7. Smartcards & Related Application Infrastructures Flashcards

1
Q

Smartcards

A

small computers with memory, operating system, software, processor, I/O & access control used, when security of data (e.g. for keys, signatures, physical access control, payment) needed in insecure environments (chip protected against manipulation)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why Smartcards?

A

protection needed against: unauthorised usage of service through forged user data, duplication of a user’s credentials, “cracking” of credentials, billing fraud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Defintion: Subscriber Identity Module (SIM)

A

SIMs are smartcards!

  • -represents contract between subscriber & network operator
    • authorizes a “phone” to use the network by linking it to a subscription
  • -contain International Mobile Subscriber Identity (IMSI) for subscriber identification & the key K(i) provided by mobile operator
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Functionality of SIM (3)

A
  • -SIM serves as “identity card” for GSM cellular phone subscribers
  • -Allows for secure billing & roaming subscribers
  • -Contains additional configuration data of GSM system
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SIM - Card Content

A

static data (IMSI, PIN, PUK, A3, A8, language preferred by subscriber) & dynamic data (cell & frequency information, dynamically generated keys, user data)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Integration of SIM into Mobile Phones

A

ETSI GSM 11.11 specifies electrical & software interfaces between SIM and device –> “SIM Application Toolkit” (SAT) allows for implementing of additional applications on a SIM, e.g. mobile banking, location-based services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

WAP

A

WAP is a protocol family implementation of Client/Server applications on mobile devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

WAP Identity Module (WIM)

A

WIM is implemented as an additional application on a -> should solve security problems raised
by WAP: Secure storage (for key/certificates), tamper resistance (of SIM based crypto algorithms), standardized interface (to security functions), RSA signatures are implemented on WIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

USIM (def., features)

A

Universal SIM (for UMTS) - FEATURES; Support for multiple applications (SIM card & others), End-to-end security from USIM to application, Authentication of the network towards the USIM via cryptography (multilateral security possible), Downward compatible to SIM, Extended phone book on card (email addresses, numbers)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

definition: Secure Elements & UICC

A

SE are hardware tokens, that offer secure services (e.g. tamper-proof storage) -> UICC are one form factor of a SE, enabling secure mobile applications & services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

definition: ISIM

A

IP Multimedia Services Identity Module -> application running on a UICC smart card in a 3G mobile phone in IP Multimedia Subsystem (IMS) (can co-exist with SIM & USIM )

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

ISIM - parameters for identifying & authenticating users

A

One private “IM Private Identity” (IMPI), One or more “IM Public Identities” (IMPU), Long-term secret used to authenticate & calculate cipher keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

name SIM Applications (4)

A

Apple SIM, Google Fi Project, Embedded SIM (eSIM), CamWebSIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Apple SIM

A

SIM contains credentials for several networks – When travelling abroad, customer can use same SIM card for a chosen mobile data tariff from selected operators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Google Fi Project

A

Connectivity through different operators (e.g. in cooperation with T-Mobile), High-speed data coverage in different countries with same conditions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Embedded SIM (eSIM)

A

Embedded as a secure element in hardware - e.g. internet-enabled car (with navigation, congestion warning system, infotainment)

17
Q

CamWebSIM

A

a small quasi-HTTP server based on a GSM SIM card – by making SIM accessible over HTTP, the phone and the SIM become a personal security server in the Internet that is based on the GSM trust model – enables applications like authorizing a transaction or an access request (paying for Internet services via one’s GSM telephone account)