📄 pkcs15.7
字号:
.PU.TH pkcs15 7 "" "" OpenSCpkcs15 \- standard for storing information on smart cards.SH DESCRIPTIONThe PKCS #15 standard is available from.BR http://www.rsasecurity.com/rsalabs/pkcs .This document does not try to cover PKCS #15 in detail; itjust tries to give readers not familiar with the standard abrief overview..PPPKCS #15 defines a standard how to store keys, certificatesand possibly other data on a smart card, and how to describecertain meta information (such as what PIN the user needs topresent before he's allowed to use a certain private key)..PPA PKCS #15 compliant smart card can contain one or moreapplications. There is one ``meta directory'' that containsa list of all applications. On cards that support an ISO 7816compatible file system, each application usually resides ina directory of its own..PPWithin each application directory,PKCS #15 defines a structure of meta files (alsocalled Directory Files) that contain information on objectsstored on the card. For instance, there is a private keydirectory file (or PrKDF for short) that contains a list ofprivate keys stored on the card. Likewise, there's apublic key directory file (PuKDF) and a certificate directoryfile (CDF)..PPOne fairly important PKCS #15 directory file is the AODF, orauthorization object directory file, which describesthe PINs held by the card. Note the AODF does not containthe PINs themselves; this is something that is highlycard specific. What the AODF does contain however isa descriptive label for each PIN, and additional informationrequired to authenticate against this PIN (sorry if thisis very vague, but unless you really want to know, we'llbetter leave it at that, for the sake of your and my sanity :-)..PPEach object stored in a PKCS #15 structure has an IDassigned to it, so that related objects can referenceone another. For instance, if a private key is protectedby a PIN, the PrKDF entry for this key will containan Authentication ID field that points to the AODF entryfor this PIN..PPSimilarly, if the card contains a certificate correspondingto a private key stored on this card, the CDF entry for thecertificate will have the same ID as the PrKDF entry forthe private key. The same is true of public key objects..SH BUGSThis manual page is a little terse..PPThe use of the term Directory File in PKCS #15 is somewhatunfortunate. Normally, a PKCS #15 DF is just a plain(elementary) file, not a directory file in the sense ofISO 7816..SH AUTHORSThis manual page was written by Olaf Kirch <okir@lst.de>.
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -