Unlocking the Smart Card

Total Page:16

File Type:pdf, Size:1020Kb

Unlocking the Smart Card Episode Four: Unlocking the Smart Card This is an excerpt from Unlocked — an ASSA ABLOY podcast series on campus security. Unlocked explores the security issues and challenges that colleges and universities face as they strive to create a safe and secure learning environment. Visit intelligentopenings.com/unlocked to hear more. How We Got Smart Before diving into the current broken cards and physical wear on the credential technologies, it helps to readers. Prox solved these problems. understand where we came from. Lower maintenance costs, increased In 1960, a young engineer from IBM user convenience, and new options named Forrest Parry invented the for form factors like fobs made the magnetic stripe card. Once prox card a winner. But the low- ubiquitous on campus doors, more frequency proximity technology is reliable and secure technologies not without its limitations. are quickly eclipsing the mag stripe. Mag stripe cards are simple. A card gets swiped in a reader. That reader then reads a sequence of numbers Outside of higher stored on the stripe of that card. education and If the number matches what’s stored in the access system’s older hotels, hardly Whether installing a new door access database, the door unlocks. system for your campus or upgrading from a legacy system you have a lot of Many campuses still use the mag anyone still uses decisions to make. stripe card for their door access. This is mainly because the cards are mag stripe cards You first must choose the right access inexpensive, the cost to replace the software and locking hardware. You existing swipe readers is high, and for door access. also need to find a knowledgeable other systems aside from security and trustworthy integrator to install still rely on that technology—namely and service your system. And you campus one-card systems that use need to determine which card the card for dining, laundry, Like the mag stripe, the prox card is technology is right for your campus. vending and other purchases. unencrypted and static—making them easy to clone or forge. You also And this last task is not always as Yet, outside of higher education and can’t encode additional information easy as it might seem. older hotels, hardly anyone still uses onto the prox cards, like multiple IDs. mag stripe cards for door access. A common misunderstanding for In the 90’s the access control Out of these security limitations and campus IT professionals that deal industry made a wholesale shift frustrations came the contactless with physical access security is from mag stripe to the new, “smart card” as we know it today. differentiating between the access contactless technology called The biggest technology difference cards. How do you know which prox—known more officially as between smart cards and prox cards is technology is the right one for you? “low-frequency proximity”. the frequency of the chip inside. Prox cards use a low-frequency 125kHz A lot of technology is packed into When the prox card came on the technology, whereas the new breed of the cards. And there are a lot of scene, everyone was thrilled. smart cards use a high-frequency marketing materials surrounding 13.56 MHz technology. which cards are best for you. It can The mag stripe card was cumbersome be difficult to figure out exactly what and inefficient. Not to mention your campus needs. administrators felt the financial sting and maintenance headaches from And what you don’t. Smart Card vs. Prox Smart “One Cards” Although a massive install base of prox The difference in frequencies between A source of confusion unique to technology exists, the last five years the prox card and the smart card can higher ed when it comes to smart have a seen a transition to smart card also affect performance. But not in the cards, is the term itself “smart card”. technologies. According to Eric Widlitz, way you might think. While smart card is used universally vice president of sales at Vanderbilt in other verticals of the physical Industries, he sees no reason not to Schools that purchase the smart, security industry, in higher ed we make the transition. or contactless, card for the sake of tend to refer to them as convenience for their students can be contactless cards. “You certainly have a gigantic install surprised to find out the read range is base of prox technology that you’ll limited on the smart card. Why? Well here’s a little history continue to support for a long time lesson. A bunch of years ago smart moving forward,” says Widlitz. “But This is because the difference in cards became popular on a handful smart card technologies today from a frequencies on the card can have of large universities for student cost perspective are pretty much the an impact and effect on the card’s purchases like vending and laundry, same price. And in some cases, may read range. You typically get a slight and for meal plans. What we now even cost less money than a reduction in read range with smart call One Card systems. These smart proximity card.” cards. And the read time and the cards were of the contact chip communication time between card variety. The eventual problem with It’s well known that smart cards are a and reader is a little bit longer. them was the money was stored more secure credential than prox. But “offline” on purses on the card. As another advantage that smart cards “You definitely take a little hit on the networked, “online” systems gained have over prox is the ability to store and convenience side on the speed and in popularity these smart card secure other useful information on the read range that you have. But you have systems became irrelevant. card itself. the insurance that your information Just about all those smart card is secure on that card and that people systems have been ripped out and can’t take that information off your replaced on the campuses who card,“ says Widlitz. used them. “From a cost This is something to keep in mind And because of that experience, perspective, today’s when your campus starts discussing the term “smart card” when talking the benefits of smart cards. Fortunately, to campus folks who also deal smart card as people get accustomed to longer with the one card, payment side read times of EMV credit cards they are of the credential has left a bad technologies are less prone to notice the slight increase taste in their mouth. That is why of speed on the contactless cards most vendors dealing with the pretty much the over the prox. payment side refer to the newer technology cards almost exclusively same price as a To recap, here are three reasons to as contactless. choose a contactless smart card over proximity card. In a prox card. Or why you might So you see how confusion can arise consider upgrading from an existing when a one card vendor calls them some cases, they may prox card installation: contactless, and a security vendor calls the same card a smart card. even cost less.” 1. Contactless smart cards are safer. They can’t be copied, Most people in the security industry or “skimmed” in the way prox will use the term smart card to Widlitz explains: “A prox card is kind of cards can. encompass pretty much all types of like a license plate. It will transmit one 2. They can cost the same—or in contactless cards that aren’t prox. ID number to the system and that is all some cases—cost less than prox. it is capable to do. And it’s not secure. 3. They can store additional data On a smart chip, you have multiple and be used for other applications, containers that you can store different like transit systems. applications in. Each one of those containers is secured. Think about it “There is absolutely no good reason like a filing cabinet, and you have a key today—starting with a new, fresh to each one of the drawers on the filing install—why you would ever put in cabinet. There’s an encryption key that proximity technology or put in mag secures the information on the card for stripe technology,” says Widlitz. each one of those applications. It can be used for multiple applications where “You should always think about you can’t use any of the previous types moving forward with some sort of of technologies for that.” smart card technology.” “ If you are considering purchasing a smart card and only plan to use the serial number, it’s no different than using a prox card.” Trust in a Handshake For colleges and universities, one of the And if they authenticate each other, something goes wrong at that initial biggest benefits of smart cards is that then the smart card will start releasing communication, then the card and they are more secure than the prox the information that’s being asked for.” reader will stop communicating and the card. This is because of something door will remain locked. called mutual authentication. So, the card reader performs a couple tests that the smart card Without delving into the details of According to Widlitz, mutual needs to go through to make sure it’s the cryptographic authentication, authentication works like this: “In the communicating with the right type it’s important to know that this secure simplest of terms, a reader will boot up of card. And if they have that correct technology is available today and at a chip, start a chip, they’ll start talking handshake together then the process a comparable cost to older, less to each other.
Recommended publications
  • SMART CARD GET SMART, GET CARDAX Cardax Smart Card Solutions
    © Copyright Cardax (International) Limited 1999 All rights reserved SMART CARD GET SMART, GET CARDAX Cardax Smart Card Solutions SMART CARD GET SMART, GET CARDAX Presentation Outline • Business Requirements • What is Smart Card technology? • Features and Benefits of Smart Cards • Contactless Smart Cards • MIFARE? Technology SMART CARD GET SMART, GET CARDAX Presentation Outline • Meeting Business Requirements • Cardax Smart Card Solutions • References • Recommendation SMART CARD GET SMART, GET CARDAX Business Requirements • Electronic funds transfer at point of sale (EFTPOS) through the banking system • Network accessibility to an intranet environment where all building facilities, from access control to recreational facilities to fax machines, internet, vending machines etc are interconnected SMART CARD GET SMART, GET CARDAX Business Requirements The system needs to provide: • a process to authenticate users • a secure login process • a record of utilisation time SMART CARD GET SMART, GET CARDAX What is Smart Card Technology? Smart card technology allows multiple applications to co-exist on a single IC (integrated circuit) card. SMART CARD GET SMART, GET CARDAX Features and Benefits of Smart Card Technology • The ability to use a single card for multiple applications has many benefits – Cardholders only need to carry one card – There are lower card costs because one card supports many applications – By using the default industry standard more applications can be more readily added SMART CARD GET SMART, GET CARDAX Features and Benefits
    [Show full text]
  • Trends in Smartcard Fraud•
    Trends in Smartcard fraud• Susan Burns, George R. S. Weir Department of Computer and Information Sciences, University of Strathclyde, Glasgow G1 1XH, UK {susan.burns, george.weir}@cis.strath.ac.uk Abstract. The introduction of smartcard technologies has reduced the incidence of card fraud in the UK, but there are still significant losses from fraudulent card use. In this paper we detail the context of smartcard introduction and de- scribe the types of fraud that remain a threat to cardholders and other stake- holders in the card system. We conclude with a risk analysis from the card- holder’s perspective and recommend greater cardholder awareness of such risks. Key words. Smartcards, fraud, consumer security, risk assessment. 1. Introduction A recent report from the European Security Transport Association (ESTA) found that nearly 20% of the adult population in Great Britain has been targeted as part of a credit or debit card scam. As a result, the UK has been termed the ‘Card Fraud Capital of Europe’ [1], with UK citizens twice as likely to become victims of card fraud as other Europeans. Plastic card fraud is a lucrative exploit for criminals and the pro- ceeds may be used to fund organised crime. Smart payment cards (Chip and PIN cards) were introduced in the UK to replace magnetic stripe cards and support PIN verification of card transactions. By the end of 2005, more than 107 million of the 141.6 million cards in the UK had been upgraded to smart cards [2]. Levels of plastic card fraud fell by 13% to £439.4 million in 2005 [3] and again to £428 million in 2006 (Figure 1).
    [Show full text]
  • Contactless Operating Mode Requirements Clarification Whitepaper
    Contactless Operating Mode Requirements Clarification Whitepaper Version 1.0 Publication Date: February 2020 U.S. Payments Forum ©2020 Page 1 About the U.S. Payments Forum The U.S. Payments Forum, formerly the EMV Migration Forum, is a cross-industry body focused on supporting the introduction and implementation of EMV chip and other new and emerging technologies that protect the security of, and enhance opportunities for payment transactions within the United States. The Forum is the only non-profit organization whose membership includes the entire payments ecosystem, ensuring that all stakeholders have the opportunity to coordinate, cooperate on, and have a voice in the future of the U.S. payments industry. Additional information can be found at http://www.uspaymentsforum.org. EMV ® is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC. Copyright ©2020 U.S. Payments Forum and Smart Card Alliance. All rights reserved. The U.S. Payments Forum has used best efforts to ensure, but cannot guarantee, that the information described in this document is accurate as of the publication date. The U.S. Payments Forum disclaims all warranties as to the accuracy, completeness or adequacy of information in this document. Comments or recommendations for edits or additions to this document should be submitted to: [email protected]. U.S. Payments Forum ©2020 Page 2 Table of Contents 1. Introduction .......................................................................................................................................... 4 2. Contactless Operating Modes ............................................................................................................... 5 2.1 Impact of Contactless Operating Mode on Debit Routing Options .............................................. 6 3. Contactless Issuance Requirements ..................................................................................................... 7 4.
    [Show full text]
  • Introduction: History
    Introduction: "Key to the global village", that is how the Smart Card has been described. Smart Cards will bring big changes to the way people provide and receive information and the way they spend money. They will have a profound impact on retailing and service delivery. A Smart Card is like an "electronic wallet". It is a standard credit card-sized plastic intelligent token within which a microchip has been embedded within its body and which makes it 'smart'. It provides not only memory capacity, but computational capability as well and thus the chip is capable of processing data. It has gold contacts that allow other devices to communicate with it. This chip holds a variety of information, from stored (monetary) value used for retail and vending machines to secure information and applications for higher-end operations such as medical/healthcare records. New information and applications can be added depending on the chip capabilities. Smart Cards can store several hundred times more data than a conventional card with a magnetic stripe and can be programmed to reveal only the relevant information. For example, it could tell a device in a store that there is sufficient balance in an account to pay for a transaction without revealing the balance amount. The marriage between a convenient plastic card and a microprocessor allows information to be stored, accessed and processed either online or offline. Therefore, unlike the read-only plastic card, the processing power of Smart Cards gives them the versatility needed to make payments, to configure your cell phones, TVs and video players and to connect to your computers via telephone, satellite or the Internet anytime, anywhere in the world.
    [Show full text]
  • Smart Cards Contents
    Smart cards Contents 1 Smart card 1 1.1 History ................................................ 1 1.1.1 Invention ........................................... 1 1.1.2 Carte Bleue .......................................... 2 1.1.3 EMV ............................................. 2 1.1.4 Development of contactless systems ............................. 2 1.2 Design ................................................ 2 1.2.1 Contact smart cards ..................................... 3 1.2.2 Contactless smart cards .................................... 3 1.2.3 Hybrids ............................................ 4 1.3 Applications .............................................. 4 1.3.1 Financial ........................................... 4 1.3.2 SIM .............................................. 4 1.3.3 Identification ......................................... 4 1.3.4 Public transit ......................................... 5 1.3.5 Computer security ...................................... 6 1.3.6 Schools ............................................ 6 1.3.7 Healthcare .......................................... 6 1.3.8 Other uses .......................................... 6 1.3.9 Multiple-use systems ..................................... 6 1.4 Security ................................................ 6 1.5 Benefits ................................................ 6 1.6 Problems ............................................... 7 1.7 See also ................................................ 7 1.8 Further reading ...........................................
    [Show full text]
  • EMF Implementing EMV at The
    Implementing EMV®at the ATM: Requirements and Recommendations for the U.S. ATM Community Version 2.0 Date: June 2015 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community About the EMV Migration Forum The EMV Migration Forum is a cross-industry body focused on supporting the EMV implementation steps required for global and regional payment networks, issuers, processors, merchants, and consumers to help ensure a successful introduction of more secure EMV chip technology in the United States. The focus of the Forum is to address topics that require some level of industry cooperation and/or coordination to migrate successfully to EMV technology in the United States. For more information on the EMV Migration Forum, please visit http://www.emv- connection.com/emv-migration-forum/. EMV is a trademark owned by EMVCo LLC. Copyright ©2015 EMV Migration Forum and Smart Card Alliance. All rights reserved. The EMV Migration Forum has used best efforts to ensure, but cannot guarantee, that the information described in this document is accurate as of the publication date. The EMV Migration Forum disclaims all warranties as to the accuracy, completeness or adequacy of information in this document. Comments or recommendations for edits or additions to this document should be submitted to: ATM- [email protected]. __________________________________________________________________________________ Page 2 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community TABLE OF CONTENTS
    [Show full text]
  • RFP for Selection of Financial Institution for Open Loop Smart Card Common City Payments System
    RFP for Selection of Financial Institution for Open Loop Smart Card Common City Payments System Selection of Financial Institution for Providing Smart Card Based Eco System for Unified City Payments Including Mobility, Recreational and Amusement Areas of SMC, Municipal Bills, Utility Payments, Retail and Other Payments within Surat City PART 1 – INSTRUCTIONS TO BIDDERS SECTION AND DRAFT LICENSE AGREEMENT Invited by Surat Smart City Development Limited 115, Smart City Cell, Surat Municipal Corporation, Muglisara, Main Road, Surat – 395003, Gujarat RFP No.: SSCDL-CityPaymentCard-RFP-01-2016 Last date (deadline) for online Price Bid Submission: 15.12.2016 Last date (deadline) for Technical Bid Submission: 19.12.2016 DISCLAIMER This RFP is being issued by the Surat Smart City Development Limited (hereunder called “Authority”/“SSCDL”) for inviting tenders to shortlist Financial Institutions for providing smart card based eco system for unified city payments including mobility, recreational and amusement areas of SMC, municipal bills, utility payments, retail and other payments within Surat City. It is hereby clarified that this RFP is not an agreement and is not an offer or invitation by Authority to any party hereunder. The purpose of this RFP is to provide the Bidder(s) with information to assist in the formulation of their proposal submission. This RFP document does not purport to contain all the information Bidders may require. This RFP document may not be appropriate for all persons, and it is not possible for Authority to consider particular needs of each Bidder. Each Bidder should conduct its own investigation and analysis, and should check the accuracy, reliability and completeness of information in this RFP document and obtain independent advice from appropriate sources.
    [Show full text]
  • 1 Terms and Conditions of the Uob Smart$ Rebate
    TERMS AND CONDITIONS OF THE UOB SMART$ REBATE PROGRAMME 1. DEFINITIONS AND INTERPRETATIONS 1.1. In these Terms and Conditions, unless the context otherwise requires, the following expressions shall have the following meaning: “Bank” or “UOB” means United Overseas Bank Limited and its successors and assigns. “Card Transaction” means a payment for goods or services made using a UOB Card. “Excluded Cards” means UOB PRVI Miles Platinum American Express Card, UOB Preferred Platinum American Express Card, UOB UnionPay Platinum Card, UOB Travel Account Card, Purchasing and Private Label Card and any other card as may be determined by the Bank in its discretion. “SMART$ Merchant” means the merchant establishment participating in the UOB SMART$ Rebates Programme. “UOB Card” means each or any of the UOB Credit Cards and UOB Debit Cards. “Eligible Cardmember” or “UOB Cardmember” means each or any of the principal cardmember (i.e. the person to whom the Bank issued the principal UOB Card) and the supplementary cardmember (i.e. the person to whom the Bank issued the supplementary UOB Card). “UOB Credit Card” means any principal or supplementary credit card issued by the Bank in Singapore (but excluding all Excluded Cards); and which is valid, subsisting, in good standing and satisfactorily conducted in the opinion of the Bank. “UOB Debit Card” means any principal or supplementary debit card issued by the Bank in Singapore (but excluding all Excluded Cards); and which is valid, subsisting, in good standing and satisfactorily conducted in the opinion of the Bank. 2. ELIGIBILITY UOB SMART$ Rebates Programme does not apply to Excluded Cards unless otherwise stated.
    [Show full text]
  • Chairman's Letter More Than an Industry, It Is a World of News ISCAN
    QUARTERLY NEWSLETTER OF THE GLOBAL SMART CARD INDUSTRY JANUARY 2011 ISSUE this issue Welcome to the Chairman’s Letter P.1 International Smart ISCAN Member News P.1‐5 Card Associations Network 2011 Event Calendar P.4 International Smart Card Associations Network ‐ ISCAN ‐ is an international alliance of More than an industry, it is a world of news independent smart card associations combining manufacturers, systems integrators, issuers, Chairman’s Letter ISCAN NEWS potential issuers and From Catherine Johnston, CEO ACT Canada economic or social Every year ISCAN members meet in Q4 to discuss actors involved in the smart card activities. the state of the global market and how we can In Payments – The Canadian Task Force for contribute to progress in the coming year. the Payments System Review is well underway, identifying four payment 2010, a year where everyone was nervous landscape scenarios that could unfold over because of the global financial crisis, saw the Goals of the the next nine years. shipment of the one billionth EMV card and China Network committing to EMV. In fact, Eurosmart Continued on Page 3 announced that the overall growth in shipments ISCAN's major purpose of smart cards was 18% with financial services, is to support the loyalty and retail accounting for 880 million units proliferation of smart shipped. The effect of China converting to EMV • Eurosmart publishes smart cards card usage worldwide will see that number grow over the coming years. shipments for 2010 and 2011 forecasts by promoting results of 2011 is expected to also see double digit growth. tasks and facilitating Continued on Page 4 exchanges of views The contactless market experienced significant between participating growth in 2010 (40%) as well and is expected to national, continental continue that growth by another 28% in 2011.
    [Show full text]
  • Smart Cards Vs Mag Stripe Cards
    Benefits of Smart Cards versus Magnetic Stripe Cards for Healthcare Applications Smart cards have significant benefits versus magnetic stripe (“mag stripe”) cards for healthcare applications. First, smart cards are highly secure and are used worldwide in applications where the security and privacy of information are critical requirements. • Smart cards embedded with microprocessors can encrypt and securely store information, protecting the patient’s personal health information. • Smart cards can allow access to stored information only to authorized users. For example, all or portions of the patient’s personal health information can be protected so that only authorized doctors, hospitals and medical staff can access it. The rules for accessing medical information can be enforced by the smart card, even when used offline. • Smart cards support strong authentication for accessing personal health information. Patients and providers can use smart health ID cards as a second factor when logging in to access information. In addition, smart cards support personal identification numbers and biometrics (e.g., a fingerprint) to further protect access. • Smart cards support digital signatures, which can be used to determine that the card was issued by a valid organization and that the data on the card has not been fraudulently altered since issuance. • Smart cards use secure chip technology and are designed and manufactured with features that help to deter counterfeiting and thwart tampering. • Smart cards can help to reduce healthcare fraud by providing strong identity authentication of patients and providers. The use of secure smart chip technology, encryption and other cryptography measures makes it extremely difficult for unauthorized users to access or use information on a smart card or to create duplicate cards.
    [Show full text]
  • Axis Bank in Association with BMTC Launches India's First Open Loop EMV Contactless Smart Card for Transit in Bengaluru
    Axis Bank in association with BMTC launches India’s first open loop EMV contactless smart card for transit in Bengaluru India’s first Open loop – single wallet EMV Contactless Transit Card with the objective to create a Scalable, Interoperable ecosystem for convergence of Transit & Retail Payments. Prepaid Transit Card that allows cashless commuting and enhances shopping experience Bengaluru June 14, 2016: Axis Bank, India’s third largest private sector bank has associated with Bengaluru Metropolitan Transport Corporation (BMTC) to launch ‘Axis Bank BMTC Smart card’, India’s first ever open loop EMV contactless smart card that would make travel by bus, a convenient and hassle free experience for the daily commuters in Bengaluru. This initiative is in support Ministry of Urban Development’s vision to address the need of Common Mobility Card. Axis Bank BMTC Smart Card is India’s first prepaid transit card offering integrated single wallet that supports both EMV wallet and transit functions. The card offers integrated services to the commuters by offering them cashless bus travel; and also offers shopping experience at about 1.2 Mn merchant outlets across the country, and therefore, no hassle of carrying multiple cards. Axis Bank has partnered with National Payments Corporation of India (NPCI) for this project for developing the transit EMV contactless specification on interoperable open standards. These specifications can be used by any other transit operator (Metro/Cabs/Auto) by incorporating these standards with their existing fare collection systems. This will make it more convenient for the commuters, as it would allow them to use the same card for purchasing tickets/passes & for all other daily purchase transactions The Smart Card will be issued and loaded at BMTC issuance counters such as pass counters, and Traffic and Transit Management Centres (TTMC) and various other touch points across Bengaluru For balances below Rs 10,000/-, cards would be issued by capturing the minimum mandatory requirements of the customer in the system.
    [Show full text]
  • Maturity of Smart Card Chip Technology and Its Application to Web Security Cathy Medich, Sree Swaminathan, Kelly Urban, Siva Narendra Smart Card Alliance 1
    Maturity of Smart Card Chip Technology and Its Application to Web Security Cathy Medich, Sree Swaminathan, Kelly Urban, Siva Narendra Smart Card Alliance 1. Abstract This position paper provides an overview of smart card secure element chip technology, the markets and applications that use smart card chip technology, the security provided by smart card technology, and the standards that are used to support smart card applications. Contrary to some beliefs, smart card silicon is a highly standardized piece of security hardware that is widely available in the market, and is already in use globally in payments, identity (e.g., e-passports, government employee ID) and access control applications. The scale and standardization of secure smart card technology bring the most obvious core security component that should be integrated into the next generation of unified web security standards. 2. Smart Card Chip Technology Overview A smart card chip is an integrated circuit that includes an embedded secure microcontroller and supports the ISO/IEC 7816 standard for direct physical contact and/or the ISO/IEC 14443 standard for a remote contactless radio frequency interface. With a secure microcontroller, smart cards have the unique ability to store large amounts of data, carry out their own on-card functions (e.g., encryption and mutual authentication) and interact intelligently with computers, mobile phones, and other readers. Smart card technology conforms to international standards and industry specifications also govern the use of smart card technology for various applications. The term, "smart card," is something of misnomer. While the plastic card was the initial smart card form factor, smart card technology is now available in a wide variety of form factors, including plastic cards, key fobs, subscriber identification modules (SIMs) used in mobile phones, watches, electronic passports and USB-based tokens.
    [Show full text]