Creation of ISO/IEC Smart Card Registration Authority

The ISO/IEC 24727 standard provides a globally harmonized approach to the widely recognised need for consistency in the way smart card technology – specifically, their crucial authentication protocols – are standardized. The new registration component is contained in Part 6 of the standard. The Australia-based SAI Global has been appointed as the ISO/IEC 24727-6 Smart Card Registration Authority . From now on, there is a central repository where any authentication protocol can be publicly registered. From this point on, the specific authentication protocol can be explicitly referenced by its unique ISO/IEC compliant object identifier (OID). Prior to the advent of ISO/IEC 24727, and the new registration authority, most smart card authentication protocols were either proprietary, not publicly documented, or there was no definitive publicly available reference document for them. Minor protocol differences can cause major interoperability issues. This new approach has been long awaited and is welcomed by both developers and adopters of smart card technology. It has been designed to provide greater extensibility, efficiency and interoperability for smart card schemes – with associated benefits to the entire international community. This is especially the case for governments and other major organizations that are looking for ways to inter-operate between local, national and international smart card schemes in an increasingly globalized world. Because new authentication protocols can be registered in real time, the registration authority also opens the door for the latest and most innovative technology to come to market sooner. “There are perhaps thousands of variants on hundreds of smart card authentication protocols in use globally,” comments Graeme Freedman, a leading international expert in smart card and related technology and the ISO editor of the standard. For the first time, ISO/IEC 24727 provides a standardized, but flexible language for explicitly describing these authentication protocols. The new registration authority further improves interoperability by providing a methodology for rapidly communicating the details of both existing and new authentication protocols via its Website. End users can even register their use of particular protocols so that other parties can determine which protocols they must support in order to authenticate with them. The methodology provides certainty about interoperability and integrity that is very much needed in our global society. In the last few years, lack of standardization, and even uncertainty about how proprietary protocols actually work, has led to an increase in the likelihood of successful systematic attacks. Having to evaluate and accredit the myriad of proprietary protocols has been a significant waste of money and resources and may be beyond the capability of many projects, or even certification organizations. Weak authentication protocols leave potential for major disruptions to essential services across the globe and a quick search of the Internet shows a number have recently been breached. The methodology of documenting authentication protocols via a public registration authority means they can be openly evaluated by the top specialists in this area and, if weak, those weaknesses can be publicised in an open fashion on the Internet. End-users can therefore evaluate the risks and countermeasures in possession of all the information they need.” This does not mean there is no place for proprietary protocols. The registration authority also provides the commercial, licensing and patent contact details for each authentication protocol so that potential end-users can contact the owner to arrange a licence. Authentication protocols which attract no licensing costs, such as those developed for ISO/IEC standards, and ones contributed by supporting companies and industry organizations, are also available from the registration authority. “For developers, there has been a lack of clarity around intellectual property issues when it comes to using or trying to develop better protocols, because no one knows which protocols are already are in use, are owned by companies. or are in the public domain,” says Graeme Freedman. “The register component of the standard has been developed to address these critical issues.” Smart Card Registration Authority www.iso.org 

Neueste Artikel

Ein neuer Digitaler Ausweis-Service ermöglicht die vollautomatisierte Identifikation und Legitimierung von Sparkassen-Kunden innerhalb kürzester Zeit. Entwickelt wurde der Service von der S-Markt & Mehrwert. Die Pilotierung und Einführung wird…

Der Vorsitzende des IT-Planungsrates und der Hauptgeschäftsführer des Bankenverbandes sowie die Geschäftsführer von Bank-Verlag und Governikus vereinbaren intensiven Informationsaustausch der beiden Branchen.

Nach der Hauptversammlung vom 29. April 2019 berief der Aufsichtsrat auf seiner Sitzung am 9. Mai Massimo Sarmi zum Vizepräsidenten des Aufsichtsrats. Zugleich wurde Nicola Cordone als Vorstandsvorsitzender (CEO) des…