|
||||||||||
| PREV CLASS NEXT CLASS | FRAMES NO FRAMES | |||||||||
| SUMMARY: NESTED | FIELD | CONSTR | METHOD | DETAIL: FIELD | CONSTR | METHOD | |||||||||
java.lang.Objectcom.ibm.jc.JCApplet
com.ibm.jc.OPApplet
This class implements the off-card behavior of an applet on a (Open) Global Platform JavaCard. It provides functionality to manage keys and to communicate over a secure channel as defined in Global Platform 2.1.1 ( Secure Messaging Protocol (SCP) 01 and 02). Note: It's optional for an applet to support any of the Open Platform commands provided here.
| Field Summary | |
static int |
ADD_NEW_KEYSET
PutKey mode: add new key set |
protected static int |
APDU_BIG_MAC
Indicates MAC spanning multiple APDU - if APDU_MAC is on |
static int |
APDU_CLR
Security level: No secure messaging |
static int |
APDU_CRMAC
Security level: C-MAC and R-MAC (command and response MACing) Applicable for SCP 02 only. |
static int |
APDU_CRMAC_ENC
Security level: C-DECRYPTION, C-MAC and R-MAC Applicable for SCP 02 only. |
static int |
APDU_ENC
Security level: C-DECRYPTION and C-MAC (command MACing and encryption) |
static int |
APDU_MAC
Security level: C-MAC (command MACing) |
protected static int |
APDU_MAC_START
Indicates the first APDU. |
static int |
APDU_RMAC
Security level: R-MAC (response MACing). |
static int |
APDU_SUPER_MAC
Deprecated. |
static byte |
APPLICATION_LCD
Accessing application/Security Domain life cycle data. |
static int |
BLOCKED
application life cycle state |
static int |
CARD_TERMINATE_PRIV
application privilege: Card Terminate |
static byte |
CM_LCD
Accessing Card Manager life cycle data. |
static int |
CM_LOCK_PRIV
application privilege: Card Manager Lock |
static byte |
GS_FIRST_ALL
Get first or all occurence(s) |
static byte |
GS_FORMAT_1
Response structured according Global Platform 2.1.1 table 9-22 and 9-24 |
static byte |
GS_FORMAT_2
Response structured according Global Platform 2.1.1 table 9-23 |
static byte |
GS_NEXT
Get next occurence(s) |
protected byte[] |
icv
Temp buffer for DES ICV. |
static int |
IMP_SELECTABLE_PRIV
application privilege: Implicit Selectable (default applet) |
static int |
INSTALLED
application life cycle state |
protected byte[] |
K_dek
Session key for sensitive data encryption. |
protected byte[] |
K_ea
Session key for encryption and authentication. |
protected byte[] |
K_m
Session key for C-MAC generation. |
protected byte[] |
K_rm
Session key for R-MAC generation. |
protected OPKey |
Kkek
Static key encryption key of the key set version used during Initialize Update. |
static byte |
LOAD_FILE_LCD
Accessing Executable Load File life cycle data. |
static byte |
LOAD_FILE_MODULE_LCD
Accessing Executable Load File and Executable Module life cycle data. |
static int |
LOCKED
application life cycle state |
static int |
LOGICALLY_DELETED
application life cycle state |
static int |
macSize
Deprecated. |
static int |
MANDATED_DAP_PRIV
application privilege: Mandated DAP verification |
static int |
MODIFY_KEYSET
PutKey mode: modify key set |
protected int |
msgMode
Secure messaging mode |
static int |
NO_PRIVS
application privilege: none |
static int |
NO_SESSION
Session state: No secure channel session established |
static int |
NOT_AVAILABLE
application life cycle state |
static int |
PERSONALIZED
application life cycle state |
static int |
PIN_CHANGE_PRIV
application privilege: PIN Change |
static int |
REPLACE_KEYSET
PutKey mode: replace key set |
protected byte[] |
ricv
Temp buffer for DES ICV. |
protected byte[] |
rmbuf
Buffer for R-MAC calculation |
static int |
SCP_01_05
secure channel protocol 01 option '05' (compatible with VOP 2.0.1') |
static int |
SCP_01_15
secure channel protocol 01 option '15' |
static int |
SCP_02_04
secure channel protocol 02 option '04' |
static int |
SCP_02_05
secure channel protocol 02 option '05' |
static int |
SCP_02_0A
secure channel protocol 02 option '0A' |
static int |
SCP_02_0B
secure channel protocol 02 option '0B' |
static int |
SCP_02_14
secure channel protocol 02 option '14' |
static int |
SCP_02_15
secure channel protocol 02 option '15' |
static int |
SCP_02_1A
secure channel protocol 02 option '1A' |
static int |
SCP_02_1B
secure channel protocol 02 option '1B' |
static int |
SCP_UNDEFINED
secure channel protocol undefined |
protected int |
scpMode
Secure Channel Protocol mode |
static int |
SD_DAP_PRIV
application privilege: Security Domain with DAP verification |
static int |
SD_DELEGATE_PRIV
application privilege: Security Domain with Delegated Managment |
static int |
SD_PRIV
application privilege: Security Domain |
static int |
SELECTABLE
application life cycle state |
static int |
SESSION_AUTH
Session state: Secure channel established (mutual authentication done) |
static int |
SESSION_OK
Session state: Card authenticated (Initialize Update done) |
protected int |
sessionMode
Global Platform session mode |
static int |
VOP_201
Open Platform 2.0.1' compatible session mode |
static int |
VOP_211
Global Platform 2.1.1 session mode |
static int |
VOP_NONE
No Global Platform session established |
| Fields inherited from class com.ibm.jc.JCApplet |
apdu |
| Constructor Summary | |
OPApplet()
|
|
OPApplet(JCApplet app)
Create the off-card representation of an OpenPlatform JavaCard applet. |
|
OPApplet(JCard card,
byte[] aid,
int aidBeg,
int aidLen)
Create the off-card representation of an OpenPlatform JavaCard applet. |
|
OPApplet(JCard card,
byte[] aid,
int aidBeg,
int aidLen,
byte state,
byte privs)
Create the off-card representation of an OpenPlatform JavaCard applet. |
|
| Method Summary | |
void |
beginRMACSession(int secLevel,
byte[] data,
int off,
int len)
Global Platform BEGIN R-MAC SESSION command. |
OPKey |
deleteKey(int keySet,
int keyId)
Delete specified key from key set. |
void |
endRMACSession()
Global Platform END R-MAC SESSION command. |
void |
externalAuthenticate(int secLevel)
Global Platform EXTERNAL AUTHENTICATE command. |
void |
flush()
Flush secure channel parametes and reset the session state. |
byte[] |
getData(int p1,
int p2)
Global Platform GET DATA command. |
OPKey |
getKey(int keySet,
int keyId)
Looks for a key in the off-card repository. |
OPKey[] |
getKeys()
Returns the off-card key repository. |
int |
getMaxPayload()
Returns the maximum command APDU payload (Lc) length, which can currently be sent depending on the secuity level of the secure channel. |
int |
getPrivileges()
|
int |
getSCP()
Returns current secure channel protocol version. |
int |
getSecurityLevel()
Returns the security level of the current secure channel session. |
int |
getSessionMode()
|
int |
getSessionState()
|
int |
getState()
|
byte[] |
getStatus(byte p1)
Deprecated. |
byte[] |
getStatus(byte p1,
byte p2,
byte[] qualifier,
int off,
int len)
Global Platform GET STATUS command. |
void |
initializeUpdate(int keySet,
int keyId)
Deprecated. use initializeUpdate(int keySet, int keyId, int scp) |
void |
initializeUpdate(int keySet,
int keyId,
int scp)
Global Platform INITIALIZE UPDATE command. |
void |
putData(int p1,
int p2,
byte[] data,
int beg,
int len)
Visa Open Platform PUT DATA command. |
void |
putKey(int mode,
OPKey[] keys,
int rSet)
Global Platform PUT KEY command. |
byte[] |
select()
Select applet. |
byte[] |
send(byte[] data,
int beg,
int len)
Send some APDU via the applets secure channel. |
protected byte[] |
sendAPDU(int lc,
int le)
Send APDU via secure channel. |
OPKey |
setKey(OPKey key)
Add some key to the applets off-card repository. |
void |
setSCP(int scp)
Allows defining the secure channel protocol to be used in subsequent implicit channel setup. |
void |
setSecurityLevel(int level)
Deprecated. |
void |
setStatus(byte p1,
int p2,
byte[] id)
Global Platform SET STATUS command. |
void |
storeData(byte[] data,
int beg,
int len,
int blockNumber,
boolean last)
Global Platform STORE DATA command. |
void |
storeKeyset(OPKey[] keys,
int rSet)
Set Secure Channel key information via a Global Platform STORE DATA command. |
void |
storePKDAPKey(OPKey key)
Set DAP verification public key information via a Global Platform STORE DATA command. |
| Methods inherited from class com.ibm.jc.JCApplet |
equals, getAID, getCard, getTerminal, setAID, setCard, setHeader |
| Methods inherited from class java.lang.Object |
clone, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait |
| Field Detail |
public static final int NOT_AVAILABLE
public static final int LOGICALLY_DELETED
public static final int INSTALLED
public static final int SELECTABLE
public static final int PERSONALIZED
public static final int BLOCKED
public static final int LOCKED
public static final int SD_PRIV
public static final int SD_DAP_PRIV
public static final int SD_DELEGATE_PRIV
public static final int CM_LOCK_PRIV
public static final int CARD_TERMINATE_PRIV
public static final int IMP_SELECTABLE_PRIV
public static final int PIN_CHANGE_PRIV
public static final int MANDATED_DAP_PRIV
public static final int NO_PRIVS
public static final int SCP_UNDEFINED
public static final int SCP_01_05
public static final int SCP_01_15
public static final int SCP_02_04
public static final int SCP_02_05
public static final int SCP_02_0A
public static final int SCP_02_0B
public static final int SCP_02_14
public static final int SCP_02_15
public static final int SCP_02_1A
public static final int SCP_02_1B
protected static final int APDU_BIG_MAC
msgMode,
Constant Field Valuesprotected static final int APDU_MAC_START
msgMode,
Constant Field Valuespublic static final int APDU_CLR
getSecurityLevel(),
Constant Field Valuespublic static final int APDU_MAC
getSecurityLevel(),
Constant Field Valuespublic static final int APDU_ENC
getSecurityLevel(),
Constant Field Valuespublic static final int APDU_RMAC
getSecurityLevel(),
Constant Field Valuespublic static final int APDU_CRMAC
getSecurityLevel(),
Constant Field Valuespublic static final int APDU_CRMAC_ENC
getSecurityLevel(),
Constant Field Valuespublic static final int APDU_SUPER_MAC
public static final int NO_SESSION
getSessionState(),
Constant Field Valuespublic static final int SESSION_OK
getSessionState(),
Constant Field Valuespublic static final int SESSION_AUTH
getSessionState(),
Constant Field Valuespublic static final byte CM_LCD
public static final byte APPLICATION_LCD
public static final byte LOAD_FILE_LCD
public static final byte LOAD_FILE_MODULE_LCD
public static final byte GS_FIRST_ALL
public static final byte GS_NEXT
public static final byte GS_FORMAT_1
public static final byte GS_FORMAT_2
public static final int macSize
public static final int MODIFY_KEYSET
public static final int REPLACE_KEYSET
public static final int ADD_NEW_KEYSET
public static final int VOP_201
public static final int VOP_211
public static final int VOP_NONE
protected int sessionMode
protected int scpMode
protected byte[] icv
protected byte[] ricv
protected byte[] rmbuf
protected int msgMode
protected byte[] K_m
initializeUpdate(int, int)protected byte[] K_ea
initializeUpdate(int, int)protected byte[] K_rm
initializeUpdate(int, int)protected byte[] K_dek
initializeUpdate(int, int)protected OPKey Kkek
initializeUpdate(int, int)| Constructor Detail |
public OPApplet(JCard card,
byte[] aid,
int aidBeg,
int aidLen,
byte state,
byte privs)
card - the JavaCard on which this applet livesaid - the buffer containing the AID of the appletaidBeg - start offset for AIDaidLen - the length of the applet AID. This value must be
in the range [5;16].state - the life cycle state of the applet.privs - the privileges of the applet.JCApplet
public OPApplet(JCard card,
byte[] aid,
int aidBeg,
int aidLen)
card - the JavaCard on which this applet livesaid - the buffer containing the AID of the appletaidBeg - start offset for AIDaidLen - the length of the applet AID. This value must be
in the range [5;16].JCAppletpublic OPApplet(JCApplet app)
app - JCApplet object.JCAppletpublic OPApplet()
| Method Detail |
public int getState()
NOT_AVAILABLE,
LOGICALLY_DELETED,
INSTALLED,
SELECTABLE,
PERSONALIZED,
BLOCKED,
LOCKEDpublic int getPrivileges()
NO_PRIVS,
SD_PRIV,
SD_DAP_PRIV,
SD_DELEGATE_PRIV,
MANDATED_DAP_PRIV,
CM_LOCK_PRIV,
CARD_TERMINATE_PRIV,
IMP_SELECTABLE_PRIV,
PIN_CHANGE_PRIVpublic int getMaxPayload()
public byte[] send(byte[] data,
int beg,
int len)
getSessionState() == NO_SESSION)
and a SCP, which allows implicit session initiation has been set via
setSCP(), then implicit session initiation takes place automatically.
data - APDU bufferbeg - where APDU startslen - length of APDU
JCException - if APDU format (e.g. LC and APDU length) is
inconsistent.
protected byte[] sendAPDU(int lc,
int le)
getSessionState() == NO_SESSION)
and a SCP, which allows implicit session initiation has been set via
setSCP(), then implicit session initiation takes place automatically.
lc - length control value. If -1 then send only 4 byte APDU.
The final LC value after possible MACing and possible encryption
must hold: 0<=lc<=255.le - Length of expected response. If -1 then no le is added to the APDU
JCException - if the session state is illegal or lc is invalid.msgModepublic void setSecurityLevel(int level)
APDU_CLR,
APDU_MAC,
APDU_ENC,
APDU_RMAC,
APDU_CRMAC,
APDU_CRMAC_ENCpublic int getSecurityLevel()
APDU_CLR,
APDU_MAC,
APDU_ENC,
APDU_RMAC,
APDU_CRMAC,
APDU_CRMAC_ENCpublic int getSessionState()
NO_SESSION,
SESSION_OK,
SESSION_AUTHpublic int getSessionMode()
VOP_NONE,
VOP_201,
VOP_211public int getSCP()
SCP_01_05,
SCP_01_15,
SCP_02_04,
SCP_02_05,
SCP_02_0A,
SCP_02_0B,
SCP_02_14,
SCP_02_15,
SCP_02_1A,
SCP_02_1Bpublic void setSCP(int scp)
scp - Desired secure channel protocol
JCException - if parameters are invalid.SCP_02_0A,
SCP_02_0B,
SCP_02_1A,
SCP_02_1B
public byte[] getData(int p1,
int p2)
p1 - high byte of the tag indicating which data object to be retrieved.p2 - low byte of the tag indicating which data object to be retrieved.
JCException - if response status is not equals 0x9000 or the
format of the response is not TLV.
public void putData(int p1,
int p2,
byte[] data,
int beg,
int len)
p1 - high byte of the data tag indicating which data to be put.p2 - low byte of the data tag indicating which data to be put.data - array holding the data to be put.beg - offset in the data array.len - length of the data.
JCException - if response status is not equals 0x9000
public void storeData(byte[] data,
int beg,
int len,
int blockNumber,
boolean last)
data - array holding the data to be stored.beg - offset in the data array.len - length of the data.blockNumber - block number 0x00-0xFF.last - true if this is the last block, false otherwise.
JCException - if response status is not equals 0x9000
public void setStatus(byte p1,
int p2,
byte[] id)
p1 - defines whether card manager or application state is
to be modified (APPLICATION_LCD, CM_LCD)p2 - the state to transition to (e.g. PERSONALIZED).id - AID of the target (AID of this applet if null)
JCException - if response status is not equals 0x9000CM_LCD,
APPLICATION_LCD,
INSTALLED,
SELECTABLE,
PERSONALIZED,
BLOCKED,
LOCKED,
CardManagerpublic byte[] getStatus(byte p1)
p1 - defines whether card manager, application or load file life cycle data is
to be retrieved (APPLICATION_LCD, CM_LCD or LOAD_FILE_LCD)
JCException - if response status is not equals 0x9000CM_LCD,
APPLICATION_LCD,
LOAD_FILE_LCD
public byte[] getStatus(byte p1,
byte p2,
byte[] qualifier,
int off,
int len)
p1 - defines whether Card Manager (CM_LCD), application/Security Domain
(APPLICATION_LCD), Executable Load file (LOAD_FILE_LCD) or
Executable Load file and Executable Module (LOAD_FILE_MODULE_LCD)
life cycle data is to be retrieved.p2 - controls the number of consecutive GET STATUS commands and indicates the
format of the response message. Must be a combination of the following
flags: GS_FIRST_ALL, GS_NEXT, GS_FORMAT_1, GS_FORMAT_2.qualifier - TLV coded serach qualifier(s). If null, search criteria 0x4F00 is
used meaning that all occurences match.off - offset where the seach qualifier(s) start.len - length of the seach qualifier(s).
JCException - if response status is not equals 0x9000CM_LCD,
APPLICATION_LCD,
LOAD_FILE_LCD,
LOAD_FILE_MODULE_LCD,
GS_FIRST_ALL,
GS_NEXT,
GS_FORMAT_1,
GS_FORMAT_2
public OPKey getKey(int keySet,
int keyId)
keySet - the key set version of the key to look for.keyId - the ID of the key to look for.
JCException - if the requested key is not present.public OPKey[] getKeys()
public OPKey deleteKey(int keySet,
int keyId)
keySet - the key set version of the key to delete.keyId - the ID of the key to delete.
public OPKey setKey(OPKey key)
If such a key already exists the new key replaces the existing one.
key - the key object to add.putKey(int, com.ibm.jc.OPKey[], int)public void flush()
flush in class JCAppletpublic byte[] select()
select in class JCAppletif - status of R-APDU is neither JCStatus.NOERROR (9000) nor JCStatus.APPLET_INVALIDATED (6283).
public void initializeUpdate(int keySet,
int keyId)
initializeUpdate(int keySet, int keyId, int scp)
keySet - Key Set Version to be used for session key generation. If
set to zero the on-card counterpart dictates which
key set to be used.keyId - Key ID. This parameter is usually ignored and shall
be set to zero.
JCException - If response data or keys are invalid.
public void initializeUpdate(int keySet,
int keyId,
int scp)
keySet - Key Set Version to be used for session key generation. If
set to zero the on-card counterpart dictates which
key set to be used.keyId - Key ID. This parameter is usually ignored and shall
be set to zero.scp - Desired secure channel protocol. If this parameter is SCP_UNDEFINED,
SCP_02_15 is used if the card indicates SCP 02 in the
INITIALIZE UPDATE response APDU, SCP_01_05 is used otherwise.
JCException - If response data, keys or parameters are invalid.SCP_UNDEFINED,
SCP_01_05,
SCP_01_15,
SCP_02_04,
SCP_02_05,
SCP_02_14,
SCP_02_15public void externalAuthenticate(int secLevel)
initializeUpdate() must have been executed
successfully beforehand.
secLevel - the desired level of security required for all
subsequent APDUs.
JCException - If authentication failed or invalid session state.APDU_CLR,
APDU_MAC,
APDU_ENC,
APDU_RMAC,
APDU_CRMAC,
APDU_CRMAC_ENC
public void beginRMACSession(int secLevel,
byte[] data,
int off,
int len)
secLevel - the desired level of security required for all
subsequent response APDUs.data - Data to be included in the command. Might be null.off - Offset where the data starts.len - Length of the data.
JCException - If parameteres are invalid, no secure channel
is established or the the command failed for some reason.APDU_CLR,
APDU_RMACpublic void endRMACSession()
JCException - If no secure channel with R-MAC
exists or the the command failed for some reason.public void storePKDAPKey(OPKey key)
key - the 1024 bits RSA public key to be stored.
JCException - if the key is invalid or the STORE DATA command fails.
public void storeKeyset(OPKey[] keys,
int rSet)
keys - array holding the three keys to be stored. All keys in this
array must belong to the same key set version and they must be
sorted (key with lowest index (1) at array position 0).
Array elements must not be null.rSet - the key set version to be replaced (value 0x01-0x6F). If a
new key set version is to be added, this parameter must be zero.
JCException - if parameters are invalid or the STORE DATA command fails.
public void putKey(int mode,
OPKey[] keys,
int rSet)
mode - defines whether the key set to which the keys belong to
is to be modified, replaced or added.keys - array holding the keys to be put. All keys in this
array must be in the same key set and they must be
sorted (key with lowest index at array position 0).
Array elements must not be null.rSet - the key set which is to be replaced if the
mode parameter is set to REPLACE_KEYSET.
Otherwise this parameter is ignored and the
target key set is always the key set the keys
belong to.
JCException - if the parameters or the card response
(e.g. the key check values) are invalid.MODIFY_KEYSET,
REPLACE_KEYSET,
ADD_NEW_KEYSET
|
||||||||||
| PREV CLASS NEXT CLASS | FRAMES NO FRAMES | |||||||||
| SUMMARY: NESTED | FIELD | CONSTR | METHOD | DETAIL: FIELD | CONSTR | METHOD | |||||||||