摘要
智能卡系统与传统的计算机系统不同,它不仅仅受制于单一的信任周界。本文介绍了智能卡的可信任环境模型,讨论了智能卡系统中的不同分支的安全性,并针对智能卡的威胁模型提出了相应的抵抗模型。
Smart card systems differ from conventional computer systems in that different aspects of the system are not under a single trust boundary . We discuss the security ramifications of these 'splits' in trust,and outline a pair of fundamental defenses for cards, that operate at the system design level ,offering system designers a new model in which to evaluate their systems.
关键词
智能卡
威胁模型
安全周界
smart card, threat model, security boundary, attack, transparency