Identification cards — ICC-managed devices — Part 3: Organization, security and commands for interchange

ISO/IEC 18328-3:2016 specifies the logical interface of an application supporting the necessary security features in a card-IC which communicates with the external world by a physical interface supporting APDUs. This application supports the usage of electronic devices. This involves the design of commands, data structures and security mechanisms which are required to handle the data and handling the additional devices itself. The handling of the additional devices is always controlled by the card-IC. External inputs or outputs shall be managed by the existing interfaces. This document deals not with physical characteristics of the card and interface technology, but only with the logical aspects. Management of data for additional devices that is not subdued by the COS or application control is out of the scope of this document. Definitions of coding requirement for "trust assessment" of the managed data like warning, font, colour etc. is in the scope of this document. A description of the logical internal interface functionality used by the COS or by device drivers, if any, is also part of this document. Due to the fact that relevant technologies may evolve or be adopted very fast, this document defines commands and structures supporting extensions and adaptations.

Cartes d'identification — Dispositifs contrôlés par carte — Partie 3: Organisation, sécurité et commandes pour les échanges

General Information

Status
Published
Publication Date
13-Oct-2016
Current Stage
9093 - International Standard confirmed
Start Date
27-Oct-2022
Completion Date
19-Apr-2025
Ref Project
Standard
ISO/IEC 18328-3:2016 - Identification cards -- ICC-managed devices
English language
42 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)


INTERNATIONAL ISO/IEC
STANDARD 18328-3
First edition
2016-10-15
Identification cards — ICC-managed
devices —
Part 3:
Organization, security and commands
for interchange
Cartes d’identification — Dispositifs contrôlés par carte —
Partie 3: Organisation, sécurité et commandes pour les échanges
Reference number
©
ISO/IEC 2016
© ISO/IEC 2016, Published in Switzerland
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form
or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior
written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of
the requester.
ISO copyright office
Ch. de Blandonnet 8 • CP 401
CH-1214 Vernier, Geneva, Switzerland
Tel. +41 22 749 01 11
Fax +41 22 749 09 47
copyright@iso.org
www.iso.org
ii © ISO/IEC 2016 – All rights reserved

Contents Page
Foreword .v
Introduction .vi
1 Scope .1
2 Normative references .1
3 Terms and definitions .1
4 Symbols and abbreviated terms .4
5 Architectural aspects .5
5.1 General architecture . 5
5.2 Operational conditions. 6
5.2.1 Interfaces . 6
5.2.2 Identification of additional devices . 7
5.2.3 Device discovery mechanism . 7
5.2.4 Logical activation of additional devices . 8
5.2.5 Activation sequence . 8
5.2.6 Activity states of additional devices . 8
5.2.7 Exclusive usage attribute .10
5.2.8 General functionality .11
5.2.9 Timer control .12
5.3 Energy depending activation .12
5.4 Addressing of an additional device .12
5.4.1 General.12
5.4.2 Device identifier .12
5.4.3 Device handle.13
5.5 Device control information .13
5.5.1 Administration of additional devices .13
5.5.2 Device control parameter DVCP .13
5.5.3 General device information template .15
6 Functions of the additional device management command .17
6.1 General .17
6.2 Specific status bytes for additional device management .18
6.3 Functions of additional device management command .18
6.3.1 General command handling .18
6.3.2 general device reset function .18
6.3.3 logical device reset function .19
6.3.4 open device function . . .19
6.3.5 deactivate device function .20
6.3.6 reactivate device function .20
6.3.7 exclusive device usage function .20
6.3.8 general device usage function .21
6.3.9 get from device function .21
6.3.10 put to device function .22
6.3.11 get device information function .23
6.3.12 erase device content function .23
6.3.13 manage device configuration function .24
7 Usage of off-card devices .24
7.1 General .24
7.2 Transmission mechanism .26
7.3 Device handle .27
7.4 Secure channel .27
8 Command structures with adm functions in applications .28
9 Security aspects .28
© ISO/IEC 2016 – All rights reserved iii

9.1 Security attributes .28
9.1.1 Access mode field for adm command .28
9.1.2 Security conditions .29
9.2 Data integrity and confidentiality.29
9.3 Security with off-card-devices .30
9.4 Trust assessment .30
10 Device configuration template .30
10.1 Configuration template .30
10.2 Usage of device configuration templates .31
Annex A (informative) Activity sequences .32
Annex B (informative) Examples for information templates .34
Annex C (informative) Example of command sequences with additional devices .38
Annex D (informative) General system description .41
Bibliography .42
iv © ISO/IEC 2016 – All rights reserved

Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work. In the field of information technology, ISO and IEC have established a joint technical committee,
ISO/IEC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for
the different types of document should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject
of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent
rights. Details of any patent rights identified during the development of the document will be in the
Introduction and/or on the ISO list of patent declarations received (see www.iso.org/patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation on the meaning of ISO specific terms and expressions related to conformity
assessment, as well as information about ISO’s adherence to the WTO principles in the Technical
Barriers to Trade (TBT) see the following URL: Foreword - Supplementary information
The
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.