Title
Caught in the Maze of Security Standards.
Abstract
We analyze the interactions between several national and international standards relevant for eCard applications, noting deficiencies in those standards, or at least deficiencies in the documentation of their dependencies. We show that smart card protocols are currently specified in a way that standard compliant protocol implementations may be vulnerable to attacks. We further show that attempts to upgrade security by increasing the length of cryptographic keys may fail when message formats in protocols are not re-examined at the same time. We argue that the entities responsible for accrediting smart card based applications thus require security expertise beyond the knowledge encoded in security standards and that a purely compliance based certification of eCard applications is insufficient.
Year
DOI
Venue
2010
10.1007/978-3-642-15497-3_27
Security Protocols Workshop
Keywords
DocType
Volume
international standard,security expertise,standard compliant protocol implementation,security standard,cryptographic key,smart card,message format,smart card protocol,ecard application,internal standard
Conference
6345
ISSN
ISBN
Citations 
0302-9743
3-642-15496-4
0
PageRank 
References 
Authors
0.34
2
2
Name
Order
Citations
PageRank
Jan Meier1283.42
Dieter Gollmann2931170.89