SlideShare uma empresa Scribd logo
1 de 24
INSTITUTE OF TECHNOLOGY AND
MANAGEMENT, MEERUT




                 SATYENDER KUMAR
                         0728531039
DEFINITION

   A Smart card is a portable devices that
    contains some non-volatile memory and a
    microprocessor.

   This card contains some kind of an
    encrypted key that is compared to a secret
    key contained on the user’s processor.
History of SMART CARD

 In 1968 German rocket scientist Helmut
  Grottrup and his colleague Jurgen
  Dethloff invented the automated chip
  card, receiving a patent only in 1982.
 The first mass use of the cards was as a
  Telecarte for payment in French pay
  phones, starting in 1983.
Types of SMART CARD

   Contactless smart cards ( e.g. Highway toll
    Tags )

 Contact smart card
(SIM Card, Driving license, Electronic purses
  like debit card etc. )
Contactless SMART CARD
 These smart cards do not require any physical
  contact between the card and the reader and
  becoming popular for payment and ticketing
  applications such as highway tolls.
 They communicates with the reader and gets
  powered through R-f induction technology (at data
  rate of 106-848 Kbits/sec.)
Most commonly used contactless smart cards are:
Montreal’s OPUS card, Hongkong’s OCTOPUS card,
Songhai's public transportation card.
Contact SMART CARD
 Contact smart cards have a contact area
  of about 1sq. Cm (.16 sq. inch)
  comprising of several gold plated
  contact pads.
 These pads provides electrical
  connectivity when inserted in to a reader
Plastic Cards
   Visual identity application
    Plain plastic card is enough
   Magnetic strip (e.g. credit cards)
    Visual data also available in machine
     readable form
    No security of data
   Electronic memory cards
    Machine readable data
SMART CARDS
 Processor cards (and therefore memory
  too)
 Credit card size
    With or without contacts
 Cards have an operating system too.
 The OS provides
    A standard way of interchanging information
    An interpretation of the commands and data.
   Cards must interface to a computer or
    terminal through a standard card reader.
What’s in a Card?


               CL   RST
               K          Vcc
      RFU

      GND


       RFU
                          Vpp
        I/O
Terminologies
 VCC : Power supply input
 RST : Reset signal, used to reset the
  card's communications.
 CLK : Provides the card with a clock
  signal , from which data communications
  timing is derived.
 GND : Ground(reference voltage).
 VPP : Programming voltage input -
  originally an input for a higher voltage to
  program persistent memory e.g.
  EEPROM.
 I/O : Serial input and output .
 RFU : Reserved for future use.
Typical Configurations
 256 bytes to 4KB RAM.
 8KB to 32KB ROM.
 1KB to 32KB EEPROM.
 8-bit to 16-bit CPU. 8051 based designs
  are common.
Smart Card Readers
                                  Computer based readers
                                   Connect through USB or
                                   COM (Serial) ports




   Dedicated terminals
    Usually with a small screen,
    keypad, printer, often also
    have biometric devices such
    as thumb print scanner.
Communication mechanisms
   Communication between smart card and reader
    is standardized
     ISO 7816 standard
   Commands are initiated by the terminal
     Interpreted by the card OS
     Card state is updated
     Response is given by the card.
Why SMART CARD
 Improve the convenience and security of
  any transaction.
 Provide tamper-proof storage of user
  account and identity.
 Provide vital components of system
  security.
 Protect against a full range of security
  threats
Security Mechanisms
   Password
    Card holder’s protection
   Cryptographic challenge Response
    Entity authentication
   Biometric information
    Person’s identification
Password Verification
   Terminal asks the user to provide a
    password.

   Password is sent to Card for verification.

   Scheme can be used to permit user
    authentication.
Cryptographic verification
   Terminal verify card
     Terminal sends a random number to card to be
      hashed or encrypted using a key.
     Card provides the hash or hypertext.
     Terminal can know that the card is authentic.
Biometric techniques
   Finger print identification.
    Features of finger prints can be kept on the
     card (even verified on the card)

   Photograph pattern .
    Such information is to be verified by a
     person. The information can be stored in the
     card securely.
Access & control of the files
   Applications may specify the access
    controls
    A password (PIN) on the MF selection
    (For example SIM password in mobiles)
    Multiple passwords can be used and levels
      of security access may be given
   Applications may also use cryptographic
    authentication
How does it all work?
Card is inserted in the terminal
                                   Card gets power. OS boots up.
                                   Sends ATR (Answer to reset)
ATR negotiations take place to
set up data transfer speeds,
capability negotiations etc.

Terminal sends first command to    Card responds with an error
select MF                          (because MF selection is only on
                                   password presentation)
Terminal prompts the user to
provide password
Terminal sends password for        Card verifies P2. Stores a status
verification                       “P2 Verified”. Responds “OK”
Terminal sends command to          Card responds “OK”
select MF again                    Card supplies personal data and
                                   responds “OK”
Terminal sends command to read
Applications
   Payphones
   Mobile Communications
   Banking & Retail
   Electronic Purse
   Health Care
   ID Verification and Access Control
   Transport purpose
Any Query ?
   THANK YOU

Mais conteúdo relacionado

Mais procurados (20)

Embedded system in Smart Cards
Embedded system in Smart CardsEmbedded system in Smart Cards
Embedded system in Smart Cards
 
Smart cards
Smart cards Smart cards
Smart cards
 
Smart card
Smart cardSmart card
Smart card
 
Abstract Smart Card Technology
Abstract  Smart Card TechnologyAbstract  Smart Card Technology
Abstract Smart Card Technology
 
Smart Card Presentation
Smart Card Presentation Smart Card Presentation
Smart Card Presentation
 
Smartcard
SmartcardSmartcard
Smartcard
 
Smart card technology
Smart card technologySmart card technology
Smart card technology
 
Smart cards
Smart cardsSmart cards
Smart cards
 
Smart Card
Smart CardSmart Card
Smart Card
 
SMART CARDS
SMART CARDSSMART CARDS
SMART CARDS
 
Smart Card
Smart CardSmart Card
Smart Card
 
Smart card
Smart cardSmart card
Smart card
 
Smart cards
Smart cardsSmart cards
Smart cards
 
Smart card
Smart cardSmart card
Smart card
 
SMART CARD
SMART CARDSMART CARD
SMART CARD
 
SMART CARD BASICS
SMART CARD BASICSSMART CARD BASICS
SMART CARD BASICS
 
Smart card
Smart cardSmart card
Smart card
 
Smart card system ppt
Smart card system ppt Smart card system ppt
Smart card system ppt
 
RFID security ppt
RFID security pptRFID security ppt
RFID security ppt
 
Smart shopping system using rfid
Smart shopping system using rfidSmart shopping system using rfid
Smart shopping system using rfid
 

Semelhante a smart card

Embedded systems presentation power point.ppt
Embedded systems presentation power point.pptEmbedded systems presentation power point.ppt
Embedded systems presentation power point.pptssuser1b4013
 
51775454-SMART-CARDS.ppt
51775454-SMART-CARDS.ppt51775454-SMART-CARDS.ppt
51775454-SMART-CARDS.pptAjaySahre
 
51775454-SMART-CARDS.ppt
51775454-SMART-CARDS.ppt51775454-SMART-CARDS.ppt
51775454-SMART-CARDS.pptKumar290483
 
smartcard-120830090352-phpapp02.pdf
smartcard-120830090352-phpapp02.pdfsmartcard-120830090352-phpapp02.pdf
smartcard-120830090352-phpapp02.pdfssuser5b47c8
 
dewanshuppt-130808103546-phpapp02.pdf
dewanshuppt-130808103546-phpapp02.pdfdewanshuppt-130808103546-phpapp02.pdf
dewanshuppt-130808103546-phpapp02.pdfssuser5b47c8
 
smartcard-121018150432-phpapp01.pdf
smartcard-121018150432-phpapp01.pdfsmartcard-121018150432-phpapp01.pdf
smartcard-121018150432-phpapp01.pdfssuser5b47c8
 
Access control basics-3
Access control basics-3Access control basics-3
Access control basics-3grantlerc
 
smartcard-090723101806-phpapp01.pdf
smartcard-090723101806-phpapp01.pdfsmartcard-090723101806-phpapp01.pdf
smartcard-090723101806-phpapp01.pdfssuser5b47c8
 
Architecture and Development of NFC Applications
Architecture and Development of NFC ApplicationsArchitecture and Development of NFC Applications
Architecture and Development of NFC ApplicationsThomas de Lazzari
 
Smartcards and Authentication Tokens
Smartcards and Authentication TokensSmartcards and Authentication Tokens
Smartcards and Authentication Tokenssaniacorreya
 
Smart card based electronic passport system
Smart card based electronic passport systemSmart card based electronic passport system
Smart card based electronic passport systemEdgefxkits & Solutions
 
Emerging Technologies in Payment Industry
Emerging Technologies in Payment IndustryEmerging Technologies in Payment Industry
Emerging Technologies in Payment IndustryErfan Moradian
 
Smart cards
Smart cardsSmart cards
Smart cardssnv09
 

Semelhante a smart card (20)

Smart Card
Smart CardSmart Card
Smart Card
 
Smart Card
Smart CardSmart Card
Smart Card
 
Smart Cards
Smart CardsSmart Cards
Smart Cards
 
Embedded systems presentation power point.ppt
Embedded systems presentation power point.pptEmbedded systems presentation power point.ppt
Embedded systems presentation power point.ppt
 
51775454-SMART-CARDS.ppt
51775454-SMART-CARDS.ppt51775454-SMART-CARDS.ppt
51775454-SMART-CARDS.ppt
 
51775454-SMART-CARDS.ppt
51775454-SMART-CARDS.ppt51775454-SMART-CARDS.ppt
51775454-SMART-CARDS.ppt
 
smartcard-120830090352-phpapp02.pdf
smartcard-120830090352-phpapp02.pdfsmartcard-120830090352-phpapp02.pdf
smartcard-120830090352-phpapp02.pdf
 
dewanshuppt-130808103546-phpapp02.pdf
dewanshuppt-130808103546-phpapp02.pdfdewanshuppt-130808103546-phpapp02.pdf
dewanshuppt-130808103546-phpapp02.pdf
 
smartcard-121018150432-phpapp01.pdf
smartcard-121018150432-phpapp01.pdfsmartcard-121018150432-phpapp01.pdf
smartcard-121018150432-phpapp01.pdf
 
Card reader
Card readerCard reader
Card reader
 
Smartcard lecture #5
Smartcard lecture #5Smartcard lecture #5
Smartcard lecture #5
 
Access control basics-3
Access control basics-3Access control basics-3
Access control basics-3
 
smartcard-090723101806-phpapp01.pdf
smartcard-090723101806-phpapp01.pdfsmartcard-090723101806-phpapp01.pdf
smartcard-090723101806-phpapp01.pdf
 
Architecture and Development of NFC Applications
Architecture and Development of NFC ApplicationsArchitecture and Development of NFC Applications
Architecture and Development of NFC Applications
 
Smartcards and Authentication Tokens
Smartcards and Authentication TokensSmartcards and Authentication Tokens
Smartcards and Authentication Tokens
 
Smart card based electronic passport system
Smart card based electronic passport systemSmart card based electronic passport system
Smart card based electronic passport system
 
M Commerce
M CommerceM Commerce
M Commerce
 
Smart card security
Smart card securitySmart card security
Smart card security
 
Emerging Technologies in Payment Industry
Emerging Technologies in Payment IndustryEmerging Technologies in Payment Industry
Emerging Technologies in Payment Industry
 
Smart cards
Smart cardsSmart cards
Smart cards
 

Último

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdfChristopherTHyatt
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 

Último (20)

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 

smart card

  • 1. INSTITUTE OF TECHNOLOGY AND MANAGEMENT, MEERUT SATYENDER KUMAR 0728531039
  • 2. DEFINITION  A Smart card is a portable devices that contains some non-volatile memory and a microprocessor.  This card contains some kind of an encrypted key that is compared to a secret key contained on the user’s processor.
  • 3. History of SMART CARD  In 1968 German rocket scientist Helmut Grottrup and his colleague Jurgen Dethloff invented the automated chip card, receiving a patent only in 1982.  The first mass use of the cards was as a Telecarte for payment in French pay phones, starting in 1983.
  • 4. Types of SMART CARD  Contactless smart cards ( e.g. Highway toll Tags )  Contact smart card (SIM Card, Driving license, Electronic purses like debit card etc. )
  • 5. Contactless SMART CARD  These smart cards do not require any physical contact between the card and the reader and becoming popular for payment and ticketing applications such as highway tolls.  They communicates with the reader and gets powered through R-f induction technology (at data rate of 106-848 Kbits/sec.) Most commonly used contactless smart cards are: Montreal’s OPUS card, Hongkong’s OCTOPUS card, Songhai's public transportation card.
  • 6. Contact SMART CARD  Contact smart cards have a contact area of about 1sq. Cm (.16 sq. inch) comprising of several gold plated contact pads.  These pads provides electrical connectivity when inserted in to a reader
  • 7. Plastic Cards  Visual identity application Plain plastic card is enough  Magnetic strip (e.g. credit cards) Visual data also available in machine readable form No security of data  Electronic memory cards Machine readable data
  • 8. SMART CARDS  Processor cards (and therefore memory too)  Credit card size With or without contacts  Cards have an operating system too.  The OS provides A standard way of interchanging information An interpretation of the commands and data.  Cards must interface to a computer or terminal through a standard card reader.
  • 9. What’s in a Card? CL RST K Vcc RFU GND RFU Vpp I/O
  • 10. Terminologies  VCC : Power supply input  RST : Reset signal, used to reset the card's communications.  CLK : Provides the card with a clock signal , from which data communications timing is derived.  GND : Ground(reference voltage).
  • 11.  VPP : Programming voltage input - originally an input for a higher voltage to program persistent memory e.g. EEPROM.  I/O : Serial input and output .  RFU : Reserved for future use.
  • 12. Typical Configurations  256 bytes to 4KB RAM.  8KB to 32KB ROM.  1KB to 32KB EEPROM.  8-bit to 16-bit CPU. 8051 based designs are common.
  • 13. Smart Card Readers  Computer based readers Connect through USB or COM (Serial) ports  Dedicated terminals Usually with a small screen, keypad, printer, often also have biometric devices such as thumb print scanner.
  • 14. Communication mechanisms  Communication between smart card and reader is standardized  ISO 7816 standard  Commands are initiated by the terminal  Interpreted by the card OS  Card state is updated  Response is given by the card.
  • 15. Why SMART CARD  Improve the convenience and security of any transaction.  Provide tamper-proof storage of user account and identity.  Provide vital components of system security.  Protect against a full range of security threats
  • 16. Security Mechanisms  Password Card holder’s protection  Cryptographic challenge Response Entity authentication  Biometric information Person’s identification
  • 17. Password Verification  Terminal asks the user to provide a password.  Password is sent to Card for verification.  Scheme can be used to permit user authentication.
  • 18. Cryptographic verification  Terminal verify card  Terminal sends a random number to card to be hashed or encrypted using a key.  Card provides the hash or hypertext.  Terminal can know that the card is authentic.
  • 19. Biometric techniques  Finger print identification. Features of finger prints can be kept on the card (even verified on the card)  Photograph pattern . Such information is to be verified by a person. The information can be stored in the card securely.
  • 20. Access & control of the files  Applications may specify the access controls A password (PIN) on the MF selection (For example SIM password in mobiles) Multiple passwords can be used and levels of security access may be given  Applications may also use cryptographic authentication
  • 21. How does it all work? Card is inserted in the terminal Card gets power. OS boots up. Sends ATR (Answer to reset) ATR negotiations take place to set up data transfer speeds, capability negotiations etc. Terminal sends first command to Card responds with an error select MF (because MF selection is only on password presentation) Terminal prompts the user to provide password Terminal sends password for Card verifies P2. Stores a status verification “P2 Verified”. Responds “OK” Terminal sends command to Card responds “OK” select MF again Card supplies personal data and responds “OK” Terminal sends command to read
  • 22. Applications  Payphones  Mobile Communications  Banking & Retail  Electronic Purse  Health Care  ID Verification and Access Control  Transport purpose
  • 24. THANK YOU