Engineering

Smartcards & Card Technology

Smartcards are in our DNA. We design card operating systems, build multi-application applets, manage card life-cycles and secure the server side of card schemes — a complete, in-house capability from silicon to scheme.

Card operating systems

Our ISO 7816-4 card operating system provides secure communications, e-purse functionality and key diversification on secure microcontrollers, with EEPROM file-system support and a documented command-set.

GlobalPlatform & Javacard applets

We are a registered GlobalPlatform application-issuer with our own RID, and we port standards-based card-edge interfaces into Javacard applets. Off-the-shelf emulation applets include Piggy (EasyFlex dual-interface), Piglet Access (Cryptoflex) and MemCap (SLE4442 memory card on a micro-controller). We also offer an ITSO Customer Media Definition (CMD) applet, ready for transport and ticketing schemes, and develop custom applets with standards-based or proprietary cryptography. Supporting tools include smartcard mini-drivers for the Microsoft Base Smartcard Provider and OpenSC card interfaces.

Card management

Our Card Management Toolkit handles chip-map configuration, personalisation and issuance. It is highly customisable, uses card-specific APDU modules, and reads personalisation data from Excel for small schemes or any ODBC database for large ones. A script-driven engine — with a record-and-playback feature that adjusts automatically for dynamic data — makes post-issuance management straightforward with no scripting skills required, and can drive a card printer for combined artwork and chip personalisation.

SAM Server — server-side key security

Our SAM Server is a cost-effective, scalable alternative to local key storage or expensive crypto-processors. Running as a Linux daemon controlling arrays of USB smartcard readers, it groups secure access modules (SAMs), load-balances across readers, supports hot-swapping with automatic request redirection, and exposes native and JINI interfaces so any application or web server can target cryptographic operations to a SAM group.

For more information please contact us at .