Showing posts with label pki. Show all posts
Showing posts with label pki. Show all posts

Friday, August 3, 2012

Possession is nine tenths of the law? Part 2


Part Two “It’s Mine I Can Prove It.” 

Why PKI should be used to address the digital rights management question 


The second half of this essay looks at how various media providers use DRM and the limitations of the current solutions.  PKI is presented as an alternative.  I hope you enjoy the paper and encourage you to comment.

Digital Rights Management

Accepting the fact that you are really not buying anything tangible, a digital content provider like Apple® is not necessarily out to get you.  The “Terms and Conditions [for] ITunes store, Mac App Store, App Store and iBookstore” allow for content sharing on up to ten devices five of which may be a I Tunes authorized computers.  It allows burning to CD your full playlist up to seven times.  For a fee you can get additional cloud services that make accessing your purchased content even easier.  On the flip side Apple® reserves the right to change the usage rules at any time.  The Apple® business model is not about making money with the content it is about making money on the hardware.  This is not the typical hardware /software paradigm.  With the majority of companies that deal in both hardware and software the real profit is in the software and ultimately the accompanying service and support plans.  Apples approach is not unique but is atypical in the software community though it seems to be part of a consensus in the digital content management community.  "The iPod makes money. The iTunes Music Store doesn't," said Apple Senior Vice President Phil Schiller.   "It's maybe a feature your platform should offer, but it's not like you're going to make some (big) markup," Microsoft Chairman Bill Gates said at the company's July [2003] analysts' meeting in response to questions about a proposed online music store.(Fried, 2003)

You have a certain amount of freedom in using and managing the content you purchase/lease from Apple ® although you are limited to using Apple® hardware, or apple software on non Apple® hardware like PC’s and Laptops.  The Apple® formats are proprietary as is the security mechanism they use to ensure compliance with their policies. This is the difference between the underperforming subscription models like Napster, Rhapsody, and Pressplay, and the Apple a la carte model which has been copied by most of the major players in the industry today.  Security is enforced using Digital Rights Management (DRM) Digital rights management.

 “DRM is a class of access control technologies that are used by hardware manufacturers, publishers, copyright holders and individuals with the intent to limit the use of digital content and devices after sale. DRM is any technology that inhibits uses of digital content that are not desired or intended by the content provider. DRM also includes specific instances of digital works or devices. Companies such as Amazon, AT&T, AOL, Apple Inc., BBC, Microsoft, Electronic Arts and Sony use digital rights management.” (Wikipedia, 2012)  

DRM has its detractors who often predict gloom and doom scenarios.  These scenarios often focus on a complete loss of your digital media should the DRM standard change in the future or the original service provider go out of business.  Although it does not seem likely that the world will be without the I Store™, Kindle™ store, or any of the other megalithic providers anytime soon the point is valid. Additional charges are that DRM stifles innovation and competition but perhaps the most disconcerting charge it that DRM goes beyond the constraints required by current copyright law which could be a slippery slope indeed.   

Apple has its own proprietary version of DRM known as FairPlay which is in turn only supported by Apple ® products.  This is no surprise if the afore mentioned quote by Apple Senior Vice President Phil Schiller is representative of Apples long term business model.  Apple, like other digital content providers, does have a loyal following but the question needs to be asked; are we heading for a single source world in which you must pick your provider and be satisfied with the available offerings.   What happens when your favorite author’s publisher or recording artist’s studio will not sign a contract with your provider?  Do you buy a new device every time you seek to increase the variety of your library?  To be fair to Apple® although they continue to use DRM in other media they removed FairPlay and any sort of DRM from the music tracks bought in the iTunes music library in 2009. (Apple Inc, 2012)   Apple does continue to digitally watermark its music tracks offering an excellent segue into DRM alternatives.

The pivotal issue of the digital media conundrum is the establishment of ownership and the ability to trace that ownership.  There are those who do not believe that any sort of identifier that would allow for tracing of ownership is in any way necessary or justified.  Perhaps there are merits to specific arguments in that regard however a system without ownership principles will simply result in the eventual extinction of the art form.  Individuals cannot be allowed unfettered access to works without compensation to the originator or allowed the ability to, without limitation, reproduce and distribute said material.  It is obvious that DRM is not the solution of the future.  Apple uses digital watermarking, the process by which code is buried in an underlying carrier signal allowing for the verification of the signals ownership or authenticity.  This technology has been used to track down the source of pirated movies.  Unlike the Metadata like that placed in websites to improve visibility to search engines, Digital watermarking does not change the size of the file.  One would think that this is an effective solution until the realization that digital watermarking is proprietary, and not standards driven, comes to light. A digital watermark also cannot be easily altered or added to without sacrificing some of the quality of the original file.  With this limitation it becomes problematic at best to transfer ownership of the media.

 DRM Alternatives

Other methods for establishing ownership of digital media are in use.  For example, Palm Digital Media, now known as E-reader, links the credit card information of the purchaser to the e-book copy in order to discourage distribution of the books. (Noring, 2004)  The big disadvantage is the risk to Personally Identifiable Information (PII).  The thought of using credit card information to indicate ownership of a piece of digital media is scary at best.   So what is the solution?  One proposition is that establishing ownership of digital media, securing a multibillion dollar industry and preventing hundreds of millions of dollars in fraud in the US alone, is a great argument for furthering individual digital identities in the US; enter PKI and Digital Certificates. 

Public key infrastructure (PKI) enables users of a basically unsecure public network such as the Internet to securely and privately exchange data and money through the use of a public and a private cryptographic key pair that is obtained and shared through a trusted authority. The public key infrastructure provides for a digital certificate that can identify an individual or an organization and directory services that can store and, when necessary, revoke the certificates. 

In cryptography, a public key “certificate” (or identity certificate) is an electronic document which incorporates a digital signature to bind together a public key with an identity - information such as the name of a person or an organization, their address, and so forth. The certificate can be used to provide very strong verification that a public key belongs to an individual.
In a typical public key infrastructure (PKI) scheme, the signature will be of a certificate authority. In a web of trust scheme, the signature is of either the user (a self-signed certificate) or other users (”endorsements”). In either case, the signatures on a certificate are attestations by the certificate signer that the identity information and the public key belong together. (Operational Research Consultants Inc., 2011)
 
This would appear to be an excellent solution for both the producers and consumers of digital media. For example if I were to buy an e-book and sign both the purchase and the resulting digital file with a public key certificate it would be the digital equivalent of signing each and every page of a hardcover novel with my name.  It does raise some rather childish euphemistic comparisons but effectively marks that digital media as mine.  More importantly unlike a five year old scribbling this book belongs to “Tommy” across the pages a digital signature can be edited, exchanged, or added to without harming the underlying file. This allows for the establishment of a chain of ownership and subsequently for the smooth and traceable exchange of ownership, even one that is temporary.  

Detractors point out that the establishment of a PKI infrastructure is overly burdensome in cost and complexity.  But this argument does not stand up to the counter which is economy of scale.  The federal government has been using PKI for years for logical access security but efforts to increase the use of this proven technology outside the federal government have been hampered by lack of broad scale adoption.  Consider that Apple has more than two hundred million devices sold worldwide and Amazon can claim more than six hundred million users.  It is not too much of an exaggeration to state that using those numbers as a starting point would drive the cost of PKI digital identities into the cost range of the Venti Café Mocha from Starbucks I purchased on the way to work this morning.  It was by the way, demonstrably not ostensibly mine. Possession is nine tenths of the law, just ask my daughter.

Works Cited

Apple Inc. (2012, January 6). Chanegs Coming to iTunes Store. Retrieved June 20, 2012, from Apple Press Information: http://www.apple.com/pr/library/2009/01/06Changes-Coming-to-the-iTunes-Store.html
Apple Inc. (2012). LICENSED APPLICATION END USER LICENSE AGREEMENT . Retrieved June 18, 2012, from www.apple.com: http://www.apple.com/legal/itunes/appstore/dev/stdeula/

Fried, I. (2003, Oct 16). Will Itunes make Apple Shine. Retrieved June 19, 2012, from CNET: http://news.cnet.com/2100-1041-5092559.html?tag=nl
Hyde, B. (2001). THE FIRST SALE DOCTRINE AND DIGITAL. Retrieved june 20, 2012, from Duke Law Scholorship Repository: http://scholarship.law.duke.edu/cgi/viewcontent.cgi?article=1017&context=dltr

Kunkel, J. R. (2002). Recent Developments in Shrinkwrap, Clickwrap and Browsewrap Licenses in the United States. Murdoch University Electronic Journal of Law , 9 (3).

Noring, J. (2004). The Perils of DRM Overkill For Large Publishers. Retrieved June 20, 2012, from Teleread.org: http://web.archive.org/web/20080403175200/  http://www.teleread.org/publishersdrm.htm

Operational Research Consultants Inc. (2011). Certificates and Credentials. Retrieved June 20, 2012, from ORC.Com: http://www.orc.com/certificates/

Wikipedia. (2012, June 15). Digital rights management. Retrieved June 19, 2012, from Wikipedia, The Free Encyclopedia : http://en.wikipedia.org/wiki/Digital_rights_management#cite_note-0

Wednesday, July 18, 2012

Possession is nine tenths of the law? Part 1


Posting the Mobile Device Remote Identity Proofing paper in parts seemed to work pretty well.   The paper as a whole received many more views than its two predecessors.  “Possession” is not as long as “Mobile” but lends itself to being divided in half.  The first half will focus on the problem, how to best handle Digital Rights Management (DRM), along with the associated legal principles.  Part Two will focus on the current methods of securing Digital Rights Management and PKI as an alternative.  I hope you enjoy the paper and encourage you to comment.


The Digital Rights Management Conundrum 

 

Background on digital media ownership

Every so often I run across a word that I have not heard before or had the occasion to use.  The latest entry in that category is Ostensible.  Ostensible is an adjective defined by Merriam Webster as:
1.       1: intended for display : open to view
2.       2: being such in appearance: plausible rather than demonstrably true or real.
I came across this word while conducting the research for this post.  It was used in the Wall Street Journal’s Law Blog while paraphrasing a 2010 decision by the Ninth Circuit Court in San Francesco.  The focus of the plaintiffs and the defendant’s dispute was money, no surprise.  The argument was based on the difference in royalties paid to recording artists.  A song that is licensed typically garners a hefty fifty percent share in revenue for the artist, conversely a song that is sold brings in far lower royalty.  The catalyst for the complaint, Apple I-tunes.  Time for a reality check; did you really believe the tens of millions of dollars spent on music, movies, books, and other publications in the I-Tune store actually resulted in ownership?  You may be thinking to yourself that darn fine print well in fact the opening statement to the iTunes licensing agreement tells it all.  

“The Products transacted through the Service are licensed, not sold, to You for use only under the terms of this license, unless a Product is accompanied by a separate license agreement, in which case the terms of that separate license agreement will govern, subject to Your prior acceptance of that separate license agreement. The licensor (“Application Provider”) reserves all rights not expressly granted to You. The Product that is subject to this license is referred to in this license as the “Licensed Application.” (Apple Inc., 2012)

The fact that the songs were licensed not sold precipitated the suit against Universal Music Group by producers affiliated with rapper Eminem.  Although the decision was not favorable for Universal Music Group it is also, at least according to them, not precedent setting as it is specific to one particular contract with a single artist.   They are obviously appealing the verdict.

In order to begin to grasp the issues it is necessary to have a general understanding of the three legal principles that have become ubiquitous in the digital media debate.

Copyright

Merriam Webster defines copyright as the exclusive legal rights to reproduce, publish, sell, or distribute the matter and form of something (as a literary, musical, or artistic work).  A copyright is granted to the creator of an original expression of work; for example an author or composer.  There is more than one type of copyright, those that are registered and those that are implied. Without getting into too much detail suffice it to say that an implied copyright is granted on initial publication of the work and a registered copyright is granted by the US copyright office after the work is deposited along with application and fee.  The deposited work [sample] becomes the property of the U.S. Library of Congress.

First Sale Doctrine

First sale doctrine as applied to Copyrights allows the purchaser to sell or give away a particular lawfully made copy of the copyrighted work without permission once it has been obtained. This does not infringe the copyright owner's exclusive rights. Section 106 of the 1976 Copyright Act grants the owner of a Copyright six exclusive rights: reproduction, preparation of derivative works, distribution, public performance, public display, and digital transmission performance.  However, a Copyright owner’s right of distribution is limited by the First Sale Doctrine, as codified in Section 109 of the Act. Section 109(a) (Hyde, 2001)  First sale doctrine is an exception to the copy right.  This exception allows you to give a book to a friend or even sell it.  First Sale Doctrine enables libraries to lend books and video stores, before they started going the way of the dinosaur, to rent video’s.  First sale doctrine is not without conditions. In order to receive the afore mentioned privileges ownership must be established.  Keep in mind that ownership is not defined by mere possession which is why you cannot legally copy a rented video or DVD. 

Contract

Back in the pre-computer dark ages access to music, literature, video etc was controlled by copyright law.  During the personal computer enlightenment we were introduced to contract law as we accepted license agreements during software installation or even through the act of breaking the security seal.  The internet introduced the information revolution and really stood things on end with the Click Through License also known as a Click Wrap Agreement

Clickwrap agreements came into use when software vendors began distributing software by means other than disks, such as when the software is pre-installed on a computer for the user, or when the software is downloaded over the Internet. Upon downloading, installation or first use of the application, a window containing the terms of the license opens for the user to read. The user is asked to click either "I agree" or "I do not agree". If the user does not agree, the process is terminated. The clickwrap agreements often remove many factual questions whether the user had adequate notice of the license terms and manifested assent to them. With respect to software downloads, the clickwrap terms often are displayed at the very start of the contract formation process, although often the terms are contained in a scrollable window that requires the user to scroll down to read all of the terms. This positioning often eliminates U.C.C. Section 2-207 issues regarding agreement to additional or different terms. (Kunkel, 2002)

Statistics and Sigma Six expert Jeff Sauro confirmed a true lack of end user concern with end user license agreements (EULA).   Mr. Sauro examined a couple of thousand log records over e few different consumer software products.  He found;

 “The median time users spent on the license page was only 6 seconds! Generating a confidence interval around this sample tells us that we can be 95% sure at least 70% of users spend less than 12 seconds on the license page.
Assuming it takes a minimum of two minutes to read the License Agreement (which itself is fast) we can be 95% confident no more than 8% of users read the License Agreement in full.”

It could be argued that the sheer volume of these agreements in our everyday lives provided a disincentive in getting the end user to read them.  As digital content providers race to catch up with advances in technology the agreements compound often resulting in multiple EULA’s and Terms of use agreements for individual products.  Consider that the order of a Kindle Fire™ requires that you consent to ten different agreements with a combined forty eight pages of text (11point font, standard margins).  Disincentive or not click wrap agreements are likely here to stay and current case law is overwhelmingly in their favor.

Getting back to ostensible, you are in fact the ostensible “buyer” when it comes to electronic media.  The major providers are very aware of the propensity of people to actually read the license agreement before clicking the check box indicating “I agree”.   The media providers think of you as a buyer of a service whereas you may think of yourself as the buyer of a product.  You have no right to resell what you have purchased, in fact is difficult to lend or share what you have purchased outside of your family group in your own home and then only when using software designed to regulate that behavior.  Even if the majority of people were to read the license agreements chances are most would complete the purchase regardless of what the license agreement outlines.  This is in keeping with today’s instant gratification society. 

Monday, July 2, 2012

Mobile Device Remote Identity Proofing - Part 5 final thoughts


 

X.  Token activation


With all of the required elements in place all that is left is to do is to deal with the physical representation of the identity.  The federal government is currently both the largest issuer and relying party in the trusted identity ecosystem.  Programs like the Defense Departments Common Access Card (CAC), Homeland Securities Transportation Worker Identification Card (TWIC), and the Federal Standard FIPS 201 Personal Identity Verification (PIV) credential all have one thing in common.  They all require a physical token in the form of a Smart Card.  A smart card is a plastic card with an embedded microchip(s) that can be loaded with data which in turn can be secured with a Public Key Infrastructure (PKI) certificate or similar technology.  This brings us full circle to the ownership issue.  Having a physical manifestation of the identity can be perceived as a security liability issue as the risk of loss of the token is still inherent in the program. Despite this, current conventions are for token based programs.

It is not currently both technologically and economically feasible to use the mobile device directly for activation of an external token.   The device itself must fulfill that function.  This concept presupposes the phone in a role as a token.  To truly put identity management in the hands of John Q Public we must find a new cost effective way to support current IdM programs by greatly reducing or eliminating the currently accepted hardware intensive infrastructure required.  Because a secure connection between the mobile device and the back end systems, to include the certificate authority (CA), are inherent in the system architecture, it is not necessary to expound on the activation methodology for the device as a token scenario.  For activation of tokens other than the mobile device, the initial premise to be explored should be to leverage the “sync with my pc” capabilities of smart phones.  The synced device will provide application while using the PC in a limited role for network connection and attachments of peripherals like smart card readers, USB flash drives and other potential token variants.

XI. Policy


In theory, current technology supports all of the elements required for identity proofing in a remote or “mobile” environment, in a cost effective manner.  Truly widespread implementation will likely require changes to the currently accepted policy models.  For example, if the capture of information supporting a claimant’s identity is no longer the impediment perhaps it is time to change to change the assurance model to one that is based on the number and type of witnesses to an the initial claim.  Using this model the lowest level of assurance would be assigned to an identity remotely established and witnessed by a non credentialed individual.  A moderate level of assurance would be one based on the “witnessing” of the claim by an individual possessing a credential at a level being requested or higher.  A high level of assurance would be based on the “witnessing” of a specifically designated credentialed authority.  This would in essence be the modern digital equivalent of the traditional notary public.

With the more difficult issue of creation of the claimant’s profile being established, the comparatively easy step of binding the claim to the individual can be addressed.  There are both established precedents and regulatory guidance for this step of the process. Basic documentation proving citizenship for a Passport or eligibility for a Drivers License; I-9 Documentation for purposes of eligibility for employment; the more stringent PIV-I requirements; or the detailed requirements combining breeder documents, knowledge based quizzes and background investigations for PIV are well established.  

Once again camera technology and current application capabilities allow for a document such as a drivers license, passport, birth certificate, and other forms of identity to be captured at resolutions allowing for optical character recognition to be used.  This will speed the process flow and lessen the data exchange requirements between the mobile registration device and the processing program.  

XII. Conclusion 


More than 88% of consumers have made purchases online spending more than 142 billion dollars in 2010 with a 14% increase continuing to trend upwards through the 2nd quarter of 2011 (comScore, Inc., 2011). Within a few years this trend will represent hundreds of billions of dollars of transactions conducted with the barest of security protections.  The logical prophylactic to a multibillion dollar fraud epidemic is biometrics.  Based on physiological or behavior characteristics biometrics are distinctive and attributable to specific individuals.  Unlike the ubiquitous pin and password security that is commonplace in the United States biometrics carries a higher level of trust in information assurance.

It is evident that cell phone technology itself is mature enough to handle the requirements of the emerging need for strong general purpose identity management programs.  The computer age has ushered in an era where our identities, and the most intimate and valued attributes associated with them are immediately accessible on a twenty four seven basis.  Unfortunately we are still guarding our most valued possession with the equivalent of an old skeleton key.  With a little work that single key can open every door in our virtual house.  That house needs to be a vault with a strong identity backed with personal biometrics the only key.  Regardless of the threats, and the validity of the solutions, the one obstacle that technology cannot overcome is the mindset of the American individual.

Works Cited – Complete Paper

About.com. (2012). The Histories of Polybius published in Vol. III of the Loeb Classical Library edition. In Polybius, The Roman Military System. New York City, United States of America: New York Times Company.

Ashbourn, J. (2000). Biometrics: advanced identity verification. In J. Ashbourn, Biometrics: advanced identity verification (pp. 4-7). London, United Kingdom: Springer-Veriag.

Bronstein, A. M., Bronstein, M. M., & Kimmel, R. (2004). Three-Dimensional Face Recognition. Technion, Israel Institute of Technology, Department of Computer Science. Kluwer Academic Publishers.

Clausen, S., & Christie, N. W. (2005). Live Finger Detection. IDEX ASA. Fornebu, Norway: IDEX ASA.

comScore, Inc. (2011, August 8). comScore Reports $37.5 Billion in Q2 2011 U.S. Retail E-Commerce Spending, Up 14 Percent vs. Year Ago. Retrieved March 1, 2012, from comScore, Press & Events : http://www.comscore.com/Press_Events/Press_Releases/2011/8/comScore_Reports_37.5_Billion_in_Q2_2011_U.S._Retail_E-Commerce_Spending

Creamer, D. (2006). Understanding Resolution and the meaning of DPI, PPI, SPI, & LPI. Retrieved May 30, 2012, from http://www.ideastraining.com: 

(1966). In G. Deleuze, Bergsonism (H. Tomlinson, & B. Habberjam, Trans.). New York, New York: Zone Publishing Inc.

FBI Biometric COE. (2010, April 27). FBI Biometric Specifications FAQ. Retrieved May 31, 2012, from FBI Biometric Center of Excellence: https://www.fbibiospecs.org/iafis_FAQ.html

Foresman, C. (2012, March 2). Innovation or hype? Ars examines Nokia's 41 megapixel smartphone camera. Retrieved March 5, 2012, from arc technica: http://arstechnica.com/gadgets/news/2012/03/innovation-or-hype-ars-examines-nokias-41-megapixel-smartphone-camerainnovation-or-hype-ars-examines-nokias-41-megapixel-smartphone-camera.ars?clicked=related_right

Indovina, M., Hicklin, R. A., & Kiebuzinski, G. I. (2011). Evaluation of Latent Fingerprint Technologies: Extended Feature Sets [Evaluation #1]. U.S. Department of Commerce, National Institute of Science and Tecnhology. Washington D.C.: US Government Printing Office.

Jain, A. K., Flynn, P., & Ross, A. A. (2008). Handbook of Biometrics. New York, NY, USA: Springer Publishing Company.

Jain, A., Hong, L., & Pankanti, S. (2000, February). BIOMETRIC IDENTIFICATION. (W. Sipser, Ed.) COMMUNICATIONS OF THE ACM , 43, pp. p. 91-98.

Javelin Strategy & Research. (2012, February). ITAC Research and Statistics. Retrieved June 5, 2012, from ITAC: http://www.identitytheftassistance.org/pageview.php?cateid=47

Lee, S., Lee, C., & Kim, J. (2008). Image Preprocessing of Fingerprint Images. Biometrics Engineering Research Center at Yonsei University., Korea Science and Engineering Foundation, Seoul, Korea.

NIST. (2003, February 11). Both Fingerprints, Facial Recognition Needed to Protect U.S. Borders. Retrieved March 5, 2012, from NIST; Public and Business Affairs: http://www.nist.gov/public_affairs/releases/n03-01.cfm

Ortega-Garcia, J., Bigun, J., & Reynold, D. (2004). Authentication Gets Personal with Biometrics; Increasing security in DRM systems through biometric authentication. IEEE Signal Processing Magazine , 1053-5888 (04).

Schmandt-Besserat, D. (1977, June). The Earliest Precursor of Writing. Scientific American , 238 (June), pp. 50-58.

Sinha, P., Balas, B., Ostrovsky, Y., & Russell, R. (2006). Face Recognition by Humans: Nineteen Results All ComputerVision Researchers Should Know About. Proceedings of the IEEE , 94 (11), 1957.

Wing, B. (2011). Data Format for the Interchange of Fingerprint, Facial & Other Biometric Information. US Department of Commerce, National Institute of Science and Technology. Gaithersburg: US Government Printing Office.

Wednesday, June 13, 2012

Managed Attributes, Not Standards, Lead to Interoperability

Download Complete Paper

I.     Introduction

Managed attributes ensure essential interoperability. This is the foundation for providing the most skilled, most timely and most appropriate response to any situation, regardless of size. Emergency managers and incident commanders can make sound decisions with the additional data that comes from knowing when and where specific resources are located, what tasking assignments have been given and to whom. Not only is everyone on the scene accounted for, but tasks are given to responders with verified skills and capabilities thereby contributing to the command staff’s ability to predict the next threat and deploy resources accordingly, maintain critical situational awareness and respond to dynamic conditions quickly and effectively. Assigning responders to duty is not an issue. What’s critical is assigning the responder with the appropriate and verifiable skills to a job he/she is capable of accomplishing, ensuring a positive outcome for the situation and the responder.

II.    Setting the scene

A.                   Personal experience sets the stage for complete understanding

My first exposure to pre-hospital care was the mandatory “first responder” training required for firefighters by the State of California more than twenty years ago. The training program which was taken concurrently with a CPR class added up to more than the 120 hours of training required to be certified as Basic EMT in the Commonwealth of Massachusetts a couple of years later. In the end it was not the hours required to complete a training program that struck me as being the unusual dichotomy but the difference in skills. As a “first responder” I was trained in how to properly remove a helmet, place the electrodes from the 12-lead EKG on a patient, spike IVs, assist with medications, etc. As a “Basic EMT” in Massachusetts I was not trained in any of those skills. In fact I did not use them again until the PB waiver program was instituted. Many years later as a regional hospital preparedness coordinator I struggled with the concept that we could not send paramedics across regional boundaries within the same state, even within the same county and still allow them to work as paramedics because scope of practice and certification was regional and there was no reciprocity within the state!

Times have changed but the essential challenges in the practice of pre hospital care have not. There may be an EMS community but it is segregated even within its day-to-day practices never mind responses to what can be categorized as disasters. On February 20, 2003 the fourth deadliest   nightclub fire and the 9th deadliest place of public assembly fire in U.S. history took place at the Station Nightclub in Rhode Island. The multi-jurisdictional (on a very large scale) fire EMS response was atypical when it comes to patient care and it worked. It is conjecture but I would hypothesize that the response was modern in capability but traditional in implementation. That is, a small state with close boarder ties to services in Massachusetts and Connecticut and familiarity among the services responded as needed, there were no questions of scope of practice, patients were cared for at the level the provider was trained to without immediate regard for local or regional regulations.

In addition to the one hundred fatalities there were an estimated 230 casualties, 186 transported to hospitals by first responder agencies. Over five hundred firefighters, EMS, and Police responded with fifty-seven public and six commercial ambulance companies providing both basic and advanced life support services. (Kuntz, June 23 2000)1

I would argue the Station Nightclub fire response was a success carried out by heroic and dedicated professionals. The brethren of these same professionals also answered the call to service for hurricane Katrina in late August and early September of 2005. I would argue that that response was more typical of large multi jurisdictional, multi state responses. Some level of organization was applied to the call out and activation of resources on a national scale. The typical American answer of a call to duty resulted in a massive response. However, many police, fire and EMS organizations from outside the affected areas were reportedly hindered or otherwise slowed in their efforts to send help and assistance to the area. FEMA sent hundreds of firefighters who had volunteered to Atlanta for two days of training on topics including sexual harassment and the history of FEMA. (Bluestein, 2005)2
               

III.   Underlying Problems

So what is the underlying problem? We can look at it from a national service prospective as well as a level of service prospective. Take a look at the state of the service in general. An excellent summary is contained in a recent report issued by the National Academy of Sciences.

“Each year in the United States approximately 114 million visits to EDs occur, and 16 million of these patients arrive by ambulance. The transport of patients to available emergency care facilities is often fragmented and disorganized, and the quality of emergency medical services (EMS) is highly inconsistent from one town, city, or region to the next. Multiple EMS agencies some volunteer, some paid, some fire based, others hospital or privately operated frequently serve within a single population center and do not act cohesively. Very little is known about the quality of care delivered by EMS services. The reason for this lack of knowledge is that there are no nationally agreed-upon measures of EMS quality, no nationwide standards for the training and certification of EMS personnel, no accreditation of institutions that educate EMS personnel, and virtually no accountability for the performance of EMS systems. While most Americans assume that their communities are served by competent EMS services, the public has no idea whether this is true, and no way to know.

The education and training requirements for the EMTs and paramedics are substantially different from one state to the next and consequently, not all EMS personnel are equally prepared. For example, while the National Standard Curricula developed by the federal government calls for paramedics to receive 1,000 - 1,200 hours of didactic training, states vary in their requirements from as little as 270 hours to as much as 2,000 hours in the classroom. In addition, the range of responsibilities afforded to EMTs and paramedics, known as their scope of practice, varies significantly across the states. National efforts to promote greater uniformity have been progressing in recent years, but significant variation remains.” (Committee on the Future of Emergency Care in the United States Health System, 2006) 3

My initial brief example of the differences in training between states pales in comparison to the preceding quote. We have established the fact that we have dedicated trained and competent personnel working in an environment that is restrictive primarily due not to the lack of a national standard but to a lack of information. I will expound on that statement shortly. First, however, let’s take a look at the problem from a scope vs. patient care prospective. An excellent example was discussed in an article by Tori Socha published in February, 2011. The article dealing with stoke reminded me of the initial introduction of thrombolytic drug therapy through pre-hospital providers in Massachusetts and the personal struggle some metropolitan medics had being able to use this lifesaving tool in one region, with their big city services, but not have it available to them in the small local, sometimes volunteer ALS services in the communities in which they resided. Ms. Socha stated;

“Stroke, with direct and indirect costs totaling $68.9 billion, is a major primary health priority in the United States. Every 40 seconds, someone in the United States experiences a stroke, and every 3 to 4 minutes, someone dies of a stroke. Administering intravenous (IV) recombinant tissue plasminogen activator (tPA) within 3 hours of onset of symptoms is associated with a 30% greater likelihood of decreased disability compared with placebo. In selected patients, IV recombinant tPA may be safely used up to 4.5 hours after symptom onset. Despite its clinical efficacy and cost-effectiveness, only 3% to 8.5% of patients with stroke receive recombinant tPA. One limitation is timely access to care. In 2000, the Brain Attack Coalition recommended establishing primary stroke centers (PSCs). Researchers recently conducted a study to determine the proportion of the population with access to Acute Cerebrovascular Care in Emergency Stroke Systems (ACCESS). The analysis found that if ground ambulances are not permitted to cross state lines, fewer than 22.3% of Americans (1 in 4) have access to a PSC within 30 minutes of symptom onset.” (Socha, 2011)4

There is no doubt that lack of definition causes, at bare minimum, organizational angst and disparity in the EMS service. It can also be argued that this lack of definition can result in loss of life, not due to negligence but the inability of available service to provide a timely response across jurisdictional boundaries stymied by the invisible but very real wall of scope of practice limitations. This is evidenced by the research from the Socha article as well countless additional journal articles and studies. The truly disquieting issue is that this conundrum is not one unique to an incident of national consequence but can be found in day-to-day EMS operations.

IV.   Solutions

So what is the solution? I left emergency services several years ago to seek technology solutions for common operational problems faced by our nation’s first responders. Over the last ten years I have listened to a consistent theme propagated in general by well meaning federal civil servants. Regardless of the problem the solution is of course to regulate it at the federal level. The following quote from the Committee on the Future of Emergency Care starts with a rousing call to arms.
“While today’s emergency care system offers significantly more medical capability than was available in years past, it continues to suffer from severe fragmentation, an absence of system wide coordination and planning, and a lack of accountability. To overcome these challenges and chart a new direction for emergency care, the committee envisions a system in which all communities will be served by well planned and highly coordinated emergency care services that are accountable for their performance. In this new system, dispatchers, EMS personnel, medical providers, public safety officers, and public health officials will be fully interconnected and united in an effort to ensure that each patient receives the most appropriate care, at the optimal location, with the minimum delay.” (Committee on the Future of Emergency Care in the United States Health System, 2006)3
All communities should be served with highly coordinated emergency care services that are accountable for their performance and those services should be interconnected. I do, however, disagree with manner in which the coordination, accountability and connectivity should occur. A bit further in the report the foundation of the proposed solution is revealed.
“The National EMS Scope of Practice Model Task Force has created a national model to aid states in developing and refining their scope-of-practice parameters and licensure requirements for EMS personnel. The committee supports this effort and recommends that state governments adopt a common scope of practice for EMS personnel, with state licensing reciprocity. In addition, to support greater professionalism and consistency among and between the states, the committee recommends that states accept national certification as a prerequisite for state licensure and local credentialing of EMS providers. Further, to improve EMS education nationally, the committee recommends that states require national accreditation of paramedic education programs. The federal government should provide technical assistance and possibly financial support to state governments to help with this transition.” (Committee on the Future of Emergency Care in the United States Health System, 2006)3
There it is. Solution by national regulation. This could be effective if the United States were the size of Switzerland. It would also be quite effective if we did not have 50 different autonomous state governments, not including territories. The individual states do not want to give up their sovereignty, nor should they be forced to. It is not necessary. The solution is to allow the authority having jurisdiction the freedom to define the scope of practice. How can this premise, the perceived status quo, change things? The logical proposal is the delivery of this [scope] information in a trusted fashion attached to a non-reputable identity. For those familiar with the ongoing work to leverage trusted identity by the federal government for physical and logical access control you likely have an idea where I am going with this concept. Several states have taken definitive steps to leverage the work done by the federal government to institute their own identity management (IDM) programs. One or two truly visionary early adopters are using the trusted identity as a foundation and attaching attributes. For example some states have implemented, as part of its functional mandate, “authenticated qualifications and attributes” by which they mean trusted and validated by the authority having jurisdiction or accrediting organization and the ability to tie first responders' identities and attributes to authoritative sources of information (e.g. licensing, certification, and status databases for paramedics, police, licensed heath care practitioners, firefighters, etc). 

Management of these attributes allows for the rapid and effective allocation of personnel resources during an operation.  Historically, management of these resources, assisted through mutual aid compacts, both formal and informal, was hampered by a lack of information and trust.  Further there often is a lack of understanding as to the differing individual elements that defined the attribute from jurisdiction to jurisdiction.  Without any mechanism to provide a trusted and detailed definition of the attribute the only recourse has been to compare attributes between jurisdictions at the lowest common denominator.  Categorization of resources has been limited to generalized groupings like Emergency Services Functions (ESFs) and subsets of Critical Infrastructure and Key Resource sectors (CI/KR).  A frequently disputed alternative has been for the federal government to dictate the attribute definitions to state and local authorities.  This lack of information is compounded by the specter of legal accountability for the jurisdiction receiving the resources especially in those attributes which directly influence life safety.  The result is an under utilization of the available resources.

Attribute management within an identity system is similar to that in network management. In a network an “attribute” is the property of a managed object that has a value. Similarly in one example of an IDM attribute-enhanced system an attribute is the property of the person who has enrolled, and the value is “what that attribute is.” For example: Joe Smith enrolls and designates he is a paramedic. Joe is the “managed object” and paramedic is the “attribute.” The system then associates the “value” as the skill set of a paramedic.
Also similar to network management, certain mandatory initial values for attributes are specified as part of the managed object class definition. Associating the skill set of a paramedic is a mandatory initial value, but conditional values can also be added, these may be unique to the jurisdiction where a responder works on a local, regional, or state level. These paramedic conditional attributes could also be additional training or certifications that are above and/or beyond the initial mandatory value of a paramedic as defined by the federal AHJ. This allows all stakeholders to have their cake and eat it too. The federal government establishes the baseline and state and local jurisdictions are not forced into long term expensive programmatic changes.

When the attribute dataset is read by a computing device the retrieved information is reported to the user in local terminology and an instant comparison is made between the individual knowledge and task statements and requirements of the local jurisdictions certification requirements and the sending jurisdictions certification requirements and critical discrepancies are reported. For example as part of the comparison the table of pharmacology for a paramedic is compared between a sending jurisdiction and a receiving jurisdiction is compared and the receiving jurisdictions report shows that the medic is not trained in the administration of a thrombolytic, part of the scope of care of the receiving jurisdiction.

My example was originally designed to use national regulatory or volunteer compliance standards as a baseline. A methodology was developed allowing for local, regional, or county based training and skill sets to be incorporated into the system. The subsequent modifications to the system provided both a means of tracking these local training programs, optionally using the resources that are the outcome of these programs and communicating this information to disparate jurisdictions whose training has a completely different baseline but whose terminology and outcomes are similar. 

Systems of this type are designed to give command authorities trusted, verified, data on skills licenses and certifications held by respond in individuals and teams in order to allow use of these human resources at the highest common denominator thereby making the most effective use of the resources available and providing the highest level of care and services to those in need during times of disaster of any scale.
Twenty five years ago very little if any consideration was given to a need for instant reciprocity.  With a few exceptions emergency resources were drawn locally or regionally from immediately adjacent jurisdictions.  Today responses to critical events can be national, leveraging the spirit and altruism that defines America.  Twenty five years ago a piece of paper, a uniform, or a badge could serve as proof of qualification.  Today the litigiousness of our society has prevented even the federal government from using emergency services personnel to their demonstrated capabilities.   The advent of the “Google” age of instant access to information has raised both demand for service and expectations that such service will be quickly and effectively delivered.

[1] Kuntz, K. (June 23 2000). Federal Advisory Committee June 23 2000, National construction Safety Team Investigation, Station Nightclub Fire Emergency Response. Washington D.C.: U.S. Fire Administration, U.S. Department of Homeland Security .
 [2] Bluestein, G. (2005, September 7). Firefighters stuck in Ga. awaiting orders. USA Today .
[3] Committee on the Future of Emergency Care in the United States Health System, B. o. (2006). Emergency Medical Services at the Crossroads. Institute of Medicine , National Academy of Sciences. 500 Fifth Street, N.W. Washington DC: National Academies Press.
 [4] Socha, T. (2011, February 15). Timely Access to Primary Stroke Centers in the United States. (HMP Communications LLC) Retrieved April 12, 2011, from First Report Managed Care: http://www.firstreportnow.com/articles/timely-access-primary-stroke-centers-united-states

This concept paper was first delivered as an open letter to the National EMS Advisory Council in January of 2011.  A revised version of the paper was published by the IEEE as part of a poster presentation at the annual IEEE Conference on Technologies for Homeland Security in December of 2011.