http://www.cardwerk.com/smartcards/smartcard_standard_ISO7816-4_annex-a.aspx

Annex A: Transportation of APDU messages by T=0

A.1 Case 1

The command APDU is mapped onto the T=0 command TPDU by assigning the value '00' to P3.

Command APDU
CLA INS P1 P2
Command TPDU
CLA INS P1 P2 P3='00'

The response TPDU is mapped onto the response APDU without any change.

Response APDU
SW1 SW2
Response TPDU
SW1 SW2

A.2 Case 2 Short

It this case, Le is valued from 1 to 256 and coded on byte B1 (B1='00' means maximum, i.e. Le=256).

The command APDU is mapped onto the T=0 command TPDU without any change.

C-APDU
CLA INS P1 P2 Le=B1
C-TPDU
CLA INS P1 P2 P3=B1

The response TPDU is mapped onto the response APDU according to the acceptance of Le and according to the processing of the command.

  • Case 2S.1 - Le accepted

    The response TPDU is mapped onto the the response APDU without any change.

    R-APDU
    Le bytes SW1 SW2
    R-TPDU
    Le bytes SW1 SW2
  • Case 2S.2 - Le definitely not accepted

    Le is not accepted be the card which does not support the service of providing data if the length is wrong.

    The response TPDU from the card indicates that the card aborts the command because of wrong length (SW1='67'). The response TPDU is mapped onto the response APDU without any change.

    R-APDU
    SW1='67' SW2
    R-TPDU
    SW1='67' SW2
  • Case 2S.3 - Le not accepted, La indicated

    Le is not accepted by the card and the card indicates the available length La.

    The response TPDU from the card indicates that the command is aborted due to a wrong length and that the right length is La: (SW1='6C' and SW2 codes La).

    If the transmission system does not support the service of re-issuing the same command, it shall map the response TPDU onto the response APDU without any change.

    R-APDU
    SW1='6C' SW2=La
    R-TPDU
    SW1='6C' SW2=La

    If the transmission system supports the service of reissuing the same command, it shall re-issue the same command TPDU assigning the value La to parameter P3.

    C-TPDU
    CLA INS P1 P2 P3=SW2

    The response TPDU consists of La bytes followed by two status bytes.

    If La is smaller that or equal to Le, then the response TPDU is mapped onto the response APDU without any change.

    R-APDU
    La bytes SW1 SW2
    R-TPDU
    La bytes SW1 SW2

    If La is greater that Le, then the response TPDU is mapped onto the response APDU by keeping only the first Le bytes of the body and the status bytes SW1-SW2.

    R-APDU
    Le (< La) bytes SW1 SW2
    R-TPDU
    La bytes SW1 SW2
  • Case 2S.4 - SW1-SW2='9XYZ', expect '9000'

    The response TPDU is mapped on the response APDU without any change.

A.3 Case 3 Short

In this case, Lc is valued from 1 to 255 and coded on byte B1 (='00').

The command APDU is mapped onto the T=0 command TPDU without any change.

C-APDU
CLA INS P1 P2 Lc=B1 Lc bytes
C-TPDU
CLA INS P1 P2 P3=B1 Lc bytes

The response TPDU is mapped onto the response APDU without any change.

R-APDU
SW1 SW2
R-TPDU
SW1 SW2

A.4 Case 4 Short

In this case, Lc is valued from 1 to 255 and coded on byte B1. Le is valued from 1 to 256 and coded on byte Bl (Bl='00' means maximum i.e. Le=256).

The command APDU is mapped onto the T=0 command TPDU by cutting the last byte of the body.

C-APDU
CLA INS P1 P2 Lc=B1 Lc bytes Bl
C-TPDU
CLA INS P1 P2 P3=B1 Lc bytes
  • Case 4S.1 - Command not accepted

    The first response TPDU from the card indicates that the card aborted the command: SW1='6X', except '61'.

    The response TPDU is mapped onto the response APDU without any change.

    R-APDU
    SW1='6X' SW2
    R-TPDU
    SW1='6X' SW2
  • Case 4S.2 - Command accepted

    The first response TPDU from the card indicates that the card performed the command: SW1-SW2='9000'.

    R-TPDU
    SW1='90' SW2='00'

    The transmission system shall issue a GET RESPONSE command TPDU to the card by assigning the value Le to parameter P3.

    C-TPDU
    CLA INS=GET_RESPONSE P1 P2 P3=Bl

    Depending on the second response TPDU from the card, the transmission system shall react as described in cases 2S.1, 2S.2 and 2S.4 above.

  • Case 4S.3 - Command accepted with information added

    The first response TPDU from the card indicates that the card perfomed the command and gives information on the length of data bytes available: SW1='61' and SW2 codes Lx.

    R-TPDU
    SW1='61' SW2=Lx

    The transmission system shall issue a GET RESPONSE command TPDU to the card by assigning the minimum of Lx and Le to parameter P3.

    TPDU
    CLA INS=GET_REPONSE P1 P2 P3=min(Le,Lx)

    The second response TPDU is mapped onto the response APDU without any change.

    R-APDU
    P3 bytes SW1 SW2
    R-TPDU
    P3 bytes SW1 SW2
  • Case 4S.4 - SW1-SW2='9XYZ', except '9000'

    The response TPDU is mapped onto the response APDU without any change.

A.5 Case 2 Extended

In this case, Le is valued from 1 to 65536 and coded in 3 bytes (B1)='00', (B2||B3)=any value (B2 and B3 valued to '0000' means maximum, i.e. Le=65536).

C-APDU
CLA INS P1 P2 B1='00' B2B3=Le
  • Case 2E.1 - Le<=256, B1='00', B2B3 from '0001'-'0100'

    The command APDU shall be mapped onto the command TPDU by assigning the value of B3 to parameter P3.
    The processing by the transmission system shall be according to case 2S. <1..256 Bytes>

    C-TPDU
    CLA INS P1 P2 P3=B3
  • Case 2E.2 - Le>256, B1='00', B2B3=either '0000' or from '0101' to 'FFFF'

    The command APDU shall be mapped onto the command TPDU by assigning the value of '00' to parameter P3.

    C-TPDU
    CLA INS P1 P2 P3='00'
    • if the first response TPDU from the card indicates that the command is aborted due to a wrong length
      and that the right length is La (SW1='6C' and SW2=La),
      then the transmission system shall complete the processing as described in case 2S.3.
    • If the first response TPDU is 256 bytes of data followed by SW1-SW2='9000',
      this means that the card has no more that 256 bytes of data,
      and/or does not support the GET REPONSE command.
      The transmission system shall then map the response TPDU onto the response APDU without any change. 
      R-APDU
      256 bytes SW1='90' SW2='00'
      R-TPDU
      256 bytes SW1='90' SW2='00'
    • If the first or subsequent response TPDU from the card is SW1='61', then SW2 codes Lx
      which is the extra amount of bytes available from the card (SW2 valued to '00' indicates 256 extra bytes or more),
      the transmission system shall compute Lm=Le (sum of the lengths of the bodies of the prviously received response TPDU(s)) to obtain the amount of remaining bytes to be retrieved from the card.

      If Lm=0, then the transmission system shall concatenate the bodies of all received response TPDUs
      together with the trailer of the last received response TPDU into the response APDU.

      If Lm>0, then the transmission system shall issue a GET RESPONSE command TPDU by assigning the minimum of Lx and Lm to parameter P3.
      The corresponding response TPDU from the card shall be processed

      • according to case d), if SW1='61'
      • as above when Lm=0, if SW1='9X'

A.6 Case 3 Extended

In this case Lc is valued from 1 to 65535 and coded on 3 bytes: (B1)='00', (B2||B3)!='0000'.

C-APDU
CLA INS P1 P2 B1='00' B2B3=Lc Lc bytes
  • Case 3E.1 - 0<Lc<256, B1='00', B2='00', B3!='00'

    The command APDU is mapped onto the command TPDU by assigning the value of B3 to parameter P3.

    C-TPDU
    CLA INS P1 P2 P3=B3 Lc bytes

    In this case Lc is valued from 1 to 255 and codes on 1 byte. == Case 3 Short

    The response TPDU is mapped onto the response APDU without any change.

  • Case 3E.2 - Lc>255, B1='00', B2!='00', B3=any value 
    If the transmission system does not support the ENVELOPE command, it shall return an error response APDU meaning that the length is wrong: SW1='67'. 
    R-APDU
    SW1='67' SW2
    R-TPDU
    SW1='67' SW2

    If the transmission system supports the ENVELOPE command, it shall split the APDU into segments of length less than 256, CLA INS P1 P2 00 B2 B3 [ ------ ]
    and send those successive segments into the bodies of consecutive ENVELOPE command TPDUs.

    C-TPDU
    CLA INS=ENVELOPE P1 P2 P3 P3 bytes

    If the first response TPDU from the card indicates that the card does not support the ENVELOPE command (SW1='6D'), Instruction Wrong
    the TPDU shall be mapped onto the response TPDU without any change.

    R-APDU
    SW1='6D' SW2
    R-TPDU
    SW1='6D' SW2

    If the first response TPDU from the card indicates that the card does support eh ENVLEOPE command (SW1-SW2='9000'),
    the transmission system shall send further ENVELOPE commands as needed.

    When the ENVELOPE command is used under T=0 for transmitting data strings,
    An empty data field in an ENVELOPE command APDU means end of data string. 
    http://www.cardwerk.com/smartcards/smartcard_standard_ISO7816-4_7_transmission_interindustry_commands.aspx[ 00 C2 00 00 00 ] : Last ENVELOPE TPDU

    R-TPDU
    SW1-SW2='9000'
    C-TPDU
    CLA INS=ENVELOPE P1 P2 P3 P3 bytes

    The resource TPDU corresponding to the last ENVELOPE command is mapped onto the response APDU without any change.

    R-APDU
    SW1 SW2
    R-TPDU
    SW1 SW2

A.7 Case 4 Extended

In this case Lc is valued from 1 to 65535 and coded on 3 bytes: (B1)='00', (B2||B3)!='0000', and Le is valued from 1 to 65536 and coded on 2 bytes (Bl-1||Bl)=any value (Bl-1 and Bl valued to '0000' means maximum, i.e. Le=65536).

C-APDU
CLA INS P1 P2 B1='00' B2B3=Lc Lc bytes Bl-1Bl=Le
  • Case 4E.1 - Lc<256, B1='00', B2='00', B3!='00'

    The command APDU is mapped onto the command TPDU by cutting off the last two bytes Bl-1 and Bl and by assigning the value of B3 to parameter P3.

    C-TPDU
    CLA INS P1 P2 P3=B3 Lc bytes

    In this case Lc is valued from 1 to 255 bytes and coded on 1 byte.

    • If SW1='6X' in the first response TPDU from the card, then the response TPDU is mapped onto the response APDU without any change.

      R-APDU
      SW1='6X' SW2
      R-TPDU
      SW1='6X' SW2
    • If SW1='90' in first response TPDU from the card then

      If Le<257 (Bl-1 Bl valued from '0001' to '0100'), then the transmission system shall issue a GET RESPONSE command TPDU by assigning the value of Bl to parameter P3. The subsequent processing by the transmission system shall be according to access 2S.1, 2S.2, 2S.3 and 2S.4 above.

      If Le>256 (Bl-1 Bl valued to '0000' or more then '0100'), then the transmission system shall issue a GET RESPONSE command TPDU by assigning the value '00' to parameter P3. The subsequent processing by the transmission system shall be according to case 2E.2 above.

    • If SW1='61' in the first response TPDU from the card, then the transmission system shall proceed as specified in case 2E.2 d) above.
  • Case 4E.2 - Lc>255, B1='00', B2!='00', B3=any value

    The transmission system shall go on according to case 3E.2 described above until the command APDU has been sent completely to the card. It shall then go on as described in case 4E.1 a), b) and c) described above.

ISO 7816-4: Annex A: Transportation of APDU messages by T=0的更多相关文章

  1. ISO 7810 协议小结

    ISO 7816规定了Smart Card的传输协议分为 T=0 异步半双工字符传输协议 T=1 异步半双工块传输协议 T=0命令介绍 命令总是由接口设备启动,他以一个5字节的报头通知卡要做什么,然后 ...

  2. ISO 7816-4: Interindustry Commands for Interchange

    5. Basic Organizations 5.1 Data structures5.2 Security architecture of the card 5.3 APDU message str ...

  3. jeos没有消亡,但看 debian 的 netinst .iso格式,那就是jeos的系统!

    曾经ubuntu推出专供轻量硬件(如虚拟机)方式的just os格式的.iso [小巧.轻量.快速.干净] 但在 ubuntu 8.04后 再也没有继续 ...... 可惜 不曾想,ubuntu的老爸 ...

  4. Delphi ISO 收藏!

    CodeGear RAD Studio 2007 最终版(With Update4) v11.0.2902.10471http://altd.codegear.com/download/radstud ...

  5. 第二十六篇:USB3.0高带宽ISO(48KBytes/125us)实战

    USB3.1技术已经推出, 10Gbps的速率足以满足数据, HD视频传输的要求. 要步入USB3.1的研发, 还得将USB3.0的基础打扎实. 微软提供的SUPER MUTT仅仅包括一个接口0, 其 ...

  6. RAD Studio 2010~XE8 官方 ISO 下载地址 (2015-03-28更新)

    http://bbs.csdn.net/topics/390816856 RAD Studio XE8 目前最新版 v22.0.19027.8951 官方 ISO 文件下载(6.72GB):http: ...

  7. RedHat Linux设置yum软件源为本地ISO

    先挂载ISO到某个目录下(如我的:/media/RHEL_6.0 x86_64 Disc 1) # mount –o loop rhel-server-6.4-x86_64-dvd.iso /medi ...

  8. Collection of Boot Sector Formats for ISO 9660 Images

    http://bazaar.launchpad.net/~libburnia-team/libisofs/scdbackup/view/head:/doc/boot_sectors.txt Colle ...

  9. ISO/IEC 15444-12 MP4 封装格式标准摘录 2

    目录 Track Media Structure Media Box Media Header Box Handler Reference Box Media Information Box Medi ...

随机推荐

  1. 01:MFC应用程序编程

    一 MFC的发展 VC 1.0->VC 5.0->VC 6.0->VC2008 SP1)->VS2010 二 MFC基础 1 MFC 微软基础类库 采用类的方式,将Win32 ...

  2. 无锁并发框架Disruptor学习入门

    刚刚听说disruptor,大概理一下,只为方便自己理解,文末是一些自己认为比较好的博文,如果有需要的同学可以参考. 本文目标:快速了解Disruptor是什么,主要概念,怎么用 1.Disrupto ...

  3. kernel——make menuconfig的实现原理【转】

    转自:https://blog.csdn.net/hpr1992/article/details/41048693 .系统移植可以分为配置系统和编译系统两大块,其中通过命令makemenuconfig ...

  4. 008_MAC 终端使用技巧

    一.常用终端命令. <1>reset 的作用很简单——将目前「终端」屏幕上的内容清空,就好像刚刚打开终端一样. <2>如果你在一条终端命令中发现有输入错误的话,那么用 cont ...

  5. 初始ASP.NET数据控件【续 ListView】

    ListView控件   ListView控件可以用来显示数据,它还提供编辑,删除,插入,分页与排序等功能.ListView是GridView与DataList的融合体,它具有GridView控件编辑 ...

  6. Laravel中使用自己的类库三种方式

    虽然Composer使得我们可以重用很多现有的类库(例如packagist.org中的),但是我们仍然可能用到一些不兼容composer的包或者类库.另外在某一项目中,我们也可能会创建某一类库,而且可 ...

  7. windows 2008 启用.NET Framework 3.5

    Win2008下已经集成了.NET 3.5.1 framework,需要在管理界面打开! 方法和步骤是: 服务器管理器 -> 功能 -> 添加功能 然后在“选择功能”界面勾选“.NET F ...

  8. metasploit利用漏洞渗透攻击靶机

    1.网络测试环境构建 首先需要先配置好一个渗透测试用的网络环境,包括如图1所示的运行Kali Linux系统的计算机,如图2所示的老师给的Windows Server 2000系统的计算机.这两台计算 ...

  9. ERP渠道管理添加验证和查询(二十二)

    添加联系人的后台代码: protected void btnSubmit_Click(object sender, EventArgs e) { BioErpCrmManageChannel chan ...

  10. Java第三阶段学习(十三、会话技术、Cookie技术与Session技术)

    一.会话技术  1. 存储客户端状态 会话技术是帮助服务器记住客户端状态(区分客户端)的.  2. 会话技术 从打开一个浏览器访问某个站点,到关闭这个浏览器的整个过程,称为一次会话.会话技术就是记录这 ...