USB is indeed not the only way to go. Its only really appealing in the dongle form factor, and perhaps paper-mounted cards in passports (where the card use egate-style bonding and packaging)

For non-USB centered solutions, there are mini-PCI cards now available, with the smartcard chip mounted in the SIM socket. On i586 machines with finger-reader capable bios, the PCI card cooperates with the BIOS authentication module, which acts as the "PCI-reader's" trusted keypad, completing the card holder verification SEF by checking with the BIOS. The secure BIOS has a trusted store, controlled by a TCPA master IC, that maintains state concerning whether the user succesfully completed the secure/personal boot.

I think this mini-PCI approach is better than the older, but very similar, technique of using PCMCIA integration points. Clearly the SIM is not mobile, but is "movable" - in the same sense your phone SIM is movable (billing subsidy practices, notwithstanding). For now, these schemes are not entirely open: as the BIOS have to share inter-IC authentication and mac keys with the ICs they trust, on the common bus. However, now developers can download BIOS applets to modern machines, under Intel's mandate, BIOSs can be uppgraded with facilities like this (and key loggers too!)

It would be a useful exercise to find out how to make this boot time bio-based CHV work for PCI cards during Apple hardware's boot of BSD. Similarly for Solaris, on SUN's own hardware.

From: <[EMAIL PROTECTED]>
Reply-To: MUSCLE  <[EMAIL PROTECTED]>
To: "'MUSCLE'" <[EMAIL PROTECTED]>
Subject: RE: [Muscle] readers that work on macosx.
Date: Tue, 13 Apr 2004 09:35:02 +0200

The 4040 reader from http://www.omnikey.com have a downloadable driver from
19/3 2004 and according to this site the 243 should work
http://www.scmmicro.com/security/SCR243.html but I cant find any
downloadable driver on there site.

/G�ran

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Kory T
Sent: den 3 april 2004 04:30
To: MUSCLE
Subject: Re: [Muscle] readers that work on macosx.

Since you guys are discussing OS X supported readers, I thought I'd ask this
question


I've been researching the possibility of using smartcards for either login,
SSH, or GPG (g10code.com) authentication.  I've noticed there are a few
"USB" smartcard readers that work under OS X.  Since this will be
implemented on both desktops and laptops, I was wondering if there is any
work being done to have a PCMCIA reader work under OS X?
It would look feel better to just slide the card into the side of the
powerbook instead of a usb reader laying around on the desk.

Kory

_______________________________________________
Muscle mailing list
[EMAIL PROTECTED]
http://lists.drizzle.com/mailman/listinfo/muscle



_______________________________________________
Muscle mailing list
[EMAIL PROTECTED]
http://lists.drizzle.com/mailman/listinfo/muscle

_________________________________________________________________
Tax headache? MSN Money provides relief with tax tips, tools, IRS forms and more! http://moneycentral.msn.com/tax/workshop/welcome.asp


_______________________________________________
Muscle mailing list
[EMAIL PROTECTED]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to