DIN CEN TS 15480-2-2012 Identification card systems - European Citizen Card - Part 2 Logical data structures and security services English version CEN TS 15480-2 2012《识别卡系统 欧洲市民卡 第.pdf
《DIN CEN TS 15480-2-2012 Identification card systems - European Citizen Card - Part 2 Logical data structures and security services English version CEN TS 15480-2 2012《识别卡系统 欧洲市民卡 第.pdf》由会员分享,可在线阅读,更多相关《DIN CEN TS 15480-2-2012 Identification card systems - European Citizen Card - Part 2 Logical data structures and security services English version CEN TS 15480-2 2012《识别卡系统 欧洲市民卡 第.pdf(180页珍藏版)》请在麦多课文档分享上搜索。
1、September 2012Normenausschuss Informationstechnik und Anwendungen (NIA) im DINPreisgruppe 36DIN Deutsches Institut fr Normung e. V. Jede Art der Vervielfltigung, auch auszugsweise, nur mit Genehmigung des DIN Deutsches Institut fr Normung e. V., Berlin, gestattet.ICS 35.240.15Zur Erstellung einer DI
2、N SPEC knnen verschiedene Verfahrensweisen herangezogen werden: Das vorliegende Dokument wurde nach den Verfahrensregeln einer Vornorm erstellt.!$sT:= | := := | := PrK:= PuK := | := CH := | | := ICC := IFD := S:= | | | := AUT := KA:= RA := KE := := | := C_CV := C_X509 DIN CEN/TS 15480-2 (DIN SPEC 91
3、130-2):2012-09 CEN/TS 15480-2:2012 (E) 10 := | EXAMPLES: 1) PrK.ICC.AUT = Private key of the ICC for device authentication; 2) PuK.S.KA = Public key of the sender used for key agreement; 3) C_X509.CH.AUT = Certificate of the card holder for client/server authentication. In addition, the following no
4、tation is used: KICC/IFDRandomness provided by ICC and IFD used for session key derivation RND.ICC Random number of the ICC RND.IFD Random number of the IFD SN.ICC Serial number of the ICC SN.IFD Serial number of the IFD 5 Data elements and data structures 5.1 Supported data Structures The European
5、Citizen Card shall support the data structures described in 5.2. These data structures are used to store externally accessed data (certificates, card serial number, .). Exceptions from this rule, i.e. cases where data objects are used that can be accessed by a GET DATA command are listed in the desc
6、ription of the services. In addition, the card may support further data structures including proprietary structures to handle data as long as these structures have no effect on the services defined in this Technical Specification, i.e. on the interoperability. For example, the storage of private and
7、 secret keys, the storage of PIN reference data and of security environments is not defined in this Technical Report. The storage of these entities is out of the scope of this Technical Specification and implementation specific. 5.2 Access to data structures 5.2.1 File system considerations The Euro
8、pean Citizen Card might embed a virtual machine or be a native operating system. 1) The card may include an MF. The differentiation between cards with or without an MF is based on the card ATR/ATS or the content of EF.ATR/INFO. See ISO/IEC 7816-4:2005, 8.1 card service data byte. Consequently, the c
9、ard shall include the card service data byte when returning the ATR/ATS. 2) If an application is selected implicitly, i.e., always selected at the card reset, it has the default selection privilege. The corresponding AID shall be indicated in the historical bytes or the EF.ATR. 3) The root is the MF
10、 or the applet instance having the default selection privilege. This depends on the card manufacturer implementation choice (native or JavaCard implementation). 4) Three basic file types are supported (refer to ISO/IEC 7816-4 for definitions of EF, DF and ADF): DIN CEN/TS 15480-2 (DIN SPEC 91130-2):
11、2012-09 CEN/TS 15480-2:2012 (E) 11 i) transparent EF; ii) dedicated files DF; iii) application dedicated files ADF 5) For cards without MF, each applet instance matches with at least one application DF (ADF). 6) All cards shall contain an EF.DIR file. i) The EF.DIR is always under the root. ii) The
12、file identifier of EF.DIR is: 2F00, the short EF identifier is 30 = 1E =11110 bin. 5.3 Answer to reset (ATR) / answer to select (ATS) 5.3.1 General The ATR of the card shall follow the rules indicated in ISO/IEC 7816-3 and ISO/IEC 7816-4. The ATS of the card shall follow the rules specified in ISO/I
13、EC 14443-4. Data objects for card identification shall be provided in the historical data bytes of the ATR/ATS or in an optional EF.ATR/INFO (see, 5.3.3). In case of ISO/IEC 14443-4 and protocol type B no ATS is available and for this reason the presence of the EF.ATR/INFO is mandatory in this case.
14、 Table 1 provides the list of data objects which may be supported by the card in the ATR/ATS in the Compact-TLV format as defined in ISO/IEC 7816-4, Table 2 provides the data objects in EF.ATR/INFO for the BER-TLV structure. The data objects defined in Table 1 and Table 2 have to be used as given in
15、 the tables, these are not application specific. 5.3.2 Historical bytes The ATR/ATS contains configuration data so that ICC and IFD can communicate together (protocol, speed, etc.). The category indicator as the first historical byte shall be set to the value 00. Therefore, the last three bytes shal
16、l be a status indicator, i.e. a card life cycle status indicator followed by two status bytes SW1-SW2. Transmission in historical bytes for the data objects “card service data“ and “card capabilities“ is mandatory. For other data objects the decision is left to the card manufacturer. If a data objec
17、t from Table 1 is used in the historical bytes the length of the DO shall be used as defined in the table. Furthermore, the definitions for the coding of content of the data objects given in the table are mandatory. The coding of further parameters in the content of the data objects is left to the c
18、hoice of the card manufacturer but shall follow the rules given in ISO/IEC 7816-4. DIN CEN/TS 15480-2 (DIN SPEC 91130-2):2012-09 CEN/TS 15480-2:2012 (E) 12 Table 1 Card Identification Historical Bytes Byte # Name Value Description 1 Category indicator 00 COMPACT-TLV data objects followed by a status
19、 indicator shall be present as the last three historical bytes 2 Card service data tag 31 Tag for next byte 3 Card service data byte B9 or B8 b8=1: Application selection by full DF name b6=1: BER-TLV DO are present in EF.DIR b5=1: BER-TLV DO present in EF.ATR/INFOa b4.b2=100: EF.DIR/EF.ATR is a tran
20、sparent EF (use READ BINARY) b1 = 0: Card with MF b1 = 1: Card without MF 4 Pre-issuing DO tag 64 Tag for next 4 bytes 5 IC manufacturer XX IC Manufacturer according ISO/IEC 7816-6 6 Type of the IC XX defined by the IC or card manufacturer 7 OS Version XX Version of the operating system defined by c
21、ard manufacturer 8 Discretionary data XX Discretionary data 9 Card capabilities data tag 73 Tag for next 3 bytes 10 Card capabilities data byte 1 null Selection method 94 DF selection b8=1: DF selection full name b5=1: DF selection using file identifier EF selection b3=1: file selection using short
22、file identifier is supported 11 Card capabilities data byte 2 null Data coding byte 01 b4.b1 = 0001: data unit size is 1 byte 12 Card capabilities data byte 3 null Miscellaneous C0, 80, D0 or 90 b8=1: command chaining is supported b7=0: Extended Lc and Le fields not supported b7=1: Extended Lc and L
23、e fields supported b5, b4=00: no logical channel supported b5, b4=10: channel number assignment by the card Maximum number of channels supported: 4 13 Status indicator tag 8x Tag for next byte, x is either 2 or 3 14 Status indicator LCS | 9000 Life Cycle State (optional) followed by status words SW1
24、-SW2 aDO may be present in EF.ATR/INFO for compatible tag The list and the order of the historical bytes are compulsory unless further items complete these historical bytes according to the smart card manufacturers policy (e.g. reference and version of the application). DIN CEN/TS 15480-2 (DIN SPEC
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- DINCENTS1548022012IDENTIFICATIONCARDSYSTEMSEUROPEANCITIZENCARDPART2LOGICALDATASTRUCTURESANDSECURITYSERVICESENGLISHVERSIONCENTS1548022012

链接地址:http://www.mydoc123.com/p-663388.html