06.11.2014 Views

A User Centric Security Model for Tamper-Resistant Devices

A User Centric Security Model for Tamper-Resistant Devices

A User Centric Security Model for Tamper-Resistant Devices

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4.6 Device Ownership<br />

4.6.2 <strong>User</strong> Ownership<br />

<strong>User</strong> ownership is associated with individual users that acquire a smart card either from<br />

a supplier or an administrative authority. This ownership gives the privilege to a user<br />

to install, delete, and use applications installed in her application space. There are two<br />

scenarios in user ownership: 1) the UCTD is subscribed with an administrative authority<br />

(discussed in the previous section), and 2) there is no administrative authority on the<br />

UCTD, as in UCOM initiative [32].<br />

In the rst case, the user has to abide by the terms and conditions of the administrative<br />

authority. However, in the second case, there is no administrative authority and the user<br />

has complete freedom on the UCTD. There<strong>for</strong>e, in the second case we can say that the<br />

user is the administrator and user at the same time.<br />

4.6.3 Ownership Acquisition & Delegation<br />

A UCTD in its pre-issuance state is under the default ownership of the UCTD manufacturer.<br />

When an entity, whether an administrative authority or a user takes control of the<br />

smart card, it will initiate an ownership acquisition process. The rst step of the acquisition<br />

is to select whether the UCTD will be under administrative control or not. If it will<br />

be, then the administrative authority takes the administrative ownership and then issues<br />

the smart cards to individual users. Whether the UCTD is under administrative control or<br />

not, the user will then acquire the ownership privileges. The ownership acquisition process<br />

is same whether it is initiated by an administrator or a normal user; there<strong>for</strong>e, we will use<br />

the term user to indicate administrator and normal user during this section. The process<br />

is described below:<br />

1. The user initiates the ownership acquisition process through the Card Application<br />

Management Software (CAMS). At this stage, the user will indicate the type of ownership<br />

(e.g. administrative or user) and CAMS will select the appropriate manager of<br />

the UCTD. For administrative ownership, it will select subscription manager (section<br />

4.2.5) and <strong>for</strong> user ownership, it will select cardholder's security manager (section<br />

4.2.4). In case, the UCTD will only have one owner then the smart card will disable<br />

the administrative ownership, Unless explicitly instructed not to do so by the<br />

cardholder.<br />

2. The UCTD requests the default ownership credentials, which are communicated to<br />

the user by the card manufacturer. In response the user will provide the relevant<br />

default credentials.<br />

99

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!