Issue
97, August 1998
Designing
for Smart Cards
- Part 2: Practical Implementation
SYSTEM
SECURITY
Obviously,
access to the smart card should be limited only to authorized
users. But, thats only the first level of security
for the total system.
The software
should ensure that external, logical addresses arent
the same as the cards physical address. This interpretation
of logical and physical addresses should be coded into
the OS or application software, so an intruder cant
breach the first layer of card security, issue an ISO
read command, and access sensitive information.