From 6ff735e5d88a6b175f5e9ab49e84d9465fc7ee91 Mon Sep 17 00:00:00 2001 From: J08nY Date: Sun, 8 Mar 2026 12:19:19 +0800 Subject: Point index to repo. --- index-old.html | 1442 +++++++++++++++++++++++++++++++++++++++++++++++++++++++ index.html | 1467 +------------------------------------------------------- 2 files changed, 1467 insertions(+), 1442 deletions(-) create mode 100644 index-old.html diff --git a/index-old.html b/index-old.html new file mode 100644 index 0000000..a0aa6ef --- /dev/null +++ b/index-old.html @@ -0,0 +1,1442 @@ +--- +--- + +

ECTester

+Build status Build status GitHub release license + +

Tests support and behavior of elliptic curve cryptography implementations on JavaCards (TYPE_EC_FP and TYPE_EC_F2M) and on selected software libraries. See our github for more info.

+ + + + +
+ + + +

JavaCard Elliptic curve algorithm support#

+The JavaCard API has support for basic Elliptic Curve Cryptography, such as ECDH and ECDSA. However not many cards actually support these algorithms. The table below displays support and performance obtained by ECTester for common curve sizes. For detailed support and implementation tests see test runs. + + + +

Legend

+
+ ∗ ECDH types +
    +
  1. ALG_EC_SVDP_DH
  2. +
  3. ALG_EC_SVDP_DHC
  4. +
  5. ALG_EC_SVDP_DH_PLAIN
  6. +
  7. ALG_EC_SVDP_DHC_PLAIN
  8. +
  9. ALG_EC_PACE_GM
  10. +
  11. ALG_EC_SVDP_DH_PLAIN_XY
  12. +
+
+
+ † ECDSA types +
    +
  1. ALG_ECDSA_SHA
  2. +
  3. ALG_ECDSA_SHA_224
  4. +
  5. ALG_ECDSA_SHA_256
  6. +
  7. ALG_ECDSA_SHA_384
  8. +
  9. ALG_ECDSA_SHA_512
  10. +
+
+
+ ‡ Colors + +
+
+ +

Card list

+ +This page contains results for the following cards:
+ + +

$ \mathbb{F}_p $ support

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Card192b256b384b521b
ECDHECDSAECDHECDSAECDHECDSAECDHECDSA
ACS ACOSJ 40K1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
Athena IDProtect1,2,3,4a,b,c1,2,3,4a,b,c1,2,3,4a,b,c1,2,3,4a,b,c
Feitian A22CR
G&D SmartCafe 6.01,2,3,4a,b,c,d,e1,2,4,3a,b,c,d,e
G&D SmartCafe 7.01,2,3,4a,b,c,d,e1,2,4,3a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
Infineon CJTOP 80k1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
Infineon SLE781,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
NXP JCOP31 v2.4.11,2a1,2a
NXP JCOP CJ2A0811,2a1,2a
NXP JCOP v2.4.2 R21,3a,b,c1,3a,b,c
NXP JCOP v2.4.2 R31,3a,b,c1,3a,b,c
Oberthur Cosmo v71,2a1,2a1,2a1,2a
TaiSYS SIMoME VAULT1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
+ +

$ \mathbb{F}_p $ performance

+The following table shows performance of tested cards in ECDH and ECDSA over popular $ \mathbb{F}_p $ curve sizes. Key generation +performance is similar to ECDH performance. ECDSA timings are split for sign+verify operations. Times are in milliseconds. +
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
CardType192b256b384b521b
ECDHECDSAECDHECDSAECDHECDSAECDHECDSA
ACS ACOSJ 40K
1a172254+257209311+315360503+536
2b172255+256209311+316360505+535
3c172254+257209311+315360505+537
4d172255+261210310+316360505+537
5e255+260311+315505+538
6
Athena IDProtect
1a147110+163209148+228448279+473937537+970
2b147113+167209150+230448281+477938540+973
3c148114+165209150+231448281+475937540+972
4d146209448938
5e
6
Feitian A22CR
1a
2b
3c
4d
5e
6
G&D SmartCafe 6.0
1a128110+135192145+197
2b128122+147193158+210
3c126123+147190158+209
4d126127+152191162+214
5e127+152162+214
6
G&D SmartCafe 7.0
1a6769+809485+108161123+176254174+273
2b6771+829487+111161128+180255177+275
3c6671+839388+110160126+180253175+275
4d6672+839387+111161126+180253177+276
5e72+8388+111126+180178+276
6
Infineon CJTOP 80k
1a138144+113167175+138240254+202
2b208151+120267183+144414262+207
3c207151+121263182+145408261+207
4d205176+145264207+169408286+232
5e175+145208+171287+233
6
Infineon SLE78
1a83170+201109226+275177367+467315650+806
2b83188+220109243+293177384+483315667+827
3c79188+219105243+293173384+482308667+826
4d79208+240105263+313173405+504308688+846
5e208+241264+314405+503688+847
6
NXP JCOP31 v2.4.1
1a122140+167190192+260
2b123191
3c
4d
5e
6
NXP JCOP CJ2A081
1a7693+107124129+168
2b76124
3c
4d
5e
6
NXP JCOP v2.4.2 R3
1a101111+111154151+172
2b96114+113154+178
3c114+114154+176
4d
5e
6
Oberthur Cosmo v7
1a881806+92511831067+125621901907+239942463612+4790
2b793105118893593
3c
4d
5e
6
TaiSYS SIMoME VAULT
1a109217+288132267+352202439+585340935+1220
2b108211+282135251+340201443+590346922+1201
3c105226+293130271+356198460+586341923+1202
4d106222+289125259+348198433+579341913+1202
5e221+282261+349447+576912+1200
6
+ +

$ \mathbb{F}_p $ default curves

+The JavaCard API allows cards to specify default curves to be used when generating EC keys using the KeyPair class. +Grey background shows that no default curve is present and one should be specified after creating +the keypair, see the implementation guide. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Card112b128b160b192b224b256b384b521b
Athena IDProtect
Feitian A22 CRsecp112r1secp128r1secp160r1P-192
secp192r1
P-224
secp224r1
SMP256V1
FeitianFeitian A22
G&D Smartcafe 6.0
G&D Smartcafe 7.0
Infineon CJTOP 80kbrainpoolP160r1brainpoolP192rbrainpoolP224r1brainpoolP256r1
Infineon SLE78brainpoolP256r1
NXP JCOP31 v2.4.1secp128r1secp160r1P-192
secp192r1
NXP JCOP CJ2A081secp128r1secp160r1P-192
secp192r1
NXP JCOP v2.4.2 R2
NXP JCOP v2.4.2 R3
NXP JCOP v2.4.2 R3 J2E145G
TaiSYS SIMoME VAULTsecp112r1secp128r1secp160r1secp192r1secp224r1secp256r1
+ +

$ \mathbb{F}_{2^m} $

+Support for binary field curves on cards is very weak, very little cards have any. For more information see JCAlgTest support table. + +

Implementation guide#

+A basic example of EC KeyPair generation is visible below, for a more complete example see ECExample.java. +
+    
+    // secp256r1 from http://www.secg.org/sec2-v2.pdf
+    byte[] EC256_FP_P = new byte[]{
+            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x01,
+            (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00,
+            (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF,
+            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF};
+    byte[] EC256_FP_A = new byte[]{
+            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x01,
+            (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00,
+            (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF,
+            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFC};
+    byte[] EC256_FP_B = new byte[]{
+            (byte) 0x5A, (byte) 0xC6, (byte) 0x35, (byte) 0xD8, (byte) 0xAA, (byte) 0x3A, (byte) 0x93, (byte) 0xE7,
+            (byte) 0xB3, (byte) 0xEB, (byte) 0xBD, (byte) 0x55, (byte) 0x76, (byte) 0x98, (byte) 0x86, (byte) 0xBC,
+            (byte) 0x65, (byte) 0x1D, (byte) 0x06, (byte) 0xB0, (byte) 0xCC, (byte) 0x53, (byte) 0xB0, (byte) 0xF6,
+            (byte) 0x3B, (byte) 0xCE, (byte) 0x3C, (byte) 0x3E, (byte) 0x27, (byte) 0xD2, (byte) 0x60, (byte) 0x4B};
+    byte[] EC256_FP_G = new byte[]{
+            (byte) 0x04,
+            (byte) 0x6B, (byte) 0x17, (byte) 0xD1, (byte) 0xF2, (byte) 0xE1, (byte) 0x2C, (byte) 0x42, (byte) 0x47,
+            (byte) 0xF8, (byte) 0xBC, (byte) 0xE6, (byte) 0xE5, (byte) 0x63, (byte) 0xA4, (byte) 0x40, (byte) 0xF2,
+            (byte) 0x77, (byte) 0x03, (byte) 0x7D, (byte) 0x81, (byte) 0x2D, (byte) 0xEB, (byte) 0x33, (byte) 0xA0,
+            (byte) 0xF4, (byte) 0xA1, (byte) 0x39, (byte) 0x45, (byte) 0xD8, (byte) 0x98, (byte) 0xC2, (byte) 0x96,
+            (byte) 0x4F, (byte) 0xE3, (byte) 0x42, (byte) 0xE2, (byte) 0xFE, (byte) 0x1A, (byte) 0x7F, (byte) 0x9B,
+            (byte) 0x8E, (byte) 0xE7, (byte) 0xEB, (byte) 0x4A, (byte) 0x7C, (byte) 0x0F, (byte) 0x9E, (byte) 0x16,
+            (byte) 0x2B, (byte) 0xCE, (byte) 0x33, (byte) 0x57, (byte) 0x6B, (byte) 0x31, (byte) 0x5E, (byte) 0xCE,
+            (byte) 0xCB, (byte) 0xB6, (byte) 0x40, (byte) 0x68, (byte) 0x37, (byte) 0xBF, (byte) 0x51, (byte) 0xF5};
+    byte[] EC256_FP_R = new byte[]{
+            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00,
+            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF,
+            (byte) 0xBC, (byte) 0xE6, (byte) 0xFA, (byte) 0xAD, (byte) 0xA7, (byte) 0x17, (byte) 0x9E, (byte) 0x84,
+            (byte) 0xF3, (byte) 0xB9, (byte) 0xCA, (byte) 0xC2, (byte) 0xFC, (byte) 0x63, (byte) 0x25, (byte) 0x51};
+    short EC256_FP_K = 1;
+
+    // 1. Allocate the KeyPair object.
+    // ! This should be done in the Applet constructor !
+    KeyPair example = new KeyPair(KeyPair.ALG_EC_FP, (short) 256);
+
+    // 2. If the key parts are not available, call genKeyPair.
+    if (example.getPrivate() == null || example.getPublic() == null) {
+        // Sometimes cards require this so we have the keyparts, to
+        // set parameters on.
+        try {
+            example.genKeyPair();
+        } catch (Exception ignored) {}
+    }
+
+    // 3. Get the key parts and set custom domain parameters on them.
+    ECPrivateKey priv = (ECPrivateKey) example.getPrivate();
+    ECPublicKey pub = (ECPublicKey) example.getPublic();
+
+    priv.setFieldFP(EC256_FP_P, (short) 0, EC256_FP_P.length);
+    pub.setFieldFP(EC256_FP_P, (short) 0, EC256_FP_P.length);
+
+    priv.setA(EC256_FP_A, (short) 0, EC256_FP_A.length);
+    pub.setA(EC256_FP_A, (short) 0, EC256_FP_A.length);
+
+    priv.setB(EC256_FP_B, (short) 0, EC256_FP_B.length);
+    pub.setB(EC256_FP_B, (short) 0, EC256_FP_B.length);
+
+    priv.setG(EC256_FP_G, (short) 0, EC256_FP_G.length);
+    pub.set(EC256_FP_G, (short) 0, EC256_FP_G.length);
+
+    priv.setR(EC256_FP_R, (short) 0, EC256_FP_R.length);
+    pub.setR(EC256_FP_R, (short) 0, EC256_FP_R.length);
+
+    priv.setK(EC256_FP_K);
+    pub.setK(EC256_FP_K);
+
+    // 4. Generate the KeyPair over the custom set domain parameters.
+    example.genKeyPair();
+    // Now, the example keypair is ready for use.
+    
+
+ +

Common JavaCard ECC usage pitfalls

+The JavaCard ECC API is quite general in its requirements for implementations, which means different cards can behave +differently and cause errors. + +

No curve is set by default

+KeyPairs allocated with new KeyPair(type, size) might or might not have set some default domain parameters. +Which means using keypair.genKeyPair() just after allocating a KeyPair object will probably result in an exception. +Thus, it is always better to explicitly setup custom domain parameters, using a known/standard curve, before trying to generate the KeyPair. + +

genKeyPair() required to get key parts

+On some cards a newly allocated KeyPair does not yet contain the individual key parts (the ECPublicKey and ECPrivateKey). +Thus doing keypair.getPrivate() or keypair.getPublic() will return null. Which makes setting +custom domain parameters on the key parts harder. This can usually be fixed by calling keypair.genKeyPair(), which however might throw an exception, +and then setting the custom domain parameters on the now accessible key parts. + +

clearKey() behaviour

+The keypair.clearKey() method might clear out the set domain parameters of the keypair as well as the key contents. + +

getK() behaviour

+The ECKey.getK() method might throw an exception if the card does not support working with the cofactor value. + +

Test suite runs#

+The results of various test suites, run on a set of cards are available below: + +{% assign result_categories = site.results | group_by:"category" %} +{% assign cards = site.results | group_by_exp:"item", "item.path | split: '/' | shift | shift | sample | split: '.' | pop | join: '.' " %} + + + + {% for cat in result_categories %} + + {% endfor %} + + {% for card in cards %} + + + {% for cat in result_categories %} + + {% endfor %} + + {% endfor %} +
Card name
{{ cat.name }}
{{ card.name | replace: '_', ' ' }} + {% for document in card.items %} + {% if document.category == cat.name %} + + {% endif %} + {% endfor %} +
+ + +{% assign ecdh = site.performance | where:"category","ECDH performance" %} +{% if ecdh.size > 0 %} +

ECDH performance

+ +{% endif %} + +{% assign ecdsa = site.performance | where:"category","ECDSA performance" %} +{% if ecdsa.size > 0 %} +

ECDSA performance

+ +{% endif %} + +{% assign keygen = site.performance | where:"category","Key generation performance" %} +{% if keygen.size > 0 %} +

Key generation performance

+ +{% endif %} + +

Docs#

+ + diff --git a/index.html b/index.html index a0aa6ef..c75e5a5 100644 --- a/index.html +++ b/index.html @@ -1,1442 +1,25 @@ ---- ---- - -

ECTester

-Build status Build status GitHub release license - -

Tests support and behavior of elliptic curve cryptography implementations on JavaCards (TYPE_EC_FP and TYPE_EC_F2M) and on selected software libraries. See our github for more info.

- - - - -
- - - -

JavaCard Elliptic curve algorithm support#

-The JavaCard API has support for basic Elliptic Curve Cryptography, such as ECDH and ECDSA. However not many cards actually support these algorithms. The table below displays support and performance obtained by ECTester for common curve sizes. For detailed support and implementation tests see test runs. - - - -

Legend

-
- ∗ ECDH types -
    -
  1. ALG_EC_SVDP_DH
  2. -
  3. ALG_EC_SVDP_DHC
  4. -
  5. ALG_EC_SVDP_DH_PLAIN
  6. -
  7. ALG_EC_SVDP_DHC_PLAIN
  8. -
  9. ALG_EC_PACE_GM
  10. -
  11. ALG_EC_SVDP_DH_PLAIN_XY
  12. -
-
-
- † ECDSA types -
    -
  1. ALG_ECDSA_SHA
  2. -
  3. ALG_ECDSA_SHA_224
  4. -
  5. ALG_ECDSA_SHA_256
  6. -
  7. ALG_ECDSA_SHA_384
  8. -
  9. ALG_ECDSA_SHA_512
  10. -
-
-
- ‡ Colors - -
-
- -

Card list

- -This page contains results for the following cards:
- - -

$ \mathbb{F}_p $ support

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Card192b256b384b521b
ECDHECDSAECDHECDSAECDHECDSAECDHECDSA
ACS ACOSJ 40K1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
Athena IDProtect1,2,3,4a,b,c1,2,3,4a,b,c1,2,3,4a,b,c1,2,3,4a,b,c
Feitian A22CR
G&D SmartCafe 6.01,2,3,4a,b,c,d,e1,2,4,3a,b,c,d,e
G&D SmartCafe 7.01,2,3,4a,b,c,d,e1,2,4,3a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
Infineon CJTOP 80k1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
Infineon SLE781,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
NXP JCOP31 v2.4.11,2a1,2a
NXP JCOP CJ2A0811,2a1,2a
NXP JCOP v2.4.2 R21,3a,b,c1,3a,b,c
NXP JCOP v2.4.2 R31,3a,b,c1,3a,b,c
Oberthur Cosmo v71,2a1,2a1,2a1,2a
TaiSYS SIMoME VAULT1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e1,2,3,4a,b,c,d,e
- -

$ \mathbb{F}_p $ performance

-The following table shows performance of tested cards in ECDH and ECDSA over popular $ \mathbb{F}_p $ curve sizes. Key generation -performance is similar to ECDH performance. ECDSA timings are split for sign+verify operations. Times are in milliseconds. -
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
CardType192b256b384b521b
ECDHECDSAECDHECDSAECDHECDSAECDHECDSA
ACS ACOSJ 40K
1a172254+257209311+315360503+536
2b172255+256209311+316360505+535
3c172254+257209311+315360505+537
4d172255+261210310+316360505+537
5e255+260311+315505+538
6
Athena IDProtect
1a147110+163209148+228448279+473937537+970
2b147113+167209150+230448281+477938540+973
3c148114+165209150+231448281+475937540+972
4d146209448938
5e
6
Feitian A22CR
1a
2b
3c
4d
5e
6
G&D SmartCafe 6.0
1a128110+135192145+197
2b128122+147193158+210
3c126123+147190158+209
4d126127+152191162+214
5e127+152162+214
6
G&D SmartCafe 7.0
1a6769+809485+108161123+176254174+273
2b6771+829487+111161128+180255177+275
3c6671+839388+110160126+180253175+275
4d6672+839387+111161126+180253177+276
5e72+8388+111126+180178+276
6
Infineon CJTOP 80k
1a138144+113167175+138240254+202
2b208151+120267183+144414262+207
3c207151+121263182+145408261+207
4d205176+145264207+169408286+232
5e175+145208+171287+233
6
Infineon SLE78
1a83170+201109226+275177367+467315650+806
2b83188+220109243+293177384+483315667+827
3c79188+219105243+293173384+482308667+826
4d79208+240105263+313173405+504308688+846
5e208+241264+314405+503688+847
6
NXP JCOP31 v2.4.1
1a122140+167190192+260
2b123191
3c
4d
5e
6
NXP JCOP CJ2A081
1a7693+107124129+168
2b76124
3c
4d
5e
6
NXP JCOP v2.4.2 R3
1a101111+111154151+172
2b96114+113154+178
3c114+114154+176
4d
5e
6
Oberthur Cosmo v7
1a881806+92511831067+125621901907+239942463612+4790
2b793105118893593
3c
4d
5e
6
TaiSYS SIMoME VAULT
1a109217+288132267+352202439+585340935+1220
2b108211+282135251+340201443+590346922+1201
3c105226+293130271+356198460+586341923+1202
4d106222+289125259+348198433+579341913+1202
5e221+282261+349447+576912+1200
6
- -

$ \mathbb{F}_p $ default curves

-The JavaCard API allows cards to specify default curves to be used when generating EC keys using the KeyPair class. -Grey background shows that no default curve is present and one should be specified after creating -the keypair, see the implementation guide. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Card112b128b160b192b224b256b384b521b
Athena IDProtect
Feitian A22 CRsecp112r1secp128r1secp160r1P-192
secp192r1
P-224
secp224r1
SMP256V1
FeitianFeitian A22
G&D Smartcafe 6.0
G&D Smartcafe 7.0
Infineon CJTOP 80kbrainpoolP160r1brainpoolP192rbrainpoolP224r1brainpoolP256r1
Infineon SLE78brainpoolP256r1
NXP JCOP31 v2.4.1secp128r1secp160r1P-192
secp192r1
NXP JCOP CJ2A081secp128r1secp160r1P-192
secp192r1
NXP JCOP v2.4.2 R2
NXP JCOP v2.4.2 R3
NXP JCOP v2.4.2 R3 J2E145G
TaiSYS SIMoME VAULTsecp112r1secp128r1secp160r1secp192r1secp224r1secp256r1
- -

$ \mathbb{F}_{2^m} $

-Support for binary field curves on cards is very weak, very little cards have any. For more information see JCAlgTest support table. - -

Implementation guide#

-A basic example of EC KeyPair generation is visible below, for a more complete example see ECExample.java. -
-    
-    // secp256r1 from http://www.secg.org/sec2-v2.pdf
-    byte[] EC256_FP_P = new byte[]{
-            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x01,
-            (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00,
-            (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF,
-            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF};
-    byte[] EC256_FP_A = new byte[]{
-            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x01,
-            (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00,
-            (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF,
-            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFC};
-    byte[] EC256_FP_B = new byte[]{
-            (byte) 0x5A, (byte) 0xC6, (byte) 0x35, (byte) 0xD8, (byte) 0xAA, (byte) 0x3A, (byte) 0x93, (byte) 0xE7,
-            (byte) 0xB3, (byte) 0xEB, (byte) 0xBD, (byte) 0x55, (byte) 0x76, (byte) 0x98, (byte) 0x86, (byte) 0xBC,
-            (byte) 0x65, (byte) 0x1D, (byte) 0x06, (byte) 0xB0, (byte) 0xCC, (byte) 0x53, (byte) 0xB0, (byte) 0xF6,
-            (byte) 0x3B, (byte) 0xCE, (byte) 0x3C, (byte) 0x3E, (byte) 0x27, (byte) 0xD2, (byte) 0x60, (byte) 0x4B};
-    byte[] EC256_FP_G = new byte[]{
-            (byte) 0x04,
-            (byte) 0x6B, (byte) 0x17, (byte) 0xD1, (byte) 0xF2, (byte) 0xE1, (byte) 0x2C, (byte) 0x42, (byte) 0x47,
-            (byte) 0xF8, (byte) 0xBC, (byte) 0xE6, (byte) 0xE5, (byte) 0x63, (byte) 0xA4, (byte) 0x40, (byte) 0xF2,
-            (byte) 0x77, (byte) 0x03, (byte) 0x7D, (byte) 0x81, (byte) 0x2D, (byte) 0xEB, (byte) 0x33, (byte) 0xA0,
-            (byte) 0xF4, (byte) 0xA1, (byte) 0x39, (byte) 0x45, (byte) 0xD8, (byte) 0x98, (byte) 0xC2, (byte) 0x96,
-            (byte) 0x4F, (byte) 0xE3, (byte) 0x42, (byte) 0xE2, (byte) 0xFE, (byte) 0x1A, (byte) 0x7F, (byte) 0x9B,
-            (byte) 0x8E, (byte) 0xE7, (byte) 0xEB, (byte) 0x4A, (byte) 0x7C, (byte) 0x0F, (byte) 0x9E, (byte) 0x16,
-            (byte) 0x2B, (byte) 0xCE, (byte) 0x33, (byte) 0x57, (byte) 0x6B, (byte) 0x31, (byte) 0x5E, (byte) 0xCE,
-            (byte) 0xCB, (byte) 0xB6, (byte) 0x40, (byte) 0x68, (byte) 0x37, (byte) 0xBF, (byte) 0x51, (byte) 0xF5};
-    byte[] EC256_FP_R = new byte[]{
-            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x00,
-            (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF, (byte) 0xFF,
-            (byte) 0xBC, (byte) 0xE6, (byte) 0xFA, (byte) 0xAD, (byte) 0xA7, (byte) 0x17, (byte) 0x9E, (byte) 0x84,
-            (byte) 0xF3, (byte) 0xB9, (byte) 0xCA, (byte) 0xC2, (byte) 0xFC, (byte) 0x63, (byte) 0x25, (byte) 0x51};
-    short EC256_FP_K = 1;
-
-    // 1. Allocate the KeyPair object.
-    // ! This should be done in the Applet constructor !
-    KeyPair example = new KeyPair(KeyPair.ALG_EC_FP, (short) 256);
-
-    // 2. If the key parts are not available, call genKeyPair.
-    if (example.getPrivate() == null || example.getPublic() == null) {
-        // Sometimes cards require this so we have the keyparts, to
-        // set parameters on.
-        try {
-            example.genKeyPair();
-        } catch (Exception ignored) {}
-    }
-
-    // 3. Get the key parts and set custom domain parameters on them.
-    ECPrivateKey priv = (ECPrivateKey) example.getPrivate();
-    ECPublicKey pub = (ECPublicKey) example.getPublic();
-
-    priv.setFieldFP(EC256_FP_P, (short) 0, EC256_FP_P.length);
-    pub.setFieldFP(EC256_FP_P, (short) 0, EC256_FP_P.length);
-
-    priv.setA(EC256_FP_A, (short) 0, EC256_FP_A.length);
-    pub.setA(EC256_FP_A, (short) 0, EC256_FP_A.length);
-
-    priv.setB(EC256_FP_B, (short) 0, EC256_FP_B.length);
-    pub.setB(EC256_FP_B, (short) 0, EC256_FP_B.length);
-
-    priv.setG(EC256_FP_G, (short) 0, EC256_FP_G.length);
-    pub.set(EC256_FP_G, (short) 0, EC256_FP_G.length);
-
-    priv.setR(EC256_FP_R, (short) 0, EC256_FP_R.length);
-    pub.setR(EC256_FP_R, (short) 0, EC256_FP_R.length);
-
-    priv.setK(EC256_FP_K);
-    pub.setK(EC256_FP_K);
-
-    // 4. Generate the KeyPair over the custom set domain parameters.
-    example.genKeyPair();
-    // Now, the example keypair is ready for use.
-    
-
- -

Common JavaCard ECC usage pitfalls

-The JavaCard ECC API is quite general in its requirements for implementations, which means different cards can behave -differently and cause errors. - -

No curve is set by default

-KeyPairs allocated with new KeyPair(type, size) might or might not have set some default domain parameters. -Which means using keypair.genKeyPair() just after allocating a KeyPair object will probably result in an exception. -Thus, it is always better to explicitly setup custom domain parameters, using a known/standard curve, before trying to generate the KeyPair. - -

genKeyPair() required to get key parts

-On some cards a newly allocated KeyPair does not yet contain the individual key parts (the ECPublicKey and ECPrivateKey). -Thus doing keypair.getPrivate() or keypair.getPublic() will return null. Which makes setting -custom domain parameters on the key parts harder. This can usually be fixed by calling keypair.genKeyPair(), which however might throw an exception, -and then setting the custom domain parameters on the now accessible key parts. - -

clearKey() behaviour

-The keypair.clearKey() method might clear out the set domain parameters of the keypair as well as the key contents. - -

getK() behaviour

-The ECKey.getK() method might throw an exception if the card does not support working with the cofactor value. - -

Test suite runs#

-The results of various test suites, run on a set of cards are available below: - -{% assign result_categories = site.results | group_by:"category" %} -{% assign cards = site.results | group_by_exp:"item", "item.path | split: '/' | shift | shift | sample | split: '.' | pop | join: '.' " %} - - - - {% for cat in result_categories %} - - {% endfor %} - - {% for card in cards %} - - - {% for cat in result_categories %} - - {% endfor %} - - {% endfor %} -
Card name
{{ cat.name }}
{{ card.name | replace: '_', ' ' }} - {% for document in card.items %} - {% if document.category == cat.name %} - - {% endif %} - {% endfor %} -
- - -{% assign ecdh = site.performance | where:"category","ECDH performance" %} -{% if ecdh.size > 0 %} -

ECDH performance

- -{% endif %} - -{% assign ecdsa = site.performance | where:"category","ECDSA performance" %} -{% if ecdsa.size > 0 %} -

ECDSA performance

- -{% endif %} - -{% assign keygen = site.performance | where:"category","Key generation performance" %} -{% if keygen.size > 0 %} -

Key generation performance

- -{% endif %} - -

Docs#

- - + + + + + + Redirecting… + + + + + + + + +

+ Redirecting to + https://github.com/crocs-muni/ECTester… +

+ + + + -- cgit v1.3.1