Re: Pin generation algorithm question

From: Andrew Swallow (am.swallow_at_eatspam.btinternet.com)
Date: 04/23/04


Date: Fri, 23 Apr 2004 18:11:59 +0000 (UTC)


"Michael Amling" <nospam@nospam.com> wrote in message
news:Dxbic.1189$%K7.217@newssvr15.news.prodigy.com...
> Ernst Lippe wrote:
> > Like you said the best way is to minimize the number of secrets.
> > When the system contains a list of issued tokens, you will have
> > to worry about all the places where this list is used. When
> > you use a keyed algorithm you only have to worry about the
> > key, that you could store in some nice piece of crypto hardware.
>
> I have such a 16-digit "PIN" on a small card in front of me as I
> type. Once the number was decided on, it had to be printed on a small
> card, packaged to make the number unreadable before purchase, had a
> second unique number (SUN?) printed on the package, distributed to a
> retailer, put on a shelf, and taken to a cashier who scanned the SUN
> which activated the PIN. Weeks later I typed the PIN into a cell phone.
> I don't know if the OP's system will use SUNs or activation, but if
> so, the SUN/PIN activation process also needs attention to security.
> The small card also has a 24 decimal digit "Serial Number". I've
> discarded the package, so I don't know if it matches the SUN.
>
There are other things that can be done such as giving the
shops small printers which type out the number when the
token is paid for. Encryption needed between HQ, shop and
printer.

Andrew Swallow



Relevant Pages

  • Re: Package management
    ... > are my choices if I need to update a particular GNU package natively? ... I don't know if or when we (Sun) will be able to open-source the SVR4 ... >> compatible with containers. ...
    (comp.unix.solaris)
  • Re: Monitor calibration-profiling packages, your insight
    ... have an adjustable monitor, it provides serviceable results for most users. ... If you want to advance in color management I heartily endorse the Monaco ... The additional benefit of the Monaco package is a credible but somewhat ... For Epson printers this may not make much difference as Epson makes many ...
    (rec.photo.digital)
  • SUNWfmd
    ... Following message is popping up on Sun T2000 Console, SUNWfmd package is not there on this system. ... This message may not pop up if I install this package, any one know where to get this package for Solaris 10 sparc? ... The EFT Diagnosis Engine encountered telemetry for which it is unable to p ...
    (SunManagers)
  • Re: Pin generation algorithm question
    ... > retailer, put on a shelf, and taken to a cashier who scanned the SUN ... > discarded the package, so I don't know if it matches the SUN. ... from the PIN) on the card, ... idea to use public key signatures to generate these numbers. ...
    (sci.crypt)
  • token ring for solaris 9
    ... I have googled and searched Sun ... BigAdmin, Sun docs, and read the installation manual for the card. ... I can't find this package on the Sol9 disks of course, ...
    (SunManagers)