This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Department of Defense Common Access Card | |
|---|---|
| Name | Common Access Card |
| Caption | A Department of Defense smart card for identification and authentication |
| Issued by | Department of Defense |
| Type | Smart card, identification |
| Purpose | Identification, authentication, access control |
Department of Defense Common Access Card The Department of Defense Common Access Card is a smart card used for identification and secure access across numerous Pentagon facilities, information systems, and services linked to United States Armed Forces. It integrates cryptographic certificates, biometric templates, and physical credentials to support interoperability with systems associated with United States Department of Defense, National Security Agency, United States Cyber Command, and other defense-affiliated organizations. Its deployment affects personnel from branches such as the United States Army, United States Navy, United States Air Force, United States Marine Corps, and United States Space Force.
The Common Access Card serves as a portable credential enabling logical and physical access, leveraging standards promoted by National Institute of Standards and Technology, International Organization for Standardization, and the Federal Information Processing Standards. It supports Public Key Infrastructure functions aligned with policies from the Defense Information Systems Agency and certificate authorities used by United States Cyber Command and allied systems. Card-supported applications include secure e-mail compatible with Microsoft Exchange, VPN access used with appliances from Cisco Systems, and facility entry interoperable with readers from vendors such as HID Global.
Development began to consolidate disparate identification programs after initiatives influenced by events like the 1998 United States embassy bombings and policy shifts following the 9/11 attacks. Programs within the Defense Information Systems Agency and procurement offices at the Pentagon accelerated adoption to satisfy mandates from the Federal Information Security Management Act and directives by the Secretary of Defense. Early pilots interfaced with predecessors used by the United States Postal Service and commercial smart-card deployments in Belgium and Estonia. Integration required coordination with standards bodies including NIST and international partners such as NATO.
The card is a credit-card–sized smart card containing an embedded chip compliant with standards like ISO/IEC 7816 and ISO/IEC 14443. It contains cryptographic keys issued under a PKI hierarchy administered by Defense Root Certification Authorities and uses algorithms recommended by NIST and historically evaluated by the National Security Agency. Physical elements include printed visual identifiers consistent with directives from the Under Secretary of Defense for Personnel and Readiness, holographic security elements akin to ones used on documents from the Department of State, and optional tactile features used in access control deployments employed by contractors such as Northrop Grumman and Lockheed Martin.
Authentication methods combine possession (the chip), knowledge (a PIN), and biometric verification (fingerprint templates) interoperable with readers certified by agencies like the Defense Information Systems Agency and audited under programs with the Government Accountability Office. Certificates on the card enable digital signatures compatible with systems used by Adobe Systems for signed documents and with secure e-mail systems used in operations associated with United States Transportation Command. The card facilitates single sign-on with directories such as Active Directory and federated access in environments using protocols championed by Internet Engineering Task Force working groups.
Security analyses by entities including the Government Accountability Office and independent researchers have examined vulnerabilities such as side-channel attacks, PIN harvesting, and improper certificate revocation handling. Privacy advocates citing frameworks from Electronic Frontier Foundation and legislation like the Privacy Act of 1974 have scrutinized biometric template storage and access logs maintained by installations such as Fort Bragg and Joint Base Lewis-McChord. Cryptographic strength and lifecycle management practices have been evaluated against recommendations from NIST publications and incident responses coordinated with the Department of Homeland Security.
Cards are issued to active-duty members, reservists, select civilian employees, contractors with appropriate clearances, and affiliates identified by policies from the Office of Personnel Management and Under Secretary of Defense for Acquisition and Sustainment. Eligibility screening often involves background investigations administered by agencies like the Defense Counterintelligence and Security Agency and suitability determinations aligned with statutes such as the Espionage Act frameworks for classified access. Enrollment workflows integrate enrollment stations using hardware from manufacturers like Gemalto and software orchestrated with systems from Oracle Corporation.
Lifecycle management encompasses issuance, renewal, revocation, and destruction coordinated by the Defense Information Systems Agency in partnership with personnel offices at commands including U.S. Central Command and U.S. European Command. Certificate revocation and status checking leverage Online Certificate Status Protocols interoperable with enterprise directories used by Department of the Navy and Department of the Air Force. Logistics and supply-chain considerations engage contractors and auditors from firms such as Deloitte and Ernst & Young for compliance reviews and lifecycle audits.
Implementation disputes have arisen regarding privacy, contractor access, and interoperability with civilian systems; cases cited by oversight bodies reference audits by the Government Accountability Office and testimony before committees of the United States Senate and United States House of Representatives. Notable incidents include reported misissuances, phishing campaigns targeting card credentials during operations involving Operation Enduring Freedom, and forensic investigations conducted by teams from the Federal Bureau of Investigation and Defense Criminal Investigative Service. Responses have led to policy revisions by the Office of the Secretary of Defense and technical changes advocated by NIST and NSA.
Category:United States Department of Defense Category:Identification documents Category:Smart cards