III.  Technology Battlefields

B.  Smart Cards

Smart Cards offer a practical strategy for implementing PKI in hardware rather than merely in software, for greater security.  A smart card can contain a PKI chip containing the user's private key, which can only be used by someone with physical possession of the token (WHAT YOU HAVE), and knowledge of a secret passphrase (WHAT YOU KNOW) plus perhaps a biometric identifier (WHO YOU ARE).  Smart cards also offer a strategy for digital cash and other pseudonymous or anonymous transactions.