All Topics  
Smart card

 
Smart Card

   Email Print
   Bookmark   Link






 

Smart card



 
 
A smart card, chip card, or integrated circuit
Integrated circuit

In electronics, an integrated circuit is a miniaturized electronic circuit that has been manufactured in the surface of a thin Wafer of semiconductor material....
 card
(ICC), is in any pocket-sized card with embedded integrated circuits which can process data. This implies that it can receive input which is processed — by way of the ICC applications — and delivered as an output.






Discussion
Ask a question about 'Smart card'
Start a new discussion about 'Smart card'
Answer questions from other users
Full Discussion Forum



Encyclopedia


Carte Vitale Anonyme
A smart card, chip card, or integrated circuit
Integrated circuit

In electronics, an integrated circuit is a miniaturized electronic circuit that has been manufactured in the surface of a thin Wafer of semiconductor material....
 card
(ICC), is in any pocket-sized card with embedded integrated circuits which can process data. This implies that it can receive input which is processed — by way of the ICC applications — and delivered as an output. There are two broad categories of ICCs. Memory card
Memory card

A memory card or flash memory card is a solid-state electronic flash memory data storage device used with digital cameras, Personal Digital Assistant and Mobile computers, telephones, music players, video game consoles, and other electronics....
s contain only non-volatile memory storage components, and perhaps some specific security logic. Microprocessor cards contain volatile memory and microprocessor components. The card is made of plastic, generally PVC
Polyvinyl chloride

Polyvinyl chloride, commonly abbreviated PVC, is the third most widely used thermoplastic polymer after polyethylene and polypropylene....
, but sometimes ABS
Acrylonitrile butadiene styrene

Acrylonitrile butadiene styrene is a common thermoplastic used to make light, rigid, molded products such as piping , musical instruments , golf club heads , automotive body parts, wheel covers, enclosures, protective head gear, airsoft Airsoft gun and toys, including Lego bricks....
. The card may embed a hologram
Holography

A hologram is a picture that changes when looked at from different angles.Holography is a technique that allows the light scattered from an object to be recorded and later reconstructed so that it appears as if the object is in the same position relative to the recording medium as it was when recorded....
 to avoid counterfeit
Counterfeit

A counterfeit is an imitation made usually with the intent to deceptively represent its content or origins, thus increasing sales appeal due to the reputation of the imitated product....
ing. Using smartcards also is a form of strong security authentication for single sign-on
Single sign-on

Single sign-on is a method of access control that enables a user to log in once and gain access to the resources of multiple software systems without being prompted to log in again....
 within large companies and organizations.

Overview

A "smart card" is also characterized as follows:
  • Dimensions are normally credit card
    Credit card

    A credit card is part of a system of payments named after the small plastic card issued to users of the system. It is a card entitling its holder to buy goods and services based on the holders promise to pay for these goods and services....
     size. The ID-1 of ISO/IEC 7810
    ISO 7810

    ISO/IEC JTC1 7810:2003 is an international standard that defines four formats for identity or identification cards, ID-1, ID-2, ID-3 and ID-000....
     standard defines them as 85.60 × 53.98 mm. Another popular size is ID-000 which is 25 × 15 mm (commonly used in SIM cards
    Subscriber Identity Module

    A Subscriber Identity Module on a removable SIM Card securely stores the International Mobile Subscriber Identity used to identify a subscriber on mobile telephony devices ....
    ). Both are 0.76 mm thick.
  • Contains a security system with tamper-resistant
    Tamper resistance

    Tamper resistance is resistance to wiktionary:tamper by either the normal users of a product, package, or system or others with physical access to it....
     properties (e.g. a secure cryptoprocessor
    Secure cryptoprocessor

    A secure cryptoprocessor is a dedicated computer or microprocessor for carrying out cryptographic operations, embedded in a packaging with multiple physical security measures, which give it a degree of tamper resistance....
    , secure file system, human-readable features) and is capable of providing security services (e.g. confidentiality of information in the memory).
  • Asset managed by way of a central administration system which interchanges information and configuration settings with the card through the security system. The latter includes card hotlisting, updates for application data.
  • Card data is transferred to the central administration system through card reading devices, such as ticket readers, ATM
    Automated teller machine

    An automated teller machine is a computerized telecommunications device that provides the customers of a financial institution with access to financial transactions in a public space without the need for a human clerk or bank teller....
    s etc.


Benefits

Smart cards can be used for identification, authentication, and data storage.

Smart cards provide a means of effecting business transactions in a flexible, secure, standard way with minimal human intervention.

Smart card can provide strong authentication for single sign-on
Single sign-on

Single sign-on is a method of access control that enables a user to log in once and gain access to the resources of multiple software systems without being prompted to log in again....
 or enterprise single sign-on to computers, laptops, data
DATA

Debt, AIDS, Trade in Africa is a multinational Non-governmental organization founded in January 2002 in London by U2's Bono along with Robert Sargent Shriver III and activists from the Jubilee 2000 Drop the Debt campaign....
 with encryption
Encryption

In cryptography, encryption is the process of transforming information using an algorithm to make it unreadable to anyone except those possessing special knowledge, usually referred to as a key ....
, enterprise resource planning
Enterprise resource planning

Enterprise resource planning is an enterprise-wide information system designed to coordinate all the resources, information, and activities needed to complete business processes such as order fulfillment or billing....
 platforms such as SAP
Sap

Sap may refer to:* Plant sap, the fluid transported in xylem cells or phloem sieve tube elements of a plant* Baton #Blackjack, another word for a blackjack, an easily concealed Club ....
, etc.

History

The automated chip card was invented by German
Germany

Germany , officially the Federal Republic of Germany , is a country in Central Europe. It is bordered to the north by the North Sea, Denmark, and the Baltic Sea; to the east by Poland and the Czech Republic; to the south by Austria and Switzerland; and to the west by France, Luxembourg, Belgium, and the Netherlands....
 rocket scientist Helmut Gröttrup
Helmut Gröttrup

Helmut Gr?ttrup was a Germans electrical engineer and assistant of Wernher von Braun in the V-2 rocket-project. Gr?ttrup was responsible for the guidance system....
 and his colleague Jürgen Dethloff in 1968; the patent was finally approved in 1982. The first mass use of the cards was for payment in French pay phones
Payphone

A pay phone or payphone is a public telephone, with payment by inserting money or a credit card or debit card before a call is made. Some telephone companies have termed them, and tried to get the public to identify them as "coin phones", because the term "pay phone" may imply that other phones are free....
, starting in 1983 (Télécarte
Telephone card

A telephone card, calling card or phone card for short, is a small card, usually resembling a credit card, used to pay for telephone services....
).

Roland Moreno actually patented his first concept of the memory card in 1974. In 1977, Michel Ugon from Honeywell Bull
Groupe Bull

Groupe Bull is a France owned computer company headquartered in Les Clayes-sous-Bois, outside Paris. The company has also been known at various times as Bull General Electric, Honeywell Bull, CII Honeywell Bull, and Bull HN....
 invented the first microprocessor smart card. In 1978, Bull patented the SPOM (Self Programmable One-chip Microcomputer) that defines the necessary architecture to auto-program the chip. Three years later, the very first "CP8" based on this patent was produced by Motorola. At that time, Bull had 1200 patents related to smart cards. In 2001, Bull sold its CP8 Division together with all its patents to Schlumberger. Subsequently, Schlumberger combined its smart card department and CP8 and created Axalto. In 2006, Axalto and Gemplus, at the time the world's no.2 and no.1 smart card manufacturers, merged and became Gemalto.

The second use was with the integration of microchips into all French debit card
Debit card

A debit card is a plastic card which provides an alternative payment method to cash when making purchases. Functionally, it can be called an electronic check, as the funds are withdrawn directly from either the bank account , or from the remaining balance on the card....
s (Carte Bleue
Carte Bleue

Carte Bleue is a major debit card payment scheme operating in France. The system has now been integrated into a wider scheme called Groupement des Cartes Bancaires CB or Carte bancaire ....
) completed in 1992. When paying in France with a Carte Bleue, one inserts the card into the merchant's terminal, then types the PIN, before the transaction is accepted. Only very limited transactions (such as paying small autoroute
Autoroute

Autoroute is the French word for a major high-speed road restricted to motor vehicles without crossings and having limited access. Those are similar to a motorway or freeway in English-speaking countries....
 tolls) are accepted without PIN.

Smart-card-based electronic purse systems (in which value is stored on the card chip, not in an externally recorded account, so that machines accepting the card need no network connectivity) were tried throughout Europe from the mid-1990s, most notably in Germany (Geldkarte), Austria (Quick), Belgium (Proton), France (Moneo), the Netherlands (Chipknip and Chipper), Switzerland ("Cash"), Norway ("Mondex"), Sweden ("Cash"), Finland ("Avant"), UK ("Mondex"), Denmark ("Danmønt") and Portugal ("Porta-moedas Multibanco").

The major boom in smart card use came in the 1990s, with the introduction of the smart-card-based SIM
Subscriber Identity Module

A Subscriber Identity Module on a removable SIM Card securely stores the International Mobile Subscriber Identity used to identify a subscriber on mobile telephony devices ....
 used in GSM mobile phone equipment in Europe. With the ubiquity of mobile phones in Europe, smart cards have become very common.

The international payment brands MasterCard, Visa, and Europay agreed in 1993 to work together to develop the specifications for the use of smart cards in payment cards used as either a debit or a credit card. The first version of the EMV
EMV

EMV is a standard for interoperation of IC cards and IC capable point of sale terminals and Automated Teller Machine's, for authenticating credit card and debit card payments....
 system was released in 1994. In 1998 a stable release of the specifications was available. , the company responsible for the long-term maintenance of the system, upgraded the specification in 2000 and most recently in 2004. The goal of EMVco is to assure the various financial institutions and retailers that the specifications retain backward compatibility with the 1998 version.

With the exception of countries such as the United States of America there has been significant progress in the deployment of EMV-compliant point of sale equipment and the issuance of debit and or credit cards adhering the EMV specifications. Typically, a country's national payment association, in coordination with MasterCard
MasterCard

MasterCard Worldwide is a multinational corporation based in Purchase, New York, New York, United States. Throughout the world, its principal business is to process payments between the banks of merchants and the banks of purchasers that use its "MasterCard" brand Debit card and credit cards to make purchases....
 International, Visa International, American Express
American Express

American Express Company , sometimes known as "AmEx" or "Amex", is a Diversification global financial services company that is headquartered in New York City, New York....
 and JCB
Japan Credit Bureau

Japan Credit Bureau, usually abbreviated as JCB, is a credit card company based in Tokyo, Japan. Its English name is . The abbreviation is sometimes thought to stand for Japan Commerce Bank, but this is incorrect....
, develop detailed implementation plans assuring a coordinated effort by the various stakeholders involved.

The backers of EMV claim it is a paradigm shift in the way one looks at payment systems. In countries where banks do not currently offer a single card capable of supporting multiple account types, there may be merit to this statement. Though some banks in these countries are considering issuing one card that will serve as both a debit card and as a credit card, the business justification for this is still quite elusive. Within EMV a concept called Application Selection defines how the consumer selects which means of payment to employ for that purchase at the point of sale.

For the banks interested in introducing smart cards the only quantifiable benefit is the ability to forecast a significant reduction in fraud, in particular counterfeit, lost and stolen. The current level of fraud a country is experiencing, coupled with whether that country's laws assign the risk of fraud to the consumer or the bank, determines if there is a business case for the financial institutions. Some critics claim that the savings are far less than the cost of implementing EMV, and thus many believe that the USA payments industry will opt to wait out the current EMV life cycle in order to implement new, contactless technology.

Smart cards with contactless interfaces are becoming increasingly popular for payment and ticketing applications such as mass transit. Visa and MasterCard have agreed to an easy-to-implement version currently being deployed (2004-2006) in the USA. Across the globe, contactless fare collection systems are being implemented to drive efficiencies in public transit. The various standards emerging are local in focus and are not compatible, though the MIFARE
MIFARE

MIFARE is the NXP Semiconductors-owned trademark of the reputedly most widely installed contactless smartcard, or proximity card, technology in the world with over 1 billion smart card chips and 10 million reader modules sold....
 Standard card from Philips has a considerable market share in the US and Europe.

Smart cards are also being introduced in personal identification and entitlement schemes at regional, national, and international levels. Citizen cards, drivers’ licenses, and patient card schemes are becoming more prevalent; For example in Malaysia, the compulsory national ID scheme MyKad
MyKad

MyKad, or Government Multipurpose Card, is the official compulsory identity card of Malaysia. It is regarded as the world's first smart identity card....
 includes 8 different applications and is rolled out for 18 million users. Contactless smart cards are being integrated into ICAO biometric passport
Biometric passport

File:Map of countries with biometric passports.svgA biometric passport is a combined paper and electronic identity document that uses biometrics to authenticate the identity of travelers....
s to enhance security for international travel.

Contact smart card


Contact smart cards have a contact area, comprising several gold-plated contact pads, that is about 1 cm square. When inserted into a reader
Card reader

A memory card reader is a device used for communication with a smart card or a flash memory card.A business card reader is a scanning device used to scan and electronically save business cards....
, the chip makes contact with electrical connectors that can read information from the chip and write information back.

The ISO/IEC 7816
ISO 7816

ISO/IEC 7816 is an international standard related to electronic identification cards, especially smart cards, managed jointly by the International Organization for Standardization and the International Electrotechnical Commission....
 and ISO/IEC 7810
ISO 7810

ISO/IEC JTC1 7810:2003 is an international standard that defines four formats for identity or identification cards, ID-1, ID-2, ID-3 and ID-000....
 series of standards define:
  • the physical shape
  • the positions and shapes of the electrical connectors
  • the electrical characteristics
  • the communications protocol
    Communications protocol

    In the field of telecommunications, a communications protocol is the set of standard rules for data representation, Signalling , authentication and Error detection and correction required to send information over a communications channel....
    s, that includes the format of the commands sent to the card and the responses returned by the card.
  • robustness of the card
  • the functionality


The cards do not contain batteries
Battery (electricity)

In electronics, a battery or voltaic cell is a combination of one or more electrochemical cell Galvanic cells which store chemical energy that can be converted into electric potential energy, creating electricity....
; energy is supplied by the card reader.

Electrical signals description


VCC : Power supply input
IC power supply pin

Almost all integrated circuits have at least two pins which connect to the power supply rails of the circuit in which they are installed. These are known as the IC's power supply pins....


RST : Either used itself (reset signal supplied from the interface device) or in combination with an internal reset control circuit (optional use by the card). If internal reset is implemented, the voltage supply on Vcc is mandatory.

CLK : Clocking or timing signal (optional use by the card).

GND : Ground
Ground (electricity)

In electrical engineering, ground or earth may be the reference point in an electrical circuit from which other voltages are measured, or a common return path for electric current, or a direct physical connection to the Earth....
 (reference voltage).

VPP : Programming voltage input (deprecated / optional use by the card).

I/O : Input or Output for serial data to the integrated circuit inside the card.

NOTE - The use of the two remaining contacts will be defined in the appropriate application standards.

Reader


Contact smart card readers are used as a communications medium between the smart card and a host, e.g. a computer, a point of sale terminal, or a mobile telephone.

Since the chips in the financial cards are the same as those used for mobile phone Subscriber Identity Module
Subscriber Identity Module

A Subscriber Identity Module on a removable SIM Card securely stores the International Mobile Subscriber Identity used to identify a subscriber on mobile telephony devices ....
 (SIM) cards, just programmed differently and embedded in a different shaped piece of PVC
Polyvinyl chloride

Polyvinyl chloride, commonly abbreviated PVC, is the third most widely used thermoplastic polymer after polyethylene and polypropylene....
, the chip manufacturers are building to the more demanding GSM/3G standards. So, for instance, although EMV allows a chip card to draw 50 mA from its terminal, cards are normally well inside the telephone industry's 6mA limit. This is allowing financial card terminals to become smaller and cheaper, and moves are afoot to equip every home PC with a card reader and software to make internet shopping more secure.

Contactless smart card

Main Article
Contactless smart card

File:OctopusFrontNew.jpgA contactless smart card, or Smart Card is in any pocket-sized card with embedded integrated circuits which can process and store data....


A second type is the contactless smart card
Proximity card

Proximity card is a generic name for contactless integrated circuit devices used for Access control or payment systems. It can refer to the older 125 kHz devices or the newer 13.56 MHz contactless RFID cards, most commonly known as contactless smartcards....
, in which the chip communicates with the card reader through RFID induction technology (at data rates of 106 to 848 kbit/s). These cards require only close proximity to an antenna to complete transaction. They are often used when transactions must be processed quickly or hands-free, such as on mass transit systems, where smart cards can be used without even removing them from a wallet
Wallet

A wallet, or billfold, is a small, flat case used to carry personal items such as cash, credit cards and identification documents, such as a driver's license....
.

The standard for contactless smart card communications is ISO/IEC 14443
ISO 14443

ISO/IEC 14443 defines a proximity card used for identification that usually uses the standard credit card form factor defined by ISO 7810 ID-1. Other form factors also are possible....
, dated 2001. It defines two types of contactless cards ("A" and "B"), allows for communications at distances up to 10 cm. There had been proposals for ISO 14443 types C, D, E and F that have been rejected by the International Organization for Standardization. An alternative standard for contactless smart cards is ISO 15693
ISO 15693

ISO 15693 is an International Organization for Standardization standard for "Vicinity Cards", i.e. cards which can be read from a greater distance as compared to Proximity cards....
, which allows communications at distances up to 50 cm.

Example of widely used contactless smart cards are Hong Kong's Octopus card
Octopus card

The Octopus card is a rechargeable Contactless payment stored value smart card used to transfer electronic moneys in online or offline systems in Hong Kong....
, South Korea
South Korea

South Korea, officially the Republic of Korea , ), often referred to as Korea and the "names of Korea#Revival of the names", is a Semi-presidential system republic in East Asia, located in the southern half of the Korean Peninsula....
's T-money
T-Money

T-money is a rechargeable series of cards and other "smart" devices used for paying transportation fares in and around Seoul and other areas of South Korea....
(Bus, Subway, Taxi), London's Oyster card
Oyster card

The Oyster card is a form of electronic ticketing used on public transport services within the Greater London area of the United Kingdom. It is promoted by Transport for London and is valid on a number of different travel systems including London Underground, London buses, the Docklands Light Railway , London Overground, Tramlink and some Nat...
, and Japan Rail's Suica
Suica

is a rechargeable contactless smart card used as a fare card on train lines in Japan. Launched in November 2001, the card is usable currently in the Kanto region, at East Japan Railway Company stations near Sendai, Miyagi and Niigata, Niigata, and in the Kinki region on West Japan Railway Company....
 Card, which predate the ISO/IEC 14443 standard. The following tables list smart cards used for public transportation and other electronic purse applications.

A related contactless technology is RFID (radio frequency identification). In certain cases, it can be used for applications similar to those of contactless smart cards, such as for electronic toll collection
Electronic toll collection

Electronic toll collection , an adaptation of military "identification friend or foe" technology, aims to eliminate the delay on toll roads by collecting toll s electronically....
. RFID devices usually do not include writeable memory or microcontroller processing capability as contactless smart cards often do.

There are dual-interface cards that implement contactless and contact interfaces on a single card with some shared storage and processing. An example is Porto
Porto

Porto , also Oporto in English, is Portugal's second city and capital of the Norte, Portugal NUTS II region. The city is located in the estuary of the Douro river in northern Portugal....
's multi-application transport card, called Andante
Andante ticket

Andante is a public transport ticketing system used in and around Porto, Portugal.It started operation in November 2002 at Metro do Porto stations and is now a cross-network ticket used on the Porto Metro, selected bus and train routes and the Funicular dos Guindais cable railway....
, that uses a chip in contact and contactless (ISO 14443B).

Like smart cards with contacts, contactless cards do not have a battery. Instead, they use a built-in inductor
Inductor

An inductor is a Passive component Electronic component that can store energy in a magnetic field created by the electric current passing through it....
 to capture some of the incident radio-frequency interrogation signal, rectify
Rectifier

A rectifier is an electrical device that converts alternating current to direct current , a process known as rectification. Rectifiers have many uses including as components of power supply and as detector s of radio signals....
 it, and use it to power the card's electronics.

Communication protocols

Communication protocols
NameDescription
T=0Byte-level transmission protocol, defined in ISO/IEC 7816-3
ISO 7816

ISO/IEC 7816 is an international standard related to electronic identification cards, especially smart cards, managed jointly by the International Organization for Standardization and the International Electrotechnical Commission....
T=1Block-level transmission protocol, defined in ISO/IEC 7816-3
ISO 7816

ISO/IEC 7816 is an international standard related to electronic identification cards, especially smart cards, managed jointly by the International Organization for Standardization and the International Electrotechnical Commission....
ISO/IEC 14443APDU transmission via contactless interface, defined in ISO/IEC 14443-4
ISO 14443

ISO/IEC 14443 defines a proximity card used for identification that usually uses the standard credit card form factor defined by ISO 7810 ID-1. Other form factors also are possible....


Credit card contactless technology

These are the best known payment cards (classical plastic card):
  • Visa: Visa Contactless, Quick VSDC - "qVSDC", Visa Wave, MSD, payWave
  • MasterCard: PayPass Magstripe, PayPass MChip
  • American Express: Express Pay
  • Chase: Blink (credit and debit cards)


Roll-outs started in 2005 in USA (Asia and Europe - 2006). Contactless (non PIN) transactions cover a payment range of ~$5-50. There is an ISO 14443
ISO 14443

ISO/IEC 14443 defines a proximity card used for identification that usually uses the standard credit card form factor defined by ISO 7810 ID-1. Other form factors also are possible....
 PayPass implementation. All PayPass implementations may be separated on EMV and non EMV.

Non-EMV cards work like magnetic stripe cards. This is a typical card technology in the USA (PayPass Magstripe and VISA MSD). The cards do not control amount remaining. All payment passes without a PIN and usually in off-line mode. The security level of such a transaction is no greater than with classical magnetic stripe card transaction.

EMV cards have two interfaces (contact and contactless) and they work as a normal EMV card via contact interface. Via contactless interface they work almost like an EMV (card command sequence adopted on contactless features as low power and short transaction time).

Cryptographic smart cards

Cryptographic smart cards are often used for single sign-on. Most advanced smart cards are equipped with specialized cryptographic hardware that let you use algorithms such as RSA
RSA

In cryptography, RSA is an algorithm for public-key cryptography. It is the first algorithm known to be suitable for digital signature as well as encryption, and one of the first great advances in public key cryptography....
 and DSA
Digital Signature Algorithm

The Digital Signature Algorithm is a Federal government of the United States Federal Information Processing Standard or Federal Information Processing Standard for digital signatures....
 on board. Today's cryptographic smart cards are also able to generate key pairs on board, to avoid the risk of having more than one copy of the key (since by design there usually isn't a way to extract private keys from a smart card).

Such smart cards are mainly used for digital signature
Digital signature

A digital signature or digital signature scheme is a type of asymmetric key algorithm. For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender....
 and secure identification, (see applications section).

The most common way to access cryptographic smart card functions on a computer is to use a PKCS#11
PKCS11

In cryptography, PKCS#11 is one of the family of standards called PKCS, published by RSA Laboratories. It defines a platform-independent Application programming interface to cryptographic tokens, such as Hardware Security Modules and smart cards....
 library provided by the vendor. On Microsoft Windows
Microsoft Windows

Microsoft Windows is a series of software operating systems and graphical user interfaces produced by Microsoft. Microsoft first introduced an operating environment named Windows in November 1985 as an add-on to MS-DOS in response to the growing interest in graphical user interfaces ....
 platforms the CSP
Cryptographic Service Provider

In Microsoft Windows, a Cryptographic Service Provider is a software library that implements the Cryptographic Application Programming Interface ....
 API is also adopted.

The most widely used cryptographic algorithms in smart cards (excluding the GSM so-called "crypto algorithm") are 3DES (Triple DES
Triple DES

In cryptography, Triple DES is a block cipher formed from the Data Encryption Standard cipher by using it three times....
) and RSA
RSA

In cryptography, RSA is an algorithm for public-key cryptography. It is the first algorithm known to be suitable for digital signature as well as encryption, and one of the first great advances in public key cryptography....
. The key set is usually loaded (DES) or generated (RSA) on the card at the personalization stage.

Applications


Computer security

The Mozilla Firefox
Mozilla Firefox

Mozilla Firefox is a web browser descended from the Mozilla Application Suite and managed by Mozilla Corporation. Official versions are distributed under the terms of the proprietary EULA....
 web browser can use smart cards to store certificate
Public key certificate

In cryptography, a public key certificate is an electronic document which incorporates a digital signature to bind together a public key with an identity — information such as the name of a person or an organization, their address, and so forth....
s for use in secure web browsing.

Some disk encryption systems
Disk encryption software

To protect confidentiality of the data stored on a computer disk a computer security technique called disk encryption is used. This article discusses software that is used to implement the technique ....
, such as FreeOTFE
FreeOTFE

FreeOTFE is an "on-the-fly" disk encryption program for PCs running MS Windows and Windows Mobile Personal digital assistant . It creates "virtual drive" - anything written to which is automatically encrypted before being stored on the computer's hard drive or USB drive....
 or TrueCrypt
TrueCrypt

TrueCrypt is a software application used for real-time on-the-fly encryption. It can create a virtual encrypted disk within a file or a device-hosted encrypted volume on either an individual partition or an entire Data storage device....
, can use smart cards to securely hold encryption keys, and also to add another layer of encryption to critical parts of the secured disk.

Smartcards are also used for single sign-on
Single sign-on

Single sign-on is a method of access control that enables a user to log in once and gain access to the resources of multiple software systems without being prompted to log in again....
 to log on to computers

Financial

The applications of smart cards include their use as credit or ATM cards, in a fuel card
Fuel card

A fuel card is a payment card for petrol , diesel and other fuels at filling stations. Account balances are cleared in full when due and payment terms vary depending on the supplier and can be anything from weekly to monthly....
, SIM
Subscriber Identity Module

A Subscriber Identity Module on a removable SIM Card securely stores the International Mobile Subscriber Identity used to identify a subscriber on mobile telephony devices ....
s for mobile phones, authorization cards for pay television, pre-pay utilities in household, high-security identification and access-control cards, and public transport
Public transport

Public transport comprises passenger transportation services which are available for use by the general public, as opposed to modes for private use such as automobiles or vehicles for hire....
 and public phone payment cards.

Smart cards may also be used as electronic wallets. The smart card chip can be loaded with funds which can be spent in parking meters and vending machines or at various merchants. Cryptographic protocol
Cryptographic protocol

A security protocol is an abstract or concrete protocol that performs a information security-related function and applies cryptographic methods....
s protect the exchange of money between the smart card and the accepting machine. There is no connection to the issuing bank necessary, so the holder of the card can use it regardless of him being the owner. Examples are Proton, Geldkarte, Chipknip and Mon€o
Mon€o

Moneo, branded as mon?o, is an electronic purse system available on France bank cards to allow small purchases to be made without cash.The system is aimed at small retailers such as bakeries and caf?s and intended for purchases of less than ?30....
. The German Geldkarte is also used to validate the customers age at vending machine
Vending machine

A vending machine provides various snacks, beverages, and other products to consumers. The idea is to vend products without a cashier. Items sold via vending machines vary by country and region....
s for cigarettes.

Identification

A quickly growing application is in digital identification cards. In this application, the cards are used for authentication
Authentication

Authentication is the act of establishing or confirming something as authentic, that is, that claims made by or about the subject are true....
 of identity. The most common example is in conjunction with a PKI
Public key infrastructure

The Public Key Infrastructure is a set of hardware, software, people, policies, and procedures needed to create, manage, store, distribute, and revoke digital certificates ....
. The smart card will store an encrypted digital certificate issued from the PKI along with any other relevant or needed information about the card holder. Examples include the U.S. Department of Defense
United States Department of Defense

The United States Department of Defense is the federal department charged with coordinating and supervising all agencies and functions of the government relating directly to national security and the Military of the United States....
 (DoD) Common Access Card
Common Access Card

The Common Access Card is a United States Department of Defense smart card issued as standard identification for active-duty military personnel, reserve personnel, civilian employees, non-DoD other government employees and State Employees of the National Guard and eligible contractor personnel....
 (CAC), and the use of various smart cards by many governments as identification cards for their citizens. When combined with biometrics, smart cards can provide two- or three-factor authentication. Smart cards are not always a privacy-enhancing technology, for the subject carries possibly incriminating information about him all the time. By employing contactless smart cards, that can be read without having to remove the card from the wallet or even the garment it is in, one can add even more authentication value to the human carrier of the cards.

The first smart card driver's license system in the world was issued in 1995 in Mendoza
Mendoza Province

Mendoza is one of the Provinces of Argentina of Argentina, located in the western central part of the country in the Cuyo, Argentina region. Neighboring provinces are from the north clockwise San Juan Province, Argentina, San Luis Province, La Pampa,and Neuqu?n Province....
, a province of Argentina
Argentina

Argentina, officially the Argentine Republic , is a country in South America, constituted as a federation of 23 provinces and an autonomous city....
. Mendoza has a high level of road accidents, driving offenses, and a poor record of recovering outstanding fines. The smart licenses keep an up-to-date record of driving offenses and unpaid fines. They also store personal information, license type and number, and a photograph of the holder. Emergency medical information like blood type, allergies, and biometrics (fingerprints) can be stored on the chip if the cardholder wishes. The Argentina government anticipates that this new system will help to recover more than $10 million per year in fines.

Gujarat
Gujarat

Gujarat is a States and territories of India in western India. Gujarat borders Pakistan to the north west and the state of Rajasthan to the north and northeast, Madhya Pradesh to the east, Maharashtra and the Union territory of Diu, Daman District, India, Dadra and Nagar Haveli to the south....
 was the first state in India to introduce the in 1999. To date the Gujarat Government has issued 5 million smart card driving licenses to its people. This card is basically a plastic card having ISO/IEC 7810
ISO 7810

ISO/IEC JTC1 7810:2003 is an international standard that defines four formats for identity or identification cards, ID-1, ID-2, ID-3 and ID-000....
 certification and integrated circuit, capable of storing and verifying information according to its programming.

“a national ID card, protected by a 1,024-bit key code, is impossible to break ``without a supercomputer working away for a hundred years”

By the start of 2009 the entire population of Spain
Spain

Spain or the Kingdom of Spain , is a country located in Southern Europe on the Iberian Peninsula.The Spanish constitution does not establish any official denomination of the country, even though Espa?a , Estado espa?ol and Naci?n espa?ola are used interchangeably....
 and Belgium
Belgium

* A small German-speaking Community of Belgium exists in eastern Wallonia. Belgium's linguistic diversity and related political and cultural conflicts are reflected in the history of Belgium and a complex Communities and regions of Belgium....
 will have an eID card, that is issued by the Spanish and Belgian Governments and that is used to identify an individual. These cards contain 2 certificates: one for authentication and one for signature. This signature is legally adopted. More and more services in these countries are using the eID card as an authorization token. More information on and

Other

Smart cards are widely used to protect digital television streams. See television encryption
Television encryption

Television encryption, often referred to as "scrambler", is encryption used to control access to pay television services, usually cable television or satellite television services....
 for an overview, and VideoGuard
VideoGuard

VideoGuard , produced by NDS Group, is a digital encryption system for use with conditional access television broadcasting. It is used almost exclusively on digital satellite television systems operated by News Corporation, which owns the majority of NDS....
 for a specific example of how smart card security worked (and was cracked).

The Malaysian government uses smart card technology in identity cards carried by all Malaysian citizens and resident non-citizens. The personal information inside the smart card (called MYKAD) can be read using special APDU commands.

Security

Smart cards have been advertised as suitable for personal identification tasks, because they are engineered to be tamper resistant. The embedded chip of a smart card usually implements some cryptographic algorithm
Cryptography

Cryptography is the practice and study of hiding information. In modern times cryptography is considered a branch of both mathematics and computer science and is affiliated closely with information theory, computer security and engineering....
. There are, however, several methods of recovering some of the algorithm's internal state.

Differential power analysis

Differential power analysis involves measuring the precise time and electrical current required for certain encryption or decryption operations. This is most often used against public key algorithms such as RSA
RSA

In cryptography, RSA is an algorithm for public-key cryptography. It is the first algorithm known to be suitable for digital signature as well as encryption, and one of the first great advances in public key cryptography....
 in order to deduce the on-chip private key, although some implementations of symmetric ciphers can be vulnerable to timing or power attacks as well.

Physical disassembly

Smart cards can be physically disassembled by using acid, abrasives, or some other technique to obtain direct, unrestricted access to the on-board microprocessor. Although such techniques obviously involve a fairly high risk of permanent damage to the chip, they permit much more detailed information (e.g. photomicrographs of encryption hardware) to be extracted.

Problems

Another problem of smart cards may be the failure rate. The plastic card in which the chip is embedded is fairly flexible, and the larger the chip, the higher the probability of breaking. Smart cards are often carried in wallets or pockets — a fairly harsh environment for a chip. However, for large banking systems, the failure-management cost can be more than offset by the fraud reduction. A card enclosure
Card enclosure

File:Card_case.jpgA card enclosure is a container for smart cards, credit cards, debit cards, telephone cards, visiting cards, business cards and other cards of similar size....
 might be a good idea.

Using a smart card for mass transit presents a risk for privacy
Privacy

Privacy is the ability of an individual or group to seclude themselves or information about themselves and thereby reveal themselves selectively....
, because such a system enables the mass transit operator (and the authorities) to track the movement of individuals. In Finland, the Data Protection Ombudsman
Ombudsman

An ombudsman is an official, usually appointed by government or by a non-governmental public body, who is charged with investigating complaints by citizens and, where possible, resolving them, usually by making recommendations but sometimes through mediation....
 prohibited the transport operator YTV
Helsinki Metropolitan Area Council

The Helsinki Metropolitan Area Council is a co-operation agency operating in the Helsinki Metropolitan Area. The organisation has a few responsibilities, most notably regional public transport and waste management....
 from collecting such information, in spite of YTV's argument that the owner of the card has the right to get a list of journeys paid with the card. Prior to this, such information was used in the investigation of the Myyrmanni bombing
Myyrmanni bombing

The Myyrmanni bombing took place on October 11, 2002 in the Myyrm?ki, Vantaa, Finland, in Greater Helsinki, in the local Myyrmanni shopping mall....
.

Smart cards used for client-side identification and authentication are the most secure way for eg. internet banking applications, but the security is never 100% sure. In the example of internet banking, if the PC is infected with any kind of malware, the security model is broken. A malware can override the communication (both input via keyboard and output via application screen) between the user and the internet banking application (eg. browser). This would result in modifying transactions by the malware and unnoticed by the user. There are malwares in the wild with this capability (eg. Trojan. Silentbanker). Banks like Fortis
Fortis

Fortis may refer to:*Fortis , a linguistic term*Fortis , a financial services company, based in Belgium and the Netherlands*Fortis Healthcare Limited, a chain of hospitals based in India...
 and Dexia
Dexia

Dexia is a Belgium-France financial institution, also referred to as the Dexia Group, specializing in public finance. It was founded in 1996 through the merger of Cr?dit Communal de Belgique/Gemeentekrediet van Belgi? and Cr?dit Local de France ....
 in Belgium combine a Smart card with an unconnected card reader to avoid this problem. The customer enters a challenge received from the bank's website, his PIN and the transaction amount into the card reader, the card reader returns an 8 digits signature. This signature is manually copied to the PC and verified by the bank. This method prevents a malware to change the transaction amount.

In addition to technical hurdles is the lack of standards for smart card functionality and security. To address this problem, the ERIDANE Project was launched by The Berlin Group to develop a proposal for "a new functional and security framework for smart-card based Point of Interaction (POI) equipment", equipment that would be used, for instance, in retail environments.

Terminology

ATR:Answer to Reset BCD:Binary-coded decimal
Binary-coded decimal

In computing and electronics systems, binary-coded decimal is an encoding for decimal numbers in which each digit is represented by its own binary sequence....
CHV:Card Holder Verification COS:Card operating system DF:Dedicated File IC:Integrated circuit PC/SC
PC/SC

PC/SC is a specification for SmartCard integration in computing environment.PC/SC is implemented in Microsoft Windows 200x/XP and available under Microsoft Windows NT/9x....
:Personal computer / smart card MF:Master File PPS:Protocol and Parameter Select RFU:Reserved for Future Use

See also

  • Access badge
    Access badge

    An access badge is a credential used to gain entry to an area having automated access control entry points. Entry points may be doors, turnstiles, parking gates or other barriers....
  • Access control
    Access control

    Access control is the ability to permit or deny the use of a particular resource by a particular entity. Access control mechanisms can be used in managing physical resources , logical resources , or digital resources ....
    • Keycard
    • Disk encryption
      Disk encryption

      Disk encryption is a special case of data at rest protection when the storage media is a sector-addressable device . This article presents cryptographic aspects of the problem....
    • Physical security
      Physical security

      Physical security describes both measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media and guidance on how to design structures to resist various hostile acts....
  • BasicCard
    BasicCard

    BasicCard is a smart card programmable in the ZC-BASIC language. The BasicCard Toolkit offers an Application programming interface to quickly program the terminal side and the card side of the application....
  • Biometrics
    Biometrics

    Biometrics refers to two different fields of study and application:In biological studies it refers to the collection, synthesis, analysis and management of data in biology....
  • Common Access Card
    Common Access Card

    The Common Access Card is a United States Department of Defense smart card issued as standard identification for active-duty military personnel, reserve personnel, civilian employees, non-DoD other government employees and State Employees of the National Guard and eligible contractor personnel....
  • Credential
    Credential

    A credential is an attestation of qualification, competence, or authority issued to an individual by a third party with a relevant de jure or de facto authority or assumed competence to do so....
  • Electronic money
    Electronic money

    Electronic money refers to money or scrip which is exchanged only electronically. Typically, this involves use of computer networks, the internet and Stored-value card systems....
  • Electronic passport
  • EMV credit cards
    EMV

    EMV is a standard for interoperation of IC cards and IC capable point of sale terminals and Automated Teller Machine's, for authenticating credit card and debit card payments....
  • GlobalPlatform standard
    GlobalPlatform

    GlobalPlatform is a fully independent, non-for-profit, democratic standardization organization.GlobalPlatform mission is to establish, maintain and drive adoption of standards to enable an open and interoperable infrastructure for smart cards, devices and systems that simplifies and accelerates development, deployment and management o...
  • ID card
  • Java Card
    Java Card

    Java Card refers to a technology that allows small Java platform-based applications to be run securely on smart cards and similar small memory footprint devices....
  • Magnetic stripe card
    Magnetic stripe card

    A magnetic stripe card is a type of card capable of storing data by modifying the magnetism of tiny iron-based magnetic particles on a band of magnetic material on the card....
  • MULTOS
    MULTOS

    MULTOS is a multi-application smart card operating system, that enables a smart card to carry a variety of applications, from chip & pin application for payment to on-card Biometrics matching for secure ID and ePassport....
  • PCI DSS
    PCI DSS

    PCI DSS stands for Payment card industry Data Security Standard, and is a worldwide security standard assembled by the Payment Card Industry Security Standards Council ....
  • Proximity card
    Proximity card

    Proximity card is a generic name for contactless integrated circuit devices used for Access control or payment systems. It can refer to the older 125 kHz devices or the newer 13.56 MHz contactless RFID cards, most commonly known as contactless smartcards....
  • RFID
  • Security engineering
    Security engineering

    Security engineering is a specialized field of engineering that deals with the development of detailed engineering plans and designs for security features, controls and systems....
  • Single sign-on
    Single sign-on

    Single sign-on is a method of access control that enables a user to log in once and gain access to the resources of multiple software systems without being prompted to log in again....
  • Snapi
    Snapi

    SNAPI? is a system that allows a user to record their preferences onto a smart card or other token.When a card, mobile phone, key fob token or similar portable object containing SNAPI data is put into public or share IT equipment, or moved into the field of the equipment?s sensor, it informs the terminal about the user?s preferred user interface....
  • SIM
    Subscriber Identity Module

    A Subscriber Identity Module on a removable SIM Card securely stores the International Mobile Subscriber Identity used to identify a subscriber on mobile telephony devices ....
  • Swipe card
  • Telephone card
    Telephone card

    A telephone card, calling card or phone card for short, is a small card, usually resembling a credit card, used to pay for telephone services....


External links