Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > How to prevent hack attacks against smart card systems.
Ask The Security Expert: Questions & Answers
EMAIL THIS

How to prevent hack attacks against smart card systems.

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 25 January 2008
How can smart card databases be hacked, and what are the best ways to prevent hack attacks against smart card systems?

>
Smart card systems consist of the cards themselves and the back-end databases containing their data. The cards contain chips that can carry a range of information from just authentication credentials by themselves to customer information, account information and even sums of money.

The beauty of a smart card is that it provides an extra layer of defense for an authentication system. If someone has to insert a card into a reader while also entering a user ID and password, there are two systems an attacker would have to break to gain access. This is a textbook example of a two-factor authentication system.

The idea behind a smart card is that it holds all the authentication credentials on a chip. Unlike user IDs and passwords, which can be forgotten or forged, smart cards are harder to exploit. But the chips on the cards are still vulnerable; if the data on them isn't encrypted, there are ways a malicious user with a reader can sift the data off the card. The small size of the chips on the cards only allows a limited amount of memory, which also limits the size of the encryption keys the card can hold, which in turn weakens the strength of the encryption of the card.

But these vulnerabilities are unique to the card itself. As for the databases supporting smart cards and holding their data, the vulnerabilities are the same as for any server-based system. There's nothing special about them just because they're part of a smart card system.

The same rules apply to database servers -- or for any server, for that matter. The database and its hosting server should have up-to-date security patches from the vendor, and access should be limited to those who need it. Data sent to and from the database should be encrypted in transit and sensitive data in the database itself should be encrypted.

In addition, the server hosting the database should have all unnecessary services turned off. The server should be dedicated to that database only and no other applications besides the operating system required to run the server. The only ports open should be those required for access to the database and should be filtered to only allow access from the application server needing to connect to the database. The database shouldn't sit in a DMZ and should be behind a firewall without a direct connection to any outside network.

But, that said, in most cases, since smart cards are used mostly for authentication, they're linked to directory services like Active Directory and LDAP. Both of these systems allow smart card data from individual users to be integrated into their profile. Though Active Directory or LDAP have their own security issues, unlike plain old databases, they encrypt authentication data by default and tend to be more secure.

More information:


BROWSE BY TAG
Identity Management and Access Control,   Security Token and Smart Card Technology,   Enterprise Identity and Access Management,   User Authentication Services,   Enterprise Data Protection,   Identity Theft and Data Security Breaches,   Expert Archive: Identity Management and Access Control,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Identity Management and Access Control
Is Identity Management as a Service (IDaaS) a good idea?
How to log in to multiple servers with federated single sign-on (SSO)
How to confirm the receipt of an email with security protocols
Learn about enterprise strategy for server virtualization single sign-on
Employee information security awareness training for new IAM systems
Can you combine RFID tag technology with GPS to track stolen goods?
Is there a free enterprise-caliber password-management tool?
Cryptosystem attacks that do not involve obtaining the decryption key
Can any firm or organization get a digital signature certificate?
Should the CTO have domain administrator access?

Security Token and Smart Card Technology
First Data, RSA push tokenization for payment processing
How to log in to multiple servers with federated single sign-on (SSO)
Best Authentication Products
Are 'strong authentication' methods strong enough for compliance?
Risk management must include physical-logical security convergence
RSA researcher Ari Juels: RFID tags may be easily hacked
Portable security storage device could replace OTP devices
Can you combine RFID tag technology with GPS to track stolen goods?
Security token and smart card authentication
Embedded smart card chips are open to hack attacks

Identity Theft and Data Security Breaches
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Chip and PIN adoption serves lesson for U.S. payment industry
Group to shed light on secure identity management threats
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
University data breach exposes 163,000 women to identity theft
TJX thrives following breach, bucks sour economy

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
authentication server  (SearchSecurity.com)
Chameleon Card  (SearchSecurity.com)
key chain  (SearchSecurity.com)
key fob  (SearchSecurity.com)
key string  (SearchSecurity.com)
national identity card  (SearchSecurity.com)
security token  (SearchSecurity.com)
smart card  (SearchSecurity.com)
tokenization  (SearchSecurity.com)
two-factor authentication  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts