390 likes | 617 Views
Co se stane s kartami ve světě chytrých věcí?. Jan N ě mec. K v ěten 2014. Agenda. Smart Cards & Devices Forum 2014. Smart cards Near Field Communication Host Card Emulation ISIS NFC case study Bluetooth Low Energy and Beacons Smart card and Internet of Things M ůjCard and Fidesmo.
E N D
Co se stane s kartami ve světě chytrých věcí? Jan Němec Květen 2014
Agenda Smart Cards & Devices Forum 2014 Smart cards Near Field Communication Host Card Emulation ISIS NFC case study Bluetooth Low Energy and Beacons Smart card and Internet of Things MůjCard and Fidesmo
Smart cards Smart Cards & Devices Forum 2014
Smart cards/Secure elements - no news SP-TSM3 SSD3 SP-TSM2 SSD2 ISD SSD1 SP-TSM1 SEI-TSM Smart Cards & Devices Forum 2014 • Java Card 3.0.1 • Management of multiple contact/contactless interfaces • Support for up to 20 logical channels • Additional cryptography • GP 2.2.1 with amendments A, C and D • Multiple TSM management • Multiple Service providers • Multiple NFC services • NFC Type A and B • Huge certification effort • Common Criteria EAL4+ • CAST and EMVCo • FIME GP2.2
Near Field Communication versus Host Card Emulation Smart Cards & Devices Forum 2014
Overview of the different NFC modes Requires NFC SE or specific adaptation to HCE Reader Information … Cardemulation Payment Transport Access control … P2P Data exchange … Smart Cards & Devices Forum 2014
Secure Element versus HCE Smart Cards & Devices Forum 2014
NFC Controller routing rules HCE-based transaction SE-based transaction Before HCE, Card Emulation transactions were isolated from the Host OS Smart Cards & Devices Forum 2014
Implicit vs Explicit Selection of Applications Smart Cards & Devices Forum 2014
Where are credentials stored? Source: UL – HCE Security Webinar Jan 2014 Smart Cards & Devices Forum 2014 • HCE ≠ SE • HCE is only emulating the logic of an NFC smart card • SE-Based Card Emulation • Both Application and Credentials reside in a Secure Element • UICC, embedded SE or secured µSD • SE is about secure (i.e. extremely hard to break or clone) storage of sensitive data. • Host Card Emulation (HCE): • HCE Service runs on the Device OS • Credentials can be stored anywhere • In the rich OS • In a TEE • In the Cloud • In a SE
What use cases with or without SE? Use cases Payment Transport Access Control Identity Secure P2P Ticketing Tag reading /info retrieval Devicematching for P2P Possible with HCE but withsecurity and compatibility limitations • 2017 • ~1700 milions units Smart Cards & Devices Forum 2014 • 2014 • 34 brands, 350 models • 290 Android • 270 UICC, 55 eSE, 35 HCE • ~500 milion units
ISIS NFC case study Smart Cards & Devices Forum 2014
Isis is a Joint Venture between 3 of the biggest US MNOs Partnering with major banks & payment schemes: Smart Cards & Devices Forum 2014
ISIS Mobile Wallet is now available nationwide! • Started as a pilot in 2 cities: Austin & Salt Lake City, in October 2012 • National launch on November 14th, 2013 • A lot of incentives for users Smart Cards & Devices Forum 2014 Gemalto Confidential - Internal Use Only
68 Isis-ready phones available The Isis Wallet is also available on iPhone 4, 4S, 5 and 5S with the IncipioCashwrap Isis Ready case. The Isis Wallet is now pre-loaded in 14 handsets. Smart Cards & Devices Forum 2014 Gemalto Confidential - Internal Use Only
Near Field Communication versus Bluetooth Low Energy Smart Cards & Devices Forum 2014
Bluetooth Low Energy (BLE) Smart Cards & Devices Forum 2014
BLE Beacons Smart Cards & Devices Forum 2014
BLE versus NFC Smart Cards & Devices Forum 2014
Wearable devicesandInternet of Things Smart Cards & Devices Forum 2014
SundayTimes newpaper article in 2006 Smart Cards & Devices Forum 2014
Chandan’s All-In-One Card desing in2006 https://blogs.oracle.com/chandan/entry/the_all_in_one_card Smart Cards & Devices Forum 2014
Arduino Smart Cards & Devices Forum 2014
PRINTOO Printoo's modules will be thin and bendable. Smart Cards & Devices Forum 2014
PRINTOO Thin and flexible polymer solar cell. You can cut it into the shape you want! Smart Cards & Devices Forum 2014
PRINTOO Paper-Thin Electrochromic Screen Smart Cards & Devices Forum 2014
PRINTOO modules Smart Cards & Devices Forum 2014
MůjCard Smart Cards & Devices Forum 2014
MůjCard world values … Smart Cards & Devices Forum 2014 • …for end users • Access to more contactless service thanks to MůjStore with the apps • Instant way to get, manage and use these service thanks to MůjManager • …for service provides • Ability to offer services • small players at city/regional level have no chance to talk to MNO/handset vendor • global players are not ready to agree and integrate with X+ MNOs/handset vendors • Ability to offer services without need to provide own secure elements • … for group users (corporations, government) • Access to simple post issuance of their cards, which doesn’t exist today • Simple/portable interface for their users merging usage and discovery experience • … for MNOs not willing to join NFC wave • Ability to offer an external SE as NFC equivalent to their end users (revenue share) • … for MNO not ready to invest in expensive TSM infrastructure • Quick access to SPs - giving an SD on NFC SIM (cheaper SIM or revenue share)
MůjCard world in pictures Terminal accessing MůjCardApps MůjStore HTTPS ISO 7816 ISO 14443 ISO 7816 ISO 14443 Terminal with MůjManager MůjCard with MůjCardApps Smart Cards & Devices Forum 2014
MůjCard in pictures MůjCard Admin Applet User auth Terminal auth Manager reference Apps registry Store auth Apps access control App #1 App #n App #2 App #3 Smart Cards & Devices Forum 2014
MůjManager in pictures Terminal MůjManager MůjStore communication module MůjCard discovery MůjStore discovery APDU script player APDU communication module MůjCardcommunication service Smart Cards & Devices Forum 2014
MůjStore in pictures Users MůjStore End user account #1 Apps container MůjCard #1 MůjCard #1 UZone #1 MůjCard #2 Public Zones – public apps UZone #2 MůjCard #3 Ap #n Ap #1 Ap #2 Group account #1 Restricted Zones – own apps MůjCard #1 UZone #1 Group Zone #1 MůjCard #2 App #1 App #2 UZone #2 MůjCard #3 Smart Cards & Devices Forum 2014
MůjCardApps examples – publiczones Smart Cards & Devices Forum 2014 • MůjManager is separated from MůjCard UI / terminal apps • End user offer – standalone apps • NFC business card • Secure storage – phonebook, passwords, pins, keys, etc. • PC authentication • Web authentication • Bitcoin wallet • End user offer – service provider apps • Access – hotel keys, house keys, cinema, stadium, ski resorts, etc. • Transport • Car rental • Couponing, Loyalty • DRM – applications/games • OTP, etc.
MůjCardApps examples – restricted zones Smart Cards & Devices Forum 2014 • MůjManager can be merged with MůjCard UI / terminal apps • Corporate offer • Access apps • NFC business card • PC authentication • Web authentication • Signature/ciphering • Proprietary payment – canteen, coffee and other machines • Travel apps • Goverment offer • Digital signature • Voting • ID, Driving license, Health card, etc.
Fidesmo Fidesmo, a technology startup connecting cards with mobile phones. They are just three guys, based in Stockholm and Madrid. - http://fidesmo.com/ Smart Cards & Devices Forum 2014 Fidesmowins MIFARE Award for the most innovative idea for new services. - http://fidesmo.com/press-releases/ Fidesmo Aims To Be The Only Card You Need For Public Transit (And Eventually, Anything Else). - http://techcrunch.com/2014/05/06/fidesmo-aims-to-be-the-only-card-you-need-for-public-transit-and-eventually-anything-else/
Thank you! Jan Nemec Jan.Nemec@gemalto.com