This repository was archived by the owner on May 24, 2026. It is now read-only.
Request to review and merge latest code changes - #7
Merged
Conversation
- removed command related classes and combined them into KMKeymasterApplet class - removed context class as it is no longer needed. - changed the random number generation logic to use aes cbc with aes 128 bit key encryption as simulator does not support aes ecb and aes 256 bit key. - changed exception throwing to use ISOException.throwit() to use runtime environment's instance.
Implemented transient memory based code.
- Some Code optimizations. - ImportKey, GenerateKey and GetKeyCharacteristics functionality. - GetKeyCharacteristics only tested on jcardSim.
Code changes to crypto provider. New feature implemented but not tested.
Removed untested code from KeymasterApplet.
- Tested only with jcard sim. - Basic testing with Begin, Update, Finish and Abort. - Basic testing with Upgrade Key, Delete Key, DeleteAllKeys.
Tested Import Wrapped key with jcard sim. Optimization is still necessary.
Also fixed vts related requirement for rsa decryption without padding. JCardSim automaticaly removes the leading zeros after decryption. VTS test fails due to this.
- Added AES GCM cipher for begin, update and finish operations. - Also added some bugfixes.
Also added some bug fixes related to EC key import.
Added RSA OAEP based SHA1 and SHA256 encrypt and decrypt functionality. This uses SunJce as jacardsim does not support it.
This uses RSA private key decryption with no padding from jcard sim to sign the data. The padding for pkcs1 and padding none is done before the jcard sim api is called. However there is no way to verify the signature using jcard sim as the public key encryption without padding allows only 255 bytes of input data.
Added AttestKey command and provision command functionality. Currently JCardSim tests pass whereas OracleSimulator tests fails as the command strings are not correct and also commands larger then 256 bytes are failing. This will be fixed in later releases.
Added functionality for destroyAttestationIds.
Added support for ECDSA related subject pub key info in attest key certificate. Bug fix related importwrappedkey and hmac key sizes to pass VTS tests.
Added two more enum values for boot state.
- EC Keys support in X509 subject pub key info - AES CTR support - OAEP 256 for import wrapped key - hmac key size from 64 to 512
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The current code has most of the code. Following commands are not yet tested.
Following commands will be added to the code in future pull requests.
All other commands are functionally tested with jcard sim basic tests- more testing is on going.