Infrastructure Standards for Smart ID Card Deployment

Smart card deployment is increasing thanks to the addition of security features and improvements in computing power to support cryptographic algorithms with bigger footprints (for digitally signing and encrypting) in the smart card chips in the past five or six years. Typical applications include su...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:IEEE security & privacy 2007-03, Vol.5 (2), p.92-96
Hauptverfasser: Chandramouli, Ramaswamy, Lee, Philip
Format: Magazinearticle
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Smart card deployment is increasing thanks to the addition of security features and improvements in computing power to support cryptographic algorithms with bigger footprints (for digitally signing and encrypting) in the smart card chips in the past five or six years. Typical applications include subscriber identification module (SIM) cards (in telecommunications), micropayments (in financial transactions), commuter cards (in urban transportation systems), and identification (ID) cards. Although the share of cards used for identification applications (which we'll call smart ID cards) is relatively small within the overall smart card market, it's one of the fastest growing segments. Smart ID cards control physical access to secure facilities and logical access to IT systems (Web servers, database servers, and workstations) and applications. Authentication of the card and holder takes place using a set of credentials. An organization deploying such cards must have an infrastructure for generating, collecting, storing, provisioning, and maintaining credentials. The components involved in these credential life-cycle management activities constitute what we'll call the smart ID card system infrastructure, which supports smart ID card deployment. Not all components involved in this infrastructure have standardized interfaces. Moreover, no robust messaging standards exist for information exchange among the components. Yet, some efforts are under way to partially address the standards gap in this area
ISSN:1540-7993
1558-4046
DOI:10.1109/MSP.2007.34