Archives
 
 
 
  Special
 
 
 
  About Us
 
 
 

Newsletter
Free E-mail Newsletter from BYTE.com

 
    
           
Visit the home page Browse the four-year online archive Download platform-neutral CPU/FPU benchmarks Find information for advertisers, authors, vendors, subscribers

ArticlesAre Smartcards a Certificate Solution?


June 1997 / Cover Story / Who Goes There? / Are Smartcards a Certificate Solution?

Personal computers have flourished because they are versatile and easy to program. Good for games, bad for security. The same facility that makes it easy to hack into the keyboard device drivers makes it easy to grab a password's keystrokes.

Hardware tokens (also known as smartcards or dongles) are one solution. These devices are built around a chip dedicated to creating digital signatures. A smartcard log-in session begins with the host sending a challenge string. The smartcard signs the challenge and returns it. The challenge string (and therefore the response) changes each time to prevent replay attacks.

Dallas Semiconductor recently released the iButton, a round metal tag with a diameter of about 16 mm. The company also manufactures a small interface that plugs into the parallel port of a computer and can be added for less than $20. A user can touch the button to this interface and the computer can pass messages back and forth to the button, which creates digital signatures on the fly. The buttons are quite useful for people who must log in to a central computer remotely because they remove the threat that a password sniffer will record the password.

Many smartcard manufacturers, like Dallas Semiconductor and Security Dynamics, are attempting to make a tamper-resistant package to protect the certificate. While the degree of necessary tamper-resistance is debated, developers and ha ckers play cat and mouse.

It may not be long before PCs standardize upon a smartcard interface. Oracle is already strongly recommending that a smartcard interface be available on any network computer (NC). Smartcards are an important part of letting people carry their information and identities with them if they switch between NCs. WebTV has the electronics built into its design.


How a Smartcard Works

illustration_link (25 Kbytes)


Up to the Cover Story section contentsGo to previous article: Are Smartcards a Certificate Solution?Go to next article: Extending Certificates
Flexible C++
Matthew Wilson
My approach to software engineering is far more pragmatic than it is theoretical--and no language better exemplifies this than C++.

more...

BYTE Digest

BYTE Digest editors every month analyze and evaluate the best articles from Information Week, EE Times, Dr. Dobb's Journal, Network Computing, Sys Admin, and dozens of other CMP publications—bringing you critical news and information about wireless communication, computer security, software development, embedded systems, and more!

Find out more

BYTE.com Store

BYTE CD-ROM
NOW, on one CD-ROM, you can instantly access more than 8 years of BYTE.
 
The Best of BYTE Volume 1: Programming Languages
The Best of BYTE
Volume 1: Programming Languages
In this issue of Best of BYTE, we bring together some of the leading programming language designers and implementors...

Copyright © 2005 CMP Media LLC, Privacy Policy, Your California Privacy rights, Terms of Service
Site comments: webmaster@byte.com
SDMG Web Sites: BYTE.com, C/C++ Users Journal, Dr. Dobb's Journal, MSDN Magazine, New Architect, SD Expo, SD Magazine, Sys Admin, The Perl Journal, UnixReview.com, Windows Developer Network