ACOS5 Functional Specification
ACOS5 Functional Specification
Reference Manual
[email protected]
Subject to change without prior notice
www.acs.com.hk
Table of Contents
1.0. Introduction ............................................................................................................... 3
1.1. Features.................................................................................................................................3
1.2. Technical Specifications ........................................................................................................3
1.2.1. Electrical........................................................................................................................3
1.2.2. EEPROM.......................................................................................................................3
1.2.3. Environmental ...............................................................................................................3
1.3. Symbols and Abbreviations ...................................................................................................3
2.0. Card Management ..................................................................................................... 5
2.1. Anti Tearing ...........................................................................................................................5
2.2. Card Life States .....................................................................................................................5
2.3. Answer To Reset ...................................................................................................................6
2.3.1. Customizing the ATR ....................................................................................................6
3.0. File System ................................................................................................................ 7
3.1. Hierarchical File System ........................................................................................................7
3.2. File Header Data....................................................................................................................7
3.3. Internal Security Files ............................................................................................................7
4.0. Security ...................................................................................................................... 8
4.1. File Security Attributes...........................................................................................................8
4.2. Security Environment.............................................................................................................8
4.3. Authentication ........................................................................................................................8
4.4. Secure Messaging .................................................................................................................8
5.0. Life Support Application .......................................................................................... 9
6.0. Contact Information ................................................................................................ 10
Figures
Figure 1. Card life cycle states ......................................................................................................... 5
Figure 2. Example of hierarchy of DFs ............................................................................................. 7
Tables
Table 1. Default Configuration of the Answer-to-Reset ...................................................................... 6
Page 2 of 10
1.1. Features
ACOS5 provides the following features:
• Full 32Kbytes of EEPROM memory for application data
• Compliance with ISO 7816 Parts 1,2,3,4,8,9
• ISO7816-2 compliant 8-contact module
• High baud rate switchable from 9.6 Kbps to 115.2 Kbps
• Supports ISO7816 Part 4 file structures: Transparent, Linear fixed, Linear Variable, Cyclic
• Hardware DES / Triple DES / SHA1 / RSA capability
• On-board RSA key generation of up to 2048 bit.
• AES-128 support.
• FIPS 140-2 compliant random number generator
• Mutual Authentication with Session Key generation
• Secure Messaging ensures data transfers are confidential and authenticated.
• Multilevel secured access hierarchy
• Anti-tearing ensures file headers and system information are protected.
• Common Criteria EAL5+ (Chip Level)
• FIPS140-2 compatible
1.2.2. EEPROM
• Capacity: 32Kbytes
• EEPROM endurance: 500K Erase/Write cycles
• Data retention: 10 years
1.2.3. Environmental
• Operating temperature: -25 °C to 85 °C
• Storage temperature: -40°C to 100°C
Page 3 of 10
Page 4 of 10
Pre-Personalization State
Personalization State
User State
Page 5 of 10
Page 6 of 10
EF MF EF
EF
EF DF DF Application DF
Files of an application
DF DF
Files of an application EF EF
Page 7 of 10
4.3. Authentication
Mutual Authentication is a process in which both the card and the card-accepting device verify that the
respective entity is genuine. A Session Key is the result of a successful execution of mutual
authentication. The session key is only valid during a session. A session is defined as the time after
a successful execution of the mutual authentication procedure and a reset of the card or the execution
of another mutual authentication procedure. The execution of a SELECT FILE command also ends a
session.
Page 8 of 10
Page 9 of 10
Page 10 of 10