Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Provably Secure Chipcard Personalization, or, How to Fool Malicious Insiders

We present 'malicious insider attacks' on chip-card personalization processes and suggest an improved way to securely generate secret-keys shared between an issuer and the user's smart card. Our procedure which results in a situation where even the card manufacturer producing the card cannot determine the value of the secret-keys that he personalizes into the card, uses public key techniques to provide integrity and privacy of the generated keys with respect to the complete initialisation chain. Our solution, which provides a noninteractive alternative to authenticated key agreement protocols, achieves provable security in the random oracle model under standard complexity assumptions. Our mechanism also features a certain genericity and, when coupled to a cryptosystem with fast encryption like RSA, allows low-cost intrusion-secure secret key generation.

Helena Handschuh, Gemplus Card International

David Naccache, Gemplus Card International

Pascal Paillier, Gemplus Card International

Christophe Tymen, Gemplus Card International

BibTeX
@inproceedings {270479,
author = {Helena Handschuh and David Naccache and Pascal Paillier and Christophe Tymen},
title = {Provably Secure Chipcard Personalization, or, How to Fool Malicious Insiders},
booktitle = {5th Smart Card Research and Advanced Application Conference (CARDIS 02)},
year = {2002},
address = {San Jose, CA},
url = {https://www.usenix.org/conference/cardis-02/provably-secure-chipcard-personalization-or-how-fool-malicious-insiders},
publisher = {USENIX Association},
month = nov
}
Download

Links

Paper: 
http://www.usenix.org/events/cardis02/full_papers/handschuh/handschuh.pdf
Slides: 
http://www.usenix.org/events/cardis02/full_papers/handschuh/handschuh_ppt/
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us