06.11.2014 Views

A User Centric Security Model for Tamper-Resistant Devices

A User Centric Security Model for Tamper-Resistant Devices

A User Centric Security Model for Tamper-Resistant Devices

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4.2 Plat<strong>for</strong>m Architecture<br />

4.2.4 Cardholder's <strong>Security</strong> Manager<br />

The cardholder's security manager maintains services that facilitate an eective and secure<br />

management of the smart card contents by its user (cardholder).<br />

At the time a UCTD is delivered to a user, it might be a blank card, which is under<br />

the default ownership of the smart card manufacturer. The cardholder's security manager<br />

facilitates a cardholder to acquire the control of the smart card (section 4.6), which will<br />

enable her to install or delete any application she desires.<br />

Furthermore, when a user requests any privilege services (e.g. application installation,<br />

application deletion, a list of installed applications), she has to authenticate herself to<br />

the cardholder's security manager. On successful authentication, the cardholder's security<br />

manager will proceed with the requested service.<br />

When a user takes the ownership of a smart card, the card contents (e.g. cryptographic keys<br />

and certicates) are specic to the user. There<strong>for</strong>e, when the ownership changes hands,<br />

the cardholder's security manager requests the card security manager (section 4.2.2) to<br />

initiate the clean-up command that deletes all applications and data, returning the smart<br />

card to the default ownership (card manufacturer's ownership). This process is referred to<br />

as decommissioning and is discussed in chapter 9.<br />

The cardholder's security manager provides functionality to satisfy requirements CR1,<br />

CR2, SCR1, and SCR7.<br />

4.2.5 Subscription Manager<br />

The subscription manager handles the registration of a smart card with an administrative<br />

authority. The authority can be a corporate and home-network administrator and/or a<br />

centralised scheme manager like a card issuer or TSM. These entities might be registered<br />

be<strong>for</strong>e the card was issued or the user might choose to register her smart card to a particular<br />

authority to get better services.<br />

The subscription manager facilitates the registered administrative authority to manage<br />

their application space on the UCTD. In addition, if a user is allowed to evict the administrative<br />

authority then the subscription manager will proceed with the removal process.<br />

This process will include deleting the associated space and all applications (domains) in<br />

the respective space, along with revoking any privileges delegated to the administrative<br />

authority on the UCTD. In carrying out this process, the subscription manager is similar<br />

84

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!