Smart card

A card with an embedded chip that stores keys and performs cryptographic operations. Unlocked with a PIN, it combines something you have with something you know.

A smart card is a card with an embedded integrated circuit that can store data and, in cards used for authentication, hold a private key and perform cryptographic operations on the card itself. The card commonly holds a certificate issued through a public key infrastructure: the system sends a challenge, the card signs it, and the private key is designed to stay on the chip. The US Personal Identity Verification (PIV) card, specified in FIPS 201, works this way.

The card is something you have, and unlocking it with a PIN adds something you know, giving multi-factor authentication with one device. NIST SP 800-63B-4 notes that PIV and Common Access Card (CAC) cards, which use client-authenticated TLS, provide phishing resistance through channel binding (section 3.2.5). Smart cards differ from memory cards, such as magnetic stripe cards, which store data but cannot process it and are easier to copy. Their risks include loss, theft combined with an observed PIN, and side-channel attacks on the chip.

Exam relevance: a scenario is likely to set a smart card against a memory card, or to ask how many factors a card plus PIN provides. Candidates are expected to count factors by type, giving two, and to recognise the processing chip as what separates the two card types.