Command: EXTRADITE

USAGE extradite sdAID appAID
DESCRIPTION Extradite an applet to another Security Domain. For more information, refer to the Global Platform Install [for extradition] command description.
PARAMETER
NameDescriptionRequired
sdAID AID of the Security Domain to which the applet is to be extradited. Yes
appAID AID of the applet instance to be extradited. Yes
EXAMPLE The following example loads a signed applet (Load-file) and extradite it to the supplementary security domain with DAP verification.
  • Create a supplementary security domain (SSD) as an instance of the ISD with extradition support:
  • cm> install -i A00000000353900001 -q c90145 -s -b A0000000035350 A000000003535041
    Status: No Error
    
    cm> card-info
    Status: No Error
    
    Card Manager AID   :  A000000003000000
    Card Manager state :  OP_READY
    
        Sec. Domain:  SELECTABLE (SV------) A00000000353900001
        Load File  :      LOADED (--------) A0000000035350   (Security Domain)
         Module    :                        A000000003535041
    
  • Select the SSD and authenticate, set new keyset (1) for SSD:
  • cm> /select A00000000353900001
    Status: No Error
    
    cm> set-key 1/1/DES-ECB/707172737475767778797a7b7c7d7e7f 1/2/DES-ECB/707172737475767778797a7b7c7d7e7f 1/3/DES-ECB/707172737475767778797a7b7c7d7e7f
    
    cm> print-key
    255/1/DES-ECB/404142434445464748494A4B4C4D4E4F
    255/2/DES-ECB/404142434445464748494A4B4C4D4E4F
    255/3/DES-ECB/404142434445464748494A4B4C4D4E4F
    1/1/DES-ECB/707172737475767778797A7B7C7D7E7F
    1/2/DES-ECB/707172737475767778797A7B7C7D7E7F
    1/3/DES-ECB/707172737475767778797A7B7C7D7E7F
    
    cm> auth
    Status: No Error
    
    cm> put-keyset 1
    Status: No Error
    
  • Put the DAP key (Key1.pfx) into keyset (version) 0x73 / ID=1 of the SSD:
  • cm> put-pub-key --tokenpin sslight 115 Key1.pfx
    Status: No Error
    
  • Sign the cap-file with DAP key and it's verification through the SSD:
  • cm> /cap-sign --tokenpin sslight --target data/test--key1.cap -a GP211 bin/com/ibm/test/javacard/test.cap A00000000353900001 Key1.pfx
    
  • Upload the cap-file into the ISD and create an applet instance. Extradite the applet instance to the SSD:
  • cm> /card
    Status: No Error
    
    cm> auth mac
    Status: No Error
    
    cm> upload -c data/test--key1.cap
    Load report:
      447 bytes loaded in 0.2 seconds
      effective code size on card:
          + package AID       7
          + applet AIDs       16
          + classes           17
          + methods           110
          + statics           0
          + exports           0
         ------------------------------
            overall           150  bytes
    
    cm> install -i A00000000353800001  -q C9#() a0000000035380 A00000000353800001
    Status: No Error
    
    cm> extradite A00000000353900001 A00000000353800001
    Status: No Error
    
    cm> card-info
    Status: No Error
    
    Card Manager AID   :  A000000003000000
    Card Manager state :  OP_READY
    
        Application:  SELECTABLE (--------) A00000000353800001
        Sec. Domain:PERSONALIZED (SV------) A00000000353900001
        Load File  :      LOADED (--------) A0000000035350   (Security Domain)
         Module    :                        A000000003535041
        Load File  :      LOADED (--------) A0000000035380
         Module    :                        A00000000353800001
    
CONDITIONS A secure channel must be established (refer to the auth command)