From bb79725dd64aee8a2231d37a2818d2b1243138d3 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:05:05 +0000 Subject: [PATCH 1/2] Initial plan From e628f44172a959b0e8699e1ba5405a51701c1329 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:08:27 +0000 Subject: [PATCH 2/2] Clarify SD-selection precondition for SCP authenticate docs Co-authored-by: yuki-js <20838151+yuki-js@users.noreply.github.com> --- .../java/app/aoki/cinpo/gp/scp/Scp02Protocol.java | 14 ++++++++++++++ .../java/app/aoki/cinpo/gp/scp/Scp03Protocol.java | 6 ++++-- .../aoki/cinpo/gp/scp/SecureChannelSession.java | 6 ++++-- 3 files changed, 22 insertions(+), 4 deletions(-) diff --git a/src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java b/src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java index 6a224d2..fcb2c93 100644 --- a/src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java +++ b/src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java @@ -81,6 +81,20 @@ final class Scp02Protocol implements InternalSecureChannelProtocol { validateStaticConfiguration(); } + /** + * Performs SCP02 authentication and initializes secure-messaging state. + * + *

Precondition: the card's Security Domain identified by + * {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling + * this method. Callers are responsible for issuing the plain SELECT command. + * + *

The flow starts by discovering implementation options, then performs explicit + * (INITIALIZE UPDATE + EXTERNAL AUTHENTICATE) or implicit initiation depending on the card + * configuration. + * + * @param channel the raw APDU transport channel + * @throws IllegalStateException if SCP02 setup or cryptographic checks fail + */ @Override public void authenticate(ApduChannel channel) { try { diff --git a/src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java b/src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java index 4e8476a..830b14b 100644 --- a/src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java +++ b/src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java @@ -124,10 +124,12 @@ final class Scp03Protocol implements InternalSecureChannelProtocol { /** * Performs SCP03 mutual authentication with the card (Figure 5-1, [Amd D] §5.2). * + *

Precondition: the card's Security Domain identified by + * {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling + * this method. Callers are responsible for issuing the plain SELECT command. + * *

The authentication flow consists of the following steps: *

    - *
  1. SELECT – selects the Security Domain identified by - * {@link SecureChannelProfile#securityDomainAid()}.
  2. *
  3. INITIALIZE UPDATE ([Amd D] §7.1.1) – sends the 8-byte host challenge to * the card. The card generates its own card challenge, derives session keys, and * returns its card cryptogram along with the SCP identifier and the "i" parameter.
  4. diff --git a/src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java b/src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java index 6c0e350..eb5a519 100644 --- a/src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java +++ b/src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java @@ -82,10 +82,12 @@ public static SecureChannelSession create(ApduChannel channel, SecureChannelProf /** * Performs explicit Secure Channel initiation ([GPCS] §10.2.1). * + *

    Precondition: the card's Security Domain identified by + * {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling + * this method. Callers are responsible for issuing the plain SELECT command. + * *

    The following sequence is executed: *

      - *
    1. SELECT – selects the Security Domain identified by - * {@link SecureChannelProfile#securityDomainAid()}.
    2. *
    3. INITIALIZE UPDATE ([Amd D] §7.1.1) – transmits the 8-byte host challenge * to the card and receives key diversification data, the card challenge, and the * card cryptogram. Session keys are derived from the static key set.