CardOS V5.4

CardOS (DI) V5.4 is a multifunctional native smart card operating system, which is extendable by customized packages to amend or adjust the operating system functionality.

In addition, the authentication framework is a flexible option to realize authentication protocols by using configuration data.

By supporting NFC, CardOS DI V5.4 is suited for logical access with mobile devices. CardOS (DI) V5.4 offers state-of-the-art crypto algorithms with AES, SHA-2, and elliptic curves.

Eviden CardOS API middleware is available separately and provides seamless integration to standard applications on Windows, Linux, and macOS.

CardOS V5.4 Datasheet

Categories: , Tags: ,

Description

Basic Features

    • Contact-based interface according to ISO/IEC 7816,
    • Contactless interfaces in accordance with ISO/IEC 14443 Type A or B (default),
    • ISO/IEC 7816 compatible commands,
    • Compatibility with the most important international standards providing long-term security for integration in standardized environments (readers, applications, etc.),
    • Expandability of the operating system with the subsequent addition of software packages,
    • Integrity protection of all active software packages preventing the use of corrupt software,
    • “Command chaining” in accordance with ISO/IEC 7816-4,
    • A dynamic, flexible file system based on ISO/IEC 7816-4 with the following characteristics:

      – Number of files and folders with any depth of nesting limited only by the storage capacity of the chip,
      – Support of Short File IDs,
      – Dynamic memory management for optimal utilization of the available EEPROM,
      – Protection mechanisms against EEPROM defects, power failure, and card tearing,
      – Flexible Memory Management for RAM and EEPROM,

    • Support of CV (card verifiable) certificates

      – Extraction and use of the public key directly from the certificate,
      – Verification of certificates and certificate chains.

Cryptographic Functions

    • Symmetric Algorithms

      – Triple DES (CBC) with ISO padding,
      – Triple DES MAC (also called Retail MAC) with ISO or ANSI padding,
      – AES (CBC) with key length 128, 192, 256 bit,
      – AES CMAC with ISO padding.

    • Asymmetric algorithms:

      – RSA based on CRT with and without a specified public exponent with key length up to 3072 bit,
      – PKCS#1-BT1 or PKCS#1-BT2 padding,
      – PSS and OAEP Padding according to PKCS#1 V2.1,
      – Elliptic Curve Cryptography based on GF(p) with key length up to 521 bit.

    • Calculation of cryptographic hash values with SHA-1, SHA-224, SHA-256, SHA-384, SHA-512,
    • Creation and verification of digital signatures with RSA and ECDSA,
    • Internal and external key generation for RSA and EC keys,
    • Secured key import with Secure Messaging,
    • EC Key Agreement of ElGamal Type (ECKA-EG) and support of EC Key Agreement with Diffie-Hellmann (ECKA-DH),
    • Flexible derivation of session keys,
    • True random number generator with AIS31 class DRG.4 or PTG.3.


Communication Protocols
Transmission protocol according to ISO/IEC:

    • T=1 (ISO/IEC 7816-3) and T=CL (ISO/IEC 14443-4 protocol Type A or B),
    • Support of extended length APDUs according to ISO/IEC 7816-4,
    • Up to four logical channels,
    • Support of protocol parameter selection (PPS),
    • Support of WTX (Waiting Time eXtension),
    • Fast, selectable card communication:

      – Contact-based with up to 446 kbaud as per ISO/IEC 7816-3,
      – Contactless with up to 848 kbaud.

    • Pseudo-Unique PICC Identifier (PUPI),
    • Card Identifier (CID) Handling,
    • NFC Tag Type 4.


Hardware Platform
CardOS (DI) V5.4 is based on the innovative digital security technology ‘Integrity Guard’ from Infineon and is implemented on the SLE78 security controller platform using SOLID FLASHTM*. SOLID FLASHTM products offer significant value add like increased logistic flexibility and faster time to market.

CardOS (DI) V5.4 is available on the chip SLE78CLFX400BPH. CardOS (DI) V5.4 provides about 108 kByte user memory.

CardOS DI V5.4 is available in wafer form, as COM10.6 module with Coil on Module technology (DI) or as smart card in ID-1 format. CardOS V5.4 as a pure contact-based product is available in wafer form, as S-MID4.8 module or as smart card in ID-1, ID-000 or Micro-SIM format.

* SOLID FLASHTM is a registered trademark of Infineon Technologies AG


Initialization and Personalization
The personalization and initialization procedures facilitate cost-efficient mass production of the CardOS (DI) V5.4 cards as well as high performance, highly secure modification of existing applications and the addition of new applications in the field.

    • Support of independent personalization for individual applications,
    • Integrated security concept for initialization and personalization.

ICAO and eID Support
CardOS (DI) V5.4 provides support of ePassport and eID features according to ICAO Doc 9303 and BSI TR-03110:

    • Basic Access Control (BAC),
    • Extended Access Control (EACv1):

      – Chip Authentication (CA) with ECDH,
      – Terminal Authentication (TA) with ECDSA,

    • Password Authenticated Connection Establishment (PACEv2) with ECDH,
    • Active Authentication with ECDSA,
    • Restricted Identification (RI) with ECDH.

You may also like…