|
||||||||||
| PREV CLASS NEXT CLASS | FRAMES NO FRAMES | |||||||||
| SUMMARY: NESTED | FIELD | CONSTR | METHOD | DETAIL: FIELD | CONSTR | METHOD | |||||||||
java.lang.Objectcom.ibm.jc.JCApplet
com.ibm.jc.OPApplet
com.ibm.jc.SecurityDomain
This class implements the off-card behavior of a Security Domain (usually a Provider Security Domain) on a Global Platform JavaCard. It provides functionality to install, load, personalize, extradite and delete applications. Some of the functionality is only available if the Security Domain has DAP Verification or/and Delegated Management privileges.
| Field Summary | |
static int |
LOAD_ALL
loading mode: load concatenated CAP-file components |
static int |
LOAD_COMP
loading mode: load CAP-file components seperately |
static int |
LOAD_DEBUG
loading mode: do not skip descriptor/debug component |
static int |
LOAD_RND
loading mode: load with random APDU size |
| Fields inherited from class com.ibm.jc.OPApplet |
ADD_NEW_KEYSET, APDU_BIG_MAC, APDU_CLR, APDU_CRMAC, APDU_CRMAC_ENC, APDU_ENC, APDU_MAC, APDU_MAC_START, APDU_RMAC, APDU_SUPER_MAC, APPLICATION_LCD, BLOCKED, CARD_TERMINATE_PRIV, CM_LCD, CM_LOCK_PRIV, GS_FIRST_ALL, GS_FORMAT_1, GS_FORMAT_2, GS_NEXT, icv, IMP_SELECTABLE_PRIV, INSTALLED, K_dek, K_ea, K_m, K_rm, Kkek, LOAD_FILE_LCD, LOAD_FILE_MODULE_LCD, LOCKED, LOGICALLY_DELETED, macSize, MANDATED_DAP_PRIV, MODIFY_KEYSET, msgMode, NO_PRIVS, NO_SESSION, NOT_AVAILABLE, PERSONALIZED, PIN_CHANGE_PRIV, REPLACE_KEYSET, ricv, rmbuf, SCP_01_05, SCP_01_15, SCP_02_04, SCP_02_05, SCP_02_0A, SCP_02_0B, SCP_02_14, SCP_02_15, SCP_02_1A, SCP_02_1B, SCP_UNDEFINED, scpMode, SD_DAP_PRIV, SD_DELEGATE_PRIV, SD_PRIV, SELECTABLE, SESSION_AUTH, SESSION_OK, sessionMode, VOP_201, VOP_211, VOP_NONE |
| Fields inherited from class com.ibm.jc.JCApplet |
apdu |
| Constructor Summary | |
SecurityDomain()
|
|
SecurityDomain(JCApplet app)
Create the off-card representation of a Security Domain. |
|
SecurityDomain(JCard card,
byte[] aid,
int aidBeg,
int aidLen)
Create the off-card representation of a Security Domain. |
|
SecurityDomain(JCard card,
byte[] aid,
int aidBeg,
int aidLen,
byte state,
byte privs)
Create the off-card representation of a Security Domain. |
|
| Method Summary | |
byte[] |
delete(byte[] id,
int beg,
int len,
boolean last)
Deprecated. |
void |
deleteKeyObject(int keyID,
int keyVersion)
This corresponds with the Global Platform DELETE [key] command. |
byte[] |
deleteObject(byte[] aid,
int beg,
int len,
boolean deleteRelated)
This corresponds with the Global Platform DELETE command. |
static byte[] |
generateReceipt(byte[] d,
int beg,
int len,
OPKey rKey)
Generate a load, install, extradition or delete receipt. |
byte[] |
installForExtradition(byte[] sdAID,
int sdAIDBeg,
int sdAIDLen,
byte[] instAID,
int instAIDBeg,
int instAIDLen,
byte[] token,
int tokenBeg)
This method corresponds with the Global Platform INSTALL [for extradition] command. |
byte[] |
installForInstall(byte[] pkgAID,
int pkgAIDBeg,
int pkgAIDLen,
byte[] appAID,
int appAIDBeg,
int appAIDLen,
byte[] instAID,
int instAIDBeg,
int instAIDLen,
int privs,
byte[] param,
int paramBeg,
int paramLen,
byte[] token,
int tokenBeg)
This method corresponds with the Global Platform INSTALL [for install] command. |
byte[] |
installForInstallAndMakeSelectable(byte[] pkgAID,
int pkgAIDBeg,
int pkgAIDLen,
byte[] appAID,
int appAIDBeg,
int appAIDLen,
byte[] instAID,
int instAIDBeg,
int instAIDLen,
int privs,
byte[] param,
int paramBeg,
int paramLen,
byte[] token,
int tokenBeg)
This method corresponds with the Global Platform INSTALL [for install and make selectable] command. |
void |
installForLoad(byte[] pkgAID,
int pkgAIDBeg,
int pkgAIDLen,
byte[] sdAID,
int sdAIDBeg,
int sdAIDLen,
byte[] dap,
int dapBeg,
byte[] param,
int paramBeg,
int paramLen,
byte[] token,
int tokenBeg)
This method corresponds with the Golbal Platform INSTALL [for load] command. |
void |
installForMakeSelectable(byte[] instAID,
int instAIDBeg,
int instAIDLen,
int privs,
byte[] token,
int tokenBeg)
This corresponds with the Global Platform INSTALL [for make selectable] command. |
void |
installForPersonalization(byte[] instAID,
int instAIDBeg,
int instAIDLen)
This method corresponds with the Global Platform INSTALL [for personalization] command. |
byte[] |
load(CapFile capfile,
int[] progress,
int mode,
java.io.PrintWriter msgOut,
int mbl)
Loads a CAP-file (package) onto the card by utilizing the Global Platform LOAD command. |
static void |
verifyReceipt(byte[] d,
int beg,
int len,
OPKey rKey)
Verify a load, install, extradition or delete receipt generated during one of these operations via Delegated Management. |
| Methods inherited from class com.ibm.jc.OPApplet |
beginRMACSession, deleteKey, endRMACSession, externalAuthenticate, flush, getData, getKey, getKeys, getMaxPayload, getPrivileges, getSCP, getSecurityLevel, getSessionMode, getSessionState, getState, getStatus, getStatus, initializeUpdate, initializeUpdate, putData, putKey, select, send, sendAPDU, setKey, setSCP, setSecurityLevel, setStatus, storeData, storeKeyset, storePKDAPKey |
| Methods inherited from class com.ibm.jc.JCApplet |
equals, getAID, getCard, getTerminal, setAID, setCard, setHeader |
| Methods inherited from class java.lang.Object |
clone, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait |
| Field Detail |
public static final int LOAD_ALL
public static final int LOAD_COMP
public static final int LOAD_RND
public static final int LOAD_DEBUG
| Constructor Detail |
public SecurityDomain(JCard card,
byte[] aid,
int aidBeg,
int aidLen,
byte state,
byte privs)
card - the JavaCard this Security Domain resides on.aid - the buffer containing the AID of the Security Domain.aidBeg - offset into aid.aidLen - the length of the Security Domain AID. This value must be
in the range [5;16].state - the life cycle state of the Security Domain.privs - the privileges of the Security Domain.OPApplet
public SecurityDomain(JCard card,
byte[] aid,
int aidBeg,
int aidLen)
card - the JavaCard this Security Domain resides on.aid - the buffer containing the AID of the Security Domain.aidBeg - offset into aid.aidLen - the length of the Security Domain AID. This value must be
in the range [5;16].OPAppletpublic SecurityDomain(JCApplet app)
app - SecurityDomain object.OPAppletpublic SecurityDomain()
| Method Detail |
public void installForLoad(byte[] pkgAID,
int pkgAIDBeg,
int pkgAIDLen,
byte[] sdAID,
int sdAIDBeg,
int sdAIDLen,
byte[] dap,
int dapBeg,
byte[] param,
int paramBeg,
int paramLen,
byte[] token,
int tokenBeg)
pkgAID - Load File (package) AID.pkgAIDBeg - offset in pkgAID.pkgAIDLen - Load File AID length.sdAID - Security Domain AID. This Security Domain will
become the associated Security Domain for any application
within the load file. If this parameter is null
the currently selected Security Domain is used.sdAIDBeg - offset in sdAID.sdAIDLen - Security Domain AID length.dap - the Load File Data Block Hash (SHA-1 hash over the Load File).
This parameter is only required in the case of Delegated
Loading and/or DAP Verification (Global Platform 2.1.1).
Otherwise (e.g. in case of GP 2.0.1' DAP verification) it
can be null.dapBeg - offset in dap.param - optional load parameters. Might be null.paramBeg - offset in param.paramLen - load parameters length.token - the Load Token (128 bytes RSA PKCS#1 signature).
This parameter is only required in case of Delegated Loading
and can be null otherwise.tokenBeg - offset in token.
JCException - if parameters are invalid or the command fails.
public byte[] installForInstall(byte[] pkgAID,
int pkgAIDBeg,
int pkgAIDLen,
byte[] appAID,
int appAIDBeg,
int appAIDLen,
byte[] instAID,
int instAIDBeg,
int instAIDLen,
int privs,
byte[] param,
int paramBeg,
int paramLen,
byte[] token,
int tokenBeg)
pkgAID - Load File (package) AID of the package including the
Executable Module (applet) to be installed.pkgAIDBeg - offset in pkgAID.pkgAIDLen - Load file AID length.appAID - AID of the applet to be installed.appAIDBeg - offset in appAID.appAIDLen - applet AID length.instAID - AID of the applet instance to be created.
If this parameter is null the instance AID will
default to the applet AID.instAIDBeg - offset in instAID.instAIDLen - instance AID length.privs - the desired application privileges (see below).param - application/system specific install parameters.
Might be null.paramBeg - offset in paramLen - install parameters length.token - the Install Token (128 bytes RSA PKCS#1 signature).
This parameter is only required in case of Delegated Installation
and can be null otherwise.tokenBeg - offset in token.
verifyReceipt()
method takes this information as input.
In case of non-delegated installation null is returned.
JCException - if parameters are invalid or the command fails.verifyReceipt(byte[], int, int, com.ibm.jc.OPKey),
com.ibm.jc.OPApplet.SD_PRIV,
com.ibm.jc.OPApplet.SD_DAP_PRIV,
com.ibm.jc.OPApplet.SD_DELEGATE_PRIV,
com.ibm.jc.OPApplet.CM_LOCK_PRIV,
com.ibm.jc.OPApplet.CARD_TERMINATE_PRIV,
com.ibm.jc.OPApplet.IMP_SELECTABLE_PRIV,
com.ibm.jc.OPApplet.PIN_CHANGE_PRIV,
com.ibm.jc.OPApplet.MANDATED_DAP_PRIV,
com.ibm.jc.OPApplet.NO_PRIVS
public byte[] installForInstallAndMakeSelectable(byte[] pkgAID,
int pkgAIDBeg,
int pkgAIDLen,
byte[] appAID,
int appAIDBeg,
int appAIDLen,
byte[] instAID,
int instAIDBeg,
int instAIDLen,
int privs,
byte[] param,
int paramBeg,
int paramLen,
byte[] token,
int tokenBeg)
pkgAID - Load File (package) AID of the package including the
Executable Module (applet) to be installed.pkgAIDBeg - offset in pkgAID.pkgAIDLen - Load file AID length.appAID - AID of the applet to be installed.appAIDBeg - offset in appAID.appAIDLen - applet AID length.instAID - AID of the applet instance to be created.
If this parameter is null the instance AID will
default to the applet AID.instAIDBeg - offset in instAID.instAIDLen - instance AID length.privs - the desired application privileges (see below).param - application/system specific install parameters.
Might be null.paramBeg - offset in paramLen - install parameters length.token - the Install Token (128 bytes RSA PKCS#1 signature).
This parameter is only required in case of Delegated Installation
and can be null otherwise.tokenBeg - offset in token.
verifyReceipt()
method takes this information as input.
In case of non-delegated installation null is returned.
JCException - if parameters are invalid or the command fails.verifyReceipt(byte[], int, int, com.ibm.jc.OPKey),
com.ibm.jc.OPApplet.SD_PRIV,
com.ibm.jc.OPApplet.SD_DAP_PRIV,
com.ibm.jc.OPApplet.SD_DELEGATE_PRIV,
com.ibm.jc.OPApplet.CM_LOCK_PRIV,
com.ibm.jc.OPApplet.CARD_TERMINATE_PRIV,
com.ibm.jc.OPApplet.IMP_SELECTABLE_PRIV,
com.ibm.jc.OPApplet.PIN_CHANGE_PRIV,
com.ibm.jc.OPApplet.MANDATED_DAP_PRIV,
com.ibm.jc.OPApplet.NO_PRIVS
public void installForMakeSelectable(byte[] instAID,
int instAIDBeg,
int instAIDLen,
int privs,
byte[] token,
int tokenBeg)
instAID - AID of the applet instance which is to be made selectable.instAIDBeg - offset in instAID.instAIDLen - instance AID length.privs - the desired application privilege for Implicit Selectable (see below).token - the Install Token (128 bytes RSA PKCS#1 signature).
This parameter is only required in case of Delegated Installation
and can be null otherwise.tokenBeg - offset in token.
JCException - if parameters are invalid or the command fails.com.ibm.jc.OPApplet.IMP_SELECTABLE_PRIV,
com.ibm.jc.OPApplet.NO_PRIVS
public byte[] installForExtradition(byte[] sdAID,
int sdAIDBeg,
int sdAIDLen,
byte[] instAID,
int instAIDBeg,
int instAIDLen,
byte[] token,
int tokenBeg)
sdAID - AID of the Security Domain to which the application is to be extraditedsdAIDBeg - offset in sdAID.sdAIDLen - Security Domain AID length.instAID - AID of the application to be extradited.instAIDBeg - offset in instAID.instAIDLen - instance AID length.token - the Extradition Token (128 bytes RSA PKCS#1 signature).
This parameter is only required in case of Delegated Extradition
and can be null otherwise.tokenBeg - offset in token.
verifyReceipt()
method takes this information as input.
In case of non-delegated installation null is returned.
JCException - if parameters are invalid or the command fails.verifyReceipt(byte[], int, int, com.ibm.jc.OPKey)
public void installForPersonalization(byte[] instAID,
int instAIDBeg,
int instAIDLen)
instAID - AID of the application to be personalized.instAIDBeg - offset in instAID.instAIDLen - instance AID length.
JCException - if parameters are invalid or the command fails.
public byte[] load(CapFile capfile,
int[] progress,
int mode,
java.io.PrintWriter msgOut,
int mbl)
capfile - the CAP-file object to load.progress - if this reference is non-null then this object signals the
progress of the upload via this array. progress[1] contains
the total size of the data to be uploaded and progress[0]
the amount that is already transferred. Whenever the numbers
are updated this method calls progress.notifyAll().mode - the loading mode (can be mixed):
LOAD_ALL - load concatenated CAP-file components (default)
LOAD_COMP - load CAP-file components separately
LOAD_RND - load with random APDU size (can be combined with the
other two modes).
LOAD_DEBUG - load debug and descriptor components (if available)msgOut - if not null, load information is printed to this stream
(e.g. the component names (mode equals 0x02 only), component
sizes at end of load process, etc.).mbl - max. block length. Maximum command APDU payload.
verifyReceipt method takes this
information as input.
In case of non delegated loading null will be returned.
JCException - if parameters or response data is invalid.verifyReceipt(byte[], int, int, com.ibm.jc.OPKey),
LOAD_ALL,
LOAD_COMP,
LOAD_DEBUG,
LOAD_RND
public void deleteKeyObject(int keyID,
int keyVersion)
keyID - key identifier of the key to be deleted.keyVersion - key version of the key to be deleted.
JCException - if the command fails.
public byte[] deleteObject(byte[] aid,
int beg,
int len,
boolean deleteRelated)
aid - AID of the object to be deleted.beg - offset in aid.len - AID length.deleteRelated - true if related objects are also to be deleted, false
otherwise.
verifyReceipt() method takes this
information as input.
In case of non delegated deletion null will be returned.
JCException - if parameters or response data is invalid.OPApplet.deleteKey(int, int),
verifyReceipt(byte[], int, int, com.ibm.jc.OPKey)
public byte[] delete(byte[] id,
int beg,
int len,
boolean last)
id - application identifier of instance or package to be deleted.beg - offset in id.len - AID length.last - true if this is the last or only object to be deleted, false
otherwise.
verifyReceipt() method takes this
information as input.
In case of non delegated deletion null will be returned.
JCException - if parameters or response data is invalid.verifyReceipt(byte[], int, int, com.ibm.jc.OPKey)
public static void verifyReceipt(byte[] d,
int beg,
int len,
OPKey rKey)
d - the receipt followed by its generation data as returned by the
methods: load(), installForInstall(), installForInstallAndMakeSelectable(),
installForExtradition() or delete().rKey - the (DES) key to verify the signature.load(com.ibm.jc.CapFile, int[], int, java.io.PrintWriter, int),
delete(byte[], int, int, boolean),
installForInstall(byte[], int, int, byte[], int, int, byte[], int, int, int, byte[], int, int, byte[], int),
#installForInstallAndMakeSelektable,
installForExtradition(byte[], int, int, byte[], int, int, byte[], int),
generateReceipt(byte[], int, int, com.ibm.jc.OPKey)
public static byte[] generateReceipt(byte[] d,
int beg,
int len,
OPKey rKey)
d - the receipt generation data (not padded).beg - offset in d.len - receipt generation data length.rKey - the (DES) key to be used for receipt generation.
verifyReceipt(byte[], int, int, com.ibm.jc.OPKey)
|
||||||||||
| PREV CLASS NEXT CLASS | FRAMES NO FRAMES | |||||||||
| SUMMARY: NESTED | FIELD | CONSTR | METHOD | DETAIL: FIELD | CONSTR | METHOD | |||||||||