Smart Cards: The Open Platform Protection Profile (OP3)

نویسندگان

  • Marc Kekicheff
  • Forough Kashef
  • David Brewer
چکیده

Global Platform’s “Open Platform Specification” sets a new cross-industry standard for smart cards, governing the loading, installation and removal of applications at any time that the card is on-line during the card lifecycle prior to card termination. The Open Platform Protection Profile (OP3) recasts the Open Platform (OP) security requirements into the language of the Common Criteria (CC) to facilitate the formal evaluation of OP smart cards. In doing so, OP3 stretches the CC to new limits. There are four areas of innovation: The use of “packages” to deal with the optional components within the OP Card Specification. The use of the CC to evaluate Java Card TM byte code verification algorithms. The integration of the Target of Evaluation (TOE) with the “Card/Chip Operating Environment (COE)” on which the OP software sits. The definition of an Application Programming Interface (API), so that applications may use a variety of OP security services without the need to re-evaluate OP each time an application is evaluated. The paper also discusses other practical aspects of the application of the CC to the OP Program. It is the authors’ intention that this paper will help people to apply the CC, particularly those who face similar challenges, and to create awareness of the security needs of smart card technology.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The Open Platform Protection Profile (op3) Taking the Common Criteria to the Outer Limits

The Open Platform Specification sets a new standard for smart cards, governing the loading, installation and deletion of applications at any time that the card is on-line during the card lifecycle prior to card termination. The Open Platform Protection Profile (OP3) recasts the Open Platform (OP) security requirements into the language of the Common Criteria (CC) to facilitate the formal evalua...

متن کامل

Mutual Authentication Scheme with Smart Cards and Password under Trusted Computing

Only identities of the server and the user are authenticated in traditional smart cards based password authentication schemes, but the platform does not be verified, and which cannot provide enough protection on personal information of the user. A mutual authentication scheme based on smart cards and password is proposed under trusted computing, in which hash functions are used to authenticate ...

متن کامل

User Authentication with Smart Cards in Trusted Computing Architecture

The introduction of smart cards into trusted architectures establishes a clear-cut separation between the roles and responsibilities of both platform and user. On one hand, the Trusted Platform Module (TPM) ensures the platform trustworthiness and secures platform credentials and secrets, while smart cards guarantee user identity and protect user credentials and access authorization. Starting f...

متن کامل

Javacard-enabled Smart Cards for Collaborative Engineering Environments

Confidentiality and security in data access and transmission over multiple open networks are of utmost importance for most collaborative engineering environments. In this article, we review smart card based security technologies for their application in computer-based collaborative engineering environments. We focus on most recent microprocessor-based smart cards and on JavaCard as a developmen...

متن کامل

Java Card or How to Cope with the New Security Issues Raised by Open Cards?

In this paper, we aim to discuss various threats raised by Java Cards at various levels of the system. First, we address the Java Card platform security itself, from the chip security features to the Java Card virtual machine. Next, we expose how to deal with application security which is a standard problem for smart card manufacturers but a quite new one for third party Java developers beginni...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2001