nPA: added support for checking Expiry date
This commit is contained in:
@@ -143,6 +143,7 @@ class CardGenerator(object):
|
|||||||
from virtualsmartcard.cards.nPA import nPA_SAM
|
from virtualsmartcard.cards.nPA import nPA_SAM
|
||||||
ALGO_MAPPING["\x04\x00\x7f\x00\x07\x02\x02\x04\x02\x02"] = "PACE"
|
ALGO_MAPPING["\x04\x00\x7f\x00\x07\x02\x02\x04\x02\x02"] = "PACE"
|
||||||
ALGO_MAPPING["\x04\x00\x7f\x00\x07\x02\x02\x03\x02\x02"] = "CA"
|
ALGO_MAPPING["\x04\x00\x7f\x00\x07\x02\x02\x03\x02\x02"] = "CA"
|
||||||
|
ALGO_MAPPING["\x04\x00\x7f\x00\x07\x03\x01\x04\x02"] = "DateOfExpiry"
|
||||||
|
|
||||||
self.mf = MF()
|
self.mf = MF()
|
||||||
|
|
||||||
|
|||||||
@@ -19,10 +19,10 @@
|
|||||||
from virtualsmartcard.SmartcardSAM import SAM
|
from virtualsmartcard.SmartcardSAM import SAM
|
||||||
from virtualsmartcard.SEutils import ControlReferenceTemplate, Security_Environment
|
from virtualsmartcard.SEutils import ControlReferenceTemplate, Security_Environment
|
||||||
from virtualsmartcard.SWutils import SwError, SW
|
from virtualsmartcard.SWutils import SwError, SW
|
||||||
from virtualsmartcard.ConstantDefinitions import CRT_TEMPLATE, SM_Class
|
from virtualsmartcard.ConstantDefinitions import CRT_TEMPLATE, SM_Class, ALGO_MAPPING
|
||||||
from virtualsmartcard.TLVutils import unpack, bertlv_pack
|
from virtualsmartcard.TLVutils import unpack, bertlv_pack
|
||||||
from virtualsmartcard.SmartcardFilesystem import make_property
|
from virtualsmartcard.SmartcardFilesystem import make_property
|
||||||
from virtualsmartcard.utils import inttostring, hexdump
|
from virtualsmartcard.utils import inttostring
|
||||||
import virtualsmartcard.CryptoUtils as vsCrypto
|
import virtualsmartcard.CryptoUtils as vsCrypto
|
||||||
from chat import CHAT
|
from chat import CHAT
|
||||||
import pace
|
import pace
|
||||||
@@ -321,6 +321,8 @@ class nPA_SE(Security_Environment):
|
|||||||
|
|
||||||
nonce, token = pace.CA_STEP5_derive_keys(self.eac_ctx, pubkey)
|
nonce, token = pace.CA_STEP5_derive_keys(self.eac_ctx, pubkey)
|
||||||
|
|
||||||
|
self.eac_step += 1
|
||||||
|
|
||||||
print "Generated Nonce and Authentication Token for CA"
|
print "Generated Nonce and Authentication Token for CA"
|
||||||
|
|
||||||
# TODO activate SM
|
# TODO activate SM
|
||||||
@@ -515,6 +517,19 @@ class nPA_SAM(SAM):
|
|||||||
|
|
||||||
return SW["NORMAL"], self.last_challenge
|
return SW["NORMAL"], self.last_challenge
|
||||||
|
|
||||||
|
def verify(self, p1, p2, data):
|
||||||
|
if (p1 != 0x80 or p2 != 0x00):
|
||||||
|
raise SwError(SW["ERR_INCORRECTP1P2"])
|
||||||
|
|
||||||
|
if self.current_SE.eac_step == 6:
|
||||||
|
structure = unpack(data)
|
||||||
|
for tag, length, value in structure:
|
||||||
|
if tag == 6 and ALGO_MAPPING[value] == "DateOfExpiry":
|
||||||
|
# hell yes, this is a valid nPA
|
||||||
|
return SW["NORMAL"], ""
|
||||||
|
|
||||||
|
raise SwError(SW["WARN_NOINFO63"])
|
||||||
|
|
||||||
def parse_SM_CAPDU(self, CAPDU, header_authentication):
|
def parse_SM_CAPDU(self, CAPDU, header_authentication):
|
||||||
if hasattr(self.current_SE, "new_encryption_ctx"):
|
if hasattr(self.current_SE, "new_encryption_ctx"):
|
||||||
if self.current_SE.new_encryption_ctx == pace.EAC_ID_PACE:
|
if self.current_SE.new_encryption_ctx == pace.EAC_ID_PACE:
|
||||||
@@ -530,7 +545,7 @@ class nPA_SAM(SAM):
|
|||||||
delattr(self.current_SE, "new_encryption_ctx")
|
delattr(self.current_SE, "new_encryption_ctx")
|
||||||
|
|
||||||
self.current_SE.ssc += 1
|
self.current_SE.ssc += 1
|
||||||
return SAM.parse_SM_CAPDU(self, CAPDU, header_authentication)
|
return SAM.parse_SM_CAPDU(self, CAPDU, 1)
|
||||||
|
|
||||||
def protect_result(self, sw, unprotected_result):
|
def protect_result(self, sw, unprotected_result):
|
||||||
self.current_SE.ssc += 1
|
self.current_SE.ssc += 1
|
||||||
|
|||||||
Reference in New Issue
Block a user