06.11.2014 Views

A User Centric Security Model for Tamper-Resistant Devices

A User Centric Security Model for Tamper-Resistant Devices

A User Centric Security Model for Tamper-Resistant Devices

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3.4 <strong>User</strong> <strong>Centric</strong> Smart Card Ownership <strong>Model</strong> (UCOM)<br />

ZC6.5). Like WfSC, they also support the FAT le system, but unlike any other smart<br />

card framework, they support oating-point numbers natively [6]. Although these are less<br />

expensive than other options available to customers, they have not seen an exponential<br />

growth such as Java Card.<br />

3.4 <strong>User</strong> <strong>Centric</strong> Smart Card Ownership <strong>Model</strong> (UCOM)<br />

The UCOM provides to dierent entities the architectural, operational, and security framework<br />

needed to support the delegation of smart card ownership to its users. In this section,<br />

a detailed description of the UCOM is provided, dening the basic working principles of<br />

the UCOM along with a description of the UCOM components. Figure 3.5 illustrates the<br />

basic architecture of the model.<br />

<strong>User</strong> <strong>Centric</strong><br />

Smart Card<br />

(UCSC)<br />

Supplier<br />

1. Smart Card Ordered<br />

2. Smart Card Delivered<br />

5. Service Request<br />

Cardholder<br />

8. Service Response<br />

3. Application Lease Request<br />

4. Application Leased<br />

7. Response<br />

6. Request<br />

Smart Card<br />

Based Service<br />

Provider<br />

Service Access Point<br />

Figure 3.5: Overview of the <strong>User</strong> <strong>Centric</strong> Smart Card Ownership <strong>Model</strong> (UCOM)<br />

In the UCOM, a card issuer is denoted as a Service Provider (SP). An SP and a card<br />

issuer represent the same entity in dierent contexts of UCOM and ICOM, respectively.<br />

The main dierence between an issuer and an SP is that a card issuer provides a smart<br />

card's hardware and application(s) to their customers, whereas an SP only oers smart<br />

card application(s) that can be downloaded to a customer's smart card on request.<br />

The aim of the UCOM is not to replace users with card issuers as the open card initiative<br />

(see section 2.4.2.1) does. The UCOM ensures that the same level of security and<br />

application control is provided to an SP as in the ICOM, while provisioning the freedom<br />

of choice to individual cardholders. Going back to the list of privileges <strong>for</strong> ICOM (section<br />

3.2), the UCOM transfers the privileges (rights) one, two and four to the smart card users.<br />

65

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!