SAMASC: Security Analysis for Multi-Applet Smart Cards

Project

Security protocols are essential for providing security. They are sets of rules for the secure exchange of information in insecure environments, based on cryptographic techniques. Smart cards are currently a standard means of providing secure authentication over networks, notably used in all mobile phones (as SIMs) and in many bank cards, and their use for controlling access to network-based services will increase in the near future. The latest generation of smart cards has a simple operating system for the execution of application programs (called applets), written in a Java-like language. Multiple applets may exist on a single card, and may even be added after card issuance. This simplifies the development of applications, and makes interesting new applications possible, but at the same time it poses entirely new security threats, which are complicated in nature because of the many parties that may be involved (and the non-trivial trust relationships that may exist between them).

The innovation of the proposal lies in its aim to analyse security protocols in the context of scenarios for smart cards with multiple applets. The presence of multiple applets adds a completely new dimension with its own security risks. Another innovative aspect of the proposed research is its aim to study security protocols ``in context'': we do not not just consider the abstract core of a protocol (as is commonly done in most work in the literature), but explicitly include the particular setting in which the protocol is used. The analysis will involve an appropriate combination, and likely extension, of existing techniques from the literature, involving actual verification with theorem provers.

The two main case studies are security of mobile commerce and of applet downloading. The project combines existing expertise in smart cards, security, and formal methods, and strengthens the position of the Netherlands in this important area. In the project there will be light-weighted industrial participation through KPN Research guaranteeing appropriate practical focus.

Lees meer...

Deelnemers en geinteresseerden

Bijeenkomsten

Kick off meeting 14 mei 2002 10.15-13.00 Eindhoven
Meeting 26 augustus 2002 14.00-17.00 Nijmegen
Meeting 4 november 2002 13.30-16.30 Nijmegen
Meeting 14 april 2003 12.00-16.30 Nijmegen
Meeting 23 juni 2003 12.00-16.00 Nijmegen
Meeting 13 november 2003 11.00- Eindhoven