[Muscle] Protecting a PIN with keyed hashing?
Sébastien Lorquet
squalyl at gmail.com
Fri Jul 17 05:55:49 PDT 2009
the muscle applet is for global platform javacards right?
Then about the GP secure channel already implemented
(org.globalplatform.SecureChannel
org.globalplatform.GPSystem.getSecureChannel() ) in these cards for secure
messaging? it provides a mac+tdes encryption. also, writing a software
implementation is not difficult, if needed (to use other keys than SD's
ones)
sebastien
ps: the muscle applet also support strong authentication with a
challenge/response exchange. A 128 bits TDES key can be seen as a
16-character PIN, that can be right padded with zeroes or other if needed.
what do you think of this?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.drizzle.com/pipermail/muscle/attachments/20090717/5d023a9b/attachment.html
More information about the Muscle
mailing list