Archives
 
 
 
  Special
 
 
 
  About Us
 
 
 

Newsletter
Free E-mail Newsletter from BYTE.com

 
    
           
Visit the home page Browse the four-year online archive Download platform-neutral CPU/FPU benchmarks Find information for advertisers, authors, vendors, subscribers

ArticlesSmartcard Invasion Continues


April 1998 / Reseller / Smartcard Invasion Continues

Security applications will be the spearhead for smartcards, with financial applications to follow.

Stephen Cobb

Think of smartcards as credit cards with brains. The same size as magnetic-stripe cards, their 8-bit processing power almost equals the first desktop computers (see the sidebar "Working Smart"). Analysts have tagged smartcards as one of the top 25 technologies of 1998. But how can this be if most Americans have never even seen one?

Deployment Maneuvers

To start, be aware that smartcards are widely used all over the world. They first appeared in 1974. The first smartcard trial took place in 1982, in France, and by 1993, French banks had issued 22 million of them. Today smartcards are common in Europe, with over 100 million pay-phone cards in France, 80 million health-insurance cards in Germany, and "electronic purse" cards in more than 20 countries (see the sidebar "Smartcards in Action").

Theories about why such applications have lagged in the U.S. probably outnumber successful American smartcard trials. It could be a case of leapfrog technology. By the time practical smartcards appeared, America's love affair with mag-stripe cards was already in full swing. In contrast, mag-stripe use in many European countries was not yet entrenched. Other explanations involve American attitudes toward public infrastructure, privacy concerns, and even religious opposition (from those who see smartcards as the "mark of the beast" -- at least one smartcard company executive has received death threats).

Secure Perime ter

But we still think that there's a smartcard in your future. Consider this: As a BYTE reader, you likely use computers that either contain, or access, valuable information -- and it's information-security applications that are leading the smartcard invasion. According to Chandra Shah , vice president of Litronic, a leading provider of smartcard-enabled security solutions, "Just as personnel ID badges have become commonplace in company and government offices throughout America, we expect smartcards to become practically universal for authenticating computer users." At the RSA Data Security Conference in January, Litronic was handing out photo ID/smartcards that double as both logical authentication and physical identification.

Security concerns are certainly nothing new, but these days they are magnified by the widespread use of a public and notoriously insecure data network: the Internet. Conditions are now ripe for smartcards to emerge as the answer to many concerns. Comme rcial public-key encryption is now widely available in toolkit and end-user formats from companies like RSA and Network Associates (which acquired PGP). Digital certificates, which enable commercially acceptable levels of assurance for secured transactions, are now available. The problem is: Digital keys residing on a computer are only as reliable as the access controls on that computer. Secure sessions authenticate the computer, not an individual.

The two most obvious solutions are: install strong access controls or remove the keys from the computer. Smartcards can do both. Public-key transactions at unsecured computers or open-access terminals can depend on inserting the certificate-bearing smartcard at the appropriate time. Cryptographic functions on the smartcard prevent any unauthorized access, or change, to data stored on it.

Alternatively, you can control access to a computer. If it requires inserting your smartcard and entering your PIN, there's a high probability that it's really you logging on. This is two-factor authentication ("something you have" plus "something you know"). Traditional username/password authentication is only single-factor ("something you know") authentication. If you require a biometric, such as a fingerprint scan to compare to a digital fingerprint on the smartcard, you add "something you are": three-factor authentication.

One strong indicator of smartcard growth in this area is that two leading suppliers of token-based authentication, Security Dynamics and DataKey, are now offering smartcards as alternatives to their proprietary tokens. The partnership between crypto-maker RSA and BIOS-maker Phoenix Technologies enhances the ability of smartcards to further lock down PC security. Through the jointly developed Preboot Crypto API, it will be possible to integrate smartcards into the PC's preboot, ROM-based routines.

Security Scenario

To see where smartcards fit into the information system security picture, look at the figure "Integration of Security Services" . The figure includes applications for which people might encounter smartcard readers, such as e-mail encryption, file encryption, remote access authentication, Web site authentication, network log-in, and software access. Card readers, the size of a cigarette pack, are less than $100 and attach to serial, parallel, and keyboard ports. Smaller readers fit in PC Card slots on laptops or, using Fischer International's Smarty, in floppy disk drives. HP and Keytronic offer keyboards with integrated smartcard readers.

Suppose you are logging on to the corporate network from your smartcard-enabled office workstation. Instead of the usual dialog box, you insert your smartcard and enter your personal identification number (PIN). Next, you check your e-mail. Someone in the Rome office has sent you an encrypted message. Again, your smartcard and PIN decrypt it. At home you need to access the network from your laptop. Guess what? The RSA password you don't even know is on your smartcard. Ins ert it into the PC Card smartcard reader, enter your PIN, and you can make that connection, too. You work on the spreadsheet you have to present to a client. You store the file on your laptop, encrypted by keys stored on the smartcard, just in case someone steals your machine.

All this activity can use off-the-shelf applications, like Netscape Communicator, or applications modified with existing cryptographic APIs and available tool-kits. The security management center (SMC, on the left of the figure "Integration of Security Services" ) manages the activity, and the security officer's smartcard controls the SMC. None of this is a projection; all the pieces are in place.

Compelling Forces

To a security professional like David Brussin of Miora Systems Consulting (Los Angeles), this is good news. "Password-based protection of computing resources just doesn't cut it any more. Moving to digital IDs and tokens is just common sense, particularly if one token can support multip le services."

Of course, it may be a while before all applications support digital certificates and public-key encryption. A contractor developing intranet applications for the military, speaking on condition of anonymity, admitted that, "Our client will rely on passwords for remote access for some time, so hiding hard-to-crack passwords on smartcards lets us increase the effective security level without completely reengineering current systems."

While the cost of deploying smartcards (now about $7 just for the card) continues to decline as technology matures, it is still a resistance factor. However, in situations where security breaches obviously equate to losses, like insurance fraud, the return on investment can be substantial. Litronic's Shah cites an HMO that cut fraud losses dramatically as soon as it deployed smartcards containing a scan of the holder's fingerprint.

On the Home Front

But what about the American mass market? As BYTE's January article on smartcards indicated (see "The Smartcard Invasion"), financial institutions cite lack of infrastructure and merchant acceptance as hurdles to wide deployment. But developers should not take a wait-and-see attitude to smartcards. Don't underestimate the interest in smartcards of major players like Visa and MasterCard, for whom fraud is a costly motivator.

On the technology end, big names like IBM, Hewlett-Packard, Sun, and Oracle all have heavy commitments to smartcards. Now is definitely the time to acquaint yourself with this technology, if you haven't already. Some American companies are already competing successfully for the huge market outside the United States.

For developers, start with a toolkit, from companies such as Gemplus, Aladdin, IBM, Schlumberger, and Litronic. This is a big change from the past, when developers, even major system integrators, had a hard time getting the cooperation they needed from card manufacturers.

That led to the Independent Smartcard Developer Association, a nonvendor organization th at emerged from the Cypherpunk group. Says coordinator Lucky Green (not his real name), "Many members are potential users of smartcard technology in their daytime jobs. But we found it challenging at best to get information from vendors." Not only are development toolkits highly vendor-specific, says Green, "one vendor in particular will not provide specifications for its cards unless you agree to use only their solutions."

Such attitudes are a red flag to cypherpunks like Green who test and advance security technology. The group has released a free software toolkit that will talk to any smartcard. Group members created a reader-independent abstraction layer and have pretty much finished a card-independent abstraction layer. The software, which is available at the group's Web site (go to http://www.cy pherpunks.to ), supports the more popular crypto-capable cards and, says Green, "makes it trivial to add support for additional cards."

Security is part of every smartcard application, whether it's a cyber-purse, a bus pass, or a network access control system. However, the smartcard invasion in the U.S. will be led by security-specific applications, from e-mail encryption on PCs to user authentication on network computers.


Where to Find


Aladdin Knowledge Systems

New York, NY
Phone:    800-223-4277
Phone:    212-564-5678
Internet: 
http://www.aks.com



DataKey

Burnsville, MN
Phone:    612-890-6850
Internet: 
http://www.datakey.com
 


Fischer International Systems

Naples, FL
Phone:    941-643-1500
Internet: 
http://www.fisc.com
 


Gemplus

Gémenos, France
Phone:    +33 442 3656 54
Internet: 
http://www.gemplus.com
 


Hewlett-Packard

Palo Alto, CA
Phone:    800-752-0900
Phone:    650-857-1501
Internet: 
http://www.hp.com



IBM

Armonk, NY
Phone:    800-426-3333
Phone:    914-765-1900
Internet: 
http://www.ibm.com
 


Keytronic Corp.

Spokane, WA
Phone:    800-262-6006
Phone:    509-928-8000
Internet: 
http://www.keytronic.com



Litronic

Costa Mesa, CA
Phone:    714-545-6649
Internet: 
http://www.litronic.com
 


Network Associates

San Mateo, CA
Phone:    650-572-0430
Internet: 
http://www.pgp.com
.


Phoenix Technologies

San Jose, CA
Phone:    408-570-1000
Internet: 
http://www.phoenix.com
 


RSA

Redwood City, CA
Phone:    650-595-8782
Internet: 
http://www.rsa.com
 


Security Dynamics

Bedford, MA
Phone:    781-687-7000
Internet: 
http://www.securid.com



3-G International

Springfield, VA 
Phone:    703-922-5090
Internet: 
http://www.3gi.com
 


Integration of Security Services

illustration_link (63 Kbytes)

Smartcard security must integrate hardware, software, and services. (Example based on Litronic's SMC model.)


Chandra Shah

photo_link (79 Kbytes)

"We expect smartcards to become practically universal for authenticating computer users." -- Chandra Shah, Vice President, Litronic


Stephen Cobb is the author of numerous computer books and is also a Certified Information Systems Security Professional. You can reach him at stephen@iu.net .

Up to the Reseller section contentsGo to next article: Working Smart
Flexible C++
Matthew Wilson
My approach to software engineering is far more pragmatic than it is theoretical--and no language better exemplifies this than C++.

more...

BYTE Digest

BYTE Digest editors every month analyze and evaluate the best articles from Information Week, EE Times, Dr. Dobb's Journal, Network Computing, Sys Admin, and dozens of other CMP publications—bringing you critical news and information about wireless communication, computer security, software development, embedded systems, and more!

Find out more

BYTE.com Store

BYTE CD-ROM
NOW, on one CD-ROM, you can instantly access more than 8 years of BYTE.
 
The Best of BYTE Volume 1: Programming Languages
The Best of BYTE
Volume 1: Programming Languages
In this issue of Best of BYTE, we bring together some of the leading programming language designers and implementors...

Copyright © 2005 CMP Media LLC, Privacy Policy, Your California Privacy rights, Terms of Service
Site comments: webmaster@byte.com
SDMG Web Sites: BYTE.com, C/C++ Users Journal, Dr. Dobb's Journal, MSDN Magazine, New Architect, SD Expo, SD Magazine, Sys Admin, The Perl Journal, UnixReview.com, Windows Developer Network