1、 ETSI TS 102 225 V13.0.0 (2018-07) Smart Cards; Secured packet structure for UICC based applications (Release 13) TECHNICAL SPECIFICATION ETSI ETSI TS 102 225 V13.0.0 (2018-07)2Release 13 Reference RTS/SCP-T0284vd00 Keywords security, smart card ETSI 650 Route des Lucioles F-06921 Sophia Antipolis C
2、edex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org/standards-search The present document
3、 may be made available in electronic versions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or i
4、n print, the only prevailing document is the print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status
5、 of this and other ETSI documents is available at https:/portal.etsi.org/TB/ETSIDeliverableStatus.aspx If you find errors in the present document, please send your comment to one of the following services: https:/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be
6、reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restr
7、iction extend to reproduction in all media. ETSI 2018. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are trademarks of ETSI registered for the benefit of its Members. 3GPPTM and LTETMare trademarks of ETSI registered for the benefit of its Members and of the 3GPP Organizational P
8、artners. oneM2M logo is protected for the benefit of its Members. GSMand the GSM logo are trademarks registered and owned by the GSM Association. ETSI ETSI TS 102 225 V13.0.0 (2018-07)3Release 13 Contents Intellectual Property Rights 4g3Foreword . 4g3Modal verbs terminology 4g31 Scope 5g32 Reference
9、s 5g32.1 Normative references . 5g32.2 Informative references 6g33 Definitions and abbreviations . 6g33.1 Definitions 6g33.2 Abbreviations . 8g34 Overview of security system 9g34.0 Overview 9g34.1 Protocol for generalized secured packets . 9g34.2 Protocol for secured messages based on HTTPS . 10g35
10、Generalized secured packet structure . 10g35.0 Packet structure 10g35.1 Command packet structure . 11g35.1.0 Overview 11g35.1.1 Coding of the SPI 12g35.1.2 Coding of the KIc . 13g35.1.3 Coding of the KID 14g35.1.3.1 Coding of the KID for Cryptographic Checksum . 14g35.1.3.2 Coding of the KID for Red
11、undancy Check . 14g35.1.4 Counter Management 15g35.2 Response Packet structure 16g36 Implementation for CAT_TP . 17g37 Implementation for TCP/IP 17g38 Secured message structure for HTTPS . 18g3Annex A (normative): Relation between security layer and GlobalPlatform security architecture. 19g3A.0 Over
12、view 19g3A.1 Key version - counter association within a Security Domain 19g3A.2 Security keys KIc, KID 19g3Annex B (informative): Example for CRC computation 20g3Annex C (informative): Change history . 21g3History 23g3ETSI ETSI TS 102 225 V13.0.0 (2018-07)4Release 13 Intellectual Property Rights Ess
13、ential patents IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPR
14、s); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server (https:/ipr.etsi.org/). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been
15、carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the present document. Trademarks The present document may include trademarks and/or tradenames
16、which are asserted and/or registered by their owners. ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does not constitute a
17、n endorsement by ETSI of products, services or organizations associated with those trademarks. Foreword This Technical Specification (TS) has been produced by ETSI Technical Committee Smart Card Platform (SCP). It is based on work originally done in the 3GPP in TSG-terminals WG3 and ETSI SMG. The co
18、ntents of the present document are subject to continuing work within TC SCP and may change following formal TC SCP approval. If TC SCP modifies the contents of the present document, it will then be republished by ETSI with an identifying change of release date and an increase in version number as fo
19、llows: Version x.y.z where: x the first digit: 0 early working draft; 1 presented to TC SCP for information; 2 presented to TC SCP for approval; 3 or greater indicates TC SCP approved document under change control. y the second digit is incremented for all changes of substance, i.e. technical enhanc
20、ements, corrections, updates, etc. z the third digit is incremented when editorial only changes have been incorporated in the document. Modal verbs terminology In the present document “shall“, “shall not“, “should“, “should not“, “may“, “need not“, “will“, “will not“, “can“ and “cannot“ are to be in
21、terpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. ETSI ETSI TS 102 225 V13.0.0 (2018-07)5Release 13 1 Scope The present document specifies th
22、e structure of Secured Packets for different transport and security mechanisms. It is applicable to the exchange of secured packets between an entity in a network and an entity in the UICC. Secured Packets contain application messages to which certain mechanisms according to ETSI TS 102 224 1 have b
23、een applied. Application messages are commands or data exchanged between an application resident in or behind the network and on the UICC. The Sending/Receiving Entity in the network and the UICC are responsible for applying the security mechanisms to the application messages and thus turning them i
24、nto Secured Packets. 2 References 2.1 Normative references References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the refer
25、enced document (including any amendments) applies. Referenced documents which are not found to be publicly available in the expected location might be found at https:/docbox.etsi.org/Reference/. In the case of a reference to a TC SCP document, a non specific reference implicitly refers to the latest
26、 version of that document in the same Release as the present document. NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee their long term validity. The following referenced documents are necessary for the application of the present documen
27、t. 1 ETSI TS 102 224: “Smart Cards; Security mechanisms for UICC based Applications - Functional requirements“. 2 Void. 3 ISO 16609 (2004): “Banking - Requirements for message authentication using symmetric techniques“. 4 Void. 5 ETSI TS 131 115: “Digital cellular telecommunications system (Phase 2+
28、); Universal Mobile Telecommunications System (UMTS); LTE; Secured packet structure for (Universal) Subscriber Identity Module (U)SIM Toolkit applications (3GPP TS 31.115)“. 6 GlobalPlatform: “GlobalPlatform Card Specification“, Version 2.3. NOTE: See http:/www.globalplatform.org/. 7 Applied Cryptog
29、raphy: “Protocols, Algorithms, and Source Code in C“, 2nd Edition, Bruce Schneier, John Wiley ETSI numbering system for telecommunication application providers“. 9 ETSI TS 102 226: “Smart Cards; Remote APDU structure for UICC based applications“. 10 ETSI TS 102 127: “Smart Cards; Transport protocol
30、for CAT applications; Stage 2“. 11 ISO/IEC 13239 (2002): “Information technology - Telecommunications and information exchange between systems - High-level data link control (HDLC) procedures“. ETSI ETSI TS 102 225 V13.0.0 (2018-07)6Release 13 12 NIST Special Publication FIPS-197 (2001): “Advanced E
31、ncryption Standard (AES)“. NOTE: See http:/csrc.nist.gov/publications/fips/index.html. 13 NIST Special Publication 800-38A (2001): “Recommendation for Block Cipher Modes of Operation - Methods and Techniques“. NOTE: See http:/csrc.nist.gov/publications/nistpubs/. 14 NIST Special Publication 800-38B
32、(2005): “Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication“. NOTE: See http:/csrc.nist.gov/publications/nistpubs/. 15 GlobalPlatform: “GlobalPlatform Card UICC Configuration“, Version 1.2.0. 16 ETSI TS 102 484: “Smart Cards; Secure channel between a UICC and an end
33、-point terminal“. 17 ETSI TS 102 483: “Smart cards; UICC-Terminal interface; Internet Protocol connectivity between UICC and terminal“. 18 ETSI TS 102 223: “Smart Cards; Card Application Toolkit (CAT)“. 19 GlobalPlatform: “GlobalPlatform Card, Remote Application Management over HTTP, Card Specificat
34、ion v2.2 - Amendment B“, Version 1.1.3. NOTE: See http:/www.globalplatform.org/. 2.2 Informative references References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references, only the cited version applies. For non-spe
35、cific references, the latest version of the referenced document (including any amendments) applies. In the case of a reference to a TC SCP document, a non specific reference implicitly refers to the latest version of that document in the same Release as the present document. NOTE: While any hyperlin
36、ks included in this clause were valid at the time of publication, ETSI cannot guarantee their long term validity. The following referenced documents are not necessary for the application of the present document but they assist the user with regard to a particular subject area. Not applicable. 3 Defi
37、nitions and abbreviations 3.1 Definitions For the purposes of the present document, the following terms and definitions apply: Advanced Encryption Standard (AES): standard cryptographic algorithm specified in FIPS-197 12 application layer: layer above the Transport Layer on which the Application Mes
38、sages are exchanged between the sending and receiving applications application message: package of commands or data sent from the Sending Application to the Receiving Application, or vice versa, independently of the transport mechanism NOTE: An Application Message is transformed with respect to a ch
39、osen Transport Layer and chosen level of security into one or more secured packets. ETSI ETSI TS 102 225 V13.0.0 (2018-07)7Release 13 card manager: generic term for the 3 card management entities of a GlobalPlatform card i.e. the OPEN, Issuer Security Domain and the Cardholder Verification Method Se
40、rvices provider as defined in the GlobalPlatform Card Specification 6 command header: security header of a command packet NOTE: It includes all fields except the Secured Data. command packet: secured packet transmitted by the Sending Entity to the Receiving Entity, containing a secured Application M
41、essage counter: mechanism or data field used for keeping track of a message sequence NOTE: This could be realized as a sequence oriented or time stamp derived value, maintaining a level of synchronization between the Sending Entity and the Receiving Entity. cryptographic checksum: string of bits der
42、ived from some secret information, (e.g. a secret key), part or all of the Application Message, and possible further information (e.g. part of the Security Header) NOTE: The secret key is known to the Sending Entity and to the Receiving Entity. The Cryptographic Checksum is often referred to as Mess
43、age Authentication Code. Data Encryption Standard (DES): standard cryptographic algorithm specified as DEA in ISO 16609 3 Data Encryption Key (DEK): key identifier for ciphering keys as defined in ETSI TS 102 226 9 digital signature: string of bits derived from some secret information, (e.g. a secre
44、t key), the complete Application Message, and possible further information (e.g. part of the Security Header) NOTE: The secret information is known only to the Sending Entity. Although the authenticity of the Digital Signature can be proved by the Receiving Entity, the Receiving Entity is not able t
45、o reproduce the Digital Signature without knowledge of the secret information owned by the Sending Entity. issuer security domain: on-card entity providing support for the control, security, and communication requirements of the Card Issuer as defined in the GlobalPlatform Card Specification 6 recei
46、ving application: entity to which the Application Message is destined receiving entity: entity where the Secured Packet is received (e.g. SMS-SC, UICC, USSD entry point, or dedicated Toolkit Server) and where the security mechanisms are utilized NOTE: The Receiving Entity processes the Secured Packe
47、ts. redundancy check: string of bits derived from the Application Message and possible further information for the purpose of detecting accidental changes to the message, without the use of any secret information response header: security header of a response packet response packet: secured packet t
48、ransmitted by the Receiving Entity to the Sending Entity, containing a secured response and possibly application data secured data: this field contains the secured application message and possibly padding octets secured packet: information flow on top of which the level of required security has been
49、 applied NOTE: An Application Message is transformed with respect to a chosen Transport Layer and chosen level of security into one or more Secured Packets. security domain: on-card entity providing support for the control, security, and communication requirements of the Application Provider as defined in the GlobalPlatform Card Specification 6 security header: that part of the secured packet which consists of all security information (e.g. counter, key identification, indication of security level, checksum or Digital
copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1