Secure Channel Communication
Applications that utilize the services of security domains can use a
Secure Channel Protocol (SCP) supported by their associated security domains.
These protocols provide a means by which the Issuer Security Domain, a Security Domain,
or an application may communicate with an off-card entity within a logically secure environment.
The secure channel provides a secure communication channel between a card and an off-card entity during a
application session. It can be divided into three sequential phases:
- Secure Channel Initiation - The on-card application and the off-card entity have exchanged sufficient
information enabling them to perform the required cryptographic functions. The Secure Channel Session initiation
always includes the authentication of the off-card entity by the on-card application.
- Secure Channel Operation - The on-card application and the off-card entity exchange data within the
cryptographic protection of the Secure Channel Session. The Secure Channel services offered may vary from one
Secure Channel Protocol to the other.
- Secure Channel Termination - Either the on-card application or the off-card entity determines that no
further communication is required or allowed via an established Secure Channel Session.
Secure Channel Protocol Identifier
The secure channel protocol identifies which particular secure communication protocol and
set of security services are implemented in a Security Domain.
The following protocols are supported:
- SCP01 - The Secure Channel Protocol '01' is backward compatible with the Open Platform Card Specification version 2.0.1'
- SCP02 - The Secure Channel Protocol '02' includes services in addition to those provided by Secure Channel Protocol '01'
as well as optimizing the operation of some services compared to SCP01
For further details about secure channel communications, refer to the 'GlobalPlatform Card Specification'