smart card technology why is a smart card so smart?

21
Smart Card Smart Card Technology Technology Why is a Smart Card So Smart? Why is a Smart Card So Smart? CIS4360 – Introduction Computer Security CIS4360 – Introduction Computer Security Joey Ferreira Joey Ferreira Joshua Lawrence Joshua Lawrence

Upload: alima

Post on 09-Jan-2016

108 views

Category:

Documents


20 download

DESCRIPTION

Smart Card Technology Why is a Smart Card So Smart?. CIS4360 – Introduction Computer Security Joey Ferreira Joshua Lawrence. History. 1968 German inventor Jurgen Dethloff along with Helmet Grotrupp filed a patent for using plastic as a carrier for microchips. 1970 - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Smart Card Technology Why is a Smart Card So Smart?

Smart Card TechnologySmart Card Technology Why is a Smart Card So Smart?Why is a Smart Card So Smart?

CIS4360 – Introduction Computer SecurityCIS4360 – Introduction Computer SecurityJoey FerreiraJoey Ferreira

Joshua LawrenceJoshua Lawrence

Page 2: Smart Card Technology Why is a Smart Card So Smart?

HistoryHistory 19681968

German inventor Jurgen Dethloff along with Helmet Grotrupp filed German inventor Jurgen Dethloff along with Helmet Grotrupp filed a patent for using plastic as a carrier for microchips. a patent for using plastic as a carrier for microchips.

19701970Dr. Kunitaka Arimura of Japan filed the first and only patent on the Dr. Kunitaka Arimura of Japan filed the first and only patent on the smart card conceptsmart card concept

19741974Roland Moreno of France files the original patent for the IC card, Roland Moreno of France files the original patent for the IC card, later dubbed the “smart card.”later dubbed the “smart card.”

19771977Three commercial manufacturers, Bull CP8, SGS Thomson, and Three commercial manufacturers, Bull CP8, SGS Thomson, and Schlumberger began developing the IC card product. Schlumberger began developing the IC card product.

Source: smart.govSource: smart.gov

Page 3: Smart Card Technology Why is a Smart Card So Smart?

HistoryHistory 19791979

Motorola developed first single chip Microcontroller for French Motorola developed first single chip Microcontroller for French BankingBanking

19821982World's first major IC card testingWorld's first major IC card testing

19921992Nationwide prepaid card project started in DenmarkNationwide prepaid card project started in Denmark

1999 1999 Federal Government began a Federal employee smart card Federal Government began a Federal employee smart card identificationidentification

Source: smart.govSource: smart.gov

Page 4: Smart Card Technology Why is a Smart Card So Smart?

What is a Smart Card?What is a Smart Card?

The standard definition of a a smart card, or The standard definition of a a smart card, or integrated circuit card (ICC), is any pocket sized integrated circuit card (ICC), is any pocket sized card with embedded integrated circuits. card with embedded integrated circuits.

Loosely definedLoosely defined, a smart card is any card with a , a smart card is any card with a capability to relate information to a particular capability to relate information to a particular application such as:application such as:• Magnetic Stripe CardsMagnetic Stripe Cards• Optical CardsOptical Cards• Memory CardsMemory Cards• Microprocessor CardsMicroprocessor Cards

Page 5: Smart Card Technology Why is a Smart Card So Smart?

Magnetic Stripe CardsMagnetic Stripe Cards

Standard technology for bank cards, driver’s licenses, library cards, and so on……

Page 6: Smart Card Technology Why is a Smart Card So Smart?

Optical CardsOptical Cards

Uses a laser to read Uses a laser to read and write the cardand write the card

CANPASS Contains:CANPASS Contains:• Photo IDPhoto ID• FingerprintFingerprint

Page 7: Smart Card Technology Why is a Smart Card So Smart?

Memory CardsMemory Cards

Can store:Can store:• Financial InfoFinancial Info• Personal InfoPersonal Info• Specialized InfoSpecialized Info

Cannot process InfoCannot process Info

Page 8: Smart Card Technology Why is a Smart Card So Smart?

Microprocessor CardsMicroprocessor Cards Has an integrated Has an integrated

circuit chipcircuit chip Has the ability to:Has the ability to:

• Store informationStore information• Carry out local Carry out local

processingprocessing• Perform Complex Perform Complex

CalculationsCalculations

Page 9: Smart Card Technology Why is a Smart Card So Smart?

Microprocessor CardsMicroprocessor CardsContact Smart CardContact Smart Card

Page 10: Smart Card Technology Why is a Smart Card So Smart?

ContactContact

Page 11: Smart Card Technology Why is a Smart Card So Smart?

Microprocessor CardsMicroprocessor CardsContactless Smart CardContactless Smart Card

Page 12: Smart Card Technology Why is a Smart Card So Smart?

Microprocessor CardsMicroprocessor CardsCombi / Hybrid CardsCombi / Hybrid Cards

Hybrid CardHybrid Card• Has two chips: contact and contactless Has two chips: contact and contactless

interface. interface. • The two chips are not connected. The two chips are not connected.

Combi CardCombi Card• Has a single chip with a contact and Has a single chip with a contact and

contactless interface. contactless interface. • Can access the same chip via a contact or Can access the same chip via a contact or

contactless interface, with a very high level of contactless interface, with a very high level of security. security.

Page 13: Smart Card Technology Why is a Smart Card So Smart?

Microprocessor CardsMicroprocessor CardsCombi / Hybrid CardsCombi / Hybrid Cards

Page 14: Smart Card Technology Why is a Smart Card So Smart?

How are Smart Cards Used?How are Smart Cards Used? Commercial ApplicationsCommercial Applications

• Banking/payment Banking/payment • Identification Identification • Ticketing Ticketing • Parking and toll collection Parking and toll collection • Universities use smart cards for ID purposes Universities use smart cards for ID purposes

and at the the library, vending machines, and at the the library, vending machines, copy machines, and other services on copy machines, and other services on campus.campus.

Mobile TelecommunicationsMobile Telecommunications• SIM cards used on cell phonesSIM cards used on cell phones• Over 300,000,000 GSM phones with smart Over 300,000,000 GSM phones with smart

cards cards • Contains mobile phone security, subscription Contains mobile phone security, subscription

information, phone number on the network, information, phone number on the network, billing information, and frequently called billing information, and frequently called numbers. numbers.

Page 15: Smart Card Technology Why is a Smart Card So Smart?

How are Smart Cards Used?How are Smart Cards Used? Information TechnologyInformation Technology

• Secure logon and authentication of users to PCs and networks Secure logon and authentication of users to PCs and networks • Encryption of sensitive dataEncryption of sensitive data

Other ApplicationsOther Applications• Over 4 million small dish TV satellite receivers in the US use a Over 4 million small dish TV satellite receivers in the US use a

smart card as its removable security element and subscription smart card as its removable security element and subscription information. information.

• Pre-paid, reloadable telephone cardsPre-paid, reloadable telephone cards• Health Care, stores the history of a patientHealth Care, stores the history of a patient• Fast ticketing in public transport, parking, and road tolling in Fast ticketing in public transport, parking, and road tolling in

many countriesmany countries

Page 16: Smart Card Technology Why is a Smart Card So Smart?

AdvantagesAdvantages

In comparison to it’s predecessor, the magnetic strip card, In comparison to it’s predecessor, the magnetic strip card, smartsmart

cards have many advantages including: cards have many advantages including:

• Life of a smart card is longerLife of a smart card is longer• A single smart card can house multiple applications. Just one A single smart card can house multiple applications. Just one

card can be used as your license, passport, credit card, ATM card can be used as your license, passport, credit card, ATM card, ID Card, etc.card, ID Card, etc.

• Smart cards cannot be easily replicated and are, as a general Smart cards cannot be easily replicated and are, as a general rule much more secure than magnetic stripe cardsrule much more secure than magnetic stripe cards

• Data on a smart card can be protected against unauthorized Data on a smart card can be protected against unauthorized viewing. As a result of this confidential data, PINs and viewing. As a result of this confidential data, PINs and passwords can be stored on a smart card. This means, passwords can be stored on a smart card. This means, merchants do not have to go online every time to authenticate merchants do not have to go online every time to authenticate a transaction. a transaction.

Page 17: Smart Card Technology Why is a Smart Card So Smart?

AdvantagesAdvantages

• • chip is tamper-resistantchip is tamper-resistant- information stored on the card can be PIN code and/or read-- information stored on the card can be PIN code and/or read-write protectedwrite protected- capable of performing encryption- capable of performing encryption- each smart card has its own, unique serial number - each smart card has its own, unique serial number

• • capable of processing, not just storing informationcapable of processing, not just storing information- Smart cards can communicate with computing devices - Smart cards can communicate with computing devices through a smart card readerthrough a smart card reader- information and applications on a card can be updated - information and applications on a card can be updated without having to issue new cardswithout having to issue new cards

• • A smart card carries more information than can be A smart card carries more information than can be accommodated on a magnetic stripe card. It can make a accommodated on a magnetic stripe card. It can make a decision, as it has relatively powerful processing capabilities decision, as it has relatively powerful processing capabilities that allow it to do more than a magnetic stripe card (e.g., data that allow it to do more than a magnetic stripe card (e.g., data encryption).encryption).

Page 18: Smart Card Technology Why is a Smart Card So Smart?

DisadvantagesDisadvantages

+ NOT tamper proof + NOT tamper proof

+ Can be lost/stolen+ Can be lost/stolen

+ Lack of user mobility – only possible if user has smart + Lack of user mobility – only possible if user has smart card reader every he goescard reader every he goes

+ Has to use the same reader technology+ Has to use the same reader technology

+ Can be expensive+ Can be expensive

+ Working from PC – software based token will be better+ Working from PC – software based token will be better

+ No benefits to using a token on multiple PCs to using a + No benefits to using a token on multiple PCs to using a smart cardsmart card

+ Still working on bugs+ Still working on bugs

Page 19: Smart Card Technology Why is a Smart Card So Smart?

Security MechanismsSecurity Mechanisms

Page 20: Smart Card Technology Why is a Smart Card So Smart?

OS Based ClassificationOS Based Classification Smart cards are also classified on the basis of their Smart cards are also classified on the basis of their

Operating System. There are many Smart Card Operating Operating System. There are many Smart Card Operating Systems available in the market, the main ones being:Systems available in the market, the main ones being:

1. MultOS 1. MultOS 2. JavaCard2. JavaCard3. Cyberflex3. Cyberflex4. StarCOS4. StarCOS5. MFC5. MFC

Smart Card Operating Systems or SCOS as they are Smart Card Operating Systems or SCOS as they are commonly called, are placed on the ROM and usually commonly called, are placed on the ROM and usually occupy lesser than 16 KB. SCOS handle:occupy lesser than 16 KB. SCOS handle:

• File Handling and Manipulation.• File Handling and Manipulation.• Memory Management• Memory Management• Data Transmission Protocols.• Data Transmission Protocols.

Page 21: Smart Card Technology Why is a Smart Card So Smart?

ReferencesReferences

http://sec.isi.salford.ac.uk/download/smart.pdfhttp://sec.isi.salford.ac.uk/download/smart.pdf http://www.smart.govhttp://www.smart.gov http://www.gemplus.comhttp://www.gemplus.com http://www.smartcardalliance.org/industry_info/http://www.smartcardalliance.org/industry_info/

smart_cards_primer.cfmsmart_cards_primer.cfm http://www.axalto.com/Company/Governance/pdf/Annualhttp://www.axalto.com/Company/Governance/pdf/Annual

%20Report%202004.pdf%20Report%202004.pdf http://www.smartcard.co.uk/tutorials/sct-itsc.pdfhttp://www.smartcard.co.uk/tutorials/sct-itsc.pdf