RE: [Web Crypto WG] ACTION-40 : clarifying smart card usage in section 4 of the draft API

To the editors,

I suggest that we add the following text to clarify the role of secure elements such as smart cards in section 4.0, Scope. http://www.w3.org/2012/webcrypto/WebCryptoAPI/#scope

Append to the second paragraph as follows...

>>
Chief among the implementation-specific APIs that this specification avoids is key provisioning for use with smart cards and other forms of secure-element based key storage. In addition to the inconsistency between existing cryptographic APIs, smart card provisioning is often encumbered with vendor-specific details that make it unsuitable for a generic interface. However, the API will not preclude the use of  pre-provisioned keys that already reside in secure elements such as smart cards. The use of such keys will be at the discretion of the application. An application can request to discover keys from a certain location, such as smart card, secure storage or DB. The application may also request notification when such a key is selected, and verification that the key indeed comes from the specified location.
>>

Best regards,
--- asad


From: GALINDO Virginie
Sent: Monday, August 27, 2012 3:37 PM
To: Ali Asad
Cc: public-webcrypto@w3.org
Subject: [Web Crypto WG] ACTION-40 : clarifying smart card usage in section 4 of the draft API

Asad,
As discussed today, an action has been assigned to you to write some proposal to the editors to take into account the secure element in the scope section.
Related action is action-40.
Regards,
Virginie
gemalto

Received on Tuesday, 28 August 2012 23:05:44 UTC