Skip to main content
Home > Case Studies > Case Study: US TSA: TWIC biometric smart cards across 160+ enrolment centres

How the US TSA
secured its workforce

The US Transportation Security Administration (TSA) is the federal agency responsible for security in all modes of transportation.

At a glance

The deployment in numbers

Organisation
US Transportation Security Administration (TSA)
Industry
Federal · Aerospace & Defence
Region
United States
Scale
Millions of transportation workers across the US
Solution
MyID CMS + MyID PIV
Partner
Direct deployment
2M
TWIC cards issued
8M+
Certificates issued
160+
Enrolment centres
3 month
Delivery
Background

Secure identities for US transportation workers

Maritime workers need a tamper-resistant biometric credential to reach secure port facilities and vessels. To obtain a Transportation Worker Identification Credential (TWIC), an applicant provides biographic and fingerprint data, sits for a digital photograph and passes a security threat assessment conducted by the agency.

The agency set out to meet US Government Homeland Security Presidential Directive 12 (HSPD-12) standards, achieve interoperability with other federal identity systems and apply best practice security processes across the programme.

01 · The Challenge

A tamper-resistant biometric credential, issued to HSPD-12 standards

The agency set out to meet US Government Homeland Security Presidential Directive 12 (HSPD-12) standards, achieve interoperability with other federal identity systems and apply best practice security processes across the programme

FIPS 201 PIV technology

Centralised production, local activation

160+ enrolment centres

Bureau integration for secure printing

Multi-application card combining contact and contactless technology

Strong authentication of operators and non-repudiation of operator actions

02 · The Solution

One platform, from registration to an activated card

MyID CMS PIV sits inside the agency’s federal identity management solution and provides a single software platform that takes a transportation worker from identity registration through to a personalised, activated smart card.

1

Centralised processing

MyID software is passed registration data from the IDMS and formats it into a card personalisation request, which is forwarded to the personalisation bureau.

2

Distributed activation

printed cards are locked and sent to activation locations. The receipt of a card batch triggers notification to the applicant that their card is ready.

3

Biometric self-service activation

the applicant visits an activation location, places their card into a MyID activation station and follows a simple self-service workflow that requires biometric verification before the card is unlocked, personalised with certificates and activated for use.

4

Access enforcement

without a TWIC card transport workers cannot gain access to secure facilities and networks.

03 · The Results

Two million TWIC cards issued, live in three months

MyID issues and activates TWIC smart cards for transportation workers through a central bureau and over 160 self-service activation centres, scaled across multiple servers to a peak of 10,000 cards per day. The solution went from order to live production in three months, and has since issued over 2 million cards and 8 million certificates.

Proven at federal scale

over 2 million cards and 8 million certificates issued to date, at a peak of 10,000 cards per day, delivered from order to live production in three months, across more than 160 enrolment and activation centres.

Reliable and user-friendly

multi-server deployment for high availability, simple web-based workflows requiring minimal operator training, enabling end users to self-serve.

Secure

biometric authentication of TWIC applicants, combined with high-security printing with on-card key generation for maximum security.

Compliant

a FIPS 201 compliant solution producing PIV-compatible (TWIC / CIV) credentials, with keys generated on the card at activation.

Standards & compliance met
FIPS 201 PIV HSPD-12 Bureau issuance with self-service activation PKI / X.509 standard
About Intercede

The platform behind the deployment

Intercede is a cybersecurity software company and the digital identity experts. For over 25 years, Intercede has helped government agencies, defence programmes, financial institutions and enterprises deploy phishing-resistant digital identities at scale.

The MyID product family, MyID CMS, MyID MFA and MyID PSM, manages millions of credentials across more than 20 countries. Vendor-neutral architecture means MyID integrates with virtually any certificate authority, hardware security module or smart card manufacturer, without organisations replacing existing infrastructure.

Learn about MyID PIV →

Similar challenge in your organisation?

Whatever your sector, MyID PIV provides the proven, standards-aligned platform to secure your workforce, citizens or supply chain. Talk to Intercede about a deployment tailored to your environment.