| Instruction | Description Comments |
|---|
| July 2018 | 17 |
|---|
| Contactless card communication | PLT-03273, Rev. A.1 |
|---|
| SW1SW2 | Definition 0x9000 Operation successful. 0x6700 Wrong length (Lc or Le). 0x6A81 Function not supported. 0x6B00 Wrong parameter (P1 or P2). 0x6F00 Operation failed. |
|---|
| CLA | INS P1 P2 Lc Data In Le 0xFF 0xCA 0x00 0x00 – – XX 0x01 |
|---|
| P1 | Card type Data Out SW1SW2 0x00 ISO/IEC 14443 Type A 4, 7 or 10-byte UID 0x9000 Operation successful. |
|---|
| ISO/IEC 14443 Type B | 4-byte PUPI |
|---|
| FeliCa | 8-byte IDm |
|---|
| iCLASS 14443 Type B / 15693 | 8-byte CSN 0x01 ISO/IEC 14443 Type A n Historical bytes |
|---|
| Other | – 0x6A81 Function not supported. ■ For the ISO/IEC 14443 Type A Innovision Jewel card, the data field is 7 bytes of 0x00. ■ The number of historical bytes returned is limited to 15. 18 July 2018 |
|---|
| PLT-03273, Rev. A.1 | Contactless card communication |
|---|
| b7 | b6 b5 b4 b3 b2 b1 b0 Description 0 -- RFU ---- Card key. 1 -- ---- Reader key. |
|---|
| -- | 0 --- ---- Fixed to 0. Plain transmission. |
|---|
| --- | 0000 Fixed value 000. |
|---|
| KeyLength: | 6 or 8 or 16 bytes |
|---|
| Key: | Key in plain text |
|---|
| Data Out | SW1SW2 |
|---|
| – | 0x9000 Operation successful. 0x6982 Card key not supported. 0x6983 Reader key not supported. 0x6986 Invalid key. 0x6988 Key number not valid. 0x6989 Key length is not correct. |
|---|
| Byte 1 | Byte 2 Byte 3 Byte 4 Byte 5 |
|---|
| Version = 0x01 | Address MSB Address LSB Key Type Key Number |
|---|
| Key Types: | 0x00 = PicoPass Debit Key (KD) 0x01 = PicoPass Credit Key (KC) 0x60 =MIFARE KeyA 0x61 = MIFARE KeyB Address MSB = 0, Address LSB = the block number counted from 0 to [19 (MINI), 63 (1K), 127(2K) or 255(4K)]. Address LSB: Page number 0 - 7 Address MSB: Book number 0 or 1, bit 0 - book number, bit 1 select flag. Select flag 0 - authenticate without implicit select Select flag 1 - authenticate with i |
|---|
| Supported cards | Memory addressing |
|---|
| iCLASS | MSB = Book / LSB = Page. |
|---|
| MIFARE | Any block number in the requested sector. |
|---|
| Data field | SW1SW2 |
|---|
| empty | See following table. 20 July 2018 |
|---|
| 類型 | SW1SW2 Description |
|---|
| Normal | 0x9000 Successful. Warning |
|---|
| Execution Error | 0x6400 No Response from media (Time Out). 0x6581 Illegal block number (out of memory space). |
|---|
| Checking Error | 0x6700 Wrong APDU length. 0x6982 Security status not satisfied (not authenticated). 0x6986 Wrong key type. 0x6988 Wrong key number. |
|---|
| MIFARE 1K/4K | Block number Any multiple of a block (16 bytes) less than the sector size. |
|---|
| b5 | b4 b3 b2:0 0 0 000 Read block number (P2) without SELECT. 0 0 RFU 1 0 xxx Read block number (P2) with SELECT book 0, page xxx. 1 1 xxx Read block number (P2) with SELECT book 1, page xxx. 0 1 Rread with DES decrypted. 1 0 000000 RFU. 1 1 Read with 3-DES decrypted. |
|---|
| Warning | 0x6282 End of data reached before Le bytes (Le is greater than data length). |
|---|
| Value | Description 0xAx Tag = Operation to be performed: A0 = Increment A1 = Decrement 0x09 Length to end of command = 9. 0x80 Tag = Block index. 0x01 Length of value = 1. 0xxx Value = Index of block to be incremented or decremented (1 byte). 0x81 Tag = Value to be added or subtracted. 0x04 Length of value = 4. |
|---|
| xxxxxxxx | Value = Value to be added or subtracted from the source block (4 bytes, LSB first). |
|---|
| PC/SC key number | SE processor card API Size Type Description |
|---|
| Decimal | Hex key reference OID (bytes) 0 0x00 30 00 00 6 MIFARE Key slot 0. 1 0x01 30 00 01 6 MIFARE Key slot 1. 2 0x02 30 00 02 6 MIFARE Key slot 2. 3 0x03 30 00 03 6 MIFARE Key slot 3. 4 0x04 30 00 04 6 MIFARE Key slot 4. 5 0x05 30 00 05 6 MIFARE Key slot 5. 6 0x06 30 00 06 6 MIFARE Key slot 6. 7 0x07 30 00 07 6 MIFARE Key slot 7. 8 0x08 30 00 08 6 MIFARE Key slot 8. 9 0x09 30 00 09 6 MIFARE Key slot 9. |
|---|
| DER TLV Response PDU | See ISO 7816-4 |
|---|
| Vendor payload | Tag value (hex) Description |
|---|
| readerInformationApi | 0x02 Reader Information API. |
|---|
| response | 0x1D Response. |
|---|
| errorResponse | 0x1E Error Response. short form or long form. For the long form, the IFD uses the version with two subsequent octets. |
|---|
| DER TLV coded response PDU | See ISO 7816-4. 9E 02 xx yy 90 00 |
|---|
| cycle | Value byte 1: Cycle in which the error is occurred. See Error Cycle, below. |
|---|
| error | Value byte 2: Error code. See Error Code, below. |
|---|
| SW1 | 0x90 |
|---|
| SW2 | 0x00 First value byte |
|---|
| Cycle | Description 0 HID Proprietary Command APDU. 1 HID Proprietary Response APDU. 2 HID Read or Write EEPROM Structure. 3 RFU. 4 RFU. 5 RFU. 28 July 2018 |
|---|
| Exception | Description |
|---|
| Red | Orange Green Blue Black Purple FF 82 00 01 06 FF FF FF FF FF FF FF 86 00 00 05 01 00 01 60 01 FF B0 00 01 10 FF D6 00 02 10 00 11 22 33 44 55 66 77 88 99 AA BB CC DD EE FF |
|---|
| Command: | 90 5A 00 00 03 xx xx xx 00 |
|---|
| Response: | 91 00 |
|---|
| A1 0C | // decrement 80 01 05 // block 5 and 80 01 06 // restore to block 6 81 04 01 00 00 00 // value = 1 |
|---|
| A1 09 | // decrement 80 01 05 // block 5 81 04 64 00 00 00 // value = 100 |
|---|
| A0 09 | // increment 80 01 06 // block 6 81 04 02 00 00 00 // value = 2 |
|---|
| DER TLV coded response PDU. | See the following table. |
|---|
| Execution error | 0x6400 No response from media (Time Out). 0x6F00 Unknown error. |
|---|
| Checking error | 0x6700 Wrong APDU length. 32 July 2018 |
|---|
| xx | Length to end of command. |
|---|
| xx....xx | Value = Key reference (one of the following): User key OID (3 bytes, first byte must be 03). Key reference OID of predefined Secure Channel key (1 byte). Full OID of user defined Secure Channel key (x bytes). |
|---|
| xxxxxx | Value = Reference OID of the Key (3 bytes, first byte must be 03). 34 July 2018 |
|---|
| xx...xx | Value = Access rights of the file (x bytes). |
|---|
| SO OID | = 2B 06 01 04 01 81 E4 38 01 01 02 04 01 8F 63 13 Media type = 07 (Seos) 42 July 2018 |
|---|
| Section | 6 |
|---|
| Secure session model | PLT-03273, Rev. A.1 |
|---|
| A1 12 | // CHOICE ManageSECS |
|---|
| A0 10 | // CHOICE EstablishAUTH1 80 01 00 // VersionSECCH (Currently SAM ignores this value) 81 01 yy // Key Number (OID) 82 08 xx xx xx xx xx xx xx xx // RND.A |
|---|
| uu uu uu uu uu uu uu uu | // 8 byte UID Secure channel return |
|---|
| rr rr rr rr rr rr rr rr | // 8 byte RND.B codes. |
|---|
| xx xx xx xx xx xx xx xx | // 16 byte Reader Cryptogram xx xx xx xx xx xx xx xx 44 July 2018 |
|---|
| A1 26 | // CHOICE ManageSECS |
|---|
| A1 24 | // CHOICE EstablishAUTH2 80 10 xx xx xx xx xx xx xx xx // xx = ClientCryptogram xx xx xx xx xx xx xx xx 81 10 yy yy yy yy yy yy yy yy // yy = C-MAC yy yy yy yy yy yy yy yy |
|---|
| yy yy yy yy yy yy yy yy | // 16 byte R-MAC Secure channel return |
|---|
| APDU | Padding |
|---|
| FF B0 00 06 08 | 80 00 00 00 00 00 00 00 00 00 00 |
|---|
| A1 02 | // CHOICE ManageSECS |
|---|
| A2 00 | // CHOICE terminateSecuredSession |
|---|
| FF 70 07 6B 04 A1 02 A2 00 | 80 00 00 00 00 00 00 |
|---|
| SAM command | Padding 91 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|---|
| Object | Write Read |
|---|
| Keys 0x1F to 0x34 and 0x80 | Secure Session Key. Not allowed. |
|---|
| All other keys | Free access. Not allowed. |
|---|
| Prox PACS data | Not supported. Free access. 48 July 2018 |
|---|
| A01EA51CA51A80010181030300 NN 8210 | XXXX XXXX XXXX XXXX ■ Terminate the secure session. |
|---|
| ■ | Standard inter-industry commands as defined in ISO/IEC 7816-4:2005(E). These commands are passed transparently to the contactless card related to the CCID slot. |
|---|
| Reader configuration | PLT-03273, Rev. A.1 |
|---|
| Root | Request Branch |
|---|
| readerInformationApi (0x02) | Get (0x00) readerCapabilities (0x02) tlvVersion (0x00) deviceID (0x01) productName (0x02) productPlatform (0x03) enabledCLFeatures (0x04) firmwareVersion (0x05) hfControllerVersion (0x08) hardwareVersion (0x09) hostInterfacesFlags (0x0A) numberOfContactSlots (0x0B) numberOfContactlessSlots (0x0C) numberOfAntennas (0x01) vendorName (0x01) exchangeLevel (0x01) serialNumber (0x01) hfControllerType (0 |
|---|
| Get (0x00) | contactlessSlotConfiguration (0x04) |
|---|
| Set (0x01) | contactlessCommon (0x00) pollingSearchOrder (0x09) emdSuppresionEnable (0x07) iso14443aConfig (0x02) iso14443aEnable (0x00) iso14443aRxTxBaudRate (0x01) mifareKeyCache (0x03) mifarePreferred (0x04) iso14443bConfig (0x03) iso14443bEnable(0x00) iso14443bRxTxBaudRate (0x01) felicaConfig (0x05) felicaEnable (0x00) felicaRxTxBaudRate (0x01) iClassConfig (0x06) iClass15693Enable (0x03) iClass15693DelayT |
|---|
| A2 06 | // CHOICE ReaderInformationAPI |
|---|
| A0 04 | // CHOICE GetReaderInformation |
|---|
| A0 02 | // CHOICE ReaderCapabilites 82 00 // SEQUENCE productName |
|---|
| BD 0A 83 08 41 56 69 61 74 6F 52 00 90 00 | // ‘AViatoR’ + return code success |
|---|
| readerCapabilities (0x02) | tlvVersion (0x00) deviceID (0x01) productName (0x02) productPlatform (0x03) enabledCLFeatures (0x04) firmwareVersion (0x05) hfControllerVersion (0x08) hardwareVersion (0x09) hostInterfacesFlags (0x0A) numberOfContactSlots (0x0B) numberOfContactlessSlots (0x0C) numberOfAntennas (0x01) vendorName (0x01) exchangeLevel (0x01) serialNumber (0x01) hfControllerType (0x01) sizeOfUserEEProm (0x01) firmware |
|---|
| Tag | 0x00 |
|---|
| Access | Read-only. |
|---|
| Length | 1 byte. |
|---|
| Description | The version of the TLV encoding used by APDUs. |
|---|
| Get APDU | FF 70 07 6B 08 A2 06 A0 04 A0 02 80 00 00 |
|---|
| Sample response | BD 03 80 01 01 90 00 54 July 2018 |
|---|
| contactlessSlotConfiguration | contactlessCommon pollingSearchOrder (0x09) (0x04) (0x00) emdSuppresionEnable (0x07) |
|---|
| iso14443aConfig (0x02) | iso14443aEnable (0x00) iso14443aRxTxBaudRate (0x01) mifareKeyCache (0x03) mifarePreferred (0x04) |
|---|
| iso14443bConfig (0x03) | iso14443bEnable(0x00) iso14bRxTxBaudRate (0x01) |
|---|
| felicaConfig (0x05) | felicaEnable (0x00) felicaRxTxBaudRate (0x01) |
|---|
| iClassConfig (0x06) | iClass15693Enable (0x03) iClass15693DelayTime (0x04) iClass15693Timeout (0x05) iClassActallTimeout (0x06) Bit 0 (0x01) – 212 kbps Bit 1 (0x02) – 424 kbps Bit 2 (0x04) – 848 kbps rate from 424 kbps to 848 kbps increases transmission speed by less than 10%. The number may vary depending on the amount of data transmitted. The worst ratio is for short packets. Increasing maximum baud rate may cause tr |
|---|
| Set APDU | FF 70 07 6B 0F A2 0D A1 0B A4 09 A0 07 89 05 xx xx xx xx xx 00 |
|---|
| readerEEPROM (0x07) | eepromOffset (0x01) eepromRead (0x02) eepromWrite (0x03) |
|---|
| readerConfigurationControl | applySettings (0x00) restoreFactoryDefaults (0x01) rebootDevice (0x03) |
|---|
| ICAO test commands | PLT-03273, Rev. A.1 |
|---|
| ---- | RFU 0 0 106 kbps. No |
|---|
| RFU | --- 0 ISO/IEC 14443 Type A transmission. Yes |
|---|
| xxx | – Number of bits in last byte to be transmitted. Yes |
|---|
| XX bytes | 0x9000 Operation successful. |
|---|
| ISO/IEC 14443 Type B commands | No 1 0 0 0 1 REQB (Number of slots in P2). Yes 1 0 0 1 0 WUPB (Number of slots in P2). Yes 1 0 0 1 1 HLTB (PUPI may be in Data In). No 1 0 1 0 0 Slot-MARKER (Slot no in P2). No 1 0 1 0 1 ATTRIB (Bit rate in P2 or PUPI + PARAM in Data In) No |
|---|
| CID | ------ Card Identifier. No |
|---|
| Command | Data Out |
|---|
| REQA | ATQA (2 bytes). |
|---|
| WUPA | ATQA (2 bytes). |
|---|
| HLTA | – |
|---|
| REQA + ANTI-COLLISION + SELECT | UID (4,7 or 10 bytes) + SAK (1 byte). |
|---|
| ANTI-COLLISION CL1 | Cascade UID (4 bytes) + BCC (1 byte). |
|---|
| ANTI-COLLISION CL2 | Cascade UID (4 bytes) + BCC (1 byte). |
|---|
| ANTI-COLLISION CL3 | Cascade UID (4 bytes) + BCC (1 byte). |
|---|
| SELECT | SAK (1 byte). |
|---|
| REQB | ATQB (14 bytes). |
|---|
| WUPB | ATQB (14 bytes). |
|---|
| HLTB | 0x00 + CRCB (2 bytes). |
|---|
| Slot-MARKER | ATQB (14 bytes). |
|---|
| ATTRIB | MBLI+CID (1 byte) + CRCB (2 bytes). |
|---|
| FSDI | CID FSDI codes FSD as in ISO/IEC 14443-4. No Bit rate for PPS command |
|---|
| Appendix | A dwShareMode = SCARD_SHARE_DIRECT dwPreferredProtocols = 0 #define IOCTL_CCID_ESCAPE SCARD_CTL_CODE(3500) SCardControl(hCard, IOCTL_CCID_ESCAPE, …) SCardControl(hCard, SCARD_CTL_CODE(3500), …) |
|---|