diff --git a/src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java b/src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java index 6a224d2..fcb2c93 100644 --- a/src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java +++ b/src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java @@ -81,6 +81,20 @@ final class Scp02Protocol implements InternalSecureChannelProtocol { validateStaticConfiguration(); } + /** + * Performs SCP02 authentication and initializes secure-messaging state. + * + *

Precondition: the card's Security Domain identified by + * {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling + * this method. Callers are responsible for issuing the plain SELECT command. + * + *

The flow starts by discovering implementation options, then performs explicit + * (INITIALIZE UPDATE + EXTERNAL AUTHENTICATE) or implicit initiation depending on the card + * configuration. + * + * @param channel the raw APDU transport channel + * @throws IllegalStateException if SCP02 setup or cryptographic checks fail + */ @Override public void authenticate(ApduChannel channel) { try { diff --git a/src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java b/src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java index 4e8476a..830b14b 100644 --- a/src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java +++ b/src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java @@ -124,10 +124,12 @@ final class Scp03Protocol implements InternalSecureChannelProtocol { /** * Performs SCP03 mutual authentication with the card (Figure 5-1, [Amd D] §5.2). * + *

Precondition: the card's Security Domain identified by + * {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling + * this method. Callers are responsible for issuing the plain SELECT command. + * *

The authentication flow consists of the following steps: *

    - *
  1. SELECT – selects the Security Domain identified by - * {@link SecureChannelProfile#securityDomainAid()}.
  2. *
  3. INITIALIZE UPDATE ([Amd D] §7.1.1) – sends the 8-byte host challenge to * the card. The card generates its own card challenge, derives session keys, and * returns its card cryptogram along with the SCP identifier and the "i" parameter.
  4. diff --git a/src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java b/src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java index 6c0e350..eb5a519 100644 --- a/src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java +++ b/src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java @@ -82,10 +82,12 @@ public static SecureChannelSession create(ApduChannel channel, SecureChannelProf /** * Performs explicit Secure Channel initiation ([GPCS] §10.2.1). * + *

    Precondition: the card's Security Domain identified by + * {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling + * this method. Callers are responsible for issuing the plain SELECT command. + * *

    The following sequence is executed: *

      - *
    1. SELECT – selects the Security Domain identified by - * {@link SecureChannelProfile#securityDomainAid()}.
    2. *
    3. INITIALIZE UPDATE ([Amd D] §7.1.1) – transmits the 8-byte host challenge * to the card and receives key diversification data, the card challenge, and the * card cryptogram. Session keys are derived from the static key set.