Smart Card Personalization Environment



Similar documents
Banking. Extending Value to Customers. KONA Banking product matrix. is leading the next generation of payment solutions.

Network device management solution

System Requirements for Microsoft Dynamics SL 2015

Network operating systems typically are used to run computers that act as servers. They provide the capabilities required for network operation.

Smart Card Application Development Using Java

OT PRODUCTS AND SOLUTIONS EMV-IN-A-BOX

Most flexible, most powerful, easiest-to-use. ID software. A quantum leap in card design and production

BarTender Integration Methods. Integrating BarTender s Printing and Design Functionality with Your Custom Application WHITE PAPER

DoD CAC Middleware Requirements Release 4.0

System Requirements for Microsoft Dynamics SL 2015

Application Note Gemalto.NET 2.0 Smart Card Certificate Enrollment using Microsoft Certificate Services on Windows 2008

Smart Cards for Payment Systems

WEB COMPAS MINIMUM HOSTING REQUIREMENTS

Functions of NOS Overview of NOS Characteristics Differences Between PC and a NOS Multiuser, Multitasking, and Multiprocessor Systems NOS Server

Virtual Desktop Infrastructure in

How To Protect A Smart Card From Being Hacked

SmartCenter for Pointsec - MI Overview

EMV-TT. Now available on Android. White Paper by

How To Approve A Mastercard Tsm

MOBILE CHIP ELECTRONIC COMMERCE: ENABLING CREDIT CARD PAYMENT FOR MOBILE DEVICES

Computer Literacy. Hardware & Software Classification

17 April Remote Scan

START-UP. services DATACARD SM GLOBAL SERVICES. Prepare to streamline installation and optimize results

Inmagic Content Server Workgroup Configuration Technical Guidelines

Priority Pro v17: Hardware and Supporting Systems

Inmagic Content Server v9 Standard Configuration Technical Guidelines

Amadeus Selling Platform 3.1 P120

Lenovo Partner Pack for System Center Operations Manager

MAS 200 Supported Platform Matrix

Technical Overview of Terminal Services

Product Summary of XLReporter with OPC Servers

MarkVision Printer Management Software

Credential and Workflow Design with TruCredential. DataCard Corporation. All rights reserved.

System Requirements. Version 8.2 November 23, For the most recent version of this document, visit our documentation website.

Worldwide Smart Card Implementations using GlobalPlatform Standards

Section 1 CREDIT UNION Member Information Security Due Diligence Questionnaire

2) Xen Hypervisor 3) UEC

Tekla Structures 18 Hardware Recommendation

Managing Enterprise-wide Printing: The IT Challenge

SmartCITIES. Smart InterOperable. Solutions for Transport Authorities

Large Format Print Submission Made Easy

Platform support for UNIT4 Milestone 4

Sage MAS 200 ERP Level 3.71 Version 4.30 Supported Platform Matrix

Symantec Client Management Suite 8.0

Latitude NVMS Windows XP SP2 Configuration

DeltaV Executive Portal

A WEB-BASED VE SUPPORTING SYSTEM FOR VE FACILITATOR AND MEMBERS IN VE WORKSHOP

Citrix XenApp The need for a Citrix server will still be required so no integration with our future SCCM environment will be available.

Network device management solution.

IP-Pro (Virtual IP Protocol Independent Version) User Instructions

Virtual CD v10. Network Management Server Manual. H+H Software GmbH

Introducing etoken. What is etoken?

MAPILab Reports for Hardware and Software Inventory Installation Guide. Document version 1.0

PIE. Internal Structure

Understanding the Role of Hardware Data Encryption in EMV and P2PE from the CEO s Perspective

for Networks Installation Guide for the application on the server July 2014 (GUIDE 2) Lucid Rapid Version 6.05-N and later

Fundamentals of EMV. Guy Berg Senior Managing Consultant MasterCard Advisors

Remote Administration of Windows Servers Using Remote Desktop for Administration

Windows XP SP2 configuration

IDENTITY SOLUTIONS END-TO-END SYSTEMS SOLUTIONS TO PROTECT IDENTITIES AND SECURE ACCESS FOR A MOBILITY WORLD

THE ENTERPRISE BENEFITS OF THE INDUSTRY S FIRST REMOTE MANAGEMENT SOLUTION FOR HANDHELD SCANNERS

Central Management System

System Requirements Version 8.0 July 25, 2013

ACI Card and Merchant ManagementTM solutions overview

EMV Chip Card Payment Standard: Perspective

P2000 AND P2000LE SECURITY MANAGEMENT SYSTEM. Interactive, real time security management

Microsoft HPC. V 1.0 José M. Cámara (checam@ubu.es)

SOFTWARE TESTING TRAINING COURSES CONTENTS

791 Marion Avenue Highland Park, IL

Terminal Server Software and Hardware Requirements. Terminal Server. Software and Hardware Requirements. Datacolor Match Pigment Datacolor Tools

Lecture 6: Operating Systems and Utility Programs

Product Brief. DC-Protect. Content based backup and recovery solution. By DATACENTERTECHNOLOGIES

Microsoft Identity Lifecycle Manager & Gemalto.NET Solutions. Jan 23 rd, 2007

Océ PRISMA archive software. Archiving made easy. Powerful, high-volume. archiving software

IP Office Technical Tip

Deriving a Trusted Mobile Identity from an Existing Credential

CollectMax System Requirements

Setting up VPN and Remote Desktop for Home Use

Premium Server Client Software

Implementing and Managing Microsoft Desktop Virtualization en

MarkVision printer management software

Compliance Response Edition 07/2009. SIMATIC WinCC V7.0 Compliance Response Electronic Records / Electronic Signatures. simatic wincc DOKUMENTATION

Enterprise Edition. Hardware Requirements

How to monitor AD security with MOM

Medical 360 Network Edition and Citrix

YubiKey PIV Deployment Guide

MOHAMMED AL-ATARI Curriculum Vitae

Write up on PSIM PHYSICAL SECURITY INFORMATION MANAGEMENT

Click to view Web Link, click Chapter 8, Click Web Link from left navigation, then click BIOS below Chapter 8 p. 395 Fig. 8-4.

Considerations for Mobile Application Development

Using Remote Web Workplace Version 1.01

Objectives. At the end of this chapter students should be able to:

HP Server Management Packs for Microsoft System Center Essentials User Guide

Technical Specification Data

CMT for Exchange 3.7. Requirements

Unicenter Patch Management

Comparing Free Virtualization Products

Draft Middleware Specification. Version X.X MM/DD/YYYY

The EMV Readiness. Collis America. Guy Berg President, Collis America

WAREHOUSE MANAGEMENT SOFTWARE

Transcription:

Smart Card Personalization Environment Smart card personalization management Executive summary Smart Card Personalization Environment (SCPE) is universal server environment intended for the management of smart card personalization using Datacard personalization equipment. Here are the key features of SCPE: Support for most memory cards and cards compliant with ISO 7816 (T=0 and T=1); Simultaneous personalization of multiple card types using several items of personalization equipment; Independence of smart card applications from personalization equipment used; Ability to use scripting technology to develop smart card applications to speed up and facilitate development, implementation, integration and maintenance of personalization solutions; Scalability of the personalization system (adding personalization devices does not require modifications of smart card applications; A number of ready smart card applications for personalization of popular native and GlobalPlatform produced by Axalto, Gemplus, Setec and other vendors; Software development kit for smart card applications development.

2 SCPE features and capabilities Flexibility Components of a competitive card product (specifically, card type, set of personalized applications) are bound to change as the time passes. The operational environment that impacts personalization may also change: a set of personalization equipment, personalization data sources and format. Payment systems specifications are also bound to change, new applications and better card types are likely to appear. SCPE architecture allows fast and effective modification to personalization systems. Smart card application development technology is not closed, thus applications may be developed either by PRONIT specialists, or by third parties. Card types Along with the development of smart technologies new chip types, less costly and more functional, are developed. SCPE enables to personalize new card types and simultaneously support several card vendors. Applications It is likely that in the near future loyalty and other additional applications will be an integral part of a competitive card product. SCPE personalization management process is adjusted and customized in accordance with the requirements of a certain system. In case new card applications require new data sources or personalization information has to be processed in some special way, necessary modifications to the system can be implemented at low cost and minimal time. Personalization devices Many personalization systems require simultaneous using of several personalization devices of different models and types. Personalization system may consist of several desktop and/or high-volume devices. SCPE enables to simultaneously manage personalization on multiple Datacard devices. Figure 1. Smart card personalization system configuration example. Compatibility and versatility Every institute issuing smart cards select a certain combination of card, a set of personalized applications and personalization equipment.

3 SCPE enables fast development, implementation and modification of smart card personalization system in accordance with certain requirements. Figure 2. Most personalization devices, card types and applications are joined with SCPE. Card types Most memory cards and cards, compliant with SIO 7816 (native and Global Platform) can be personalized with SCPE. Visa (JCOPx0), Austria Card, Axalto, Gemplus, G&D, Oberthur, Setec cards of these card vendors can be personalized with SCPE. Turnkey solutions for most popular cards are available. Applications See the complete list of turnkey solution later in this document Financial applications (for instance, VSDC, M/Chip), loyalty, petrol purse and other custom applications and their combinations can be personalized using SCPE. Personalization devices Most Datacard personalization devices, both desktop and high volume, can be used to personalize cards with SCPE. See the complete list of supported personalization devices later in this document Scalability From pilots to high-volume issuance In many cases rigid inflexible pilot systems are created to personalize a single type of cards with a certain set of applications. Such systems become inapplicable with transition to high-volume issuance. And the issuer has to create a new high-volume oriented system based on the experience, received during the pilot project.

4 In case of using SCPE major settings are implemented on installation of the initial configuration. Hence, if cards are successfully personalized on a single desktop device, they can be issued using a set of high-volume devices. This entails only purchasing additional licenses for programming stations added to the personalization system. No program modifications are required for such transition. Promotional pricing of SCPE fosters pilot projects. Support In most cases PRONIT specialists support not only SCPE software, but also the entire smart card personalization system. Both at the initial stage, and during operation PRONIT specialists: Install and adjust SCPE; Train the operation staff and provide relevant documentation; Develop and modify smart card applications; Adopt the personalization system to input data formats; Provide support in office, via e-mail or phone. In addition, experienced PRONIT specialists with high expertise in creating successful card issuance systems are eager to assist in relevant fields of data preparation, cryptography and card testing. SCPE components Architecture overview SCPE technology includes four major components: SCPE server, which provides for interaction of smart card applications and personalization devices; SCPE console, which enables personalization system management and monitoring; Two applications, intended for: o o Data preprocessing (for instance, for cryptographic data processing before personalization); Personalization management (mostly for writing data into the chip). Figure 3. SCPE architecture.

5 Server SCPE server manages the interaction of applications and personalization equipment, ensuring stability and efficiency of the smart card issuance process and independence of smart card applications from the personalization equipment in use. Smart card applications independence SCPE creates the environment, that ensures interaction of smart card applications and programming stations of personalization devices. SCPE architecture makes the applications invariant from types and number of personalization devices, allowing the application developer to feel free regarding the types and number os personalization devices used in the personalization system. This ensures that applications, which personalize cards on a desktop tevice, can be successfully applied in a system of several high-volume Datacard devices (DC 9000/7000/500). Figure 4. Smart card applications are independent from personalization equipment used. System resources SCPE has a standard set of requirements to operating systems and communication channels. SCPE parameters and functions management is built on the MMC technology (Microsoft Management Console). SCPE console SCPE architecture allows centralized configuration of parameters and monitoring of the entire system by means of the console. SCPE console displays current information regarding the state of every personalization device and every programming station in it. The console displays the number of personalized cards, average, maximal and minimal speeds of personalization for each active programming station. SCPE environment generates trace protocol of the personalization process, containing detailed information regarding the personalization process flow, including the cases of card defects. In addition, SCPE console enables to: Add and delete personalization devices and programming stations; Set smart card applications for a certain batch of cards; Configure sources and format of input data;

6 Figure 5. SCPE console. Smart card applications Smart Card applications are software modules, which implement specifics of personalizing a set of applications on a certain card type. Activities, carried out by smart card applications, may include data input (including data input from an external source), data formatting, cryptographic processing and data personalization into the chip. Personalization time reduction If card personalization requires time-consuming prepersonalization data preparation activities, such as continuous cryptographic processing and/or getting data from a remote source, their contribution to the increase of total personalization time may be significantly reduced. With smart card applications such activities can be carried out simultaneously and independently from the personalization process, generating a reserve and decreasing the total personalization time. Output fields SCPE enables to return to controller a piece of information, generated during personalization. This can be used, for instance, for card serial number embossing or printing, or when personalizing MULTOS of UEPS cards. In addition, before starting to process a batch of cards, the personalization system enables to request initialization data form operator (for instance, a password or a card batch unblocking key). Standard platform Standard development platforms are used to develop smart card applications: Microsoft Visual C++, standard scripting languages, supporting Active Scripting technology (for instance, VBScript, JavaScript, Active Perl). PRONIT specialists can develop smart card applications in undertime. Applications can be developed and adopted by third parties, because relevant documentation and SDK are available.

7 Turnkey solutions The following turnkey solutions for native and GlobalPlatform cards are developed and are currently in operation. Native cards GemVision (VSDC) GemShare (M/Chip) egalleon (VSDC, M/Chip) Palmera Swift (VSDC) SetCOS (VSDC, M/Сhip) StarDC (VSDC, M/Сhip) GlobalPlatform cards GemXpresso Pro (VSDC) GemXpresso Lite (VSDC, M/Chip) JCOP (VSDC) Palmera Protect (VSDC) Subordinate solutions Script to retrieve PAN from EMV applications. The script is used to identify a certain card during line production of EMV cards with photographs and/of individual design on desktop devices (printer + embosser). Supported personalization devices SCPE personalizes cards on the majority of Datacard personalization devices. High-volume Datacard devices DC 500 DC 7000 DC 9000 Datacard embossers DC 150i DC 280P DC 450 Graphic printers SP35 SP55 Image Card IV Magna Select

8 Platform SCPE workstation Windows 2000 (Service Pack 3) Windows XP (Service Pack 2) Additional software ActiveScriptProcessor GlobalScriptProcessor ScriptSDK DeskSCAppManager Scripting technology support module; GlobalPlatform scripting technology support module; Scripts development kit; Smart card applications manager for desktop devices.