Tampilkan postingan dengan label Technology. Tampilkan semua postingan
Tampilkan postingan dengan label Technology. Tampilkan semua postingan

Implementasi Smart Card Pada Absensi

>> Selasa, 08 Desember 2009

1. Pengertian Smart Card



Smart Card adalah media penyimpan data dalam satu kartu yang merupakan pengembangan dari kartu magnetik dan mempunyai ukuran serupa dengan kartu pembayaran plastik masa kini. Beberapa jenis Smart Card masa kini memiliki chip Microprocessor serta Memory didalamnya sehingga Smart Card itu sendiri mampu menjalankan berbagai aplikasi seperti memproses



data, melakukan proteksi terhadap data, serta melakukan proses otentifikasi.



2. Contact Smart Card



Contact smart card memiliki chip kecil keemasan pada kartu, saat dibaca oleh reader, chip tersebut melakukan kontak dengan konektor yang dapat membaca informasi dari chip, dan dapat menuliskan informasi kembali kedalam chip.Pada contact smart card, beberapa standard ISO telah dikeluarkan untuk mendefinisikan bentuk fisik, posisi, karakteristik, protokol, format perintah yang dikirim dan respon yang dikembalikan, ketahanan kartu, hingga fungsinya. Kartu ini sendiri tidak memiliki baterai sebagai sumber tenaga, karena energi yang dibutuhkan akan dihasilkan oleh card reader, yang digunakan sebagai media komunikasi antara smart card dan host (misalnya komputer). Aplikasi yang melakukan proses dapat Anda letakkan pada host / komputer, bersamaan dengan database atau tools yang diperlukan oleh aplikasi.





3. Cara kerja Smart Card Secara Umum



PT Teknologi adalah layanan system proses menyimpan data absensi karyawan dengan menggunakan teknologi contact smart card berbasis smart card. Kelebihannya, memudahkan proses penyimpanan data absesnsi karyawan secara strutktur, dan memudahkan proses absensi secara cepat, dan mengurangi terjadinya kesalahan pada data absensi karyawan. Cara penggunaanya cukup mudah, kartu tinggal di sentuhkan pada reader Electronic Data Capture (EDC) dan dalam 3 detik proses data absensi telah selesai dan tersimpan.





4. Cara Kerja Smart Card pada Absensi




Cara Kerja smart card dalam kehadiran (absensi) seperti pada Gambar No 3. Aplikasi POS yang terhubung dengan EDC seperti pada Gambar No 2 Cara kerja dari aplikasi POS yang terhubung dengan EDC digambarkan pada Gambar di bawah ini sebagai berikut ;



5. Implementasi Smart Card



Untuk mudahnya, anggap Anda ingin membuat sebuah aplikasi absensi karyawan dengan menggunakan smart card, tentu saja Anda dapat membuat aplikasi yang tidak menggunakan media kartu, kartu hanyalah kemasan untuk tag atau chipnya.Tetapi untuk mudahnya kita akan berasumsi menggunakan kartu sebagai kemasannya.Untuk itu, setiap karyawan memiliki sebuah smart card agar dapat melakukan absensi. Sebuah card reader yang terhubung dengan sebuah komputer akan digunakan untuk membaca smart card tersebut, dan aplikasi Anda pada komputer tersebut akan melakukan proses pendataan yang diperlukan. Dari sisi hardware, Anda harus mengenal atau menentukan spesifikasinya, misalnya frekuensi yang digunakan (jika merupakan contactless atau RFID card), karakteristik dan kapasitas memory yang digunakan didalam chip, dan spesifikasi readernya. Dari sisi software, yang Anda butuhkan adalah interface yang mengirimkan output, dan diterima sebagai input pada aplikasi Anda. Interface ini dapat berupa API (Application Programming Interface), yang sering merupakan bagian dari SDK (Software Development Kit) yang disediakan oleh vendor hardware.Sedangkan “mantra” atau bahasa pemrograman yang Anda gunakan, adalah bahasa pemrograman favorit Anda, tentu saja jika Anda menggunakan SDK dari vendor, pastikan bahasa pemrograman yang Anda gunakan didukung oleh SDK tersebut. Agar aplikasi Anda dapat berkomunikasi dengan card reader dan memperoleh input darinya, aplikasi Anda harus terlebih dahulu mengenali card reader, untuk itu diperlukan proses inisiasi dengan card reader. Jika proses inisiasi telah berjalan, tugas berikut aplikasi Anda adalah menangkap data yang diberikan oleh card reader saat sebuah smart card terbaca. Jika sebuah smart card terdeteksi, Anda mungkin perlu melakukan beberapa validasi data yang diijinkan masuk dalam aplikasi. Mungkin Anda juga perlu mengambil beberapa informasi yang terdapat didalam smart card, mungkin berupa nomor induk karyawan atau informasi lainnya. Informasi disimpan didalam memory smart card berdasarkan blok-blok yang telah telah ditentukan. Jika diperlukan, aplikasi Anda dapat menuliskan kembali informasi pada lokasi blok memory tertentu pada smart card. Hingga langkah ini, beberapa perintah dasar yang harus Anda miliki berkaitan dengan hardware, adalah perintah-perintah:

1. Inisiasi card reader.

2. Validasi / Autentifikasi smart card.

3. Membaca informasi dari smart card.

4. Menulis informasi pada smart card.

Agar terdapat batas yang jelas, Anda perlu membuat suatu modul (mungkin Anda perlu memberikannya nama, misalnya modul Smart) yang mengakomodir kebutuhan hingga tahap ini. Perintah-perintah programming yang digunakan bisa jadi berbeda jika Anda menggunakan API atau SDK yang berbeda, tetapi fungsi dasarnya tetap sama. Selebihnya diluar modul Smart diatas, adalah aplikasi database yang umum, menyimpan dan memroses data, melakukan perhitungan yang diperlukan, menampilkan laporan, dan lain sebagainya.





Gambar 5 [Implementasi Smart Card]





Jika suatu saat Anda membuat aplikasi lain yang menggunakan smart card, Anda dapat menggunakan kembali (re-use) modul Smart diatas, dan berkonsentrasi pada proses bisnis di aplikasi dan database. Informasi didalam smart card, mungkin memiliki format tertentu, misalnya tertulis dalam karakter hexadecimal, untuk itu seperangkat library atau function konversi perlu Anda siapkan. ntuk mendukung keamanan, ada baiknya Anda melakukan enkripsi pada informasi penting yang ingin disimpan pada smart card. ari sebuah aplikasi sederhana, bukan tidak mungkin berkembang menjadi aplikasi yang lebih rumit seperti contoh-contoh yang telah dijelaskan diatas. Dalam hal ini, segala kemungkinan yang dapat dipikirkan untuk menjadi celah keamanan sistem harus diantisipasi dengan baik.



e-book gratis

Implementasi Smart Card pada Absensi



Read more...

Securing A Network

>> Minggu, 22 November 2009

In the prvious section, you learned that networks are susceptible to hackers and unauthorized access. As a result, organizations need to control access to the resources on a network. Most distributed netwroks supports multiple users, each with different access permissions to the resources and computers on the networks the informations and assets in an organization are crucial and keeping them safe constitues network security. The security model of a network should ensure

control on resources by using the following mechanisms :
  • Authenctication
  • Access Control
  • Data encryption
  • Auditing
  • Intrusion detection
  • Securing servers

Read more...

Understanding Network Security

Computers were intially used to simplify the task of computing, storing, and processing data. The number of computers and computer users was limited. As a result, the security of systems was not given much importance. The nature of computing has drastically changed over the past few years. With the introduction of network and the internet, there has been

an enormous increase in the number of computers users. Today, most organizations rely on computerized systems for storing data and coordinating businnes activities. In additions, a number of individual users use computers to avail different services, such as online shopping, online banking, and messaging.

Most computers connected to networks are vulnerable to attacks by viruses, worms, or unauthorized users. Individual users also face security threats, such as the theft and mususe of data and virus attacks.

What Is Security
The term security refers to the protection of system resources from intentional or accidental disclosure, destruction, or modification. The resources are infrastructure, hardware, software applications, files/directories, the data stored in the database, and the data in trainst. Securing resources involves implementing resource-usage policies to ensure that the resources are used per the organizational norms, unauthorized users are unable to misuse the resources, and authorized users are not denied access to the resources of the organizations.

To understand the need for security, consider the scenario of an organization that is using the IT setup. This organization is in the business of developing computer games and allows customer to download the games from its web site, which is hosted on the Microsoft Internet Information Server (IIS) Web server. In case a virus infects the files on the web server, the other IT resources of the organization also become vulanerable to the virus attack. The virus can also infect the PCs of all users donwloading games from this Web site. To prevent this type of virus attack, it is important to implement security on the Web server. In addition, PC users must implemetn security on the web server. In addition, PC users must does not infect their computer systems.

Read more...

Working With Web Servers

A Web server is a process running on the operating system, which enables users to access Web pages by using a browser. When a user requests a browser for files, text, and images, the browser sends the request over the Internet to remote computers. The web server software that runs on the remote computers sends the requested data back to the browser.

Example of web server software applications are: National Center for Supercomputing Applications (NCSA), Apache, IIS, Netscape Enterprise Server, Novell Web Server, and others.

Intorducing Internet Information Server

Internet Information Server (IIS) is a web Server from Microsoft Inc., which provides a highly realible, manageable, and scalable Web application infrastructure. This Web Server is a group of Web services. IIS help host web sites and make applications available without increasing system administration costs.

IIS provides many Web services, which are :
  • WWW service : The WWW service enable users to establish multiple Web sites on a single Web server. The integration of the WWW service with IIS provides a high level of security, better performance, and standards-based publishing protocols.
  • File Transfer Protocol (FTP) Service : The FTP service enables users to set up FTP sites for uploading and donwloading files.
  • Simple Mail Transfer Protocol (SMTP) Service : The SMTP service enables users to send and receive e-mail messages over the Internet.
  • Network News Transfer Protocol (NNTP) Service : The NNTP service enables users to host electronic discussion groups or newsgroups.
  • Front Page Server Extensions : Front Page Server Extensions enable user to create and edit HTML pages for a Web site directly on a server computer.
  • Common Gateway Interface (CGI) and Internet Server Application Programming Interface (ISAPI) : CGI and ISAP are programming interfaces that enables client/server applications over the Internet.

Read more...

Understanding Internetworking Servers

Internetworking services are the services in a networking environment that are accessible to users within an intranet or the Internet. These services allow you to share or use the resources located across networks. The servers that provide these services are known as

Internetworking Servers. Examples of Internetworking Servers are Mail servers, News Servers, and so on.

The following are some of the services provided by the Internetworking servers:
  • File Transfer - This service enables file transfer accross machines, using the HTTP protocol .
  • WWW - This services enables users to access the HTML pages at a published site.
  • E-mail - This services enables users to communicate with other users. The SMTP service needs to run for managing the receipt/delivery of mail messages.
  • Telnet - This services enables users to logon remotely to a server. THe Telnet service has to run for allowing the clients to log on to a remote server.
  • Usenet newsgroups - This service provides users a set of bulleting boards about different subjects. The NNTP service is neede for this purpose.
Other Internetworking Servers

Apart from web servers, mail servers, mailing list servers, and FTP servers, many other servers are used on an internetwork. Some of the internetworking servers are :
  • Domain Name Servers (DNS)
  • News Servers
  • Proxy and caching servers
  • Media servers
  • Certificate servers
  • Catalog servers
  • FAX servers
  • Transaction servers
  • Mirrored servers
Domain Name Servers
DNS is a service used on the Internet to translate Fully Qualified Domain Names (FQDN) to their actual IP addresses.

News Servers
A news server stores, organize, and distributes the messages posted in newsgroup.

Media Servers
A media server is a server that maintains streaming audio/video content.

Certificate Servers
Certificate are digitaly signed documents that enable you to use smart card logon, send encrypted e-mail, and sign electronic documents.

FAX Servers
A fax server allows multiple users to send faxes over the network. A fax server usually consists of three components, a computer running a Windows OS connected to any network, fax server application software, and a fax modem or an intelligent fax board.

Transaction Servers
A transaction server manages applications and databse transaction request on behalf of client computers.

Mirrored Servers
Similar to redudant disk drives, mirrored servers provide the fault-tolerance and redudancy that mission-critical information systems need.

Read more...

  © Blogger template Simple n' Sweet by Ourblogtemplates.com 2009

Back to TOP