CAC, TWIC, PIV – Oh My!

Wizard of Oz characters looking at a PIV badge with QR code and photo ID

When Telaeris deploys our handheld products for US Government projects, we are asked to work with a variety of very similar government credentials – CAC, TWIC, PIV and others. Like many industries, it feels a little like alphabet soup trying to keep track of all the acronyms. When I first started working with these cards in the late 1990s, it would have been hugely helpful to have had a reference like this to understand the technology landscape.

This blog is meant to be a quick history of these government credentials along with explaining the similarities and differences between the cards. In upcoming blogs, we will dig into what goes on with the data in the cards and provide an interesting story about the handheld badge reading industry itself.

The History

Common Access Card (CAC)

After Desert Shield and Desert Storm in 1990/1991, the Department of Defense (DoD) discovered a large hole in how their personnel information systems operated – basically the systems deployed by the Army, Navy, Air Force were not interoperable. Over the next decade, the DoD tested, piloted, and successfully launched the Common Access Card standard. This was strongly guided by the Government Smart Card Interoperability Specification (GSC-IS), led by the GSA and NIST. By 2002 more than a million cards were issued.

Line graph showing daily CAC cards issued rising from under 1,000 in June 2001 to over 6,000 by May 2002

The card was constructed with an ISO7816 contact chip running a 32K Java Card. This stored more than 500 data elements on it to meet the requirements of a variety of stakeholders, but the primary purposes of the card were:

  1. Digital signatures for electronic transactions, mostly email.
  2. PKI tokens for network security, logical access, and privilege revocation
  3. Personnel mobility processing for deployments and record access

Diagram of a Common Access Card (CAC) labeling federal identifier, expiration date, affiliation, rank, integrated circuit chip, and Geneva Conventions category fields

Very quickly, the DoD realized an omission in the CAC specification; existing DoD badges were already being used for physical access control systems (PACS). Moving to a contact chip would be a step backwards. I distinctly remember one agency that had an HID chip and coil built into their badges to allow them to use one card for both physical and logical access control.

By 2004, contactless support was being worked into the CAC spec using the ISO14443 standard, with extensive consultation with players in the security industry. 

Personal Identity Verification (PIV) Cards

With both contact and contactless in place, the stage was set for Homeland Security Presidential Directive 12 (HSPD-12) signed by President George W. Bush. This policy mandated a single standard for ID cards used by federal government employees and contractors.

In February of 2005, the document FIPS 201 was published, built strongly on the same work done by the GSC-IS. This defined the common credential set for smart cards and was closely modeled after the CAC standards. Government agencies were generally fully deployed by the start of 2009.

Transportation Worker Identification Credential (TWIC)

While all of this was playing out, a separate problem had been brewing at the ports. In 1999/2000 the US government identified that US seaports were not secure from unauthorized personnel entry in comparison to our airports. Then 9/11 made everything more urgent and the US Government quickly enacted the Aviation and Transportation Security Act. This required the TSA to come up with measures to improve security at the ports. The TWIC card came from the Maritime Transportation Security Act of 2002 which was amended in 2006 by the SAFE Port Act. 

The agency is to be commended. Instead of creating a new credential, the TSA leveraged the existing government work so that TWIC was compatible from day one. The biggest difference today with TWIC cards is the fact that the biometric data can be read over the contactless interface, as opposed to limiting it to the contact card.

Government Smart Cards Using the CAC/PIV Data Model

Card Type Relation to PIV Data Model Typical Use
CAC
Common Access Card
DoD-issued cards.
Based on GSC-IS standards
DoD military, civilian employees, contractors
PIV
Personal Identity Verification
Federal civilian agencies.
Uses FIPS 201 / SP 800-73
Federal employee/contractor identity & access
PIV-I
PIV-Interoperable
Non-federal issuers.
Same PIV data model. 
State/local government, non-federal contractors
CIV – Commercial Identity Verification Private sector
PIV data model. No federal bridge PKI verification.
Commercial/enterprise identity credentials
FRAC – First Responder Authentication Credential DHS-sponsored; PIV-I based Emergency responders
TWIC (Transportation Worker Identification Credential) TSA-issued; PIV data model w/maritime-specific extensions Port/maritime facility and vessel access

 

Staying Up To Date

In the years since, the standards have been incrementally updated. FIPS 201 is now on its third revision. The interface for PIV, GSC-IS 2.1, has been superseded by 5 subsequent revisions, now called SP 800-73. As the technology is used more broadly, documenting the capabilities is required.

When I started working with these cards in the late 1990s, nobody could tell you how the pieces were going to fit together, and the references were scattered among many working groups. Thirty years later the standards are still changing and the acronyms have multiplied. What has not changed is the need to understand the data model underneath them. 

This is one of the things our customers do not need to worry about. Our engineers spend significant time making sure we know the card data models and commands inside and out, so we can always keep our firmware up to date – meaning you don’t have to understand the alphabet soup!

Across hundreds of deployments, we can read a CAC at a base gate, muster PIV-carrying employees during a federal building evacuation, or validate a TWIC holder’s biometric at a port terminal without missing a beat. If you want to see how our solution works in your environment, email us at [email protected] and we will walk you through it.

Hand holding a PIV card with photo ID up to a Telaeris handheld badge reader for scanning

Email Subscription

Get the latest updates sent directly to your inbox!

By signing up, I understand and agree to the email marketing terms and conditions