在分析JavaSIM卡的工作原理基础上,研究了GlobalPlatform系统的安全通信和卡上多应用程序管理的安全需求,设计实现了一种保证JavaSIM卡平台安全性的方案. 该方案以密钥集的管理和应用为基础,通过划分不同密钥集的认证管理权限和提供安全信道,实现了不同卡外实体对卡内容的安全管理. 对实现方案测试的结果符合相关规范的规定.
Based on the principle of JavaSIM card, the requirements of security communication and multi-Application management on the globalPlatform are studied. A solution scheme for secure JavaSIM platform is proposed and implemented. Based on the management and application of key sets, this solution enable different off-card entities to implement security management for on-card content by means of dividing authentication levels of different key sets and providing security channel. The test results of this solution measure up to relevant specifications.