b03c781b926f5bafdcd0535bdf4129f323513aba
Adds INS_DIAG_HMAC (0xD0), INS_DIAG_ECDH (0xD1), INS_DIAG_ECDSA_SIGN (0xD2), and INS_DIAG_GCM (0xD3) to AliroApplet, gated by a DIAGNOSTICS_ENABLED compile-time flag so they're trivially strippable for production builds. Each INS runs its primitive N times (N in P3 byte) against hardcoded card-side test vectors and returns the result. Output lands in the APDU buffer at offset 16, never in scratch -- the AUTH session state stays intact even if a diag INS runs mid-session. The HMAC INS routes through a new AliroCrypto.diagHmac() wrapper that exposes the internal AliroHmac instance without leaking it through the class boundary. ECDH/ECDSA use a dedicated diagKeyPair (separate from the protocol's credentialEphemeralKeyPair) so a diagnostic call can never disturb a real AUTH flow. These INSes are what aliro-bench-profile drives over PC/SC -- they let us measure each AUTH1 primitive's cost in isolation and reconstruct the AUTH1 budget against the bench-test wall-clock. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Description
java card applet(s) for Aliro
Languages
C
89.7%
HTML
3.5%
Assembly
3.1%
CSS
2.1%
Java
0.7%
Other
0.9%