com.ibm.jc.tools
Class SWIM

java.lang.Object
  extended bycom.ibm.jc.JCApplet
      extended bycom.ibm.jc.OPApplet
          extended bycom.ibm.jc.tools.SWIM

public class SWIM
extends OPApplet

Off-card software to manage a JCOP SWIM.


Field Summary
static int CHANGE_CHV1
          Change CHV 1
static int CHANGE_CHV2
          Change CHV 2
static int CRT_CONFIDENTIALITY
          MSE SET, CRT Confidentiality Template
static int CRT_CRYPTOGRAPHIC_CHECKSUM
          MSE SET, CRT Cryptographic Checksum Template
static int CRT_DIGITAL_SIGNATURE
          MSE SET, CRT Digital Signature Template
static int P1_SIGN_DECRYPT
          MSE SET, P1 value for signing and deciphering
static int P1_VERIFY_ENCRYPT
          MSE SET, P1 value for verification and enciphering
static int QUALIFIER_PIN_G
          Qualifier of the WIM PIN-G (general)
static int QUALIFIER_PIN_NR
          Qualifier of the WIM PIN-NR (non-repudiation)
static int RECORD_ABSOLUTE
          Read Record access mode
static int RECORD_NEXT
          Read Record access mode
static int RECORD_PREVIOUS
          Read Record access mode
static int SEEK_BEGINNING_FORWARD
          Seek mode from beginning forward
static int SEEK_END_BACKWARD
          Seek mode from end backward
static int SEEK_NEXT_FORWARD
          Seek mode from next location forward
static int SEEK_PREVIOUS_BACKWARD
          Seek mode from previous location backward
static int SEEK_TYPE1
          Seek type 1
static int SEEK_TYPE2
          Seek type 2
static int UNBLOCK_CHV1
          Unblock CHV 1
static int UNBLOCK_CHV2
          Unblock CHV 2
static int VERIFY_CHV1
          Verify CHV 1
static int VERIFY_CHV2
          Verify CHV 2
static int WIM_GENERIC_RSA_SE
          WIM GENERIC SE number
static int WIM_KEY_AUTH
          WIM WTLS authentication key
static int WIM_KEY_SIGN
          WIM non-repudiation key
static int WIM_WTLS_RSA_SE
          WIM WTLS SE number
 
Fields inherited from class com.ibm.jc.OPApplet
ADD_NEW_KEYSET, APDU_BIG_MAC, APDU_CLR, APDU_CRMAC, APDU_CRMAC_ENC, APDU_ENC, APDU_MAC, APDU_MAC_START, APDU_RMAC, APDU_SUPER_MAC, APPLICATION_LCD, BLOCKED, CARD_TERMINATE_PRIV, CM_LCD, CM_LOCK_PRIV, GS_FIRST_ALL, GS_FORMAT_1, GS_FORMAT_2, GS_NEXT, icv, IMP_SELECTABLE_PRIV, INSTALLED, K_dek, K_ea, K_m, K_rm, Kkek, LOAD_FILE_LCD, LOAD_FILE_MODULE_LCD, LOCKED, LOGICALLY_DELETED, macSize, MANDATED_DAP_PRIV, MODIFY_KEYSET, msgMode, NO_PRIVS, NO_SESSION, NOT_AVAILABLE, PERSONALIZED, PIN_CHANGE_PRIV, REPLACE_KEYSET, ricv, rmbuf, SCP_01_05, SCP_01_15, SCP_02_04, SCP_02_05, SCP_02_0A, SCP_02_0B, SCP_02_14, SCP_02_15, SCP_02_1A, SCP_02_1B, SCP_UNDEFINED, scpMode, SD_DAP_PRIV, SD_DELEGATE_PRIV, SD_PRIV, SELECTABLE, SESSION_AUTH, SESSION_OK, sessionMode, VOP_201, VOP_211, VOP_NONE
 
Fields inherited from class com.ibm.jc.JCApplet
apdu
 
Constructor Summary
SWIM(JCApplet applet)
          Constructs the off-card representation of a SWIM applet on a Java Card.
 
Method Summary
 int getChannel()
          Returns the logical channel number currently used for WIM related commands.
 byte[] manageChannelClose(int c)
          Close a logical channel other than the basic one.
 int manageChannelOpen()
          Open a logical channel other than the basic one.
 byte[] sendToSIM(int cla, int ins, int p1, int p2, int p3, byte[] body, int offset, int le)
          Send the given APDU to the SIM and get the response APDU, if any.
 void setChannel(int channel)
          Sets the logical channel number to be used for WIM related commands.
 byte[] sim_changeCHV(byte[] oldValue, int oldOff, int oldLen, byte[] newValue, int newOff, int newLen, int no)
          Assign a new value to the relevant CHV given that it is not blocked or disabled.
 byte[] sim_disableCHV(byte[] value, int off, int len)
          Disable the verification requirement for CHV 1.
 byte[] sim_enableCHV(byte[] value, int off, int len)
          Enable the verification requirement for CHV 1.
 byte[] sim_envelope(byte[] data, int off, int len)
          Transmit data to the SIM Application Toolkit applications in the SIM.
 byte[] sim_fetch(int len, java.io.PrintWriter msgOut)
          Transfer an Application Toolkit command from the SIM to the ME.
 byte[] sim_increase(int value, java.io.PrintWriter msgOut)
          Add the given value to the value of the last increased/updated record of the current cyclic EF, and store the result into the oldest record.
 byte[] sim_invalidate()
          Invalidate the current EF.
 byte[] sim_menuSelection(int id, boolean help)
          Builds a menu selection envelope command and sends it to the SIM.
 byte[] sim_readBinary(int off, int len)
          Read a string of bytes from the current selected EF of the SIM.
 byte[] sim_readRecord(int recno, int mode, int len)
          Read one complete record in the current linear fixed or cyclic EF.
 byte[] sim_rehabilitate()
          Rehabilitate the current EF.
 byte[] sim_runGSMAlg(byte[] challenge, int off, java.io.PrintWriter msgOut)
          Run the GSM authentication algorithm with the given challenge.
 byte[] sim_seek(byte[] pattern, int off, int len, int type, int mode)
          Search through the current linear fixed EF to find a record starting with the given pattern.
 byte[] sim_select()
          Select the SIM applet on the card.
 byte[] sim_selectFile(byte[] fid, int off, java.io.PrintWriter msgOut)
          Select the given file in the SIM file system.
 byte[] sim_selectFile(int fid, java.io.PrintWriter msgOut)
          Select the given file in the SIM file system.
 byte[] sim_sleep()
          Obsolete GSM function only used by Phase 1 MEs.
 byte[] sim_status(java.io.PrintWriter msgOut)
          Retrieve information concerning the current directory.
 byte[] sim_terminalProfile(byte[] profile, int off, int len, java.io.PrintWriter msgOut)
          Transmit the terminal profile to the SIM.
 byte[] sim_terminalResponse(byte[] data, int off, int len)
          Transmit response data to a previously fetched SIM Application Toolkit command to the SIM.
 byte[] sim_unblockCHV(byte[] unblockValue, int unblockOff, int unblockLen, byte[] newValue, int newOff, int newLen, int no)
          Unblock a CHV that has been blocked by three consecutive wrong CHV presentations.
 byte[] sim_updateBinary(byte[] data, int off, int len, int fileOff)
          Update the current EF of the SIM with the given string of bytes.
 byte[] sim_updateRecord(int recno, byte[] data, int off, int len, int mode)
          Update one complete record in the current linear fixed or cyclic EF.
 byte[] sim_verifyADM(byte[] value, int off, int len)
          Verify the administrator password.
 byte[] sim_verifyCHV(byte[] value, int off, int len, int no)
          Verify the presented CHV with the relevant one stored in the SIM.
 byte[] swim_finalize()
          Terminate JCOP SWIM personalization and set the applet state to PERSONALIZED.
 void swim_initialize(java.lang.String xmlFile, int keySet, java.io.PrintWriter msgOut)
          Reads a JCOP SWIM initialization XML file and installs the SWIM applet using the information given in the file.
 byte[] wim_askRandom(int length)
          Generate the requested number of true random bytes.
 byte[] wim_changePIN(byte[] oldValue, int oldOff, int oldLen, byte[] newValue, int newOff, int newLen, int q)
          Assign a new value to the a WIM PIN.
 byte[] wim_disablePIN(byte[] value, int off, int len, int q)
          Disable the verification requirement for a WIM PIN.
 byte[] wim_enablePIN(byte[] value, int off, int len, int q)
          Enable the verification requirement for a WIM PIN.
 byte[] wim_importRSAKey(int targetKey, java.lang.String keyMat)
          Import a RSA key to be used as either the authentication or the non-repudiation key.
 void wim_importTrustedCACert(java.lang.String file, java.lang.String label)
          Import trusted CA certificates into the WIM.
 int wim_importUserCerts(java.lang.String file, java.lang.String pin)
          Import user certificates for the WIM keys.
 void wim_importUserCredentials(int targetKey, java.lang.String pkcs12File, java.lang.String pin, java.lang.String pattern)
          Import either the WTLS authentication (auth) key/certificate or the non-repudiation (sign) key/certificate from a PKCS#12 file into the WIM.
 byte[] wim_keyGen(int targetKey, int keyLen)
          Generate either the authenticaion RSA key-pair or the non-repudiation (signing) RSA key-pair in the WIM (on-card).
 byte[] wim_mseDeriveKey(int secretRef, byte[] seed, int off, int len)
          Derive a master secret based on the previously established pre-master secret and the provided seed value.
 byte[] wim_mseRestore(int seNumber)
          Restore a security environment (SE) within the WIM by replacing the current SE with the given SE number.
 byte[] wim_mseSet(int p1, int p2, byte[] crdos, int off, int len)
          Set one or several components of the current SE in the WIM.
 byte[] wim_psoChecksum(byte[] seed, int off, int len)
          Use the WTLS PRF to calculate a key block.
 byte[] wim_psoDecipher(byte[] cryptogram, int off, int len)
          Decipher (unwrap) a message key with a private key.
 byte[] wim_psoEncipher()
          Key transport primitive in the WTLS handshake.
 byte[] wim_psoSign(byte[] data, int off, int len)
          Compute a digital signature for the given data.
 byte[] wim_psoVerify(byte[] signature, int off, int len)
          Verify a given digital signature.
 byte[] wim_readBinary(int off, int len)
          Read a string of bytes from the current selected EF of the WIM.
 byte[] wim_select()
          Selects the WIM application using the PKCS#15 AID.
 byte[] wim_selectFile(byte[] fid, int off, java.io.PrintWriter msgOut)
          Select the given file in the WIM file system.
 byte[] wim_unblockPIN(byte[] unblockValue, int unblockOff, int unblockLen, byte[] newValue, int newOff, int newLen, int q)
          Unblock a WIM PIN by resetting it's retry counter and setting a new value.
 byte[] wim_updateBinary(byte[] data, int off, int len, int fileOff)
          Update the current EF of the WIM with the given string of bytes.
 byte[] wim_verifyPIN(byte[] value, int off, int len, int q)
          Verify the presented WIM PIN with the relevant one stored in the card or retrieve information about a certain PIN.
 
Methods inherited from class com.ibm.jc.OPApplet
beginRMACSession, deleteKey, endRMACSession, externalAuthenticate, flush, getData, getKey, getKeys, getMaxPayload, getPrivileges, getSCP, getSecurityLevel, getSessionMode, getSessionState, getState, getStatus, getStatus, initializeUpdate, initializeUpdate, putData, putKey, select, send, sendAPDU, setKey, setSCP, setSecurityLevel, setStatus, storeData, storeKeyset, storePKDAPKey
 
Methods inherited from class com.ibm.jc.JCApplet
equals, getAID, getCard, getTerminal, setAID, setCard, setHeader
 
Methods inherited from class java.lang.Object
clone, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
 

Field Detail

RECORD_ABSOLUTE

public static final int RECORD_ABSOLUTE
Read Record access mode

See Also:
Constant Field Values

RECORD_NEXT

public static final int RECORD_NEXT
Read Record access mode

See Also:
Constant Field Values

RECORD_PREVIOUS

public static final int RECORD_PREVIOUS
Read Record access mode

See Also:
Constant Field Values

VERIFY_CHV1

public static final int VERIFY_CHV1
Verify CHV 1

See Also:
Constant Field Values

VERIFY_CHV2

public static final int VERIFY_CHV2
Verify CHV 2

See Also:
Constant Field Values

CHANGE_CHV1

public static final int CHANGE_CHV1
Change CHV 1

See Also:
Constant Field Values

CHANGE_CHV2

public static final int CHANGE_CHV2
Change CHV 2

See Also:
Constant Field Values

UNBLOCK_CHV1

public static final int UNBLOCK_CHV1
Unblock CHV 1

See Also:
Constant Field Values

UNBLOCK_CHV2

public static final int UNBLOCK_CHV2
Unblock CHV 2

See Also:
Constant Field Values

SEEK_TYPE1

public static final int SEEK_TYPE1
Seek type 1

See Also:
Constant Field Values

SEEK_TYPE2

public static final int SEEK_TYPE2
Seek type 2

See Also:
Constant Field Values

SEEK_BEGINNING_FORWARD

public static final int SEEK_BEGINNING_FORWARD
Seek mode from beginning forward

See Also:
Constant Field Values

SEEK_END_BACKWARD

public static final int SEEK_END_BACKWARD
Seek mode from end backward

See Also:
Constant Field Values

SEEK_NEXT_FORWARD

public static final int SEEK_NEXT_FORWARD
Seek mode from next location forward

See Also:
Constant Field Values

SEEK_PREVIOUS_BACKWARD

public static final int SEEK_PREVIOUS_BACKWARD
Seek mode from previous location backward

See Also:
Constant Field Values

QUALIFIER_PIN_G

public static final int QUALIFIER_PIN_G
Qualifier of the WIM PIN-G (general)

See Also:
Constant Field Values

QUALIFIER_PIN_NR

public static final int QUALIFIER_PIN_NR
Qualifier of the WIM PIN-NR (non-repudiation)

See Also:
Constant Field Values

WIM_WTLS_RSA_SE

public static final int WIM_WTLS_RSA_SE
WIM WTLS SE number

See Also:
Constant Field Values

WIM_GENERIC_RSA_SE

public static final int WIM_GENERIC_RSA_SE
WIM GENERIC SE number

See Also:
Constant Field Values

P1_SIGN_DECRYPT

public static final int P1_SIGN_DECRYPT
MSE SET, P1 value for signing and deciphering

See Also:
Constant Field Values

P1_VERIFY_ENCRYPT

public static final int P1_VERIFY_ENCRYPT
MSE SET, P1 value for verification and enciphering

See Also:
Constant Field Values

CRT_DIGITAL_SIGNATURE

public static final int CRT_DIGITAL_SIGNATURE
MSE SET, CRT Digital Signature Template

See Also:
Constant Field Values

CRT_CONFIDENTIALITY

public static final int CRT_CONFIDENTIALITY
MSE SET, CRT Confidentiality Template

See Also:
Constant Field Values

CRT_CRYPTOGRAPHIC_CHECKSUM

public static final int CRT_CRYPTOGRAPHIC_CHECKSUM
MSE SET, CRT Cryptographic Checksum Template

See Also:
Constant Field Values

WIM_KEY_AUTH

public static final int WIM_KEY_AUTH
WIM WTLS authentication key

See Also:
Constant Field Values

WIM_KEY_SIGN

public static final int WIM_KEY_SIGN
WIM non-repudiation key

See Also:
Constant Field Values
Constructor Detail

SWIM

public SWIM(JCApplet applet)
Constructs the off-card representation of a SWIM applet on a Java Card.

Parameters:
applet - the Java Card applet that implements the SWIM.
Method Detail

sim_select

public byte[] sim_select()
                  throws JCException
Select the SIM applet on the card.

Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_selectFile

public byte[] sim_selectFile(int fid,
                             java.io.PrintWriter msgOut)
                      throws JCException
Select the given file in the SIM file system.

Parameters:
fid - file identifier of the file to be selected.
msgOut - if not null, some information about the file is printed to this stream
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_selectFile

public byte[] sim_selectFile(byte[] fid,
                             int off,
                             java.io.PrintWriter msgOut)
                      throws JCException
Select the given file in the SIM file system.

Parameters:
fid - byte array holding the two-byte short file identifier of the file to be selected.
off - offset into the fid byte array.
msgOut - if not null, some information about the file is printed to this stream
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_readBinary

public byte[] sim_readBinary(int off,
                             int len)
                      throws JCException
Read a string of bytes from the current selected EF of the SIM.

Parameters:
off - offset into the current EF.
len - number of bytes to be read.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_updateBinary

public byte[] sim_updateBinary(byte[] data,
                               int off,
                               int len,
                               int fileOff)
                        throws JCException
Update the current EF of the SIM with the given string of bytes.

Parameters:
data - bytes to be written.
off - offset into the data array.
len - number of bytes to be updated.
fileOff - offset into the EF.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_readRecord

public byte[] sim_readRecord(int recno,
                             int mode,
                             int len)
                      throws JCException
Read one complete record in the current linear fixed or cyclic EF.

Parameters:
recno - number of the target record.
mode - Access mode RECORD_ABSOLUTE,RECORD_NEXT or RECORD_PREVIOUS.
len - length of the record.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
RECORD_ABSOLUTE, RECORD_NEXT, RECORD_PREVIOUS

sim_updateRecord

public byte[] sim_updateRecord(int recno,
                               byte[] data,
                               int off,
                               int len,
                               int mode)
                        throws JCException
Update one complete record in the current linear fixed or cyclic EF.

Parameters:
recno - number of the target record.
data - array holding the data to be written.
off - offset into the data array.
len - length of the data/record.
mode - Access mode RECORD_ABSOLUTE,RECORD_NEXT or RECORD_PREVIOUS.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
RECORD_ABSOLUTE, RECORD_NEXT, RECORD_PREVIOUS

sim_verifyCHV

public byte[] sim_verifyCHV(byte[] value,
                            int off,
                            int len,
                            int no)
                     throws JCException
Verify the presented CHV with the relevant one stored in the SIM. The given value is padded with 0xff.

Parameters:
value - array holding the CHV value.
off - offset into the value array.
len - length of the CHV value.
no - CHV number to verify with - VERIFY_CHV1 or VERIFY_CHV2.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
VERIFY_CHV1, VERIFY_CHV2

sim_changeCHV

public byte[] sim_changeCHV(byte[] oldValue,
                            int oldOff,
                            int oldLen,
                            byte[] newValue,
                            int newOff,
                            int newLen,
                            int no)
                     throws JCException
Assign a new value to the relevant CHV given that it is not blocked or disabled. The values are padded with 0xff.

Parameters:
oldValue - array holding the old CHV value.
oldOff - offset into the oldValue array.
oldLen - length of the old CHV value.
newValue - array holding the new CHV value.
newOff - offset into the newValue array.
newLen - length of the new CHV value.
no - CHV number to change - CHANGE_CHV1 or CHANGE_CHV2.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
CHANGE_CHV1, CHANGE_CHV2

sim_unblockCHV

public byte[] sim_unblockCHV(byte[] unblockValue,
                             int unblockOff,
                             int unblockLen,
                             byte[] newValue,
                             int newOff,
                             int newLen,
                             int no)
                      throws JCException
Unblock a CHV that has been blocked by three consecutive wrong CHV presentations. The values are padded with 0xff.

Parameters:
unblockValue - array holding the unblock CHV value.
unblockOff - offset into the unblockValue array.
unblockLen - length of the unblock CHV value.
newValue - array holding the new CHV value.
newOff - offset into the newValue array.
newLen - length of the new CHV value.
no - CHV number to unblock - UNBLOCK_CHV1 or UNBLOCK_CHV2.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
UNBLOCK_CHV1, UNBLOCK_CHV2

sim_enableCHV

public byte[] sim_enableCHV(byte[] value,
                            int off,
                            int len)
                     throws JCException
Enable the verification requirement for CHV 1. The given value is padded with 0xff.

Parameters:
value - array holding the CHV 1 value.
off - offset into the value array.
len - length of the CHV 1 value.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_disableCHV

public byte[] sim_disableCHV(byte[] value,
                             int off,
                             int len)
                      throws JCException
Disable the verification requirement for CHV 1. The given value is padded with 0xff.

Parameters:
value - array holding the CHV 1 value.
off - offset into the value array.
len - length of the CHV 1 value.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_seek

public byte[] sim_seek(byte[] pattern,
                       int off,
                       int len,
                       int type,
                       int mode)
                throws JCException
Search through the current linear fixed EF to find a record starting with the given pattern.

Parameters:
pattern - array holding the pattern to search for.
off - offset into the pattern array.
len - length of the pattern.
type - seek type - SEEK_TYPE1 or SEEK_TYPE2.
mode - seek mode - SEEK_BEGINNING_FORWARD, SEEK_END_BACKWARD,SEEK_NEXT_FORWARD, SEEK_PREVIOUS_BACKWARD.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
SEEK_TYPE1, SEEK_TYPE2, SEEK_BEGINNING_FORWARD, SEEK_END_BACKWARD, #SEEK_NEX_FORWARD, SEEK_PREVIOUS_BACKWARD

sim_increase

public byte[] sim_increase(int value,
                           java.io.PrintWriter msgOut)
                    throws JCException
Add the given value to the value of the last increased/updated record of the current cyclic EF, and store the result into the oldest record.

Parameters:
value - value to be added.
msgOut - if not null, the added value and the new value is printed to this string
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_invalidate

public byte[] sim_invalidate()
                      throws JCException
Invalidate the current EF.

Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_rehabilitate

public byte[] sim_rehabilitate()
                        throws JCException
Rehabilitate the current EF.

Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_status

public byte[] sim_status(java.io.PrintWriter msgOut)
                  throws JCException
Retrieve information concerning the current directory.

Parameters:
msgOut - if not null, some information is printed to this stream.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_runGSMAlg

public byte[] sim_runGSMAlg(byte[] challenge,
                            int off,
                            java.io.PrintWriter msgOut)
                     throws JCException
Run the GSM authentication algorithm with the given challenge.

Parameters:
challenge - array holding the 16 byte challenge.
off - offset into the challenge array.
msgOut - if not null, response information is printed to this stream.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_sleep

public byte[] sim_sleep()
                 throws JCException
Obsolete GSM function only used by Phase 1 MEs.

Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_terminalProfile

public byte[] sim_terminalProfile(byte[] profile,
                                  int off,
                                  int len,
                                  java.io.PrintWriter msgOut)
                           throws JCException
Transmit the terminal profile to the SIM.

Parameters:
profile - array holding the terminal profile data.
off - offset into the profile array.
len - length of the terminal profile data.
msgOut - if not null, some information about the profile is printed to this stream.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_envelope

public byte[] sim_envelope(byte[] data,
                           int off,
                           int len)
                    throws JCException
Transmit data to the SIM Application Toolkit applications in the SIM.

Parameters:
data - data string to be transmitted.
off - offset into the data array.
len - length of the data string.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_menuSelection

public byte[] sim_menuSelection(int id,
                                boolean help)
                         throws JCException
Builds a menu selection envelope command and sends it to the SIM.

Parameters:
id - item identifier of the selected menu item.
help - indicates that the user requested help info for the given menu item.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_fetch

public byte[] sim_fetch(int len,
                        java.io.PrintWriter msgOut)
                 throws JCException
Transfer an Application Toolkit command from the SIM to the ME.

Parameters:
len - length of the command data.
msgOut - if not null, some information about the fetched command might be printed to this stream.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_terminalResponse

public byte[] sim_terminalResponse(byte[] data,
                                   int off,
                                   int len)
                            throws JCException
Transmit response data to a previously fetched SIM Application Toolkit command to the SIM.

Parameters:
data - data string to be transmitted.
off - offset into the data array.
len - length of the data string.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

sim_verifyADM

public byte[] sim_verifyADM(byte[] value,
                            int off,
                            int len)
                     throws JCException
Verify the administrator password.

Parameters:
value - array holding the PIN value.
off - offset into the value array.
len - length of the PIN value.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

manageChannelOpen

public int manageChannelOpen()
                      throws JCException
Open a logical channel other than the basic one. The assigned channel will be used in WIM related commands.

Returns:
the assigned channel number.
Throws:
JCException - if communication failed or an error was returned by the card.

getChannel

public int getChannel()
Returns the logical channel number currently used for WIM related commands.

Returns:
channel number

setChannel

public void setChannel(int channel)
Sets the logical channel number to be used for WIM related commands.

Parameters:
channel - channel number

manageChannelClose

public byte[] manageChannelClose(int c)
                          throws JCException
Close a logical channel other than the basic one.

Parameters:
c - channel number of the logical channel to be closed. If this number is negative the channel currently assigned for WIM related commands is closed.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_select

public byte[] wim_select()
                  throws JCException
Selects the WIM application using the PKCS#15 AID. The WIM is selected in the logical channel previously opened via a manageChannelOpen() call.

Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_verifyPIN

public byte[] wim_verifyPIN(byte[] value,
                            int off,
                            int len,
                            int q)
                     throws JCException
Verify the presented WIM PIN with the relevant one stored in the card or retrieve information about a certain PIN. The given value is padded with 0xff.

Parameters:
value - array holding the PIN value. If only information is to be retrieved this can be null.
off - offset into the value array.
len - length of the PIN value.
q - qualifier of the target PIN - QUALIFIER_PIN_G or QUALIFIER_PIN_NR.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
QUALIFIER_PIN_G, QUALIFIER_PIN_NR

wim_disablePIN

public byte[] wim_disablePIN(byte[] value,
                             int off,
                             int len,
                             int q)
                      throws JCException
Disable the verification requirement for a WIM PIN.

Parameters:
value - array holding the PIN value.
off - offset into the value array.
len - length of the PIN value.
q - qualifier of the target PIN - QUALIFIER_PIN_G or QUALIFIER_PIN_NR.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
QUALIFIER_PIN_G, QUALIFIER_PIN_NR

wim_enablePIN

public byte[] wim_enablePIN(byte[] value,
                            int off,
                            int len,
                            int q)
                     throws JCException
Enable the verification requirement for a WIM PIN.

Parameters:
value - array holding the PIN value.
off - offset into the value array.
len - length of the PIN value.
q - qualifier of the target PIN - QUALIFIER_PIN_G or QUALIFIER_PIN_NR.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
QUALIFIER_PIN_G, QUALIFIER_PIN_NR

wim_changePIN

public byte[] wim_changePIN(byte[] oldValue,
                            int oldOff,
                            int oldLen,
                            byte[] newValue,
                            int newOff,
                            int newLen,
                            int q)
                     throws JCException
Assign a new value to the a WIM PIN. The values are padded with 0xff.

Parameters:
oldValue - array holding the old PIN value.
oldOff - offset into the oldValue array.
oldLen - length of the old PIN value.
newValue - array holding the new PIN value.
newOff - offset into the newValue array.
newLen - length of the new PIN value.
q - qualifier of the target PIN - QUALIFIER_PIN_G or QUALIFIER_PIN_NR.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
QUALIFIER_PIN_G, QUALIFIER_PIN_NR

wim_unblockPIN

public byte[] wim_unblockPIN(byte[] unblockValue,
                             int unblockOff,
                             int unblockLen,
                             byte[] newValue,
                             int newOff,
                             int newLen,
                             int q)
                      throws JCException
Unblock a WIM PIN by resetting it's retry counter and setting a new value.

Parameters:
unblockValue - array holding the unblock PIN value.
unblockOff - offset into the unblockValue array.
unblockLen - length of the unblock PIN value.
newValue - array holding the new PIN value.
newOff - offset into the newValue array.
newLen - length of the new PIN value.
q - qualifier of the target PIN - QUALIFIER_PIN_G or QUALIFIER_PIN_NR.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
QUALIFIER_PIN_G, QUALIFIER_PIN_NR

wim_selectFile

public byte[] wim_selectFile(byte[] fid,
                             int off,
                             java.io.PrintWriter msgOut)
                      throws JCException
Select the given file in the WIM file system.

Parameters:
fid - byte array holding the two-byte short file identifier of the file to be selected.
off - offset into the fid byte array.
msgOut - if not null, some information about the file is printed to this stream.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_readBinary

public byte[] wim_readBinary(int off,
                             int len)
                      throws JCException
Read a string of bytes from the current selected EF of the WIM.

Parameters:
off - offset into the current EF.
len - number of bytes to be read.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_updateBinary

public byte[] wim_updateBinary(byte[] data,
                               int off,
                               int len,
                               int fileOff)
                        throws JCException
Update the current EF of the WIM with the given string of bytes.

Parameters:
data - bytes to be written.
off - offset into the data array.
len - number of bytes to be updated.
fileOff - offset into the EF.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_mseRestore

public byte[] wim_mseRestore(int seNumber)
                      throws JCException
Restore a security environment (SE) within the WIM by replacing the current SE with the given SE number.

Parameters:
seNumber - number of the SE to be restored - WIM_WTLS_RSA_SE or WIM_GENERIC_RSA_SE
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
WIM_WTLS_RSA_SE, WIM_GENERIC_RSA_SE

wim_mseSet

public byte[] wim_mseSet(int p1,
                         int p2,
                         byte[] crdos,
                         int off,
                         int len)
                  throws JCException
Set one or several components of the current SE in the WIM.

Parameters:
p1 - P1 value of the command - P1_SIGN_DECRYPT or P1_VERIFY_ENCRYPT.
p2 - P2 value of the command defining the target CRT - CRT_DIGITAL_SIGNATURE, CRT_CONFIDENTIALITY or CRT_CRYPTOGRAPHIC_CHECKSUM
crdos - array holding the concatination of CRDOs to be set.
off - offset into the crdos array.
len - length of the CRDO data.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.
See Also:
P1_SIGN_DECRYPT, P1_VERIFY_ENCRYPT, CRT_DIGITAL_SIGNATURE, CRT_CONFIDENTIALITY, CRT_CRYPTOGRAPHIC_CHECKSUM

wim_mseDeriveKey

public byte[] wim_mseDeriveKey(int secretRef,
                               byte[] seed,
                               int off,
                               int len)
                        throws JCException
Derive a master secret based on the previously established pre-master secret and the provided seed value.

Parameters:
secretRef - master secret reference.
seed - seed to be used in the key derivation.
off - offset into the seed array.
len - seed length.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_psoEncipher

public byte[] wim_psoEncipher()
                       throws JCException
Key transport primitive in the WTLS handshake. The client version and the internally generated random bytes are encrypted with the server public key. The required data must be set via wim_mseSet() method.

Returns:
the response APDU holding the cryptogram including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_psoChecksum

public byte[] wim_psoChecksum(byte[] seed,
                              int off,
                              int len)
                       throws JCException
Use the WTLS PRF to calculate a key block. The master secret and the desired result length must be set in the SE.

Parameters:
seed - seed to be used in the PRF.
off - offset into the seed array.
len - seed length.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_psoDecipher

public byte[] wim_psoDecipher(byte[] cryptogram,
                              int off,
                              int len)
                       throws JCException
Decipher (unwrap) a message key with a private key. PKCS#1 block type 2 padding is expected and will be stripped.

Parameters:
cryptogram - message key encrypted with the public key.
off - offset into the cryptogram array.
len - cryptogram length.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_psoSign

public byte[] wim_psoSign(byte[] data,
                          int off,
                          int len)
                   throws JCException
Compute a digital signature for the given data. The data is padded according to PKCS#1 block type 1. The current active SE defines the private key to be used.

Parameters:
data - data to be signed.
off - offset into the data array.
len - data length.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_psoVerify

public byte[] wim_psoVerify(byte[] signature,
                            int off,
                            int len)
                     throws JCException
Verify a given digital signature. The parameters digest and public key must already be present in the SE.

Parameters:
signature - signature data to be verified.
off - offset into the signature array.
len - signature length.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_askRandom

public byte[] wim_askRandom(int length)
                     throws JCException
Generate the requested number of true random bytes.

Parameters:
length - number of bytes to be generated.
Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_keyGen

public byte[] wim_keyGen(int targetKey,
                         int keyLen)
                  throws JCException
Generate either the authenticaion RSA key-pair or the non-repudiation (signing) RSA key-pair in the WIM (on-card). This command is proprietary and is only allowed during the personalization phase of the SWIM. EF_PrKDF is updated to reflect the newly generated key.

Parameters:
targetKey - key to be generated - WIM_KEY_AUTH or WIM_KEY_SIGN.
keyLen - the desired bit-length of the key to be generated (e.g. 1024 bit).
Returns:
the public key (JZSystem format)
Throws:
JCException - if communication failed, an error was returned by the card or parameters are invalid.

wim_importUserCerts

public int wim_importUserCerts(java.lang.String file,
                               java.lang.String pin)
                        throws JCException
Import user certificates for the WIM keys. This command is to be used during WIM personalization only. All certificates found in the PKCS#12 file or the certificate found in a X.509 encoded file that belong to a private key on the WIM are imported. The EF_CDF for user certificates is updated to reflect the newly imported certificate(s).

Parameters:
file - PKCS#12 token file holding the certificates to be imported or file holding one X.509 encoded certificate (in the later case no PIN is required).
pin - PKCS#12 token PIN or null if not applicable.
Returns:
number of certificates that have been imported.
Throws:
JCException - if communication failed, an error was returned by the card or parameters are invalid.

wim_importTrustedCACert

public void wim_importTrustedCACert(java.lang.String file,
                                    java.lang.String label)
                             throws JCException
Import trusted CA certificates into the WIM. This command is to be used during WIM personalization only. The EF_CDF for trusted CA certificates is updated to reflect the newly imported certificates.

Parameters:
file - file holding the WTLS binary encoded certificate to be imported.
label - label to be associated with the certificate.
Throws:
JCException - if communication failed, an error was returned by the card or parameters are invalid.

swim_finalize

public byte[] swim_finalize()
                     throws JCException
Terminate JCOP SWIM personalization and set the applet state to PERSONALIZED. The card is reset. This is a proprietary command.

Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

swim_initialize

public void swim_initialize(java.lang.String xmlFile,
                            int keySet,
                            java.io.PrintWriter msgOut)
                     throws JCException,
                            java.lang.Exception
Reads a JCOP SWIM initialization XML file and installs the SWIM applet using the information given in the file.

Parameters:
xmlFile - file holding the initialization data.
keySet - reference to the key set that holds the Card Manager key necessary for applet installation. If this parameter is zero and the msgOut parameter is is not null then initialization information is printed but SWIM installation does not take place.
msgOut - if not null, initialization information is printed to this stream.
Throws:
JCException - if communication failed or an error was returned by the card.
java.lang.Exception - if input parameters are invalid or an error occurred while parsing the XML file.

sendToSIM

public byte[] sendToSIM(int cla,
                        int ins,
                        int p1,
                        int p2,
                        int p3,
                        byte[] body,
                        int offset,
                        int le)
                 throws JCException
Send the given APDU to the SIM and get the response APDU, if any.

Returns:
the response APDU including the status word.
Throws:
JCException - if communication failed or an error was returned by the card.

wim_importRSAKey

public byte[] wim_importRSAKey(int targetKey,
                               java.lang.String keyMat)
                        throws JCException
Import a RSA key to be used as either the authentication or the non-repudiation key. This command is to be used during WIM personalization only. The key material must be provided in CRT-JZSystem format or PKCS#8 encoded (possibly in a file). The EF_PrKDF is updated to reflect the newly imported key.

Parameters:
targetKey - key to be imported - WIM_KEY_AUTH or WIM_KEY_SIGN.
keyMat - the key material as HEX-String (CRT JZSystem format or PKCS#8 encoded) or the file name of a PKCS#8 encoded file holding the key material.
Returns:
the EF_PrKDF record written to the token.
Throws:
JCException - if communication failed, an error was returned by the card or parameters are invalid.

wim_importUserCredentials

public void wim_importUserCredentials(int targetKey,
                                      java.lang.String pkcs12File,
                                      java.lang.String pin,
                                      java.lang.String pattern)
                               throws JCException
Import either the WTLS authentication (auth) key/certificate or the non-repudiation (sign) key/certificate from a PKCS#12 file into the WIM. This command is to be used during WIM personalization only. A search pattern can be defined to identify the key/certificate to be imported by providing a fragment of its label. If no pattern is provided the first key/certificate found is imported and the EF_CDF/EF_PrKDF is updated.

Parameters:
targetKey - key to be imported - WIM_KEY_AUTH or WIM_KEY_SIGN.
pkcs12File - PKCS#12 token file holding the key/certificate to be imported.
pin - PKCS#12 token PIN.
pattern - search pattern.
Throws:
JCException - if communication failed, an error was returned by the card or parameters are invalid (e.g. no key/certificate found).