ETSI TS 103 666-1 V15.0.0 (2019-11)
Smart Secure Platform (SSP); Part 1: General characteristics (Release 15)
Smart Secure Platform (SSP); Part 1: General characteristics (Release 15)
DTS/SCP-00TSSPvf00-1
General Information
Standards Content (Sample)
TECHNICAL SPECIFICATION
Smart Secure Platform (SSP);
Part 1: General characteristics
(Release 15)
Release 15 2 ETSI TS 103 666-1 V15.0.0 (2019-11)
Reference
DTS/SCP-00TSSPvf00-1
Keywords
M2M, MFF
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88
Important notice
The present document can be downloaded from:
http://www.etsi.org/standards-search
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format at www.etsi.org/deliver.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
https://portal.etsi.org/TB/ETSIDeliverableStatus.aspx
If you find errors in the present document, please send your comment to one of the following services:
https://portal.etsi.org/People/CommiteeSupportStaff.aspx
Copyright Notification
No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying
and microfilm except as authorized by written permission of ETSI.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.
© ETSI 2019.
All rights reserved.
DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its Members.
3GPP™ and LTE™ are trademarks of ETSI registered for the benefit of its Members and
of the 3GPP Organizational Partners.
oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and
of the oneM2M Partners. ®
GSM and the GSM logo are trademarks registered and owned by the GSM Association.
ETSI
Release 15 3 ETSI TS 103 666-1 V15.0.0 (2019-11)
Contents
Intellectual Property Rights . 11
Foreword . 11
Modal verbs terminology . 12
1 Scope . 13
2 References . 13
2.1 Normative references . 13
2.2 Informative references . 15
3 Definition of terms, symbols and abbreviations . 15
3.1 Terms . 15
3.2 Symbols . 16
3.3 Abbreviations . 16
4 Introduction . 18
4.1 Background . 18
4.2 Document layout . 18
4.3 References to UICC. 18
4.4 ASN.1 syntax . 18
4.4.1 Introduction. 18
4.4.2 Start of ASN.1 . 18
5 SSP architecture . 19
5.1 Overview . 19
5.2 SSP software architecture . 19
5.3 SSP hardware architecture . 20
5.4 Protocol stacks . 21
5.5 Execution frameworks . 22
6 SSP characteristics . 22
6.1 Form factors . 22
6.2 Power . 22
6.2.1 Power mode . 22
6.2.2 Power sources . 23
6.2.2.1 Types of power sources . 23
6.2.2.2 Power source of type Interface . 23
6.2.2.3 Power source of type Independent . 23
6.2.3 Power consumption. 24
6.3 Clock . 24
6.4 SSP initialization . 24
6.4.1 SSP interface session . 24
6.4.2 Capability exchange . 24
6.4.2.1 Overall description . 24
6.4.2.2 SSP not supporting SCL . 24
6.4.2.3 SSP supporting SCL . 25
6.4.2.4 Capabilities of the terminal . 25
6.4.2.5 Capabilities of the SSP . 26
6.5 Storage . 27
6.6 Data management . 27
6.6.1 UICC file system . 27
6.6.2 SSP file system . 27
6.6.2.1 Overview . 27
6.6.2.2 SSP file system structure . 28
6.6.2.2.1 Layout . 28
6.6.2.2.2 Node types . 29
6.6.2.2.3 Node descriptor . 29
6.6.2.2.4 Node identity . 30
6.6.2.2.5 File handling . 31
ETSI
Release 15 4 ETSI TS 103 666-1 V15.0.0 (2019-11)
6.6.2.2.6 Administrative operations. 32
6.6.2.2.7 SSP file system access rights . 32
6.6.2.3 Primitives of the SSP file system . 33
6.6.2.3.1 FS-ADMIN-GET-CAPABILITIES-Service-Command. 33
6.6.2.3.2 FS-ADMIN-CREATE-NODE-Service-Command . 34
6.6.2.3.3 FS-ADMIN-DELETE-NODE-Service-Command . 35
6.6.2.3.4 FS-ADMIN-UPDATE-NODE-ATTRIBUTES-Service-Command . 35
6.6.2.3.5 FS-OP-FILE-OPEN-Service-Command . 36
6.6.2.3.6 FS-OP-FILE-CLOSE-Service-Command . 37
6.6.2.3.7 FS-OP-NODE-GET-INFO-Service-Command . 37
6.6.2.3.8 FS-OP-FILE-READ-Service-Command . 38
6.6.2.3.9 FS-OP-FILE-WRITE-Service-Command . 39
6.6.2.3.10 FS-OP-FILE-GET-POSITION-Service-Command . 40
6.6.2.4 Response code . 41
6.6.2.4.1 Overview . 41
6.6.2.4.2 Response code to SSP file system primitives . 42
6.7 SSP identification . 42
6.8 Runtime environment . 42
6.8.1 CAT Runtime Environment . 42
6.9 SSP suspension . 43
6.10 SSP Applications . 43
6.10.1 Overview . 43
6.10.2 Ownership and security considerations . 44
6.10.3 Lifecycle management . 44
6.10.4 Identification and discovery . 44
6.11 SSP security. 44
6.11.1 SSP security architecture . 44
6.11.2 Mandatory requirements . 45
6.11.2.1 Overview . 45
6.11.2.2 Security of SSP code . 45
6.11.2.3 Privacy of data . 46
6.11.2.3.1 Secure storage . 46
6.11.2.4 SSP transactions . 46
6.11.2.5 Attack resistance . 46
6.11.3 Optional requirements. 46
6.11.3.1 Overview . 46
6.11.3.2 Random number generator . 46
6.11.3.3 Remote provisioning . 46
6.11.3.4 Remote auditing . 47
6.11.4 Security certification . 47
6.11.4.1 Overview . 47
6.12 User interface . 47
6.12.1 Web-based user interface . 47
6.12.1.1 Overview . 47
6.12.1.2 Port values . 48
6.12.1.3 Presentation of SSP user interface . 48
6.13 Accessor authentication service . 48
6.13.1 Overview . 48
6.13.2 Access control . 49
6.13.2.1 Overview . 49
6.13.2.2 Description . 49
6.13.2.3 Accessor rights to a resource . 50
6.13.3 Access control list . 51
6.13.4 Accessor . 51
6.13.4.1 Overview . 51
6.13.4.2 Anonymous accessor . 52
6.13.4.3 Accessor identity . 52
6.13.4.4 Accessor conditions . 52
6.13.4.5 Access rights . 54
6.13.4.6 Operations on an accessor . 55
6.13.4.6.1 Creation . 55
ETSI
Release 15 5 ETSI TS 103 666-1 V15.0.0 (2019-11)
6.13.4.6.2 Deletion . 55
6.13.4.6.3 Update of the access control list . 55
6.13.4.6.4 Update of the conditions and credentials . 55
6.13.4.6.5 Update of the group list . 55
6.13.4.7 Accessor credentials . 55
6.13.4.8 Accessor credential policy . 56
6.13.4.9 Accessor credential status . 57
6.13.5 Primitives of the access control . 58
6.13.5.1 AAS-OP-GET-CAPABILITIES-Service-Command . 58
6.13.5.2 AAS-ADMIN-CREATE-ACCESSOR-Service-Command . 59
6.13.5.3 AAS-ADMIN-UPDATE-ACCESSOR-Service-Command . 60
6.13.5.4 AAS-ADMIN-DELETE-ACCESSOR-Service-Command . 61
6.13.5.5 AAS-OP-AUTHENTICATE-ACCESSOR-Service-Command. 61
6.13.5.6 AAS-OP-ACCESS-SERVICE-Service-Command . 62
6.13.5.7 AAS-OP-GET-CHALLENGE-Service-Command . 63
6.13.6 Response code . 64
6.13.6.1 Overview . 64
6.13.6.2 Response code to access control primitives . 64
7 Physical interfaces . 65
7.1 Overview . 65
7.2 Reset . 65
7.3 ISO/IEC 7816 interface . 66
7.3.1 Electrical specifications . 66
7.3.1.1 Electrical specifications of the interface . 66
7.3.1.2 Contacts . 66
7.3.2 Initial communication establishment procedures . 66
7.3.2.1 SSP interface activation and deactivation . 66
7.3.2.2 Supply voltage switching . 66
7.3.2.3 Answer To Reset content . 66
7.3.2.4 PPS procedure . 66
7.3.2.5 Reset procedure . 66
7.3.2.6 Clock stop mode . 67
7.3.2.7 Bit/character duration and sampling time . 67
7.3.2.8 Error handling . 67
7.3.3 Data link protocols . 67
7.3.3.1 Overview . 67
7.3.3.2 Character frame . 67
7.3.3.3 Protocol T=1 . 67
7.4 SPI interface . 67
7.5 I2C interface . 67
7.6 SWP interface . 67
7.7 USB interface . 67
7.8 Proprietary interface . 67
8 SSP Common Layer (SCL) . 68
8.1 Introduction . 68
8.2 SCL network . 68
8.3 Protocol layers . 69
8.3.1 Overview . 69
8.3.2 Network layer . 69
8.3.3 Transport layer . 69
8.3.4 Session layer . 69
8.4 SCL core services . 69
8.4.1 Overview . 69
8.4.2 Common core features . 69
8.4.3 Link gate . 69
8.4.3.1 Link service gate . 69
8.4.3.1.1 General description . 69
8.4.3.1.2 Additional registry entries . 69
8.4.3.1.3 SSP_MTU . 70
8.4.3.2 Link application gate . 70
ETSI
Release 15 6 ETSI TS 103 666-1 V15.0.0 (2019-11)
8.4.4 Administration gate. 70
8.4.4.1 Administration service gate . 70
8.4.4.2 Administration application gate . 70
8.4.5 Identity gate . 70
8.4.5.1 Identity service gate . 70
8.4.5.1.1 General description . 70
8.4.5.1.2 Additional registry entries . 70
8.4.5.1.3 CAPABILITY_EXCHANGE . 71
8.4.5.1.4 GATE_URN_LIST . 71
8.4.5.2 Identity application gate . 71
8.4.6 Loopback gate . 71
8.4.6.1 Loopback service gate . 71
8.4.6.2 Loopback application gate . 71
8.5 SCL procedures . 72
8.5.1 Host registration . 72
8.5.2 Host deregistration . 72
8.5.3 Pipe management . 72
8.5.4 Registry access . 72
8.5.5 Hosts and gates discovery . 72
8.5.6 Loopback testing . 72
9 Secure SCL . 72
9.1 Protocol stack . 72
9.2 Secure datagram . 73
9.3 Security protocol . 74
9.3.1 Overview . 74
9.3.2 Shared secret initialization . 74
9.3.3 Secure SCL shared keys generation . 75
9.4 Accessor authentication service procedure . 75
9.4.1 Initialization . 75
10 Communication layers above SCL . 76
10.1 Overview . 76
10.2 APDU protocol . 76
10.2.1 Introduction. 76
10.2.2 Command-response pairs . 76
10.2.2.1 General definition . 76
10.2.2.2 CLA byte . 76
10.2.2.3 INS byte . 76
10.2.2.4 Coding of SW1 and SW2 . 77
10.2.3 SSP commands . 77
10.2.3.1 Overview . 77
10.2.3.2 EXCHANGE CAPABILITIES . 77
10.2.3.2.1 Description . 77
10.2.3.2.2 Command parameters . 77
10.2.3.2.3 Command data . 78
10.2.3.2.4 Command response . 78
10.2.3.3 SELECT . 78
10.2.4 Logical channels . 78
10.2.4.1 Overview . 78
10.2.4.2 MANAGE CHANNEL . 78
10.2.5 UICC file system commands . 79
10.2.5.1 Overview . 79
10.2.5.2 Methods for selecting a file . 79
10.2.5.3 Reservation of file IDs . 79
10.2.5.4 Security features . 79
10.2.5.5 Additional commands . 79
10.2.6 Card Application Toolkit . 79
10.2.6.1 Overview . 79
10.2.6.2 Terminal profile . 80
10.2.6.3 Proactive polling . 80
10.2.6.4 Additional commands . 80
ETSI
Release 15 7 ETSI TS 103 666-1 V15.0.0 (2019-11)
10.2.7 SSP suspension . 80
10.2.8 APDU transfer over SCL . 80
10.2.8.1 Overview . 80
10.2.8.2 UICC APDU gate . 81
10.2.8.2.1 UICC APDU overview . 81
10.2.8.2.2 UICC APDU service gate . 81
10.2.8.2.3 UICC APDU application gate . 81
10.2.8.2.4 State diagram for the UICC APDU gate . 82
10.3 File system protocol . 82
10.3.1 Overview . 82
10.3.2 Presentation layer . 83
10.3.3 File system control service gate . 83
10.3.3.1 Overview . 83
10.3.3.2 Commands . 84
10.3.3.3 Responses . 84
10.3.3.4 Events . 84
10.3.4 File system control application gate. 84
10.3.4.1 Overview . 84
10.3.4.2 Commands . 84
10.3.4.3 Responses . 85
10.3.4.4 Events . 85
10.3.5 File system data service gate. 85
10.3.5.1 Overview . 85
10.3.5.2 Commands . 85
10.3.5.3 Responses . 85
10.3.5.4 Events . 85
10.3.6 File system data application gate . 85
10.3.6.1 Overview . 85
10.3.6.2 Commands .
...








Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...