Check out the new USENIX Web site. next up previous
Next: Achieving Secure Transactions Up: Equivalence Previous: Secure output secure input.

Trusted output with one bit of trusted input trusted input.

If the customer has trusted output from the smart card and one bit of trusted input, the customer can generate trusted input. (Note: if the customer can yank his smart card out of the merchant's reader/writer, then he has at least one bit of trusted input!) The customer provides his input to the smart card and the smart card echoes back the information to the customer. If the smart card echoes the wrong information, the customer uses the one bit of trusted input to inform the smart card of the communication failure. (This method uses an implicit assumption that the possessor of the smart card is an authorized user. By itself, this method by does not provide protection against smart card theft.)



TOM Comversion
Fri Oct 4 17:57:09 EDT 1996