EMV® 3-D Secure App-based Cryptographic Worked Samples

v3.0.0 Best Practices
3-D Secure

EMV<sup>®</sup> 3-D Secure App-based Cryptographic Worked Samples Version 3.0.0 October 2019 EMVCo 3-D Secure App-based Crypto Worked Samples

Legal Notice

Legal Notice

of 88 This document summarizes EMVCo’s present plans for evaluation services and related policies and is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or non-infringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document.

Samples Contents

Samples Contents

Message to be signed: Protected header and Payload with a ‘.’ Separator. Message to be signed: Protected header and Payload with a ‘.’ Separator. Samples Contents

Samples Contents

SDK Decryption of the above message.

Samples Introduction and Scope

of 88 Introduction and Scope This document provides worked examples for the various cryptographic functions specified in the 3-D Secure Protocol and Core Functions Specification v2.2 (per June 2019 and SB 214v1). The purpose of this document is to provide input and output values, with intermediate steps where appropriate for the cryptographic mechanisms and algorithms described in the specification. This document is not an implementation guide, the data elements are constructed (not based on real implementation) and some of the values are random numbers or strings. Steps to derive a cryptographic value could vary based on the technology, tools or frameworks. The steps provided in this document are intended as an illustration and may not represent a production implementation. Please note this document will not be maintained as new versions of the specification are released to the industry and EMVCo does not plan to address queries that are related to customer implementation and customer specific crypto challenges. Color coding: − Plaintext and linking text: Black − Key Material: Red − Crypto Output: Green Note: Elliptic curve keys are shown either as x & y coordinates in base64url format, or as SEC1 point representation (the first byte is 04 followed by the x and the y coordinates) as shown in section 3 of https://tools.ietf.org/html/draft-jivsov-ecc-compact-05. Examples are numbered 1 to 12:

  • Examples 1-4 illustrate encryption of device information by the SDK using either RSA-OAEP-256 or ECDH-ES for key agreement and either A128CBC-HS256 or A128GCM for data encryption
  • Examples 5 and 6 illustrate ACS signed content using either RSA-based PS256 or EC-based ES256
  • Examples 7 and 8 illustrate ACS, and then SDK, key derivation using ECDH-ES, in preparation for Examples 9-12
  • Examples 9-12 illustrate SDK, and then ACS, message encryption using either A128CBC-HS256 or A128GCM Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128CBC-HS256 of 88 SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128CBC-HS256 Device Information Plaintext Data { "DV":"1.0", "DD": { "C001":"Android", "C002":"HTC One_M8", "C004":"5.0.1", "C005":"en_US", "C006":"Eastern Standard Time", "C007":"06797903-fb61-41ed-94c2-4d2b74e27d18", "C009":"John's Android Device" }, "DPNA": { "C010":"RE01", "C011":"RE03" }, "SW": ["SW01", "SW04"] } Without whitespace: {"DV":"1.0","DD":{"C001":"Android","C002":"HTC One_M8","C004":"5.0.1","C005":"en_US","C006":"Eastern Standard Time","C007":"06797903-fb61-41ed-94c2-4d2b74e27d18","C009":"John's Android Device"},"DPNA":{"C010":"RE01","C011":"RE03"},"SW":["SW01","SW04"]} In Hex (as will be used later to construct plaintext to be enciphered) 7B224456223A22312E30222C224444223A7B2243303031223A22416E64726F696422 2C2243303032223A22485443204F6E655F4D38222C2243303034223A22352E302E31 222C2243303035223A22656E5F5553222C2243303036223A224561737465726E2053 74616E646172642054696D65222C2243303037223A2230363739373930332D666236 312D343165642D393463322D346432623734653237643138222C2243303039223A22 4A6F686E277320416E64726F696420446576696365227D2C2244504E41223A7B2243 303130223A2252453031222C2243303131223A2252453033227D2C225357223A5B22 53573031222C2253573034225D7D Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128CBC-HS256 of 88 DS Public Key from (https://tools.ietf.org/html/rfc7520#page-8 figure 4) { "kty": "RSA", "kid": "UUIDkeyidentifierforDS", "use": "enc", "n": "n4EPtAOCc9AlkeQHPzHStgAbgs7bTZLwUBZdR8_KuKPEHLd4rHVTeT-OXV2jRojdNhxJWTDvNd7nqQ0VEiZQHz_AJmSCpMaJMRBSFKrKb2wqVwGU_NsYOYLQtiWN2lbzcEe6XC0dApr5ydQLrHqkHHig3RBordaZ6Aj-oBHqFEHYpPe7TpeOfVfHd1E6cS6M1FZcD1NNLYD5lFHpPI9bTwJlsde3uhGqC0ZCuEHg8lhzwOHrtIQbS0F Vbb9k3tVTU4fg_3L_vniUFAKwuCLqKnS2BYwdq_mzSnbLY7h_qixoR7jig3__kRhuaxwUkRz5i aiQkqgc5gHdrNP5zw", "e": "AQAB" } Modulus n in Hex: 9F810FB4038273D02591E4073F31D2B6001B82CEDB4D92F050165D47CFCAB8A3C41C B778AC7553793F8EF975768D1A2374D8712564C3BCD77B9EA434544899407CFF0099 920A931A24C4414852AB29BDB0A95C0653F36C60E60BF90B6258DDA56F37047BA5C2 D1D029AF9C9D40BAC7AA41C78A0DD1068ADD699E808FEA011EA1441D8A4F7BB4E97B E39F55F1DDD44E9C4BA335159703D4D34B603E65147A4F23D6D3C0996C75EDEE846A 82D190AE10783C961CF0387AED2106D2D0555B6FD937FAD5535387E0FF72FFBE7894 1402B0B822EA2A74B6058C1DABF9B34A76CB63B87FAA2C6847B8E2837FFF91186E6B 1C14911CF989A89092A81CE601DDACD3F9CF Exponent e in Hex: 010001 Generated Key and IV Key (Content Encryption Key and MAC Key) in hex 99831FB208244C09B44DBBED945876872A179DB1332508CCC6680B37777CC570 The second half (rightmost / least significant half) is the ENC_KEY – in Hex 2A179DB1332508CCC6680B37777CC570 The first half (leftmost / most significant half) is the MAC_KEY – in Hex 99831FB208244C09B44DBBED94587687 Initialization Vector (IV) – in Hex C385E0ED5EE632B38BBDC0C2CD1BCA33 BASE64url encoded IV: w4Xg7V7mMrOLvcDCzRvKMw Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128CBC-HS256 of 88 RSA-OAEP-256 encipherment of the Key 9983… using Modulus 9F81… n4EP…" and exponent 010001 "AQAB" produces: 0A997CB4CE5E405369D50AD7CB9706B121CA12937CEF17FA862C53A15D232C22B9FC 3CD4BE993D128281421F308FA0C470D52316F8101DBF076A9167BE48D4F78B5D38DF 58D757E28F15EA3D859C61BD32E4FF1EC5D631967296042C18F946353204469D5ABB 832E122DA455BE32CED77B64ACB77947E8E5302BF20691C54159DB70A6A57C860CD7 1A148644300CFD91A3CD073318BA57302C2F64228AA3DF1AD3022B2BEEACF055A86C 546A9955D1D6E5706AD5C0BE24ABD909BA9EEC108813C6B8F546FE0B76922FC092E1 BD8B82B0B3A658EFAEB1209E65584CDC2F94BF7830B8398294DB13BF304B0695A743 903E2BDC83778C1BA4BEE35E641EE789C54C Base64url encoded: Cpl8tM5eQFNp1QrXy5cGsSHKEpN87xf6hixToV0jLCK5_DzUvpk9EoKBQh8wj6DEcNUj FvgQHb8HapFnvkjU94tdON9Y11fijxXqPYWcYb0y5P8exdYxlnKWBCwYUY1MgRGnVq7gy4SLaRVvjLO13tkrLd5RjlMCvyBpHFQVnbcKalfIYM1xoUhkQwDP2Ro80HMxi6VzAsL2QiiqPfGtMCKyvurPBVqG xUaplV0dblcGrVwL4kq9kJup7sEIgTxrj1Rv4LdpIvwJLhvYuCsLOmWOusSCeZVhM3C-Uv3gwuDmClNsTvzBLBpWnQ5A-K9yDd4wbpL7jXmQe54nFTA Protected Header { "alg":"RSA-OAEP-256", "enc":"A128CBC-HS256" } Without whitespace: {"alg":"RSA-OAEP-256","enc":"A128CBC-HS256"} BASE64url encoded: eyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0 Before encryption the plaintext needs padding to a 16 byte boundary - using PKCS #7 padding, 4 bytes must be added, so the padded plaintext is: 7B224456223A22312E30222C224444223A7B2243303031223A22416E64726F696422 2C2243303032223A22485443204F6E655F4D38222C2243303034223A22352E302E31 222C2243303035223A22656E5F5553222C2243303036223A224561737465726E2053 74616E646172642054696D65222C2243303037223A2230363739373930332D666236 312D343165642D393463322D346432623734653237643138222C2243303039223A22 4A6F686E277320416E64726F696420446576696365227D2C2244504E41223A7B2243 303130223A2252453031222C2243303131223A2252453033227D2C225357223A5B22 53573031222C2253573034225D7D04040404 Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128CBC-HS256 of 88 Data Encipherment CBC encipherment of the plaintext using AES-128 with key "2A17…"; IV "C385…" produces: 33A3CD8FBF4D17E656FBF2B3F9F86332886A5655147301EF65D2B80B02AAE660AE63 51709241E950F2946CCA5FE8AE1D55E0A98316859D2E8419EB09EE86F52CE797D27F EF53552FEB1CE84C1E322186015F29DF34C301CFB23D0C1B92961369083C2356E278 1D59EE71E180A766557D6E49F05AE705EAA4864FE772B17512EF0FF353BB62607B08 7D3C577943A5446E5D96D35BB6A9BDEB338ECE05E191025723C0C30C7B6987D072E7 520C7376FB61BC9100D89D914F34EC6DA01499513031E37A46AAD905AD511D064B91 6AFA9747F3EFA8C1CFDF6535E8B9EA716D2504EDA1D8923F460BC01FBB54578D8A09 6E0098CB0C5865ACF275960745CE13D099A2 Base64url encoded: M6PNj79NF-ZW-_KzfhjMohqVlUUcwHvZdK4CwKq5mCuY1FwkkHpUPKUbMpf6K4dVeCpgxaFnS6EGesJ7ob1L OeX0n_vU1Uv6xzoTB4yIYYBXynfNMMBz7I9DBuSlhNpCDwjVuJ4HVnuceGAp2ZVfW5J8 FrnBeqkhk_ncrF1Eu8P81O7YmB7CH08V3lDpURuXZbTW7apveszjs4F4ZECVyPAwwx7a YfQcudSDHN22G8kQDYnZFPNOxtoBSZUTAx43pGqtkFrVEdBkuRavqXR_PvqMHP32U16LnqcW0lBO2h2 JI_RgvAH7tUV42KCW4AmMsMWGWs8nWWB0XOE9CZog Authentication Tag For the MAC, the Additional Authenticated Data (AAD) is the Protected Header, which as Hex of ASCII of base64url is: "65794A68624763694F694A535530457454304646554330794E5459694C434A6C626 D4D694F694A424D54493451304A444C5568544D6A5532496E30" so the AAD Length (AL) is 00000000000001D8 (59 bytes = 472 bits). The data to MAC is the concatenation of AAD (in ASCII), IV, Ciphertext and AL hence the data to MAC in hexadecimal is: 65794A68624763694F694A535530457454304646554330794E5459694C434A6C626D 4D694F694A424D54493451304A444C5568544D6A5532496E30 C385E0ED5EE632B38BBDC0C2CD1BCA33 33A3CD8FBF4D17E656FBF2B3F9F86332886A5655147301EF65D2B80B02AAE660AE63 51709241E950F2946CCA5FE8AE1D55E0A98316859D2E8419EB09EE86F52CE797D27F EF53552FEB1CE84C1E322186015F29DF34C301CFB23D0C1B92961369083C2356E278 1D59EE71E180A766557D6E49F05AE705EAA4864FE772B17512EF0FF353BB62607B08 7D3C577943A5446E5D96D35BB6A9BDEB338ECE05E191025723C0C30C7B6987D072E7 520C7376FB61BC9100D89D914F34EC6DA01499513031E37A46AAD905AD511D064B91 6AFA9747F3EFA8C1CFDF6535E8B9EA716D2504EDA1D8923F460BC01FBB54578D8A09 6E0098CB0C5865ACF275960745CE13D099A2 00000000000001D8 MACing using HMAC SHA256 and a key of 9983… produces: 1816E58E159BD4D4959790B6322C499DCD4D1E43C2933AD47186AC27CF2F68C9 The most significant 16 bytes are the authentication tag which is: 1816E58E159BD4D4959790B6322C499D Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128CBC-HS256 of 88 Base 64url encoded: GBbljhWb1NSVl5C2MixJnQ Resulting JWE looks like: JWE Protected Header Encrypted Key Initialization Vector Ciphertext Authentication Tag In Compact Serialization eyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0. Cpl8tM5eQFNp1QrXy5cGsSHKEpN87xf6hixToV0jLCK5_DzUvpk9EoKBQh8wj6DEcNUj FvgQHb8HapFnvkjU94tdON9Y11fijxXqPYWcYb0y5P8exdYxlnKWBCwYUY1MgRGnVq7gy4SLaRVvjLO13tkrLd5RjlMCvyBpHFQVnbcKalfIYM1xoUhkQwDP2Ro80HMxi6VzAsL2QiiqPfGtMCKyvurPBVqG xUaplV0dblcGrVwL4kq9kJup7sEIgTxrj1Rv4LdpIvwJLhvYuCsLOmWOusSCeZVhM3C-Uv3gwuDmClNsTvzBLBpWnQ5A-K9yDd4wbpL7jXmQe54nFTA. w4Xg7V7mMrOLvcDCzRvKMw. M6PNj79NF-ZW-_KzfhjMohqVlUUcwHvZdK4CwKq5mCuY1FwkkHpUPKUbMpf6K4dVeCpgxaFnS6EGesJ7ob1L OeX0n_vU1Uv6xzoTB4yIYYBXynfNMMBz7I9DBuSlhNpCDwjVuJ4HVnuceGAp2ZVfW5J8 FrnBeqkhk_ncrF1Eu8P81O7YmB7CH08V3lDpURuXZbTW7apveszjs4F4ZECVyPAwwx7a YfQcudSDHN22G8kQDYnZFPNOxtoBSZUTAx43pGqtkFrVEdBkuRavqXR_PvqMHP32U16LnqcW0lBO2h2 JI_RgvAH7tUV42KCW4AmMsMWGWs8nWWB0XOE9CZog. GBbljhWb1NSVl5C2MixJnQ DS Decryption Corresponding Private Key d from (https://tools.ietf.org/html/rfc7520#page-8) Private key d (from RFC) bWUC9B-EFRIo8kpGfh0ZuyGPvMNKvYWNtB_ikiH9k20eTO1q_I78eiZkpXxXQ0UTEs2LsNRS-8uJbvQA1irkwMSMkK1J3XTGgdrhCku9gRldY7sNA_AKZGh-Q661_42rINLRCe8WnZ34ui_qOfkLnK9QWDDqpaIsAbMwWWSDFu2MUBYwkHTMEzLYGqOe04noqeq1hExBTHBOBdkMXiuFhUq1BU6lDqEiWxqg82sXt2hLMnT3046AOYJoRioz75tSUQfGCshWTBnP5uDjd18kKhyv07lhfSJdrPdM5Plyl21hsFf 4L_mHCuoFau7gdsPfHPxxjVOcOpBrQzwQ Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128CBC-HS256 of 88 In Hex: 6D6502F41F84151228F24A467E1D19BB218FBCC34ABD858DB41FE29221FD936D1E4F E3B5ABF23BF1E8999295F15D0D144C4B362EC3514BEF2E25BBD0F80D62AE4C0C48C9 0AD49DD74C681DAE10A4BBD81195D63BB0D03F00A64687E43AEB5FF8DAB20D2D109E F16FA7677E2E8BFA8E7E42E72BD4160C3AA9688B00F9B33059648316ED8C50163090 74CC1332D81AA39ED389E8A9EAB5844C414C704E05D90C5E2B85854AB5054EA5F83A 84896C6A83CDAC5EDDA1F8B3274F7D38E80398268462A33EF9B525107C60AC8564C1 9CFE6E0E3775F242A1CAFD3B9617D225DACF74CE4F972976D61B057F82FF9870AEA0 56AEEE076C3DF1CFC718D539C3A906B433C1 Key Decryption Decryption of the encrypted key component from JWE using RSA OAEP 256 private key 6D65… "bWUC…"; modulus 9F81… "n4EP…" produces: 99831FB208244C09B44DBBED945876872A179DB1332508CCC6680B37777CC570 Validation Validating Authentication Tag component from JWE using HMAC SHA256 with MAC key 9983… MAC of data comprising the concatenation of AAD (as ASCII), IV, Ciphertext and AL. The result is: 1816E58E159BD4D4959790B6322C499DCD4D1E43C2933AD47186AC27CF2F68C9 Converting the first 16 bytes to Base64url format gives GBbljhWb1NSVl5C2MixJnQ Which equals the received Authentication Tag. Decrypting Ciphertext component from JWE using AES128 CBC with CEK 9983…; IV C385… (PKCS#7 padding removed) produces: {"DV":"1.0","DD":{"C001":"Android","C002":"HTC One_M8","C004":"5.0.1","C005":"en_US","C006":"Eastern Standard Time","C007":"06797903-fb61-41ed-94c2-4d2b74e27d18","C009":"John's Android Device"},"DPNA":{"C010":"RE01","C011":"RE03"},"SW":["SW01","SW04"]} Device Information BASE64url encoded for AReq to ACS: "deviceInfo":"ew0KCSJEViI6ICIxLjAiLA0KCSJERCI6IHsNCgkJIkMwMDEiOiAiQW 5kcm9pZCIsDQoJCSJDMDAyIjogIkhUQyBPbmVfTTgiLA0KCQkiQzAwNCI6ICI1LjAuMS IsDQoJCSJDMDA1IjogImVuX1VTIiwNCgkJIkMwMDYiOiAiRWFzdGVybiBTdGFuZGFyZC BUaW1lIiwNCgkJIkMwMDciOiAiMDY3OTc5MDMtZmI2MS00MWVkLTk0YzItNGQyYjc0ZT I3ZDE4IiwNCgkJIkMwMDkiOiAiSm9obidzIEFuZHJvaWQgRGV2aWNlIg0KCX0sDQoJIk RQTkEiOiB7DQoJCSJDMDEwIjogIlJFMDEiLA0KCQkiQzAxMSI6ICJSRTAzIg0KCX0sDQ oJIlNXIjogWyJTVzAxIiwgIlNXMDQiXQ0KfQ0K" Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128GCM of 88 SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128GCM Device Information Plaintext Data { "DV":"1.0", "DD": { "C001":"Android", "C002":"HTC One_M8", "C004":"5.0.1", "C005":"en_US", "C006":"Eastern Standard Time", "C007":"06797903-fb61-41ed-94c2-4d2b74e27d18", "C009":"John's Android Device" }, "DPNA": { "C010":"RE01", "C011":"RE03" }, "SW": ["SW01", "SW04"] } Without whitespace: {"DV":"1.0","DD":{"C001":"Android","C002":"HTC One_M8","C004":"5.0.1","C005":"en_US","C006":"Eastern Standard Time","C007":"06797903-fb61-41ed-94c2-4d2b74e27d18","C009":"John's Android Device"},"DPNA":{"C010":"RE01","C011":"RE03"},"SW":["SW01","SW04"]} In Hex (used later in encipherment): 7B224456223A22312E30222C224444223A7B2243303031223A22416E64726F696422 2C2243303032223A22485443204F6E655F4D38222C2243303034223A22352E302E31 222C2243303035223A22656E5F5553222C2243303036223A224561737465726E2053 74616E646172642054696D65222C2243303037223A2230363739373930332D666236 312D343165642D393463322D346432623734653237643138222C2243303039223A22 4A6F686E277320416E64726F696420446576696365227D2C2244504E41223A7B2243 303130223A2252453031222C2243303131223A2252453033227D2C225357223A5B22 53573031222C2253573034225D7D DS Public Key from (https://tools.ietf.org/html/rfc7520#page-8) Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128GCM of 88 { "kty":"RSA", "kid":"UUIDkeyidentifierforDS", "use": "enc", "n":"n4EPtAOCc9AlkeQHPzHStgAbgs7bTZLwUBZdR8_KuKPEHLd4rHVTeT-OXV2jRojdNhxJWTDvNd7nqQ0VEiZQHz_AJmSCpMaJMRBSFKrKb2wqVwGU_NsYOYLQtiWN2lbzcEe6XC0dApr5ydQLrHqkHHig3RBordaZ6Aj-oBHqFEHYpPe7TpeOfVfHd1E6cS6M1FZcD1NNLYD5lFHpPI9bTwJlsde3uhGqC0ZCuEHg8lhzwOHrtIQbS0F Vbb9k3tVTU4fg_3L_vniUFAKwuCLqKnS2BYwdq_mzSnbLY7h_qixoR7jig3__kRhuaxwUkRz5i aiQkqgc5gHdrNP5zw", "e": "AQAB" } Modulus n in Hex: 9F810FB4038273D02591E4073F31D2B6001B82CEDB4D92F050165D47CFCAB8A3C41C B778AC7553793F8EF975768D1A2374D8712564C3BCD77B9EA434544899407CFF0099 920A931A24C4414852AB29BDB0A95C0653F36C60E60BF90B6258DDA56F37047BA5C2 D1D029AF9C9D40BAC7AA41C78A0DD1068ADD699E808FEA011EA1441D8A4F7BB4E97B E39F55F1DDD44E9C4BA335159703D4D34B603E65147A4F23D6D3C0996C75EDEE846A 82D190AE10783C961CF0387AED2106D2D0555B6FD937FAD5535387E0FF72FFBE7894 1402B0B822EA2A74B6058C1DABF9B34A76CB63B87FAA2C6847B8E2837FFF91186E6B 1C14911CF989A89092A81CE601DDACD3F9CF Exponent e in Hex: 010001 Generated Key and IV Content Encryption Key (CEK) in hex 99831FB208244C09B44DBBED94587687 Initialization Vector (IV) – in Hex AD754DB7D24BB8358809955D BASE64url encoded IV: rXVNt9JLuDWICZVd Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128GCM of 88 RSA-OAEP-256 encipherment of the key 9983… using Modulus 9F81… "n4EP…" and exponent 010001 "AQAB" produces: 9527E1F1D91828DEF1077FE4EACA900D6E68BEB5C5C076CB2BA5A6DEDCEFCAECF89E EFCCE8733F2F8EBFE9B0BCFF92D7CDFB58C35768EF76116EBCB83F1682FD63886851 66E2BE47AA37A3F85F112A775CE1E6E7A836DE9ED8AB09F3EF7D39D78D51B337D3E6 F89029E2F0A72EA208FA6BBA98B82936767194DF17B162E19B28ED6FED2EC7601D68 7FADB6EF672BD6C5D00224123585E65E8700BB189E0C0416DE03D557F130E3325FEE B99E2519D9F38EEAA4BDDCF47BF08F454F5BF8B53A205E13B1F6868F3766CA0858E8 38EEBDD86DDE2319993BBEF15FA6ABD94DD5545B0E6542A50B326CCB1A7D8CF6F39F 6E12E100ED0529F3855D3666788DE5C9D9A0 Base64url encoded: lSfh8dkYKN7xB3_k6sqQDW5ovrXFwHbLK6Wm3tzvyuz4nu_M6HM_L46_6bC8_5LXzftY w1do73YRbry4PxaC_WOIaFFm4r5HqjejF8RKndc4ebnqDbentirCfPvfTnXjVGzN9Pm-JAp4vCnLqIImu6mLgpNnZxlN8XsWLhmyjtb-0ux2AdaHttu9nK9bF0AIkEjWF5l6HALsYngwEFt4D1VfxMOMyX65niUZ2fOO6qS93PR78I9FT1v4tTogXhOx9oaPN2bKCFjoOO692G3eIxmZO77xX6ar2U 3VVFsOZUKlCzJsyxp9jPbzn24S4QDtBSnzhV02ZniN5cnZoA Protected Header { "alg":"RSA-OAEP-256", "enc":"A128GCM" } Without whitespace: {"alg":"RSA-OAEP-256","enc":"A128GCM"} BASE64url encoded: eyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMTI4R0NNIn0 Data Encipherment Additional Authenticated Data is ASCII representation of base64url header eyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMTI4R0NNIn0 which is 65794A68624763694F694A535530457454304646554330794E5459694C434A6C626D 4D694F694A424D54493452304E4E496E30 Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128GCM of 88 Plaintext is 7B224456223A22312E30222C224444223A7B2243303031223A22416E64726F696422 2C2243303032223A22485443204F6E655F4D38222C2243303034223A22352E302E31 222C2243303035223A22656E5F5553222C2243303036223A224561737465726E2053 74616E646172642054696D65222C2243303037223A2230363739373930332D666236 312D343165642D393463322D346432623734653237643138222C2243303039223A22 4A6F686E277320416E64726F696420446576696365227D2C2244504E41223A7B2243 303130223A2252453031222C2243303131223A2252453033227D2C225357223A5B22 53573031222C2253573034225D7D GCM authenticated encryption of the plaintext using AES-128 with key "9983…" and IV "AD75…" produces: A0771E6B60E3471669775254E675ABC118A971EB6B1F8122A5651978FE80BCF224E7 2EEE22C5961B28D60DE6DB747F6834DC2D7BB60124FB16999F378D19AC15895F568D 49808E7554C85F423ED76762E51830FEB13F7D9315401117D9D9AD7EA030CE295454 AE86467D52D27E16C5ECEA8EF3647E4A3EC36AD0A38E124ADEE8747D12946BA100E9 B3A6BED3FFAA34D9E82580DF7EE76BA41E284389B9EBA5E682E53F4266350C02FCCB 8C4EFA9D3BD3B8C8933BE566BD937C9E5B3A7F9B4838EA8C726E54D7F7BCBB533A0A 11F2EB90115C8EAA7C5461FF17295A2025210E251820FD1445F062395A35EBE011AF B88A7DAC4C36D4A18BA2AF222BF6 Base64url encoded: oHcea2DjRxZpd1JU5nWrwRipcetrH4EipWUZeP6AvPIk5y7uIsWWGyjWDebbdH9oNNwt e7YBJPsWmZ83jRmsFYlfVo1JgI51VMhfQj7XZ2LlGDD-sT99kxVAERfZ2a1oDDOKVRUroZGfVLSfhbF7OqO82RSj7DatCjjhJK3uh0fRKUa6EA6bOmvtP_qjTZ6CWA337na6QeKEOJueul5oLlP0JmNQwC _MuMTvqdO9O4yJM75Wa9k3yeWzp_m0g46oxyblTX97y7UzoKEfLrkBFcjqp8VGH_Fyla ICUhDiUYIP0URfBiOVo16-ARr7iKfaxMNtShi6KvIiv2 and Authentication Tag 020CEE029B3F18DD206CBC75B1C666AB Base 64url encoded: AgzuAps_GN0gbLx1scZmqw Resulting JWE looks like: JWE Protected Header Encrypted Key Initialization Vector Ciphertext Authentication Tag Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128GCM of 88 In Compact Serialization eyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMTI4R0NNIn0. lSfh8dkYKN7xB3_k6sqQDW5ovrXFwHbLK6Wm3tzvyuz4nu_M6HM_L46_6bC8_5LXzftY w1do73YRbry4PxaC_WOIaFFm4r5HqjejF8RKndc4ebnqDbentirCfPvfTnXjVGzN9Pm-JAp4vCnLqIImu6mLgpNnZxlN8XsWLhmyjtb-0ux2AdaHttu9nK9bF0AIkEjWF5l6HALsYngwEFt4D1VfxMOMyX65niUZ2fOO6qS93PR78I9FT1v4tTogXhOx9oaPN2bKCFjoOO692G3eIxmZO77xX6ar2U 3VVFsOZUKlCzJsyxp9jPbzn24S4QDtBSnzhV02ZniN5cnZoA. rXVNt9JLuDWICZVd. oHcea2DjRxZpd1JU5nWrwRipcetrH4EipWUZeP6AvPIk5y7uIsWWGyjWDebbdH9oNNwt e7YBJPsWmZ83jRmsFYlfVo1JgI51VMhfQj7XZ2LlGDD-sT99kxVAERfZ2a1oDDOKVRUroZGfVLSfhbF7OqO82RSj7DatCjjhJK3uh0fRKUa6EA6bOmvtP_qjTZ6CWA337na6QeKEOJueul5oLlP0JmNQwC _MuMTvqdO9O4yJM75Wa9k3yeWzp_m0g46oxyblTX97y7UzoKEfLrkBFcjqp8VGH_Fyla ICUhDiUYIP0URfBiOVo16-ARr7iKfaxMNtShi6KvIiv2. AgzuAps_GN0gbLx1scZmqw DS Decryption Corresponding Private Key d from (https://tools.ietf.org/html/rfc7520#page-8) Private key d bWUC9B-EFRIo8kpGfh0ZuyGPvMNKvYWNtB_ikiH9k20eTO1q_I78eiZkpXxXQ0UTEs2LsNRS-8uJbvQA1irkwMSMkK1J3XTGgdrhCku9gRldY7sNA_AKZGh-Q661_42rINLRCe8WnZ34ui_qOfkLnK9QWDDqpaIsAbMwWWSDFu2MUBYwkHTMEzLYGqOe04noqeq1hExBTHBOBdkMXiuFhUq1BU6lDqEiWxqg82sXt2hLMnT3046AOYJoRioz75tSUQfGCshWTBnP5uDjd18kKhyv07lhfSJdrPdM5Plyl21hsFf 4L_mHCuoFau7gdsPfHPxxjVOcOpBrQzwQ In Hex: 6D6502F41F84151228F24A467E1D19BB218FBCC34ABD858DB41FE29221FD936D1E4F E3B5ABF23BF1E8999295F15D0D144C4B362EC3514BEF2E25BBD0F80D62AE4C0C48C9 0AD49DD74C681DAE10A4BBD81195D63BB0D03F00A64687E43AEB5FF8DAB20D2D109E F16FA7677E2E8BFA8E7E42E72BD4160C3AA9688B00F9B33059648316ED8C50163090 74CC1332D81AA39ED389E8A9EAB5844C414C704E05D90C5E2B85854AB5054EA5F83A 84896C6A83CDAC5EDDA1F8B3274F7D38E80398268462A33EF9B525107C60AC8564C1 9CFE6E0E3775F242A1CAFD3B9617D225DACF74CE4F972976D61B057F82FF9870AEA0 56AEEE076C3DF1CFC718D539C3A906B433C1 Samples SDK Encryption of Device Information and DS Decryption—RSA-based Using RSA-OAEP-256 and A128GCM of 88 Decrypting Encrypted Key component from JWE using RSA OAEP 256 with private key 6D65… and modulus 9F81… produces: 99831FB208244C09B44DBBED94587687 Decrypting Ciphertext component from JWE using AES128 GCM with CEK 9983… and IV AD75… produces: {"DV":"1.0","DD":{"C001":"Android","C002":"HTC One_M8","C004":"5.0.1","C005":"en_US","C006":"Eastern Standard Time","C007":"06797903-fb61-41ed-94c2-4d2b74e27d18","C009":"John's Android Device"},"DPNA":{"C010":"RE01","C011":"RE03"},"SW":["SW01","SW04"]} Validation of the Authentication Tag is integral with GCM decryption. Device Information BASE64url encoded for AReq to ACS: "deviceInfo":"ew0KCSJEViI6ICIxLjAiLA0KCSJERCI6IHsNCgkJIkMwMDEiOiAiQW 5kcm9pZCIsDQoJCSJDMDAyIjogIkhUQyBPbmVfTTgiLA0KCQkiQzAwNCI6ICI1LjAuMS IsDQoJCSJDMDA1IjogImVuX1VTIiwNCgkJIkMwMDYiOiAiRWFzdGVybiBTdGFuZGFyZC BUaW1lIiwNCgkJIkMwMDciOiAiMDY3OTc5MDMtZmI2MS00MWVkLTk0YzItNGQyYjc0ZT I3ZDE4IiwNCgkJIkMwMDkiOiAiSm9obidzIEFuZHJvaWQgRGV2aWNlIg0KCX0sDQoJIk RQTkEiOiB7DQoJCSJDMDEwIjogIlJFMDEiLA0KCQkiQzAxMSI6ICJSRTAzIg0KCX0sDQ oJIlNXIjogWyJTVzAxIiwgIlNXMDQiXQ0KfQ0K" Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128CBC-HS256 of 88 SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128CBCHS256 Device Information Plaintext Data { "DV":"1.0", "DD": { "C001":"Android", "C002":"HTC One_M8", "C004":"5.0.1", "C005":"en_US", "C006":"Eastern Standard Time", "C007":"06797903-fb61-41ed-94c2-4d2b74e27d18", "C009":"John's Android Device" }, "DPNA": { "C010":"RE01", "C011":"RE03" }, "SW": ["SW01", "SW04"] } Without whitespace: {"DV":"1.0","DD":{"C001":"Android","C002":"HTC One_M8","C004":"5.0.1","C005":"en_US","C006":"Eastern Standard Time","C007":"06797903-fb61-41ed-94c2-4d2b74e27d18","C009":"John's Android Device"},"DPNA":{"C010":"RE01","C011":"RE03"},"SW":["SW01","SW04"]} In Hex: 7B224456223A22312E30222C224444223A7B2243303031223A22416E64726F696422 2C2243303032223A22485443204F6E655F4D38222C2243303034223A22352E302E31 222C2243303035223A22656E5F5553222C2243303036223A224561737465726E2053 74616E646172642054696D65222C2243303037223A2230363739373930332D666236 312D343165642D393463322D346432623734653237643138222C2243303039223A22 4A6F686E277320416E64726F696420446576696365227D2C2244504E41223A7B2243 303130223A2252453031222C2243303131223A2252453033227D2C225357223A5B22 53573031222C2253573034225D7D Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128CBC-HS256 of 88 DS Public Key (PDS) { "kty":"EC", "crv":"P-256", "kid":"UUIDkeyidentifierforDS-EC", "x":"2_v-MuNZccqwM7PXlakW9oHLP5XyrjMG1UVS8OxYrgA", "y":"rm1ktLmFIsP2R0YyJGXtsCbaTUesUK31Xc04tHJRolc" } SDK Ephemeral Key Pair (QSDK, dSDK) The SDK generated this ephemeral keypair and uses it with the DS public key: { "kty":"EC", "crv":"P-256", "x":"C1PL42i6kmNkM61aupEAgLJ4gF1ZRzcV7lqo1TG0mL4", "y":"cNToWLSdcFQKG--PGVEUQrIHP8w6TcRyj0pyFx4-ZMc", "d":"iyn--IbkBeNoPu8cN245L6pOQWt2lTH8V0Ds92jQmWA" } Perform ECDH operation with PDS and dSDK PDS in SEC1 point representation = 04DBFBFE32E35971CAB033B3D795A916F681CB3F95F2AE3306D54552F0EC58AE00AE 6D64B4B98522C3F64746322465EDB026DA4D47AC50ADF55DCD38B47251A257 dSDK = 8B29FEF886E405E3683EEF1C376E392FAA4E416B769531FC5740ECF768D09960 dSDK
  • Qc in SEC1 point representation = 045C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2A6 FB5BD978C1064252DB6F4BA953C018916A9138FB5140FFC2D55A4F7840ECAC Z = x coordinate of above: 5C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2 Key Derivation Keydatalen = 256 (0x0100). Note: although the encryption algorithm to be used may not be known when this KDF is called, it is known that 256 bits of keying material will be needed (with A128CBC-HS256 the same 256-bit key is used in both directions, whereas with A128GCM two uni-directional 128bit keys are used). Note: RFC 7518 as referenced in the specification has the ECDH-ES key agreement in section 4.6. There is no apu, and apv is the Directory Server ID (RID in this case). Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128CBC-HS256 of 88 Concat KDF is then used to form the key value as follows: AlgorithmID = empty string (length = 0x00000000) PartyUInfo = empty string (length = 0x00000000) PartyVInfo = directoryServerID (length + ascii string) = 0x0000000A + 'A000000802' SuppPubInfo = Keydatalen = 00000100 SuppPrivInfo = empty octet sequence Concatenating (in hex) 1 + Z + AlgorithmID + PartyUInfo + PartyVInfo + SuppPubInfo + SuppPrivInfo = 00000001 5C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2 00000000 00000000 0000000A 41303030303030383032 00000100 Hashing the above data with SHA-256 yields this result: A79A1FD4598AAEDC6738B3412BE4958E82BA4A263483A2ABD478BEB547E41952 Derived Key and IV The hash result is the CEK for A128CBC-HS256 The second half (rightmost / least significant half) is the encryption key for A128CBC 82BA4A263483A2ABD478BEB547E41952 The first half (leftmost / most significant half) is the authentication key for HS256 A79A1FD4598AAEDC6738B3412BE4958E Initialization Vector - For CBC mode a fresh IV is used. In this example: DE26C1599A2F7BABB2E72223B9AD3239 In base64url: 3ibBWZove6uy5yIjua0yOQ Protected Header { "alg":"ECDH-ES", "epk": { "kty":"EC", "crv":"P-256", "x":"C1PL42i6kmNkM61aupEAgLJ4gF1ZRzcV7lqo1TG0mL4", "y":"cNToWLSdcFQKG--PGVEUQrIHP8w6TcRyj0pyFx4-ZMc" }, "enc":"A128CBC-HS256" } Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128CBC-HS256 of 88 Without whitespace: {"alg":"ECDH-ES","epk":{"kty":"EC","crv":"P256","x":"C1PL42i6kmNkM61aupEAgLJ4gF1ZRzcV7lqo1TG0mL4","y":"cNToWLSd cFQKG--PGVEUQrIHP8w6TcRyj0pyFx4-ZMc"},"enc":"A128CBC-HS256"} BASE64url encoded: eyJhbGciOiJFQ0RILUVTIiwiZXBrIjp7Imt0eSI6IkVDIiwiY3J2IjoiUC0yNTYiLCJ4 IjoiQzFQTDQyaTZrbU5rTTYxYXVwRUFnTEo0Z0YxWlJ6Y1Y3bHFvMVRHMG1MNCIsInki OiJjTlRvV0xTZGNGUUtHLS1QR1ZFVVFySUhQOHc2VGNSeWowcHlGeDQtWk1jIn0sImVu YyI6IkExMjhDQkMtSFMyNTYifQ Before encryption plaintext needs padding to 16 byte boundary - using PKCS #7 padding, 4 bytes must be added, so the padded plaintext is: 7B224456223A22312E30222C224444223A7B2243303031223A22416E64726F696422 2C2243303032223A22485443204F6E655F4D38222C2243303034223A22352E302E31 222C2243303035223A22656E5F5553222C2243303036223A224561737465726E2053 74616E646172642054696D65222C2243303037223A2230363739373930332D666236 312D343165642D393463322D346432623734653237643138222C2243303039223A22 4A6F686E277320416E64726F696420446576696365227D2C2244504E41223A7B2243 303130223A2252453031222C2243303131223A2252453033227D2C225357223A5B22 53573031222C2253573034225D7D04040404 Data Encipherment CBC encipherment of the plaintext using AES-128 with key "B2BA…"; IV "DE26…." produces: 6CDB97DD4959639A6C7E91BA0FF6D986656141BE514E5C05EA37C65F470F0A436D68 9041A0B83A94E03EC9DB9344390C1085F541EC3ED6F93C2BED47231D9C59F8DB5A10 743B03695A4F074D3791C510D6EE081083B54D3755895000338D74F5DE4C09D489342 A3F09C70A1054F4B9AD7F703B1BA3B1D80E2A769D685DC9C51E69533ADA3739AFA2 1BEA97A38BFA4111B334334AFCDAF5C5B264F6C55D7156916D98A87C58A7E39A71C EB907E0F6C71A0A5274F3CCA1867D395DB53BC76CBA97546BB6C6722A0CA7252889 C064334EFBBC9586E14CDACB67497D17ECCCC457F46923F7EA54B6F15D03880AB0D F9246E74594FF2DC6CEE1D2D3758FE196768179 Base64url encoded: bNuX3UlZY5psfpG6D_bZhmVhQb5RTlwF6jfGX0cPCkNtaJBBoLg6lOAyduTRDkMEIX1Qew-1vk8K1HIx2cWfjbWhB0OwNpWk8HTTeRxRDW7ggQg7VNN1WJUAAzjXT13kwJ1Ik0Kj8JxwoQVP S5rX9wOxujsdgOKnadaF3JxR5pUzraNzmvohvql6OLkERszQzSvza9cWyZPbFXXFWkW2YqHxYp-Oacc65BD2xxoKUnTzzKGGfTldtTvHbLqXVGu2xnIqDKclKInAZDNO7yVhuFM2stnSX0X7MzEV_RpI_fqVLbxXQOICrDfkkbnRZT_LcbO4dLTdY_hlnaBeQ Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128CBC-HS256 of 88 Authentication Tag For the MAC, the Additional Authenticated Data (AAD) is the Protected Header, which in a Hex representation of the base64url string is "65794A68624763694F694A46513052494C555654496977695A584272496A7037496 D743065534936496B56444969776959334A32496A6F69554330794E5459694C434A3 4496A6F69517A46515444517961545A726255357254545978595856775255466E544 56F305A305978576C4A3659315933624846764D5652484D47314D4E434973496E6B6 94F694A6A546C5276563078545A474E47555574484C53315152315A4656564679535 568514F48633256474E5365576F7763486C4765445174576B316A496E3073496D567 559794936496B45784D6A6844516B4D7453464D794E5459696651" so the AAD Length (AL) is 0000000000000730 (230 bytes = 1840 bits). The data to MAC is the concatenation of AAD (in ASCII), IV, Ciphertext and AL hence the data to MAC in hexadecimal is: 65794A68624763694F694A46513052494C555654496977695A584272496A7037496D 743065534936496B56444969776959334A32496A6F69554330794E5459694C434A34 496A6F69517A46515444517961545A726255357254545978595856775255466E5445 6F305A305978576C4A3659315933624846764D5652484D47314D4E434973496E6B69 4F694A6A546C5276563078545A474E47555574484C53315152315A46565646795355 68514F48633256474E5365576F7763486C4765445174576B316A496E3073496D5675 59794936496B45784D6A6844516B4D7453464D794E5459696651 DE26C1599A2F7BABB2E72223B9AD3239 6CDB97DD4959639A6C7E91BA0FF6D986656141BE514E5C05EA37C65F470F0A436D68 9041A0B83A94E03EC9DB9344390C1085F541EC3ED6F93C2BED47231D9C59F8DB5A10 743B03695A4F074D3791C510D6EE081083B54D3755895000338D74F5DE4C09D48934 2A3F09C70A1054F4B9AD7F703B1BA3B1D80E2A769D685DC9C51E69533ADA3739AFA2 1BEA97A38BFA4111B334334AFCDAF5C5B264F6C55D7156916D98A87C58A7E39A71CE B907E0F6C71A0A5274F3CCA1867D395DB53BC76CBA97546BB6C6722A0CA7252889C0 64334EFBBC9586E14CDACB67497D17ECCCC457F46923F7EA54B6F15D03880AB0DF92 46E74594FF2DC6CEE1D2D3758FE196768179 0000000000000730 MACing using HMAC SHA256 and a key of "A79A…" produces: 66FFA77A26AD02B1F97C7D5CEC6B69659DE1170C24AD25E37E9A7D6BA8D5C8F2 The most significant 16 bytes are the authentication tag which is 66FFA77A26AD02B1F97C7D5CEC6B6965 Base64url encoded Zv-neiatArH5fH1c7GtpZQ Resulting JWE looks like: JWE Protected Header Initialization Vector Ciphertext Authentication Tag Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128CBC-HS256 of 88 In Compact Serialization eyJhbGciOiJFQ0RILUVTIiwiZXBrIjp7Imt0eSI6IkVDIiwiY3J2IjoiUC0yNTYiLCJ4IjoiQzFQTDQ yaTZrbU5rTTYxYXVwRUFnTEo0Z0YxWlJ6Y1Y3bHFvMVRHMG1MNCIsInkiOiJjTlRvV0xTZ GNGUUtHLS1QR1ZFVVFySUhQOHc2VGNSeWowcHlGeDQtWk1jIn0sImVuYyI6IkExMjhD QkMtSFMyNTYifQ.. 3ibBWZove6uy5yIjua0yOQ. bNuX3UlZY5psfpG6D_bZhmVhQb5RTlwF6jfGX0cPCkNtaJBBoLg6lOAyduTRDkMEIX1Qew-1vk8K1HIx2cWfjbWhB0OwNpWk8HTTeRxRDW7ggQg7VNN1WJUAAzjXT13kwJ1Ik0Kj8JxwoQVP S5rX9wOxujsdgOKnadaF3JxR5pUzraNzmvohvql6OLkERszQzSvza9cWyZPbFXXFWkW2YqHxYp-Oacc65BD2xxoKUnTzzKGGfTldtTvHbLqXVGu2xnIqDKclKInAZDNO7yVhuFM2stnSX0X7MzEV_RpI_fqVLbxXQOICrDfkkbnRZT_LcbO4dLTdY_hlnaBeQ. Zv-neiatArH5fH1c7GtpZQ DS Decryption Decoding the protected header from the message as follows informs the DS of the algorithms and the SDK ephemeral key: {"alg":"ECDH-ES","epk":{"kty":"EC","crv":"P256","x":"C1PL42i6kmNkM61aupEAgLJ4gF1ZRzcV7lqo1TG0mL4","y":"cNToWLSd cFQKG--PGVEUQrIHP8w6TcRyj0pyFx4-ZMc"},"enc":"A128CBC-HS256"} DS Private Key corresponding to the above public key QDS dDS = rAZel3KoyQbPejeMRfKzwnqvZfX23fIKek4OKX-5Iu0 DS Performs ECDH operation with QSDK recovered from the protected header and dDS QSDK = 040B53CBE368BA92636433AD5ABA910080B278805D59473715EE5AA8D531B498BE70 D4E858B49D70540A1BEF8F19511442B2073FCC3A4DC4728F4A72171E3E64C7 dDS = AC065E9772A8C906CF7A378C45F2B3C27AAF65F5F6DDF20A7A4E0E297FB922ED dDS
  • QSDK = 045C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2A6 FB5BD978C1064252DB6F4BA953C018916A9138FB5140FFC2D55A4F7840ECAC Z = x coordinate of above: 5C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2 This matches the value derived by the SDK as shown above. Using the algorithm from the header, the DS repeats the KDF calculation to yield the same keys. Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128CBC-HS256 of 88 Validation The SDK then recomputes the authentication tag by concatenating the ASCII representation of the base64url encoded protected header, the IV, the ciphertext and the AL and obtains the result: Zv-neiatArH5fH1c7GtpZQ Which equals the received Authentication Tag. Finally the DS deciphers the message yielding the following result: {"DV":"1.0","DD":{"C001":"Android","C002":"HTC One_M8","C004":"5.0.1","C005":"en_US","C006":"Eastern Standard Time","C007":"06797903-fb61-41ed-94c2-4d2b74e27d18","C009":"John's Android Device"},"DPNA":{"C010":"RE01","C011":"RE03"},"SW":["SW01","SW04"]} Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128GCM of 88 SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128GCM Device Information Plaintext Data { "DV":"1.0", "DD": { "C001":"Android", "C002":"HTC One_M8", "C004":"5.0.1", "C005":"en_US", "C006":"Eastern Standard Time", "C007":"06797903-fb61-41ed-94c2-4d2b74e27d18", "C009":"John's Android Device" }, "DPNA": { "C010":"RE01", "C011":"RE03" }, "SW": ["SW01", "SW04"] } Without whitespace: {"DV":"1.0","DD":{"C001":"Android","C002":"HTC One_M8","C004":"5.0.1","C005":"en_US","C006":"Eastern Standard Time","C007":"06797903-fb61-41ed-94c2-4d2b74e27d18","C009":"John's Android Device"},"DPNA":{"C010":"RE01","C011":"RE03"},"SW":["SW01","SW04"]} In Hex: 7B224456223A22312E30222C224444223A7B2243303031223A22416E64726F696422 2C2243303032223A22485443204F6E655F4D38222C2243303034223A22352E302E31 222C2243303035223A22656E5F5553222C2243303036223A224561737465726E2053 74616E646172642054696D65222C2243303037223A2230363739373930332D666236 312D343165642D393463322D346432623734653237643138222C2243303039223A22 4A6F686E277320416E64726F696420446576696365227D2C2244504E41223A7B2243 303130223A2252453031222C2243303131223A2252453033227D2C225357223A5B22 53573031222C2253573034225D7D Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128GCM of 88 DS Public Key (PDS) { "kty":"EC", "crv":"P-256", "x":"2_v-MuNZccqwM7PXlakW9oHLP5XyrjMG1UVS8OxYrgA", "y":"rm1ktLmFIsP2R0YyJGXtsCbaTUesUK31Xc04tHJRolc" } SDK Ephemeral Key Pair (QSDK, dSDK) The SDK generated this ephemeral keypair and uses it with the DS public key: { "kty":"EC", "crv":"P-256", "x":"C1PL42i6kmNkM61aupEAgLJ4gF1ZRzcV7lqo1TG0mL4", "y":"cNToWLSdcFQKG--PGVEUQrIHP8w6TcRyj0pyFx4-ZMc", "d":"iyn--IbkBeNoPu8cN245L6pOQWt2lTH8V0Ds92jQmWA" } Perform ECDH operation with PDS and dSDK PDS in SEC1 point representation = 04DBFBFE32E35971CAB033B3D795A916F681CB3F95F2AE3306D54552F0EC58AE00AE 6D64B4B98522C3F64746322465EDB026DA4D47AC50ADF55DCD38B47251A257 dSDK = 8B29FEF886E405E3683EEF1C376E392FAA4E416B769531FC5740ECF768D09960 dSDK
  • Qc in SEC1 point representation = 045C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2A6 FB5BD978C1064252DB6F4BA953C018916A9138FB5140FFC2D55A4F7840ECAC Z = x coordinate of above: 5C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2 Key Derivation Keydatalen = 256 (0x0100). Note: although the encryption algorithm to be used may not be known when this KDF is called, it is known that 256 bits of keying material will be needed (with A128CBC-HS256 the same 256-bit key is used in both directions, whereas with A128GCM two uni-directional 128bit keys are used). Note: RFC 7518 as referenced in the specification has the ECDH-ES key agreement in section 4.6. There is no apu, and apv is the DS UUID. Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128GCM of 88 Concat KDF is then used to form the key value as follows: AlgorithmID = empty string (length = 0x00000000) PartyUInfo = empty string (length = 0x00000000) PartyVInfo = directoryServerID (length + ascii string) = 0x0000000A + 'A000000802' SuppPubInfo = Keydatalen = 00000100 SuppPrivInfo = empty octet sequence Concatenating (in hex) 1 + Z + AlgorithmID + PartyUInfo + PartyVInfo + SuppPubInfo + SuppPrivInfo = 00000001 5C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2 00000000 00000000 0000000A 41303030303030383032 00000100 Hashing the above data with SHA-256 yields this result: A79A1FD4598AAEDC6738B3412BE4958E82BA4A263483A2ABD478BEB547E41952 Derived Key and IV The first half (leftmost / most significant half) is the uni-directional (SDK  DS) key for A128GCM A79A1FD4598AAEDC6738B3412BE4958E Initialization Vector (IV) – in Hex AD754DB7D24BB8358809955D BASE64url encoded IV: rXVNt9JLuDWICZVd Protected Header { { "alg":"ECDH-ES", "epk": { "kty":"EC", "crv":"P-256", "x":"C1PL42i6kmNkM61aupEAgLJ4gF1ZRzcV7lqo1TG0mL4", "y":"cNToWLSdcFQKG--PGVEUQrIHP8w6TcRyj0pyFx4-ZMc" }, "enc":"A128GCM" } Without whitespace: {"alg":"ECDH-ES","epk":{"kty":"EC","crv":"P256","x":"C1PL42i6kmNkM61aupEAgLJ4gF1ZRzcV7lqo1TG0mL4","y":"cNToWLSd cFQKG--PGVEUQrIHP8w6TcRyj0pyFx4-ZMc"},"enc":"A128GCM"} Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128GCM of 88 BASE64url encoded: eyJhbGciOiJFQ0RILUVTIiwiZXBrIjp7Imt0eSI6IkVDIiwiY3J2IjoiUC0yNTYiLCJ4 IjoiQzFQTDQyaTZrbU5rTTYxYXVwRUFnTEo0Z0YxWlJ6Y1Y3bHFvMVRHMG1MNCIsInki OiJjTlRvV0xTZGNGUUtHLS1QR1ZFVVFySUhQOHc2VGNSeWowcHlGeDQtWk1jIn0sImVu YyI6IkExMjhHQ00ifQ Data Encipherment Additional Authenticated Data is ASCII representation of base64url header eyJhbGciOiJFQ0RILUVTIiwiZXBrIjp7Imt0eSI6IkVDIiwiY3J2IjoiUC0yNTYiLCJ4 IjoiQzFQTDQyaTZrbU5rTTYxYXVwRUFnTEo0Z0YxWlJ6Y1Y3bHFvMVRHMG1MNCIsInki OiJjTlRvV0xTZGNGUUtHLS1QR1ZFVVFySUhQOHc2VGNSeWowcHlGeDQtWk1jIn0sImVu YyI6IkExMjhHQ00ifQ which is 65794A68624763694F694A46513052494C555654496977695A584272496A7037496D 743065534936496B56444969776959334A32496A6F69554330794E5459694C434A34 496A6F69517A46515444517961545A726255357254545978595856775255466E5445 6F305A305978576C4A3659315933624846764D5652484D47314D4E434973496E6B69 4F694A6A546C5276563078545A474E47555574484C53315152315A46565646795355 68514F48633256474E5365576F7763486C4765445174576B316A496E3073496D5675 59794936496B45784D6A6848513030696651 Plaintext is 7B224456223A22312E30222C224444223A7B2243303031223A22416E64726F696422 2C2243303032223A22485443204F6E655F4D38222C2243303034223A22352E302E31 222C2243303035223A22656E5F5553222C2243303036223A224561737465726E2053 74616E646172642054696D65222C2243303037223A2230363739373930332D666236 312D343165642D393463322D346432623734653237643138222C2243303039223A22 4A6F686E277320416E64726F696420446576696365227D2C2244504E41223A7B2243 303130223A2252453031222C2243303131223A2252453033227D2C225357223A5B22 53573031222C2253573034225D7D GCM authenticated encryption of the plaintext using AES-128 with key "A79A…" and "IV AD75…" produces: 8318010F33C8CB0027531D53819FECF1EF3055BAC2CD30F0ECD8D866D0CD0F57DA7 C4FBD6018A633A4803E7AA33F36E459A9BA0DD87BC79A049D984711D1A3EC3C96DA 153532939F3D06EC3DC275C8D52B2BA3FBBA09B2164B3C80F691A317038EB1B2260D 22E3BF989FA5BFFB996FBAB56A30E7377E0DFD67FA2962C313B539E1D77CC7DD3E9 E28D9442EBCE0AB8B3DF91A211A9600A3A26D640FD914D67B47A485A7ED89331F5D5 608638FF244D7AECA34A63015B01174068FA43B7C303EF6DCC069D75DF821C270405 A5469B29CDE3A1BC607386423EEDFCD2246162FAE22F50DDA2D64481434CAAEB274 52813942B92F0C8750A3BB9DE7240EEC Base64url encoded: gxgBDzPIywAnUx1TgZ_s8e8wVbrCzTDw7NjYZtDND1fafE9YBimM6SAPnqjPzbkWam6Ddh7x5oEnZhHEdGj7DyW2hU1MpOfPQbsPcJ1yNUrK6P7ug myFks8gPaRoxcDjrGyJg0i47-Yn6W_5lvurVqMOc3fg39Z_opYsMTtTnh13zH3T6eKNlELrzgq4s9-RohGpYAo6JtZA_ZFNZ7R6SFp2JMx9dVghjj_JE167KNKYwFbARdAaPpDt8MD723MBp1134IcJwQFpUabKc3jobxgc4ZCPu 380iRhYvriL1DdotZEgUNMqusnRSgTlCuS8Mh1Cju53nJA7s Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128GCM of 88 and Authentication Tag 3C3ADA7E306DFEE8F7125BAA33DD21D1 Base 64url encoded: PDrafjBt_uj3EluqM90h0Q Resulting JWE looks like: JWE Protected Header Initialization Vector Ciphertext Authentication Tag In Compact Serialization eyJhbGciOiJFQ0RILUVTIiwiZXBrIjp7Imt0eSI6IkVDIiwiY3J2IjoiUC0yNTYiLCJ4 IjoiQzFQTDQyaTZrbU5rTTYxYXVwRUFnTEo0Z0YxWlJ6Y1Y3bHFvMVRHMG1MNCIsInki OiJjTlRvV0xTZGNGUUtHLS1QR1ZFVVFySUhQOHc2VGNSeWowcHlGeDQtWk1jIn0sImVu YyI6IkExMjhHQ00ifQ.. rXVNt9JLuDWICZVd. gxgBDzPIywAnUx1TgZ_s8e8wVbrCzTDw7NjYZtDND1fafE9YBimM6SAPnqjPzbkWam6Ddh7x5oEnZhHEdGj7DyW2hU1MpOfPQbsPcJ1yNUrK6P7ugm yFks8gPaRoxcDjrGyJg0i47-Yn6W_5lvurVqMOc3fg39Z_opYsMTtTnh13zH3T6eKNlELrzgq4s9RohGpYAo6JtZA_ZFNZ7R6SFp2JMx9dVghjj_JE167KNKYwFbARdAaPpDt8MD723MBp1134IcJwQFpUabKc3jobxgc4ZC Pu380iRhYvriL1DdotZEgUNMqusnRSgTlCuS8Mh1Cju53nJA7s. PDrafjBt_uj3EluqM90h0Q DS Decryption The DS unpacks the protected header thus {"alg":"ECDH-ES","epk":{"kty":"EC","crv":"P256","x":"C1PL42i6kmNkM61aupEAgLJ4gF1ZRzcV7lqo1TG0mL4","y":"cNToWLSd cFQKG--PGVEUQrIHP8w6TcRyj0pyFx4-ZMc"},"enc":"A128GCM"} From this it determines the algorithms and the ephemeral public key of the SDK DS Private Key corresponding to the above public key QDS dDS = rAZel3KoyQbPejeMRfKzwnqvZfX23fIKek4OKX-5Iu0 DS Performs ECDH operation with QSDK recovered from the protected header and dDS Samples SDK Encryption of Device Information and DS Decryption—EC-based Using ECDH-ES and A128GCM of 88 QSDK in SEC1 point representation = 040B53CBE368BA92636433AD5ABA910080B278805D59473715EE5AA8D531B498BE70 D4E858B49D70540A1BEF8F19511442B2073FCC3A4DC4728F4A72171E3E64C7 dDS = AC065E9772A8C906CF7A378C45F2B3C27AAF65F5F6DDF20A7A4E0E297FB922ED dDS
  • QSDK in SEC1 point representation = 045C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2A6 FB5BD978C1064252DB6F4BA953C018916A9138FB5140FFC2D55A4F7840ECAC Z = x coordinate of above: 5C32BC13F8ECEB148ABAF2A6B9DD1F6891BB2A80AB09347C64068231A59E8CA2 This matches the value derived by the SDK as shown above. Using the algorithm from the header, the DS repeats the KDF calculation to yield the same key A79A1FD4598AAEDC6738B3412BE4958E. Using the ASCII representation of the base64url coded protected header, the IV of rXVNt9JLuDWICZVd and the authentication tag PDrafjBt_uj3EluqM90h0Q the ACS deciphers and validates the ciphertext yielding the following result: {"DV":"1.0","DD":{"C001":"Android","C002":"HTC One_M8","C004":"5.0.1","C005":"en_US","C006":"Eastern Standard Time","C007":"06797903-fb61-41ed-94c2-4d2b74e27d18","C009":"John's Android Device"},"DPNA":{"C010":"RE01","C011":"RE03"},"SW":["SW01","SW04"]} Samples ACS Signed Content and Validation by SDK—RSA-based Using PS256 of 88 ACS Signed Content and Validation by SDK—RSA-based Using PS256 Note: PS256 uses random data to generate the signature - it might not be possible to exactly replicate the results in this example. Payload to be signed { "acsEphemPubKey":{ "kty":"EC", "crv":"P-256", "x":"mPUKT_bAWGHIhg0TpjjqVsP1rXWQu_vwVOHHtNkdYoA", "y":"8BQAsImGeAS46fyWw5MhYfGTT0IjBpFw2SS34Dv4Irs", }, "sdkEphemPubKey":{ "kty":"EC", "crv":"P-256", "x":"Ze2loSV3wrroKUN_4zhwGhCqo3Xhu1td4QjeQ5wIVR0", "y":"HlLtdXARY_f55A3fnzQbPcm6hgr34Mp8p-nuzQCE0Zw", }, "acsURL":"http://acsserver.domainname.com" } Without whitespace: {"acsEphemPubKey":{"kty":"EC","crv":"P256","x":"mPUKT_bAWGHIhg0TpjjqVsP1rXWQu_vwVOHHtNkdYoA","y":"8BQAsImG eAS46fyWw5MhfGTT0IjBpFw2SS34Dv4Irs",},"sdkEphemPubKey":{"kty":"EC"," crv":"P256","x":"Ze2loSV3wrroKUN_4zhwGhCqo3Xhu1td4QjeQ5wIVR0","y":"HlLtdXAR Y_f55A3fnzQbPcm6hgr34Mp8pnuzQCE0Zw",},"acsURL":"http://acsserver.domainname.com"} BASE64url encoded: eyJhY3NFcGhlbVB1YktleSI6eyJrdHkiOiJFQyIsImNydiI6IlAtMjU2IiwieCI6Im1Q VUtUX2JBV0dISWhnMFRwampxVnNQMXJYV1F1X3Z3Vk9ISHROa2RZb0EiLCJ5IjoiOEJR QXNJbUdlQVM0NmZ5V3c1TWhmR1RUMElqQnBGdzJTUzM0RHY0SXJzIix9LCJzZGtFcGhl bVB1YktleSI6eyJrdHkiOiJFQyIsImNydiI6IlAtMjU2IiwieCI6IlplMmxvU1Yzd3Jy b0tVTl80emh3R2hDcW8zWGh1MXRkNFFqZVE1d0lWUjAiLCJ5IjoiSGxMdGRYQVJZX2Y1 NUEzZm56UWJQY202aGdyMzRNcDhwLW51elFDRTBadyIsfSwiYWNzVVJMIjoiaHR0cDov L2Fjc3NlcnZlci5kb21haW5uYW1lLmNvbSJ9 © 2019 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo

Shown in part. Read the original for the full text.