• DocumentCode
    568441
  • Title

    A Privacy Preserving Application Acquisition Protocol

  • Author

    Akram, Raja Naeem ; Markantonakis, Konstantinos ; Mayes, Keith

  • Author_Institution
    Inf. Security Group, Univ. of London, Egham, UK
  • fYear
    2012
  • fDate
    25-27 June 2012
  • Firstpage
    383
  • Lastpage
    392
  • Abstract
    In the smart card industry, the application acquisition process involves the card issuers and application providers. During this process, the respective card issuer reveals the identity of the smart card user to the individual application providers. In certain application scenarios it might be necessary (e.g. banking and identity applications). However, with introduction of the Trusted Service Manager (TSM) architecture there might be valid cases where revealing the card user´s identity is not necessary. At the moment, the secure channel protocols for traditional smart card architecture including the TSM does not preserve the privacy of the card users. In this paper, we propose a secure and trusted channel protocol that provide such feature along with satisfying the requirements of an open and dynamic environment referred as User Centric Smart Card Ownership Model (UCOM). A comparison is provided between the proposed protocol and selected smart card protocols. In addition, we provide an informal analysis along with mechanical formal analysis using CasperFDR. Finally, we provide the test implementation and performance results.
  • Keywords
    data privacy; smart cards; CasperFDR; UCOM; application acquisition process; mechanical formal analysis; privacy preserving application acquisition protocol; smart card industry; trusted channel protocol; trusted service manager architecture; user centric smart card ownership model; Computer architecture; Cryptography; Privacy; Protocols; Reliability; Smart cards; Application Installation Protocol; CasperFDR; Privacy Preservation; Smart Cards; User Centric Smart Card Ownership Model;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
  • Conference_Location
    Liverpool
  • Print_ISBN
    978-1-4673-2172-3
  • Type

    conf

  • DOI
    10.1109/TrustCom.2012.47
  • Filename
    6295999