We need to be more realistic. We also need to recognize the standardizing power of muscle - the movement.

Most companies issuing cards certify one model (which they often rarely sell). The enhanced model (with extra memory, extra features, and extra firmware that makes it competitive in the proprietary market facing manufacturers today) is rarely certified. It has a shelf life of about 3 months, before a new model replaces it, which is similarly not certified.

having a CC evaluation cert for a "component" like an ICC is also misleading. a certified component in a "system" which is uncertified is essentially useless. I.E. a certified ICC in a reader with "competitive" features like support for memory cards by firmware download by escape codes is useless from an evaluation point of view: while being entirely practical and valid from a market (and ofen a developer/user, point of view. Obviously it needs a market that is not too fussy, is poorly educated, or is not suffering any real risk to the insecure but highly usable features. As smartcards are at an inflection point on their adoption curve, we have to be aware of how risk profiles are changing, however. A a movement, we get to predict and influence these issues.

The picture is not as bleak as I imply - never let it be said I dont resoect gemplus security engineering or its innovtations: most of the good engineering feature underlying the original cerification pass on to the next model, and its replacement. But, if you are inspecting certs, tehnically the device you HAVE is usually not certified. It just "could be certified" easily assuming the commidity market ever arrived (which it never will, in the dominant GemPlus economic model.)

NIST is good a making system standards, and its mixed technical/politica/procurement work with DoD/GSA on the common access card is bearing fruit: its about 50/50 (given the push for bio passports) that finally the Amercian scale and power in economics will force a commodity and open market for all - even tho these same forced failed in earlier crypto devices, for many & nefarious reasons. This is not good news for GemPlus, however, IMHO, which thirves on continually value-adding features, for each customer, in anything but a commodity market.

There comes a point in markets when proprietary-market companies collapse. VeriFone was the relevant example in the US, in 1996. 20 years of making proprietary card-reading terminals suddenly came to and end. The whole business of selling "features" to the particular bank which rented the merchant's card terminal just stopped being economic, for the banks. They learned to compete on different properties, other than constructing artificial tech barriers to entry (faciliated by VeriFone), to prevent merchants swapping acquirers whenever a new bank offered at better deal. (I once shared a lecture podium on secure payment protocols at Stanford with the founder of VeriFone, who was amazed that the proprietary strategy had lasted as long as it did! The profits just kept trickling in for years...and years.. way after the cost of market's development had been recouped.)

The issue of CC evaluation is thus linked to why users care about such evaluations, which can be explained in terms of market forces. Today, commercial CC evaluations of components are mystique-ware, tick-sheet items, and a sorry joke that do - however - bode well for the future commodity market based on open standards.

From: Damien Sauveron <[EMAIL PROTECTED]>
Reply-To: MUSCLE  <[EMAIL PROTECTED]>
To: MUSCLE <[EMAIL PROTECTED]>
Subject: Re: [Muscle] certified cards?
Date: Tue, 20 Apr 2004 15:54:51 +0200

Hi Pavel,

First what types of cards do you want?
- memory card
- smart card (card with microchip)
- cards supporting many applications : Java Card, Multos
- ...

For which usage do you want these cards?
- Authentication
- Development
- ...
Perhaps there already exists a solution/product that meet your requirements.


Then in Europe most of the cards are certified using Common Criteria (CC or ISO 15408) and
not ITSEC. CC are widely recognized in the world (more than ITSEC) [2].


You can look the list [1] of the products certified by the DCSSI (the french certification body).
You can also look the products certified by the other certification body in Europe (BSI, ...). You
can get the list of them at the end of [1].


There are differents manufacturers that have certified card such as Axalto, Oberthur, ...

If you decide to buy Gemplus products in small quantities, I recommend you do not buy them to
their french retailer (the NIS company) because often they sell you the cards without
documentation and keys to use them... even if you contact them after! (I have experimented
this few times and I have still 10 cards on my desk that I can not use).


Your cards will be supported by linux at least at ISO7816-4 level (APDU level) using PC/SC
Lite [3]. (except if you choose memory card)
Then depending of the card you will choose and what you want to do with it there may be
supported at application level using the Muscle framework [4] or OpenSC [5] or other
framework.


[1] http://www.ssi.gouv.fr/en/confidence/certificats.html
[2] http://www.ssi.gouv.fr/en/confidence/mra.html
[3] http://alioth.debian.org/projects/pcsclite/
[4] http://www.linuxnet.com/
[5] http://www.opensc.org/

Regards,
--
Damien Sauveron

-------------------------------------------------
This mail sent through IMP: http://horde.org/imp/
_______________________________________________
Muscle mailing list
[EMAIL PROTECTED]
http://lists.drizzle.com/mailman/listinfo/muscle

_________________________________________________________________
Lose those love handles! MSN Fitness shows you two moves to slim your waist. http://fitness.msn.com/articles/feeds/article.aspx?dept=exercise&article=et_pv_030104_lovehandles


_______________________________________________
Muscle mailing list
[EMAIL PROTECTED]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to