Hello,


Acer is selling laptops with a smartcard protection at the boot/BIOS
level [1].

What surprises me on this web page is:
  Q9. What should I do if I lose or damage my SmartCard? Will I still be
  able to access my system?

  When you first initialize the SmartCard in the TravelMate, the system
  will request you to insert a blank diskette and save necessary
  information into it. This diskette becomes the emergency recovery
  disk.  If you lose your SmartCard, you can use the emergency recovery
  disk to unlock the system and/or access the secured information,
  restoring your original setup. However, to re-enable SmartCard
  security, the system must be returned to an authorized Acer service
  centre. Generally, this procedure will entail a nominal service fee.

So the smartcard seams to be used to (at most) store a secret key (since
a diskette can do the same) but with a PIN protection.

I have an Acer laptop but not one with a smartcard proctection so I
can't tell much about it :-(

This sounds like it were a system from Compusec. They offer bootprotection and filesystem encrytption and use a repacked eToken Pro usb token. You can also store your authentication data on a diskette and on a backup token.



I don't know how easy (or hard) it would be to do it by software in a
first level boot. Maybe with a BIOS based on Linux?

I have tested the windows solution of Compusec and the relevant code is embedded in the bootsector. But it should also work with linux bios - but it would be more complicated to implement - I guess.


In a document about eToken it says that there exists a SDK for boot protection for these usb tokens:
http://www.urec.cnrs.fr/securite/CNRS/vCARS/DOCUMENTS/Bear.pdf
Has anyody on this list used this SDK already ?





Regards,


Arno Wilhelm







--
Mr Arno Wilhelm
phion Information Technologies GmbH
System Engineer
Eduard-Bodem-Gasse 1
A-6020 Innsbruck
www.phion.com
tel: +43 512 39 45 45
fax: +43 512 39 45 45 20

_______________________________________________
Muscle mailing list
[EMAIL PROTECTED]
http://lists.musclecard.com/mailman/listinfo/muscle

Reply via email to