EN 419212-1-2014 en Application Interface for smart cards used as Secure Signature Creation Devices - Part 1 Basic services (Remains Current)《安全签名生成设备智能卡的应用接口 第1部分 基本服务》.pdf
《EN 419212-1-2014 en Application Interface for smart cards used as Secure Signature Creation Devices - Part 1 Basic services (Remains Current)《安全签名生成设备智能卡的应用接口 第1部分 基本服务》.pdf》由会员分享,可在线阅读,更多相关《EN 419212-1-2014 en Application Interface for smart cards used as Secure Signature Creation Devices - Part 1 Basic services (Remains Current)《安全签名生成设备智能卡的应用接口 第1部分 基本服务》.pdf(254页珍藏版)》请在麦多课文档分享上搜索。
1、BSI Standards PublicationBS EN 419212-1:2014Application Interface for smartcards used as Secure SignatureCreation DevicesPart 1: Basic servicesBS EN 419212-1:2014 BRITISH STANDARDNational forewordThis British Standard is the UK implementation of EN 419212-1:2014.It supersedes BS EN 14890-1:2008 whic
2、h is withdrawn.The UK participation in its preparation was entrusted to TechnicalCommittee IST/17, Cards and personal identification.A list of organizations represented on this committee can beobtained on request to its secretary.This publication does not purport to include all the necessaryprovisio
3、ns of a contract. Users are responsible for its correctapplication. The British Standards Institution 2014. Published by BSI StandardsLimited 2014ISBN 978 0 580 77109 5ICS 35.240.15Compliance with a British Standard cannot confer immunity fromlegal obligations.This British Standard was published und
4、er the authority of theStandards Policy and Strategy Committee on 31 December 2014.Amendments issued since publicationDate Text affectedBS EN 419212-1:2014EUROPEAN STANDARD NORME EUROPENNE EUROPISCHE NORM EN 419212-1 December 2014 ICS 35.240.15 Supersedes EN 14890-1:2008English Version Application I
5、nterface for smart cards used as Secure Signature Creation Devices - Part 1: Basic services Interface applicative des cartes puces utilises comme dispositifs de cration de signature numrique scuriss - Partie 1 : Services de base Anwendungsschnittstelle fr Chip-Karten, die zur Erzeugung qualifizierte
6、r elektronischer Signaturen verwendet werden - Teil 1: Allgemeine Dienste This European Standard was approved by CEN on 27 September 2014. CEN members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this European Standard the status of a nation
7、al standard without any alteration. Up-to-date lists and bibliographical references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to any CEN member. This European Standard exists in three official versions (English, French, German). A versi
8、on in any other language made by translation under the responsibility of a CEN member into its own language and notified to the CEN-CENELEC Management Centre has the same status as the official versions. CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Cz
9、ech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and United Kingdom.
10、EUROPEAN COMMITTEE FOR STANDARDIZATION COMIT EUROPEN DE NORMALISATION EUROPISCHES KOMITEE FR NORMUNG CEN-CENELEC Management Centre: Avenue Marnix 17, B-1000 Brussels 2014 CEN All rights of exploitation in any form and by any means reserved worldwide for CEN national Members. Ref. No. EN 419212-1:201
11、4 EBS EN 419212-1:2014EN 419212-1:2014 (E) 2 Contents Page Foreword 7 Introduction .9 1 Scope . 10 2 Normative references . 10 3 Terms and definitions 11 4 Symbols and abbreviations . 15 5 Signature application . 18 5.1 Application Flow . 18 5.2 Trusted environment versus untrusted environment . 22
12、5.3 Selection of ESIGN application . 22 5.3.1 General . 22 5.3.2 Exceptions for Secure Messaging 23 5.4 Selection of cryptographic information application . 23 5.5 Concurrent usage of signature applications . 24 5.5.1 General . 24 5.5.2 Methods of channel selection . 24 5.5.3 Security issues on mult
13、iple channels 24 5.6 Security environment selection 24 5.7 Key selection . 25 5.8 Security Services 25 6 User verification 26 6.1 General . 26 6.2 Knowledge based user verification 26 6.2.1 General . 26 6.2.2 Explicit user verification 27 6.2.3 Password based mechanisms . 28 6.2.4 Presentation forma
14、ts 28 6.2.5 Retry and Usage counters . 28 6.2.6 Password Change . 29 6.2.7 Reset of RC and setting a new password 29 6.3 Biometric user verification 30 6.3.1 General . 30 6.3.2 Retrieval of the Biometric Information Template 31 6.3.3 Performing the biometric user verification 32 6.3.4 Reset of RC 34
15、 7 Digital Signature Service . 34 7.1 General . 34 7.2 Signature generation algorithms 35 7.3 Activation of digital signature service 35 7.4 General aspects 36 7.5 Signature Generation . 37 7.5.1 General . 37 7.5.2 No hashing in Card . 37 7.5.3 Partial hashing 38 7.5.4 All hashing in ICC . 39 7.6 Se
16、lection of different keys, algorithms and input formats . 40 7.6.1 General . 40 7.6.2 Restore an existing SE . 41 7.6.3 Setting the Hash Template (HT) of a current Security Environment (SE) . 42 7.6.4 Modify the Digital Signature Template (DST) of a current Security Environment (SE) . 42 7.7 Read ce
17、rtificates and certificate related information 43 BS EN 419212-1:2014EN 419212-1:2014 (E) 3 7.7.1 General . 43 7.7.2 Read certificate related CIOs 43 7.7.3 Read signers certificate from ICC . 44 7.7.4 Retrieval of the signers certificate from a directory service 44 8 Device authentication . 45 8.1 G
18、eneral . 45 8.2 Asymmetric Authentication introduction 46 8.3 Certification authorities and certificates . 46 8.3.1 Certificate chains . 46 8.3.2 Usage of link certificates 47 8.4 Authentication environments . 48 8.4.1 General . 48 8.4.2 SCA in trusted environment . 48 8.4.3 SCA in untrusted environ
19、ment 48 8.4.4 Specification of the environment . 49 8.4.5 Display message mechanism 49 8.4.6 Additional authentication environments . 49 8.5 Key transport and key agreement mechanisms 49 8.6 Key transport protocol based on RSA 50 8.6.1 General . 50 8.6.2 Authentication Steps . 52 8.6.3 Session Key c
20、reation 62 8.7 Device authentication with privacy protection . 63 8.7.1 General . 63 8.7.2 Authentication steps . 63 8.8 Privacy constrained Modular EAC (mEAC) protocol with non-traceability feature 82 8.8.1 General . 82 8.8.2 Example for traceability case . 83 8.8.3 Notation 83 8.8.4 Authentication
21、 steps . 84 8.8.5 Unlinkablity Mechanism with individual private keys . 99 8.9 Symmetric authentication scheme 108 8.9.1 General . 108 8.9.2 Authentication steps . 108 8.9.3 Session Key creation 112 8.10 Compute Session keys from key seed KIFD/ICC113 8.10.1 General . 113 8.10.2 Generation of key dat
22、a 113 8.10.3 Partitioning of the key data 113 8.10.4 Algorithm and method specific definition for key derivation . 113 8.10.5 Key derivation from passwords . 116 8.11 Compute send sequence counter SSC . 118 8.12 Post-authentication phase 118 8.13 Ending the secure session . 119 8.13.1 General . 119
23、8.13.2 Example for ending a secure session . 119 8.13.3 Rules for ending a secure session 119 8.14 Reading the Display Message 119 8.15 Updating the Display Message 122 9 Password-based authentication protocols . 123 9.1 General . 123 9.2 Notation 123 9.3 Authentication steps . 124 9.3.1 General . 1
24、24 9.3.2 Step 1 Reading the protocol relevant public parameters . 125 9.3.3 Step 2 Set PBM parameters and generate blinding point . 127 9.3.4 Step 3 Get encrypted nonce 128 9.3.5 Step 4.1 Map nonce and compute generator point for generic mapping . 129 9.3.6 Step 4.2 Map nonce and compute generator p
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- EN41921212014ENAPPLICATIONINTERFACEFORSMARTCARDSUSEDASSECURESIGNATURECREATIONDEVICESPART1BASICSERVICESREMAINSCURRENT

链接地址:http://www.mydoc123.com/p-716524.html