ISO/IEC 18328-3:2016 PDF
Identification cards — ICC-managed devices — Part 3: Organization, security and commands for interchange
Identification cards — ICC-managed devices — Part 3: Organization, security and commands for interchange
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 42
- Дата публикации:
- 14 октября 2016 г.
- Издание:
- ISO/IEC IS 18328 edition 1 version 1
- ICS:
- 35.240.15
ISO/IEC 18328-3:2016 specifies the logical interface of an application supporting the necessary security features in a card-IC which communicates with the external world by a physical interface supporting APDUs. This application supports the usage of electronic devices. This involves the design of commands, data structures and security mechanisms which are required to handle the data and handling the additional devices itself. The handling of the additional devices is always controlled by the card-IC. External inputs or outputs shall be managed by the existing interfaces. This document deals not with physical characteristics of the card and interface technology, but only with the logical aspects. Management of data for additional devices that is not subdued by the COS or application control is out of the scope of this document. Definitions of coding requirement for "trust assessment" of the managed data like warning, font, colour etc. is in the scope of this document. A description of the logical internal interface functionality used by the COS or by device drivers, if any, is also part of this document. Due to the fact that relevant technologies may evolve or be adopted very fast, this document defines commands and structures supporting extensions and adaptations.
Abstract
Overview
ISO/IEC 18328-3:2016 - "Identification cards - ICC‑managed devices - Part 3: Organization, security and commands for interchange" defines the logical interface and security framework for applications on card‑ICs (card‑IC) that manage additional electronic devices (for example displays, keypads or sensors) and communicate via APDUs. The standard specifies command sets, data structures, device management semantics and security mechanisms - not the physical/electrical characteristics - to enable reliable, secure interaction between the card operating system (COS), device drivers and external hosts.
Key Topics and Requirements
- Logical architecture and operational conditions
- General architecture, interfaces, device discovery and logical activation
- Activity states, activation sequence and exclusive‑usage attributes
- Addressing and device control
- Device identifiers, device handles and administration templates
- Device Control Parameter (DVCP) and general device information templates
- Command model
- Standardized ADM (additional device management) command family: open, reset (general/logical), activate/deactivate, exclusive usage, get/put, get device information, erase, manage configuration
- Specific status bytes and command handling semantics
- Off‑card devices & transmission
- Mechanisms for devices not embedded in the ICC, handle usage and transmission constraints
- Secure channel considerations for off‑card communications
- Security and trust assessment
- Security attributes, access modes and required security conditions
- Data integrity, confidentiality and trust assessment coding (warnings, fonts, colours) for managed data
- Extensibility
- Command and structure designs that support future extensions and adaptations
- Device configuration templates
- Templates and mechanisms for managing device configuration data under COS control
Practical Applications & Who Uses This Standard
ISO/IEC 18328-3:2016 is valuable when integrating electronic peripherals into smart‑card ecosystems. Typical use cases include:
- Smart card manufacturers designing cards with integrated displays, keypads, fingerprint sensors or other peripherals
- Payment and banking solutions that use on‑card displays for transaction verification (e.g., dynamic CVV, transaction signing)
- Government and ID programs deploying secure citizen ID, e‑passport or e‑voting cards with peripherals
- Card OS and device driver developers implementing the logical API, security checks and command handling
- System integrators, security architects and auditors establishing interoperable, secure device management and trust assessment policies
Adopting this part of the ISO/IEC 18328 series helps ensure interoperability, consistent security behavior, and future‑proof integration of evolving peripheral technologies.
Related Standards
- ISO/IEC 18328-2 - physical characteristics for devices on ICC (complements Part 3)
- ISO/IEC 7816 (all parts) - APDU and general smart‑card application framework referenced throughout Part 3
- Other parts of the ISO/IEC 18328 series for broader device and card guidance
Keywords: ISO/IEC 18328-3:2016, identification cards, ICC‑managed devices, card‑IC, APDU, logical interface, device management, secure channel, trust assessment.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 17 - Cards and security devices for personal identification
- SKU
- ISO/IEC 18328-3:2016
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 18328-2:2021-TC
ДействующийTracked Changes. Identification cards. ICC-managed devices. Physical characteristics and test methods for car…
ISO/IEC 7816-8:2021/Amd 1:2023
ДействующийIdentification cards — Integrated circuit cards — Part 8: Commands and mechanisms for security operations — A…
Overview ISO/IEC 7816-8:2021/Amd 1:2023 is an amendment to Part 8 of the ISO/IEC 7816 series for identification cards - integrated circuit cards (ICCs). It adds interoperability features for the inte…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…