It looks like the secure chip in the Nokia NFC phones does not support Elliptic Curve Cryptography - RSA works fine though. I've tried to create ECC keypairs using NIST curve specifications SECP160K1 and SECT163K1 but the response is 0x6F03 (no such algorithm). However the latter curve does work (signature generation and verification OK) on my single and dual interface smart cards (JCOP20/JCOP30).
In my previous post I saw that the COS for the Nokia 6131 NFC is G&D SmartCafe Expert 3.1 In G&D's sparse public documentation and SmartCafe Expert 3.1 flyer only RSA is mentioned so I conclude ECC is definitely not supported. As an interesting side note, the flyer says the COS is JavaCard 2.2.1 compliant - which confirms a conclusion in an earlier post.
Since there are so few other mobiles with NFC I guess we'll have to wait for microSD cards with embedded NFC and secure elements which support ECC.
Tuesday, 31 August 2010
Secure Chip Identifier List
Useful resource: a list of ATR/ATS for secure chip ICs and their COSs. Mirror here.
From the list:
Edit: Rousseau also hosts a free Python ATR parsing service based on the list above.
I also found "Visa Approved Visa GlobalPlatform Card Products as of December 2007" which indicates the COS and IC vendor on VISA certified secure chips.
More (albeit slightly off-topic): "Visa Approved, Visa Smart Debit Credit (VSDC) Chip Cards as of December 2007"
A list of VISA-related documents can be found here (thanks to TwinTech and Google Translate).
From the list:
3B 88 80 01 00 73 C8 40 13 00 90 00 71 Nokia 6131 NFC phone http://wiki.forum.nokia.com/index.php/Nokia_6131_NFC_-_FAQs Giesecke & Devrient’s (G&D) Sm@rtCafé Expert 3.1
3B 8D 80 01 0D 78 80 84 02 00 73 C8 40 13 00 90 FF F8 Nokia 6212 phone seen as NFC device
Edit: Rousseau also hosts a free Python ATR parsing service based on the list above.
I also found "Visa Approved Visa GlobalPlatform Card Products as of December 2007" which indicates the COS and IC vendor on VISA certified secure chips.
More (albeit slightly off-topic): "Visa Approved, Visa Smart Debit Credit (VSDC) Chip Cards as of December 2007"
A list of VISA-related documents can be found here (thanks to TwinTech and Google Translate).
Wednesday, 4 August 2010
Updated: JCOP feature info
Tracking back to a previous post where I listed features of NXP JCOP: NXP's linecard for PKI processors has been updated to document 75016728, including a new section about JCOP J2A and J3A (page 10).
Tuesday, 3 August 2010
Machine Readable Travel Documents
While hunting for info about file systems on Java Card I came across this very useful reference implementation of the ICAO MRTD standard by Radboud Uni. It demonstrates (among other things) how to wrap and unwrap SCP02 protected APDUs and how to chain object and byte arrays into a very rudimentary file system (see FileSystem.java).
Wednesday, 30 June 2010
PC/SC and contactless card ATS
I was recently puzzled by the different ATS values returned by my Omnikey Cardman 5321 (connected to PC) and my NXP PN531 (connected to embedded system). I tried with both the Nokia 6131 NFC and an NXP JCOP31 smart card; here's what the output looked like (all hex):
Nokia 6131 ...
... with PN531:
... and with Cardman 5321:
Smart card:
... with PN531:
After scratching my head for a while I gave in and RTFM for the Cardman reader. And I was reminded again that glossing over details is never good, because in fact ATS != ATR. The PC/SC standard (PC/SC v2.01 “Interoperability Specification for ICCs and Personal Computer Systems”) requires that the driver convert the received ATS to an ATR.
The PC/SC specifications can be downloaded here.
Nokia 6131 ...
... with PN531:
SENS_RES 0200
SEL_RES 38
NFCIDLENGTH 4
NFCID1 5039F5A8
ATS 0D 78 80 84 02 00 73 C8 40 13 00 90 00 .x....s.@....
... and with Cardman 5321:
(same NFCID1)
ATR 3B 88 80 01 00 73 C8 40 13 00 90 00 71
Smart card:
... with PN531:
SENS_RES 0400... and with Cardman 5321:
SEL_RES 28
NFCIDLENGTH 4
NFCID1 E0742A86
ATS 0D 38 33 B1 4A 43 4F 50 33 31 56 32 32 .83.JCOP31V22
(again, NFCID1 is similar)
ATR 3B 89 80 01 4A 43 4F 50 33 31 56 32 32 4A
After scratching my head for a while I gave in and RTFM for the Cardman reader. And I was reminded again that glossing over details is never good, because in fact ATS != ATR. The PC/SC standard (PC/SC v2.01 “Interoperability Specification for ICCs and Personal Computer Systems”) requires that the driver convert the received ATS to an ATR.
The PC/SC specifications can be downloaded here.
Wednesday, 26 May 2010
OpenSC Project
New resource found, OpenSC Project :
OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the PKCS#11 API so applications supporting this API (such as Mozilla Firefox and Thunderbird) can use it. On the card OpenSC implements the PKCS#15 standard and aims to be compatible with every software/card that does so, too.In the Java section there are useful tips and links about JNI for PKCS#11, javax.smartcardio, PKCS#15 and GlobalPlatform.
Labels:
GlobalPlatform,
OpenSC,
PKCS#11,
PKCS#15
Monday, 19 April 2010
Smart cards: The commercial project perspective
I came across a website containing very useful information for smart card projects: http://www.smartcardbasics.com/
It is an excellent starting point and reference source for any project leader since it contains - among other things - overviews of standards (ISO7816, FIPS120, EMV etc), smart card system planning, and security (systems, infosec, cryptography, and more).
It is an excellent starting point and reference source for any project leader since it contains - among other things - overviews of standards (ISO7816, FIPS120, EMV etc), smart card system planning, and security (systems, infosec, cryptography, and more).
Subscribe to:
Posts (Atom)