[Muscle] load file DAP

Peter Williams home_pw at msn.com
Mon Apr 14 11:04:14 PDT 2008


I've managed to locate (somewhat incredibly) 5 virgen USB tokens that - 
presumably as they are in their original static-proof bags - still have the 
manufacturer's app security domain applet on the card - in addition of the 
card issuers SD. (Typically, during post-manufacturing we removed the app SD 
, to free up space to load and init the muscle applet.)

What I do not have is any technical documentation and all the my people 
contacts have long since left the javacard startup company for greener 
pastures.

Anyone want to play with some of them, to test GPShell and ensure its 2.01 
era delegated loading (via RSA) is solid?

--------------------------------------------------
From: "Karsten Ohme" <widerstand at t-online.de>
Sent: Saturday, April 05, 2008 4:43 AM
To: "MUSCLE" <muscle at lists.musclecard.com>
Subject: Re: [Muscle] load file DAP

> Peter Williams schrieb:
>> 1. Has anyone used GPShell to load an RSA public key into an _issuer's_ 
>> security domain of a 201 card, so one can use the GPShell to send a DAP 
>> hash and signature for the load file?
>
> I think this does not work. I have tried a lot with different cards, but I 
> had no success. So, there might be compatibility problems, the cards do to 
> support it after all or the specification is not clear enough. You can 
> play with the code base, would be very interesting to me, if you get it 
> working.
>
> Karsten
>>  2. has anyone tested the use of SHA1 by itself for a LOAD DAP?
>>  3  If I half remember right, only a security domain OTHER than the card 
>> manager SD can verify either a DESCBC or an RSA DAP (given its knows the 
>> verification key, and knowledge that the signature is either RSA or 
>> DESCBC).
>>  ------------------------------------------------------------------------
>>
>> _______________________________________________
>> Muscle mailing list
>> Muscle at lists.musclecard.com
>> http://lists.drizzle.com/mailman/listinfo/muscle
>
> _______________________________________________
> Muscle mailing list
> Muscle at lists.musclecard.com
> http://lists.drizzle.com/mailman/listinfo/muscle
> 


More information about the Muscle mailing list