GlobalPlatform releases security management specs
GlobalPlatform, the international smart card specification organization, has finalized its Device Application Security Management Specification for terminals, including mobile phone handsets and EFT-POS devices, based of GlobalPlatform device technology.
This specification defines how multiple actors within a device environment, such as issuers and third-party application providers, can exchange and manage secure data when downloading applications either pre or post issuance.
The DASM Specification is three documents. The first – the DASM Concepts and Descriptions Specification – was introduced in May 2007 and defines the roles and responsibilities of different actors and specifies the data that needs to be shared in the application download process. The final two documents, which have just been published on the GlobalPlatform website, are:
The DASM Key and Certificate Management Specification – This document details the keys, signature scheme and certificate infrastructure that must be applied to ensure that all actors active within the device environment are verified as trustworthy.
The DASM Provisioning Specification – This document specifies the data format required to install an application and set up a security configuration on GlobalPlatform systems.





