Smartcards: a pragmatic approach
Build on what we have
- Use existing infrastructure (UMCE)
- UNIX filesystem; mail, web servers
- Kerberos
- NT GINA
- Use open standards (IETF, ISO)
- Add secure hardware: smartcard
Integrate smartcard with infrastructure
Secrets in a smartcard remain safe even if hardware / software is compromised