EN 419212-5-2018 Application Interface for Secure Elements for Electronic Identification Authentication and Trusted Services - Part 5 Trusted eService.pdf
《EN 419212-5-2018 Application Interface for Secure Elements for Electronic Identification Authentication and Trusted Services - Part 5 Trusted eService.pdf》由会员分享,可在线阅读,更多相关《EN 419212-5-2018 Application Interface for Secure Elements for Electronic Identification Authentication and Trusted Services - Part 5 Trusted eService.pdf(58页珍藏版)》请在麦多课文档分享上搜索。
1、BSI Standards PublicationWB11885_BSI_StandardCovs_2013_AW.indd 1 15/05/2013 15:06Application Interface for Secure Elements for Electronic Identification, Authentication and Trusted ServicesPart 5: Trusted eServiceBS EN 419212-5:2018National forewordThis British Standard is the UK implementation of E
2、N 419212-5:2018. Together with BS EN 419212-1:2017, BS EN 419212-2:2017, BS EN 419212-3:2017 and BS EN 419212-4:2018, it supersedes BS EN 419212-1:2014 and BS EN 419212-2:2014, which are withdrawn.The UK participation in its preparation was entrusted to Technical Committee IST/17, Cards and security
3、 devices for personal identification.A list of organizations represented on this committee can be obtained on request to its secretary.This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application. The British Standards Ins
4、titution 2018 Published by BSI Standards Limited 2018ISBN 978 0 580 95131 2ICS 35.240.15Compliance with a British Standard cannot confer immunity from legal obligations.This British Standard was published under the authority of the Standards Policy and Strategy Committee on 30 April 2018.Amendments/
5、corrigenda issued since publicationDate Text affectedBRITISH STANDARDBS EN 419212-5:2018EUROPEAN STANDARDNORME EUROPENNEEUROPISCHE NORMEN 419212-5April 2018ICS 35.240.15 Supersedes EN 419212-1:2014, EN 419212-2:2014EUROPEAN COMMITTEE FOR STANDARDIZATIONCOMIT EUROPEN DE NORMALISATIONEUROPISCHES KOMIT
6、EE FR NORMUNGCEN-CENELEC Management Centre: Avenue Marnix 17, B-1000 Brussels 2018 CEN Ref. No. EN 419212-5:2018: EAll rights of exploitation in any form and by any means reserved worldwide for CEN national MembersApplication Interface for Secure Elements for Electronic Identification, Authenticatio
7、n and Trusted Services - Part 5: Trusted eServiceInterface applicative des lments scuriss utiliss comme dispositifs de cration de signature lectronique qualifie (cachet) - Partie 5 : Services lectroniques de confianceAnwendungsschnittstelle fr sichere Elemente zur elektronischen Identifikation, Auth
8、entisierung und fr vertrauenswrdige Dienste - Teil 5: Vertrauenswrdige elektronische DiensteThis European Standard was approved by CEN on 6 February 2017.CEN members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this European Standard the sta
9、tus of a national standard without any alteration. Up-to-date lists and bibliographical references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to any CEN member.This European Standard exists in three official versions (English, French, Ge
10、rman). A version in any other language made by translation under the responsibility of a CEN member into its own language and notified to the CEN-CENELEC Management Centre has the same status as the official versions.CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Croati
11、a, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey
12、 and United Kingdom.English VersionEN 419212-5:2018 (E)European foreword 4Introduction . 51 Scope . 62 Normative references 63 Terms and definitions . 64 Abbreviations and notation 65 Additional Service Selection . 66 Client/Server Authentication .106.1 General 106.2 Client/Server protocols 106.3 St
13、eps preceding the client/server authentication .116.4 Padding format 116.4.1 PKCS #1 v 1-5 Padding.116.4.2 PKCS #1 V 2.x (PSS) Padding 126.4.3 Building the DSI on ECDSA . 136.5 Client/Server protocol . 136.5.1 General. 136.5.2 Step 1 Read certificate 146.5.3 Step 2 Set signing key for client/server
14、internal authentication .156.5.4 Step 3 Internal authentication . 166.5.5 Client/Server authentication execution flow .176.5.6 Command data field for the client server authentication 197 Role Authentication 197.1 Role Authentication of the card . 197.2 Role Authentication of the server 207.3 Symmetr
15、ical external authentication . 207.3.1 Protocol . 207.3.2 Description of the cryptographic mechanisms .237.3.3 Role description .247.4 Asymmetric external authentication 247.4.1 Protocol based on RSA .248 Symmetric key transmission between a remote server and the ICC .278.1 Steps preceding the key t
16、ransport 278.2 Key encryption with RSA . 278.2.1 General. 278.2.2 PKCS#1 v1.5 padding 288.2.3 OAEP padding 288.2.4 Execution flow.298.3 Diffie-Hellman key exchange for key encipherment318.3.1 General. 318.3.2 Execution flow.339 Signature verification .349.1 General 349.2 Signature verification execu
17、tion flow. 359.2.1 General. 359.2.2 Step 1: Receive Hash 359.2.3 Step 2: Select verification key 369.2.4 Step 3: Verify digital signature 3710 Certificates for additional services 3710.1 File structure . 372Contents PageBS EN 419212-5:2018EN 419212-5:2018 (E)10.2 File structure . 3810.3 EF.C_X509.CH
18、.DS . 3810.4 EF.C.CH.AUT 3810.5 EF.C.CH.KE 3910.6 Reading Certificates and the public key of CAs 3911 APDU data structures .3911.1 Algorithm Identifiers 3911.2 General 3911.3 CRTs . 4011.3.1 General. 4011.3.2 CRT DST for selection of ICCs private client/server auth. key .4011.3.3 CRT AT for selectio
19、n of ICCs private client/server auth. key .4011.3.4 CRT CT for selection of ICCs private key .4011.3.5 CRT DST for selection of IFDs public key (signature verification) .41Annex A (informative) Security Service Descriptor Templates .42Annex B (informative) Example of DF.CIA 47Bibliography .54 ISO IS
20、O pub-date year All rights reserved 3BS EN 419212-5:2018EN 419212-5:2018 (E)European forewordThis document (EN 419212-5:2018) has been prepared by Technical Committee CEN/TC 224 “Personal identification and related personal devices with secure element, systems, operations and privacy in a multi sect
21、orial environment”, the secretariat of which is held by AFNOR.This European Standard shall be given the status of a national standard, either by publication of an identical text or by endorsement, at the latest by October 2018, and conflicting national standards shall be withdrawn at the latest by O
22、ctober 2018.Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. CEN shall not be held responsible for identifying any or all such patent rights.This document supersedes EN 419212-1:2014 and EN 419212-2:2014.This standard supports serv
23、ices in the context of electronic IDentification, Authentication and Trust Services (eIDAS) including signatures.In EN 419212 Part 2, the standard allows support of implementations of the European legal framework for electronic signatures, defining the functional and security features for a Secure E
24、lements (SE) (e.g. smart cards) intended to be used as a Qualified electronic Signature Creation Device (QSCD) according to the Terms of the “European Regulation on Electronic Identification and Trust Services for electronic transactions in the internal market” 22.A Secure Element (SE) compliant to
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- EN41921252018APPLICATIONINTERFACEFORSECUREELEMENTSFORELECTRONICIDENTIFICATIONAUTHENTICATIONANDTRUSTEDSERVICESPART5TRUSTEDESERVICEPDF

链接地址:http://www.mydoc123.com/p-1312118.html