Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.5
Related:
Clause 5
|
5.4 Physical/token
|
7.2 Public key / PKI
|
Digital Certificates
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device
A smart card is a token with onboard processing, secure storage and often a certificate. It can serve physical door access and logical computer access with the same credential.
Stolen passwords without the card; some forms of credential cloning if the card stores keys and performs crypto on-card rather than exporting the private key.
Badge plus workstation login; sometimes combined with a PIN. Needs readers, card management and (if certificates are used) a PKI.
Cost of readers, cards, issuance and retrieval. Lost or damaged cards lock people out unless a managed fallback exists. Integration with proprietary IACS logins may be incomplete.
Worth evaluating for both door and workstation access on control-system environments. Teaching note: smart cards and PIV-style badges are more common now than in 2007; the management burden the TR flagged has not gone away.