OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Muscle] Protecting a PIN with keyed hashing?

From: Sébastien Lorquet (squalylgmail.com)
Date: Fri Jul 17 2009 - 07:55:49 CDT


the muscle applet is for global platform javacards right?

Then about the GP secure channel already implemented
(org.globalplatform.SecureChannel
org.globalplatform.GPSystem.getSecureChannel() ) in these cards for secure
messaging? it provides a mac+tdes encryption. also, writing a software
implementation is not difficult, if needed (to use other keys than SD's
ones)

sebastien

ps: the muscle applet also support strong authentication with a
challenge/response exchange. A 128 bits TDES key can be seen as a
16-character PIN, that can be right padded with zeroes or other if needed.
what do you think of this?

_______________________________________________
Muscle mailing list
Musclelists.musclecard.com
http://lists.drizzle.com/mailman/listinfo/muscle