpa minds eye program Industry Day Announcement
 
Controlled unclassified information
Controlled unclassified informationControlled unclassified information
Controlled unclassified information
 
CUI briefing II
CUI briefing IICUI briefing II
CUI briefing II
 
Office for state and local government coordination-and preparedness 2004
Office for state and local government coordination-and preparedness 2004Office for state and local government coordination-and preparedness 2004
Office for state and local government coordination-and preparedness 2004
 

Nist piv data model testing

  • 1. PIV Data Model Testing Ketan Mehta [email_address] March 3, 2006
  • 2.
  • 3. PIV Test Environment PIV Client Application Programming Interface PIV Card Command Calls Card Reader Driver Card Reader PIV Card Application PIV Data Model PIV Card Command Interface PIV MIDDLEWARE (SP 800-73) Host PC Smart Card Reader PIV CARD (FIPS 201, SP 800-73, SP 800-76, SP 800-78) Test Toolkit Application
  • 4.
  • 5. Inputs Process Outputs Derived Test Requirements & Test Assertions Lab Testing: Conformance to SP 800-73 NIST Test Guidance — SP 800-85 Lab Activity SP 800-85A PIV Test Methodology PIV Data Model Testing* Agency Activity** SP 800-85B * Conformance to FIPS 201, SP 800-76, and SP 800-78 ** The process is currently being defined FIPS 201 SP 800-73 SP 800-76 SP 800-78 Test Results NPIVP Certificate Self-certification
  • 6.
  • 7.
  • 8.
  • 9. Enrollment Process Face Templating Fingerprint Templating CBEFF Header Generation PIV-Specific Enrollment Procedures Verification Process Fingerprint Matching Documentation (Fingerprint and Facial Acquisition, Equipment, Procedures) - Quality dependent on the MINEX04 test results - External to PIV testing Tested through SP 800-85B - Dependent on the policy requirements and procedural steps - External to PIV Testing Integrated PIV Biometrics Process Format Validation Human Inspection Performance Tests SP 800-85B – Biometric Data Conformance
  • 10. Test Toolkit Application Card Reader Driver Card Reader PIV Card Application PIV Card Command Interface Agency / System Integrator Smart Card Reader Data Under Test Certificate Profile Conformance Algorithm Conformance Signature Conformance PIV Card SP 800-85B – PIV PKI Testing PIV Data Model
  • 11.
  • 12.
  • 13.
  • 14.