This article to LEGIC CPU card application programmes — "card card", for example, on the CPU card application encryption algorithm, a comprehensive introduction, pointed out that the encryption method based on universal CPU system security also poses a security risk.
Recommended CPU card application is selected through a security certification (GP, EAL +), preferably with AES encryption method of CPU card technology; the choice of the COS, the best use of a communication security certification of the system, as well as the best Java based COS, as JCOP, etc.End-to-end security
In the course of the entire card, LEGIC provides CPU card application programmes, not only from the front of the card for data confidentiality, to the end to read data from a reader sent in the process, have a very strict protection.
Figure 1 is the card to the data in the air transport, to gather data, the card reader to reader put data transmission a point-to-point data security.Figure 1
1, card data protection in the
The CPU card unique MTSC (primary token system) is a key management system.
Each token is a key gene. The key is to protect data from key genes plus the card's UID number, through the operation of the program, the card initialization process. So the card after initialization, it established a "one card" dense "and a fan of a dense" to protect the data within your sector. Using encryption methods, in addition to the General DES, 3DES, SHA-1, there are also new CPU card application uses AES encryption method. Due to a system-supplied read head and CPU card applications, and supports online update, there is a guarantee of security.System not only on the card to make protection of data, such as the application need, even open serial number (UID) can also be encrypted.
So you can guarantee the uniqueness of the UID, while enhancing security.System although the diversification of key concepts (DiversifyKey) to protect the data, but each chip card key operations program.
The "hackers", explains a chip-key operation method, does not mean that the other types of chips together, break, in fact, he has to start from scratch. In addition to the traditional logic of high security encryption technology, written on the CPU card data not only COS of key protection by, while also protecting their data, which not only more secure and will not conflict with other applications, which is also on the CPU card application.2. reader and card data transmission between
All of the reader and card at the beginning of the communication, flowing through a verification process to ensure that the card reader in front of the card is not a real CPU card, rather than "clone cards".
The advantage is that you can prevent an attempt to steal the air transport data.Card reader and card communication is absolutely not protect data key in the air transport, this is to ensure that key security.
All data transfer can choose their own encryption methods can choose to market generic DES, 3DES or AES (only on the achieved AFS4096) encryption methods.
The advantage is that even if the data was stolen in transit, or you cannot unpack the contents of the data itself.All data transmission can be combined with validation (CRCCheck), this also ensures that the data transmission of stability and reliability.
3, card reader security
CPU card reader is automatically eliminate token functionality, to match the card reader store upon illegal open, token will be automatically eliminated.
The PSAM card storage used relative key to security. Because the event sat card reader or POS terminal is stolen, along with the PSAM card will be stolen. The PSAM card technology and the DES algorithm is widely used, but it has been argued for security. First, DES as lucifer algorithm version, but the password from lucifer algorithm 128 bits in length, turned into a 56-bit. 56-bit cipher should be sufficient to protect against brute force attacks. Second, the internal structure is essential in DES of s-box design standard is confidential and cannot be sure it is secure. The password information stored on the chip itself, better security.CPU card reader accept related tokens authorization can only be related to the card reading and writing, with no password.
Authorize the card is in kind, can authorize and back, allowing to manage risk.4, the reader to the computer and communications security
Reader-to-computer communication, you can also use authentication and encryption for data protection.
Its realization and wireless interface is similar to the third certification no longer dwell. Above all the different security features are in the technology base to increase its own complexity, relative also increases resistance to cracking of the technology itself.Password management system
Password management generally include password generation, password, dispersion, password pass, the following password management is the management of the Ministry of construction's password.
Key card in a new key is generated mainly two kind of way: that is, directly in the key card in the new key; in other security devices to generate new key, and then load it into the key card.
Generate a new key data, can be a bit single, key in the form of seeds. Code key single is actually a form of seed, it will seed data into several parts, respectively controlled by different people, which can raise security of system.Different application keys are based on the encryption algorithm for distributed computing.
After the data from the seeds, to apply the master key, the distinction between keys, cards, multi-tiered distributed key progressive decentralized. The key purpose of decentralized even when aSub key compromise, nor the security threat management master key because the key is not available from the child and decentralized data derived from the master key, thereby improving system security, reduces security risks and management costs.[1] [2] [3]
No comments:
Post a Comment