Contactless Smart Cards, RFID, Payment, Transit and Security

Smart Card Alliance recommends best practices for RF technology in identity management

Wednesday, January 31, 2007

User notification about the information stored on a person’s contactless ID card and how it will be used and accessed and guaranteeing protection of the database where the information is stored are some of the best practices the Smart Card Alliance Identity Council recommends for RFID-style cards.


PRINCETON JUNCTION, NJ –The Smart Card Alliance Identity Council has released guidance regarding best practices for organizations implementing radio frequency (RF) technology in identity management systems.

In “Best Practices for the Use of RF-Enabled Technology in Identity Management,” the Alliance provides recommended guidelines for issuers of ID credentials using RF technology to ensure the confidentiality, integrity and validity of identity information and protect the credential holder’s privacy. The publication and accompanying FAQ document also address common misunderstandings about the use of RF technology to transmit identity information, which have led to questions about the security and privacy of RF-enabled ID credentials.

“There is a public misperception that all RF-enabled technology is synonymous with RFID,” said Randy Vanderhoof, executive director of the Alliance. “These new documents achieve a twofold purpose – providing rules for good behavior when using RF-enabled technology in identity management and clearly delineating the differences between RFID and contactless smart cards that use RF and provide security and privacy protection in identity applications.”

Radio frequency identification (RFID) is commonly used in product tags for tracking and supply chain management. Contactless smart cards are RF-enabled devices with onboard computers designed to protect identity information and its communication. Widespread corporate and government use, including the worldwide e-passport program, has validated contactless smart card technology as a secure, reliable way to transmit ID information.

Key elements of the Alliance’s best practices for using RF technology in ID management call on credential issuers to:

– Implement security techniques, such as mutual authentication, cryptography and verification of message integrity, to protect identity information throughout the application. – Ensure protection of all user and credential information stored in central identity system databases, allowing access to specific information only according to designated access rights. – Notify the user as to the nature and purpose of the personally identifiable information (PII) collected – its usage and length of retention. – Notify the user about what information is used; how and when it is accessed and by whom; and provide a redress mechanism to correct information and to resolve disputes.

Vanderhoof emphasized that RF-enabled smart cards are able to meet all the guidelines in the Alliance’s best practices document. The use of RFID tags in identity credentials, however – due to their long read range of up to 25 feet and lack of appropriate security features – could leave users open to the types of fraud and identity theft most feared by privacy advocates and government officials, he said.

“Adherence to these best practices not only helps ensure the validity, security and integrity of vital identity information, but at the same time addresses the concerns of citizens and government officials about privacy and the growing threat of identity theft,” Vanderhoof said.

About the Smart Card Alliance The Smart Card Alliance is a not-for-profit, multi-industry association working to stimulate the understanding, adoption, use and widespread application of smart card technology.For more information, visit www.smartcardalliance.org[end] 

The Smart Card Alliance Transportation Council has published a white paper examining how the transit industry can best make use of NFC technology.

“One of the major challenges facing transit agencies today is how to capitalize on the ever-growing popularity of mobile phones with a solid mobile strategy,” said Transportation Council Chairman Craig Roberts. “This white paper builds on the knowledge base developed in earlier white papers to foster a greater understanding of NFC technology, explain its role in the transit industry, and shed light on key issues facing the transit industry in developing a mobile strategy.”

read more »

Smart Chip Limited, the Indian subsidiary of Morpho, has received the Software Engineering Institute’s certification for the Maturity 3 level of the Capability Maturity Model Integration for Development (CMMI-DEV).

read more »

Intercede Group plc and Oxford Computer Group LLC (OCG) have formed a strategic alliance to sell PIV products to non-Federal organizations in the United States.

read more »

To commemorate the smart card industry’s achievements throughout 2011, the Smart Card Alliance has decided to release its first-ever E-Yearbook.

The nearly 70-page e-book discusses the year’s leadership and advancement in the smart card industry and highlights industry achievements.

read more »

ValidSoft partnered with Opus Research and released a report titled “Voice Biometrics Authentication Best Practices: Overcoming Obstacles to Adoption” that predicts the technology will be deployed in payment authentication assuming the best practices it lays out are followed.

read more »

The NFC Forum and WIMA, a global conference and exhibition for NFC applications, have issued a call for entries for the 2012 Tap Into Innovation: NFC Global Competition.

read more »

Subscribe to the Contactless News Library
Gain access to the largest collection of Auto-ID analysis on the Internet.