8e999b770d4ad51f7f7bb5bae331a06a79265cec
After AUTH1 parks StepUpSK in SessionContext, the reader issues SELECT to the Step-Up AID per spec §10.2. StepUpApplet.select() now picks up the parked SK, derives StepUpSKDevice / StepUpSKReader via the §8.4.3 HKDF (already implemented in AliroCrypto.deriveStepUpSessionKeys), and stages both in transient CLEAR_ON_DESELECT fields for the ENVELOPE (M1C.1) and EXCHANGE (M1B.1) handlers. Introduces CryptoSingletons -- a lazy package-private holder for the single AliroCrypto instance shared between AliroApplet and StepUpApplet. Saves ~352 B of transient (kdfWorkbuf + hkdfPrevT + expandScratch) versus a per-applet duplicate. Java Card forbids new in <clinit> so the singleton uses lazy null-check init. Opt 1 prelude per docs/plans/2026-06-11-step-up-implementation-v2.md. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Description
java card applet(s) for Aliro
Languages
C
89.7%
HTML
3.5%
Assembly
3.1%
CSS
2.1%
Java
0.7%
Other
0.9%