EN 419212-2-2017 en Application Interface for Secure Elements for Electronic Identification Authentication and Trusted Services - Part 2 Signature and Seal Services.pdf
《EN 419212-2-2017 en Application Interface for Secure Elements for Electronic Identification Authentication and Trusted Services - Part 2 Signature and Seal Services.pdf》由会员分享,可在线阅读,更多相关《EN 419212-2-2017 en Application Interface for Secure Elements for Electronic Identification Authentication and Trusted Services - Part 2 Signature and Seal Services.pdf(110页珍藏版)》请在麦多课文档分享上搜索。
1、BSI Standards PublicationWB11885_BSI_StandardCovs_2013_AW.indd 1 15/05/2013 15:06Application Interface for Secure Elements for Electronic Identification, Authentication and Trusted ServicesPart 2: Signature and Seal ServicesBS EN 4192122:2017National forewordThis British Standard is the UK implement
2、ation of EN 4192122:2017. Together with BS EN 419212 parts 1, 3, 4 the value of the KID and the purpose of the signature password shall be indicated in the cryptographic information objects.Also other passwords may be of the type “local”.KID = 0x Key reference to global reference data; the value of
3、the KID and the purpose of the password shall be indicated in the cryptographic information objects.In order to allow the coexistence of EMVapplications and ESIGNapplications on the same ICC, only the three least significant bits should be used to differentiate keys. Refer to 6.5.12.2 Table 23 of 23
4、.Password Based Mechanisms should implement PIN error or usage counters in order to avoid exhaustive retries with the PIN or password.Table 5 VERIFY response APDUResponse ParameterMeaningData field absentSW1SW2 Refer to ISO/IEC 781646.2.3 Passwordbased mechanismsPassword based mechanisms provide an
5、implicit user verification by performing a multi-step authentication protocol, see PACEv2 in Clause 8 “Passwordbased authentication protocols”. In contrast to the application as device authentication protocol the corresponding password is not printed on the card but known by the user only. A reset c
6、ounter is recommended to be assigned to the password. A password change and a reset of the Reset Counter shall be done applying the RESET RETRY COUNTER command, see 6.2.6.6.2.4 Presentation formatsThe data field codes the verification data in one of the following formats.17BS EN 4192122:2017EN 41921
7、2-2:2017 (E)Figure 3 Example of coding 12345 in different presentation formatsFigure 3 demonstrates the coding when the different presentation formats are used. The actual presentation format may be retrieved from information presented in DF.CIA (refer to clause 14) unless implicitly known.National
8、regulations may specify additional security requirements.6.2.5 Retry and Usage countersIn order to avoid exhaustive search (brute force) attacks, the password should be protected by an appropriate retry or usage counter. For a password of 6 numerical digits the retry counter is typically 3 to achiev
9、e a guessing probability of 3/106. For longer or randomly chosen alphanumerical passwords a greater value of the retry counter can be selected with a similar or smaller guessing probability.This depends on the range where the password is selected from, e.g. if the password is a randomly chosen strin
10、g of 32 bytes, then a retry counter may even be not necessary. Passwords protecting the usage of signature keys shall consist, unless otherwise specified, of at least 6 digits or characters.In order to avoid an exhaustive search attack on the password under a known resetting code, the resetting code
11、 should be protected by an appropriate usage counter with a usage counter limit with a low value (typically U = 3 for a resetting code of numerical digits).After successful presentation, the appropriate retry counter is automatically reset to its initial value.For the definition of the counter types
12、 refer to Clause 3.6.2.6 Password ChangeThe CHANGE REFERENCE DATA command for changing the global password may be used under the same access conditions defined for the VERIFY command.The change of DF-specific (local) password can only be performed after selection of the appropriate DF.Execution Flow
13、 1 of 1 Table 6 Password Change command APDUCommand ParameterMeaningCLA according to ISO/IEC 78164INS 24 CHANGE REFERENCE DATA18 BS EN 4192122:2017EN 419212-2:2017 (E)Command ParameterMeaningP1 00 no algorithm specifiedP2 0x | 8x KID of referenced passwordLc field Length of command data fieldData fi
14、eld | For the description of the command refer to ISO/IEC 78164, 11.5.7.The length of the existing Reference Data are known in the ICC, so that neither a delimiter nor padding for filling up fixed formats is necessary. The length of the new password therefore computes Lnew= Lc Lold.Table 7 Password
15、Change response APDUResponse ParameterMeaningData field absentSW1SW2 Refer to ISO/IEC 781646.2.7 Reset of RC and setting a new passwordAfter N (N as specified by application) subsequent false presentations of the password, the password is locked and does not allow further usage of the protected func
16、tions.With the ISO/IEC 78164 command RESET RETRY COUNTER, the cardholder can initiate the reset of the RC to its initial value N. The Resetting Code shall have a minimum length of 6 digits2).It is also possible to define a new password with the RESET RC command.The reset of DF-specific (local) retry
17、 counter can only be performed after selection of the appropriate DF.Table 8 RESET RETRY COUNTER command APDUCommand ParameterMeaningCLA according to ISO/IEC 78164INS 2C RESET RETRY COUNTERP1 00 03P2 0x | 8x KID of referenced passwordLc field Length of command data fieldData field see belowFor the c
18、oding of the RESET RETRY COUNTER command refer to ISO/IEC 78164, 11.5.10.The content of the data field depends on the value of P1. The RESET RETRY COUNTER shall not change the security status, i.e. for using the signature creation key a VERIFY command is still required.P1 = 00 Resetting code followe
19、d without delimitation by new reference dataP1 = 01 Resetting codeP1 = 02 New reference dataP1 = 03 Data field absent2) digit can also be a character as part of a password.19BS EN 4192122:2017EN 419212-2:2017 (E)Table 9 RESET RETRY COUNTER response APDUResponse ParameterMeaningData field absentSW1SW
20、2 See ISO/IEC 78164After successful presentation of the Resetting Code, the retry counter of the referenced password is automatically reset to its initial value (typically N = 3) for a 6 numerical digit password.6.3 Biometric user verification6.3.1 GeneralThe support of a biometric user verification
21、 (on-card matching) is optional. User verification shall always be done with a password. If biometric user verification is available in the IFD and ICC then the biometric user verification can be performed instead of password verification.The following general methods of biometric user verification
22、are available:1. The sensor is offcard, whereas the following cases apply:a. The biometric verification data are sent from the interface device to the ICC and is compared by a match on card mechanism.b. The biometric verification and reference data are transformed by a suitable application specific
23、mechanism as e.g. Fuzzy Vault 39 to password / PIN format. The verification mechanism is then performed as used for passwords / PINs by means of the VERIFY command or a password based mechanism2. The sensor is oncard, so there is no need to transmit the biometric verification data from the interface
24、 device to the ICC.Transforming biometric data to a unique value (b.) has the consequence that the biometric algorithm is performed completely in the offcard application and the ICC only has to perform a user verification by means of direct comparison with yes / no response.The users have the benefi
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- EN41921222017ENAPPLICATIONINTERFACEFORSECUREELEMENTSFORELECTRONICIDENTIFICATIONAUTHENTICATIONANDTRUSTEDSERVICESPART2SIGNATUREANDSEALSERVICESPDF

链接地址:http://www.mydoc123.com/p-716527.html