The Need for Digital Identities - SureID Aug 2015

20
110-SI-F00006 EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION The Need for Digital Identities 1 Susan Krautbauer Regional Account Manager, Strategic Alliances 03Q15

Transcript of The Need for Digital Identities - SureID Aug 2015

Page 1: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION

The Need for Digital Identities

1

Susan KrautbauerRegional Account Manager, Strategic Alliances

03Q15

Page 2: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 2

Identity Verification - a growing problem

One, Social Security Numbers which are universal, but not reliable;

Two, state-issued driver's licenses which are reliable, but not universal.

March 26, 2012, David Frum, CNN

The U.S. has created two forms of de facto ID:

Page 3: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 3

In Minnesota, over 10,000

fraudulent driver’s license

were discovered in 2012.

Individuals were using stolen

SSN to obtain a driver’s

licenses.

Identity Theft is Rampant

June 11, 2015 – Hackers…are believed to have stolen SSN records for as many as 18 million current and former federal employees and contractors. ~Associated Press

Page 4: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 4

Did you know 65 million U.S. adults,

over one in four people, have a criminal record.

Source: The National Employee Law Project, March 2011

Page 5: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 5

Your Customers Trust You To Keep Them Safe.NOT KNOWING WHO YOU CAN TRUST PUTS YOUR CUSTOMERS AND BUSINESS AT RISK

Not truly knowing who you are sending to interact with your customers can lead to consequences (e.g., robberies, inappropriate behavior, violent crime, trafficking)

Actions on-premise reflect on your business and you may be legally liable for harm and/or damages

Your business has inherent business risks using third-party vendors since you are not privy to their employment screening (or if they had one)

Page 6: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 6

How will you protect & secure…

Intellectual Property 3rd Party Vendor Access Business Operations

Children, Elderly, At-Risk Volunteers, Disaster Response In-Home & Shared Economy

Page 7: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 7

The SolutionAn effective solution would be to issue tamper-proof, biometric ID cards — using fingerprints or a comparably unique identifier — to demonstrate legal status and identity by “non-forgeable electronic means.” Helderman and Branigin,

Page 8: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 8

Page 9: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 9

WHO USES OUR SERVICES?

Eid Passport has provided identity authentication to 818,000+ employees of more than 60,000 small, medium, and large companies doing business with

the U.S. Navy, Army, Marine Corps, and Coast Guard.

Page 10: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 10

RAPIDGate® Program: Identity Management for U.S. Department of Defense (DoD)

Page 11: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 11

IDENTIFYKBA (knowledge -based

authentication)

SSN VerificationAddress History

CREDENTIALSmart CardTechnologyTamper-ResistantSureID Brand

VERIFYWebMobileBiometric Authentication

SCREENFelonyMisdemeanorsLifecycle ScreeningSex OffendersMultiple Providers

Assurance

Page 12: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 12

Real Time Verification

Mobile Access

By utilizing the SureID mobile application, not only can your security personnel validate a

person’s right-to-access in real time while inside your corporate

facilities, but end users and organizations in the public service

arena can also be assured that volunteers, staff, contractors and

coaches are to be trusted.

Page 13: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 13

Watch Dog Services

The SureID Service runs a

reoccurring background screen every

92 days.

It will tell you who belongs. And who doesn’t.

Page 14: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 14

How will you use ?

Page 15: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 15

Three Levels of Engagement

Adopt(standard)

Amplify(premier)

Accept(entry level)

Agree to accept the SureID credential throughout your organization

Utilize SureID on campus for staff, 3rd party vendors / contractors

Deploy SureID across your distributed field organization /volunteer network

Page 16: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 16

How will you participate in the Trust Network? It’s your choice.

Page 17: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 17

Learn more about SureID and Eid Passport

For Business https://vimeo.com/125268837

For Volunteers https://vimeo.com/113761758

For Disaster Response https://vimeo.com/124257212

For Highly Secure (PIV-I) https://vimeo.com/74734324Critical Access Control

RAPIDGate® Program awarded Best Integrated System for HSPD-12/FIPS-201 Compliance

Over the past three years, Eid Passport has grown revenue by 400%+ percent

Page 18: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 18

sureid.com

To learn how you can get involved in the SureID trusted network, please contact:

Susan KrautbauerRegional Account Manager, Strategic Alliances

Minneapolis Office: [email protected]

Page 19: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 19

Level of Assurance (LOA) OverviewLevels of Assurance Examples

“Level 1 appears to be positioned as an identifier rather than an actual identity an identifier can be used to present information on a

consistent basis and can be, but does not have to be, loosely associated with an individual.”

Library Card

“Level 2 assurance is provided when a secret token or key is memorized by one or more parties allowing a trusted relationship

to exist, without the need for full identification.”Gmail Account

“Level 3 can best be described as an account based credential with additional verification…To confirm the validity of the information in

the context of usage, relying parties should undertake some verification of the identity information. Some enrollment is required and verification of the enrollment information is needed to confirm

the claimed identity.”

SureID

“Level 4 implies knowledge of a person’s identity with personal identifiable information (PII) required and present….For there to be non-reputable chain of trust, this credential must provide two or

three factor authentication.”

Military CACRapidGate(Passport)

Source: Smart Card Alliance, “Assurance Levels Overviews and Recommendations”

Page 20: The Need for Digital Identities -  SureID Aug 2015

110-SI-F00006

EID PASSPORT PROPRIETARY AND BUSINESS SENSITIVE INFORMATION 20

Accreditations and CertificationsDIACAP - Defense Information Assurance Certification & Accreditation ProcessMAC II ATO & PIA (U.S. Army)MAC III ATO & PIA (U.S. Navy)MAC III ATO (U.S. Marines)MAC – Mission Assurance Category | ATO – Authority to Operate | PIA – Privacy Impact Assessment

FBI ChannelerElectronic fingerprint submission to Criminal Justice Information SystemDisseminate criminal history summary on behalf of the FBI

National Institute of Standards and Technology SP800-63 Electronic AuthenticationLevel of Assurance 4 (Very High Confidence)

FIPS Federal Information Processing Standards201-1 Personal Identity Verification140-2 Communications Encryption

Federal Bridge Certificate Authority (FBCA)RAPIDGate Premiere Personal Identity Verification–Interoperable (PIV-I) credential

20