JCShell Tutorial - Authorization
Select the Card Manager Plugin
The JCShell provides a default command set. Use the Card Manager Plugin implementation
for communication with a card or simulation.
Usage: /card -a a000000003000000 -c com.ibm.jc.CardManager
(for more info see: /card command description)
Setting keys
Authorization is a Global Platform defined processs which requires three keys on both sides (on-card and off-card).
- MAC key
- ENC key
- Sensitive data key
Set the keys on the client side with the command:
Usage: set-key keydef
(for more info see: set-key command description)
Use the default keyset for any JCOP simulation:
Usage: set-key 255/1/DES-ECB/404142434445464748494a4b4c4d4e4f
255/2/DES-ECB/404142434445464748494a4b4c4d4e4f
255/3/DES-ECB/404142434445464748494a4b4c4d4e4f
In all other cases, use the keyset provided with your individual card.
Note: The "set-key" command registers only the keyset on the client side. The keyset on the card
can't be modified by user action.
Authorization
The Card Manager Plugin provides two authorization methods:
- Single step authorization method
Usage: auth [plain|mac|enc] [keydata]
(for more info see: auth command description)
- Double step authorization method
- Initialize Update
Usage: init-update [key-set [scp]]
(for more info see: init-update command description)
- External Authenticate
Usage: ext-auth [plain|mac|enc|rmac|crmac|crmacenc]
(for more info see: ext-auth command description)
Inspect the Card
Retrieve the current card content to check what's on your card before starting any other actions.
Usage: card-info
(for more info see: card-info command description)