ISO 7816

ISO 7816

ISO/IEC 7816 is an international standard related to electronic identification cards, especially smart cards, managed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It is an extension of ISO/IEC 7810.

It is edited by the Joint technical committee (JTC) 1 / Sub-Committee (SC) 17, [http://www.iso.org/iso/en/stdsdevelopment/tc/tclist/TechnicalCommitteeDetailPage.TechnicalCommitteeDetail?COMMID=64 Cards and personal identification] .

The following describes the different parts of this standard.:"Note: abstracts and dates, when present, are mere quotations from the ISO website, and are neither guaranteed at the time of edition nor in the future".

7816-1: Physical characteristics

Created in 1987, updated in 1998, amended in 2003 ( [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=29257&ICS1=35&ICS2=240&ICS3=15 source] ).

7816-2: Cards with contacts — Dimensions and location of the contacts

Created in 1988, updated in 1999, amended in 2004 ( [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=26536&ICS1=35&ICS2=240&ICS3=15 source] ).

7816-3: Cards with contacts — Electrical interface and transmission protocols

Created in 1989, updated in 1997, amended in 2002 and in 2006 ( [http://www.iso.org/iso/iso_catalogue/catalogue_ics/catalogue_detail_ics.htm?csnumber=38770 source] ).

7816-4: Organization, security and commands for interchange

Created in 1995, updated in 2005.

From its [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=36134&ICS1=35&ICS2=240&ICS3=15 abstract] , it specifies:
* contents of command-response pairs exchanged at the interface,
* means of retrieval of data elements and data objects in the card,
* structures and contents of historical bytes to describe operating characteristics of the card,
* structures for applications and data in the card, as seen at the interface when processing commands,
* access methods to files and data in the card,
* a security architecture defining access rights to files and data in the card,
* means and mechanisms for identifying and addressing applications in the card,
* methods for secure messaging,
* access methods to the algorithms processed by the card. It does not describe these algorithms.

It does not cover the internal implementation within the card or the outside world.

ISO/IEC 7816-4:2005 is independent from the physical interface technology. It applies to cards accessed by one or more of the following methods: contacts, close coupling, and radio frequency.

7816-5: Registration of application providers

Created in 1995, updated in 2004.

From its [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=34259&ICS1=35&ICS2=240&ICS3=15&showrevision=y abstract] , ISO/IEC 7816-5 defines how to use an application identifier to ascertain the presence of and/or perform the retrieval of an application in a card.

ISO/IEC 7816-5:2004 shows how to grant the uniqueness of application identifiers through the international registration of a part of this identifier, and defines
* the registration procedure,
* the authorities in charge thereof,
* the availability of the register which links the registered parts of the identifiers and the relevant application providers.

7816-6: Interindustry data elements for interchange

Created in 1996, updated in 2004.

From its [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=38780&ICS1=35&ICS2=240&ICS3=15&showrevision=y abstract] , it specifies the Data Elements (DEs) used for interindustry interchange based on integrated circuit cards (ICCs) both with contacts and without contacts. It gives the identifier, name, description, format, coding and layout of each DE and defines the means of retrieval of DEs from the card.

7816-7: Interindustry commands for Structured Card Query Language (SCQL)

Created (or updated) in 1999 ( [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=28869&ICS1=35&ICS2=240&ICS3=15 source] ).

7816-8: Commands for security operations

Created in 1995, updated in 2004.

From its [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=37989&ICS1=35&ICS2=240&ICS3=15&showrevision=y abstract] , it specifies interindustry commands for integrated circuit cards (either with contacts or without contacts) that may be used for cryptographic operations. These commands are complementary to and based on the commands listed in ISO/IEC 7816-4.

Annexes are provided that give examples of operations related to digital signatures, certificates and the import and export of asymmetric keys.

The choice and conditions of use of cryptographic mechanisms may affect card exportability. The evaluation of the suitability of algorithms and protocols is outside the scope of ISO/IEC 7816-8.

7816-9: Commands for card management

Created in 1995, updated in 2004.

From its [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=37990&ICS1=35&ICS2=240&ICS3=15&showrevision=y abstract] , it specifies interindustry commands for integrated circuit cards (both with contacts and without contacts) for card and file management, e.g. file creation and deletion. These commands cover the entire life cycle of the card and therefore some commands may be used before the card has been issued to the cardholder or after the card has expired.

An annex is provided that shows how to control the loading of data (secure download) into the card, by means of verifying the access rights of the loading entity and protection of the transmitted data with secure messaging. The loaded data may contain, for example, code, keys and applets.

7816-10: Electronic signals and answer to reset for synchronous cards

Created (or updated) in 1999 ( [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=30558&ICS1=35&ICS2=240&ICS3=15 source] ).

This part specifies the power, signal structures, and the structure for the answer to reset between an integrated circuit card(s) with synchronous transmission and an interface device such as a terminal.

7816-11 Personal verification through biometric methods

Created (or updated) in 2004.

From its [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=31419&ICS1=35&ICS2=240&ICS3=15 abstract] , it specifies the usage of interindustry commands and data objects related to personal verification through biometric methods in integrated circuit cards. The interindustry commands used are defined in ISO/IEC 7816-4. The data objects are partially defined in this International Standard, partially imported from ISO/IEC 19785-1.

ISO/IEC 7816-11 also presents examples for enrollment and verification and addresses security issues.

7816-12 Cards with contacts -- USB electrical interface and operating procedures

Created in 2005.

From its [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=40604&ICS1=35&ICS2=240&ICS3=15 abstract] , it specifies the operating conditions of an integrated circuit card that provides a USB interface. An integrated circuit card with a USB interface is named USB-ICC.

ISO/IEC 7816-12:2005 specifies:
* the electrical conditions when a USB-ICC is operated by an interface device - for those contact fields that are not used, when the USB interface is applied;
* the USB standard descriptors and the USB-ICC class specific descriptor;
* the data transfer between host and USB-ICC using bulk transfers or control transfers;
* the control transfers which allow two different protocols named version A and version B;
* the (optional) interrupt transfers to indicate asynchronous events;
* status and error conditions.

ISO/IEC 7816-12:2005 provides two protocols for control transfers. This is to support the protocol T=0 (version A) or to use the transfer on APDU level (version B). ISO/IEC 7816-12:2005 provides the state diagrams for the USB-ICC for each of the transfers (bulk transfers, control transfers version A and version B). Examples of possible sequences which the USB-ICC must be able to handle are given in an informative annex.

7816-13: Commands for application management in multi-application environment

As of 2006, this document is in development ( [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=40605&scopelist=PROGRAMME source] ) and is supposed to integrate methods from the GlobalPlatform [http://globalplatform.org/ *] standard, like its "Secure Channel Protocols" (see this NIST [http://csrc.nist.gov/publications/nistir/ir7284/nistir-7284.pdf report (in PDF format)] for more information).

7816-15: Cryptographic information application

Created in 2004.

From its [http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=35168&ICS1=35&ICS2=240&ICS3=15 abstract] , it specifies a card application. This application contains information on cryptographic functionality. Further, ISO/IEC 7816-15:2004 defines a common syntax (in ASN.1) and format for the cryptographic information and mechanisms to share this information whenever appropriate.

ISO/IEC 7816-15:2004 supports the following capabilities:

* storage of multiple instances of cryptographic information in a card;
* use of the cryptographic information;
* retrieval of the cryptographic information;
* cross-referencing of the cryptographic information with DOs defined in ISO/IEC 7816 when appropriate;
* different authentication mechanisms; and
* multiple cryptographic algorithms.

ee also

* Smart card
* ISO/IEC 14443, a proximity card standard related to smart cards, on a different physical communication support.
* List of ISO standards

Links

* [http://www.cardwerk.com/smartcards/smartcard_standard_ISO7816.aspx Overview of ISO/IEC 7816 parts 1-4]
* [http://www.sc17.com/ ISO/IEC JTC1/SC17 Working Groups]
* [http://www.scdb.rd-logic.com/ On-line Smart Card ATR Database]
* [http://cheef.ru/docs/HowTo/APDU.info Selected list of smartcard APDU commands]


Wikimedia Foundation. 2010.

Игры ⚽ Поможем решить контрольную работу

Look at other dictionaries:

  • ISO 7816 — ist ein mehrteiliger internationaler Standard der Internationalen Organisation für Normung und der Internationalen elektrotechnischen Kommission, der wesentliche Merkmale von Chipkarten vereinheitlicht. Der Standard ist eine Erweiterung zur ISO… …   Deutsch Wikipedia

  • ISO 7816 — es un estándar internacional relacionado con las tarjetas de identificación electrónicas, en especial las tarjetas inteligentes, gestionado conjuntamente por la Organización Internacional De Normalización (ISO) y Comisión Electrotécnica… …   Wikipedia Español

  • ISO/IEC 7816 — ISO 7816 ist ein mehrteiliger internationaler Standard der Internationalen Organisation für Normung und der Internationalen elektrotechnischen Kommission, der wesentliche Merkmale von Chipkarten vereinheitlicht. Der Standard ist eine Erweiterung… …   Deutsch Wikipedia

  • ISO/IEC 7816 — ISO/IEC 7816  стандарт относится к смарт картам (в первую очередь контактным). Описывает форму карты, контактов, их расположение и назначение; протоколы обмена и некоторые аспекты работы с данными. Стандарт можно назвать базовым для всех… …   Википедия

  • ISO/IEC 14443 — ISO/IEC 14443  стандарт, описывающий частотный диапазон, метод модуляции и протокол обмена бесконтактных пассивных карт (RFID) ближнего радиуса действия (до 10 см) на магнитосвязанных индуктивностях. Стандарт был разработан 8 й рабочей… …   Википедия

  • Iso 7810 — est un standard international qui définit quatre formats pour des cartes d identité ou d identification : ID 1, ID 2, ID 3 et ID 000. Sommaire 1 ID 1 2 ID 2 3 ID 3 4 ID 000 …   Wikipédia en Français

  • ISO 7812 — ISO 7812, first published by the International Organization for Standardization (ISO) in 1989, is the international standard governing magnetic stripe identification cards, such as door entry cards, automated teller machine (ATM) cards, and… …   Wikipedia

  • ISO 7810 — est une norme internationale qui définit quatre formats pour des cartes d identité ou d identification : ID 1, ID 2, ID 3 et ID 000. Sommaire 1 ID 1 2 ID 2 3 ID 3 4 ID 000 …   Wikipédia en Français

  • ISO 14443 — es un estándar internacional relacionado con las tarjetas de identificación electrónicas, en especial las tarjetas inteligentes, gestionado conjuntamente por la Organización Internacional de Normalización (ISO) y Comisión Electrotécnica… …   Wikipedia Español

  • ISO/IEC 14443 — defines a proximity card used for identification that usually uses the standard credit card form factor defined by ISO/IEC 7810 ID 1. Other form factors also are possible. tandardThe standard was developed by the Working Group 8 of Subcommittee… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”