Secure Channel Communication

Applications that utilize the services of security domains can use a Secure Channel Protocol (SCP) supported by their associated security domains. These protocols provide a means by which the Issuer Security Domain, a Security Domain, or an application may communicate with an off-card entity within a logically secure environment.

The secure channel provides a secure communication channel between a card and an off-card entity during a application session. It can be divided into three sequential phases:

  1. Secure Channel Initiation - The on-card application and the off-card entity have exchanged sufficient information enabling them to perform the required cryptographic functions. The Secure Channel Session initiation always includes the authentication of the off-card entity by the on-card application.

  2. Secure Channel Operation - The on-card application and the off-card entity exchange data within the cryptographic protection of the Secure Channel Session. The Secure Channel services offered may vary from one Secure Channel Protocol to the other.

  3. Secure Channel Termination - Either the on-card application or the off-card entity determines that no further communication is required or allowed via an established Secure Channel Session.

Secure Channel Protocol Identifier

The secure channel protocol identifies which particular secure communication protocol and set of security services are implemented in a Security Domain.
The following protocols are supported:

For further details about secure channel communications, refer to the 'GlobalPlatform Card Specification'