Title :
Simulator Problem in User Centric Smart Card Ownership Model
Author :
Akram, Raja Naeem ; Markantonakis, Konstantinos ; Mayes, Keith
Author_Institution :
Smart Card Centre, Univ. of London, Egham, UK
Abstract :
The Issuer Centric Smart Card Ownership Model (ICOM) gives complete control of smart cards to their respective card issuers, enabling them to install, modify or delete applications remotely, in a secure manner. However, the User Centric Smart Card Ownership Model (UCOM) delegates the ownership of smart cards to their users, entitling them to install or delete any application according to their requirements. In the UCOM there might be no off-card relationship between a smart card and an application provider, referred to as a Service Provider, which is the cornerstone of the ICOM security framework. Therefore, this creates unique security issues like the simulator problem, in which a malicious user may simulate the smart card environment on a computing device and requests installation of an application. Following this, it might be possible to retrieve sensitive application data by reverse engineering. In this paper, we analyse the simulator problem, how it affects the UCOM and propose a possible solution.
Keywords :
security of data; smart cards; issuer centric smart card ownership model; reverse engineering; security framework; sensitive application data retrieval; simulator problem; user centric smart card ownership model; Ownership Model; Smart Card; Trusted Platform Module; User´s Ownership;
Conference_Titel :
Embedded and Ubiquitous Computing (EUC), 2010 IEEE/IFIP 8th International Conference on
Conference_Location :
Hong Kong
Print_ISBN :
978-1-4244-9719-5
Electronic_ISBN :
978-0-7695-4322-2
DOI :
10.1109/EUC.2010.108