Files
vsmartcard/virtualsmartcard
Frank Morgner f6e922222e removed the currently unused getenc and setenc
These functions intended to do encryption and decryption respecting file
acls. This however was never implemented. Better use object properties
with appropriately setters and getters to realize this functionality.
2012-09-05 09:54:06 +02:00
..
2009-08-22 08:01:54 +00:00
2012-04-11 19:51:06 +00:00
2012-08-31 18:06:09 +02:00
2009-08-22 08:01:54 +00:00
2012-08-31 18:06:09 +02:00
2010-05-08 20:58:58 +00:00

.. highlight:: sh

.. _PBKDF2: https://www.dlitz.net/software/python-pbkdf2/
.. _PCSC-lite: http://pcsclite.alioth.debian.org/
.. _PCSC-lite: http://pcsclite.alioth.debian.org/
.. _PIP: http://www.pythonware.com/products/pil/
.. _PyCrypto: http://pycrypto.org/
.. _Python: http://www.python.org/
.. _cyberflex-shell: https://github.com/henryk/cyberflex-shell
.. _pyscard: http://pyscard.sourceforge.net/

.. |vpicc| replace:: :abbr:`vpicc (virtual smart card)`
.. |vpcd| replace:: :abbr:`vpcd (virtual smart card reader)`
.. |EAC| replace:: :abbr:`EAC (Extended Access Control)`
.. |PACE| replace:: :abbr:`PACE (Password Authenticated Connection Establishment)`

.. _vicc:

********************************************************************************
Virtual Smart Card
********************************************************************************

:Authors:
    - Frank Morgner <morgner@informatik.hu-berlin.de>
    - Dominik Oepen <oepen@informatik.hu-berlin.de>
:License:
    GPL version 3
:Tested Platforms:
    - Linux (Debian, Ubuntu, OpenMoko)
    - Windows (|vpicc| natively, |vpcd| only via Cygwin)
:Potential Platforms:
    Unix-like operating systems (Mac OS, Solaris, BSD, ...)

Virtual Smart Card emulates a smart card and makes it accessible through PC/SC.
Currently the Virtual Smart Card supports the following types of smart cards:

- Generic ISO-7816 smart card including secure messaging
- German electronic identity card (nPA) with |EAC| including |PACE|
- German electronic passport (ePass) with basic access control
- Cryptoflex smart card (incomplete)
      
The |vpcd| is a smart card driver for PCSC-Lite_. It allows
smart card applications to access the |vpicc| through the PC/SC API.  By
default |vpicc| communicates with |vpcd| through a socket on localhost port
35963. But the |vpicc| does not need to run on the same machine as the |vpcd|,
they can connect over the internet for example.

Although the Virtual Smart Card is a software emulator, you can use
:ref:`pcsc-relay` to make it accessible to an external contact-less smart card
reader.

The file :file:`utils.py` was taken from Henryk Plötz's cyberflex-shell_.


.. include:: autotools.rst

Depending on your usage of the |vpicc| you might or might not need
the following:

- Python_
- pyscard_
- PyCrypto_
- PBKDF2_
- PIP_

The |vpcd| depends on PCSC-Lite_.


================================================================================
Running the Virtual Smart Card
================================================================================

First you need to make sure that :command:`pcscd` loads the |vpcd|. You might
need to run :command:`update-reader.conf` to update its configuration file.
Then :command:`pcscd -f -d` should say something like "Attempting startup of
Virtual PCD"

Now you can run :command:`vicc` which connects to the |vpcd|. The command
:command:`vicc --help` gives an overview about the command line options.

.. program-output:: vicc --help

You should now be able to access the |vpicc| through the PC/SC API via
|vpcd|/:command:`pcscd`. You can use the :command:`opensc-explorer` or
:command:`pcsc_scan` for testing.

--------------------------------------------------------------------------------
Accessing the Virtual Smart Card from Windows applications
--------------------------------------------------------------------------------

Running |vpcd| under Windows is currently not supported, because it implements
a smart card driver specific for PCSC-Lite (:command:`pcscd`). This means, that
although you can run |vpicc| under Windows (for example in relay mode), it
can't be accessed by Windows' smart card applications.

However, there are several more or less complicated paths you can go:

- Run |vpcd|/:command:`pcscd` in Linux and use :ref:`pcsc-relay` to forward the
  |vpicc| via NFC to a contactless reader which is attached to the Windows
  machine. This has been tested tested with a ACR122U (touchatag).
- Run your windows machine as virtual machine in a Linux host. Then run
  |vpcd|/:command:`pcscd` in the Linux host and grab the |vpicc| with the
  :ref:`ccid-emulator`. Now forward the emulated USB device to the Windows VM.
  This is easy, but the :ref:`ccid-emulator` is not tested very well under
  Windows.
- Use the combination above (|vpcd|/:ref:`ccid-emulator` under Linux) on a
  device, that you can put in USB client mode. Then use a USB connector to
  physically connect the Linux machine in client mode to the Windows machine.
- Port the |vpcd| from PCSC-Lite to Windows' PC/SC service. Then, |vpcd| runs
  natively under Windows. Although |vpcd| is relatively simple and should be
  POSIX compliant, this could be a lot of work.
- Run |vpcd|/:command:`pcscd` under Cygwin on the Windows machine. This has
  been reported to work, but it is unclear whether you can use PCSC-Lite as
  PC/SC provider for a native Windows application.


.. include:: questions.rst