Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions src/main/java/app/aoki/cinpo/gp/scp/Scp02Protocol.java
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,20 @@ final class Scp02Protocol implements InternalSecureChannelProtocol {
validateStaticConfiguration();
}

/**
* Performs SCP02 authentication and initializes secure-messaging state.
*
* <p><strong>Precondition:</strong> the card's Security Domain identified by
* {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling
* this method. Callers are responsible for issuing the plain SELECT command.
*
* <p>The flow starts by discovering implementation options, then performs explicit
* (INITIALIZE UPDATE + EXTERNAL AUTHENTICATE) or implicit initiation depending on the card
* configuration.
*
* @param channel the raw APDU transport channel
* @throws IllegalStateException if SCP02 setup or cryptographic checks fail
*/
@Override
public void authenticate(ApduChannel channel) {
try {
Expand Down
6 changes: 4 additions & 2 deletions src/main/java/app/aoki/cinpo/gp/scp/Scp03Protocol.java
Original file line number Diff line number Diff line change
Expand Up @@ -124,10 +124,12 @@ final class Scp03Protocol implements InternalSecureChannelProtocol {
/**
* Performs SCP03 mutual authentication with the card (Figure 5-1, [Amd D] §5.2).
*
* <p><strong>Precondition:</strong> the card's Security Domain identified by
* {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling
* this method. Callers are responsible for issuing the plain SELECT command.
*
* <p>The authentication flow consists of the following steps:
* <ol>
* <li><b>SELECT</b> – selects the Security Domain identified by
* {@link SecureChannelProfile#securityDomainAid()}.</li>
* <li><b>INITIALIZE UPDATE</b> ([Amd D] §7.1.1) – sends the 8-byte host challenge to
* the card. The card generates its own card challenge, derives session keys, and
* returns its card cryptogram along with the SCP identifier and the "i" parameter.</li>
Expand Down
6 changes: 4 additions & 2 deletions src/main/java/app/aoki/cinpo/gp/scp/SecureChannelSession.java
Original file line number Diff line number Diff line change
Expand Up @@ -82,10 +82,12 @@ public static SecureChannelSession create(ApduChannel channel, SecureChannelProf
/**
* Performs explicit Secure Channel initiation ([GPCS] §10.2.1).
*
* <p><strong>Precondition:</strong> the card's Security Domain identified by
* {@link SecureChannelProfile#securityDomainAid()} must already be selected before calling
* this method. Callers are responsible for issuing the plain SELECT command.
*
* <p>The following sequence is executed:
* <ol>
* <li><b>SELECT</b> – selects the Security Domain identified by
* {@link SecureChannelProfile#securityDomainAid()}.</li>
* <li><b>INITIALIZE UPDATE</b> ([Amd D] §7.1.1) – transmits the 8-byte host challenge
* to the card and receives key diversification data, the card challenge, and the
* card cryptogram. Session keys are derived from the static key set.</li>
Expand Down