Search code examples
c#javacard

Verify Card Authentication Cryptogram


I'm having trouble doing the Verify Card Authentication Cryptogram, the result of the signature doesn't be equal to the cryptogram sent by the card.

select_ret: 6F108408A000000003000000A5049F6501FF9000

AID: A000000003000000

host_challenge: 1122334455667788

init_update_ret: 00000000000000000000 FF02 005CD352A259A8F2 D5DF4D69873546C3 9000
                                           card_challenge   card_cryptogram?
key_diversification_data: 00000000000000000000

key_information_data: FF02

card_challenge: 005CD352A259A8F2

card_cryptogram: D5DF4D69873546C3

enc_session:  339F1D7F5D5841EB034F5CE234557894

cmac_session: C6713F31B8DC1F8905DFECB4065CB81E

dek_session:  06E72D52EEFBD1D8DB5C230C3F2B56E9
              
cryptogram_data: 1122334455667788 005CD352A259A8F2 8000000000000000
                 host_challenge   card_challenge
                                  
cryptogram_session: A9A159B6CB28156194027554A8603DDF 59A7313E1B3293B2
                                                     signature?

Verify Card Authentication Cryptogram: Concatenating the 8-byte host challenge and 8-byte card challenge resulting in a 16-byte block. Using enc_session to sign the data 1122334455667788 + 005CD352A259A8F2 + 8000000000000000 with DES_MAC4_ISO9797_M1, ICV=0

I tried as follows, but I get signature(59A7313E1B3293B2) doesn't be equal with card_cryptogram(D5DF4D69873546C3)?

I'm stuck in MACEncrypt (DES_MAC4_ISO9797_M1), do you think this function is correct? Thanks.

byte[] cryptogram_iv = ToHexBytes("0000000000000000");
byte[] cryptogram_key = ToHexBytes("339F1D7F5D5841EB034F5CE234557894");
byte[] host_challenge = ToHexBytes("1122334455667788");
byte[] card_challenge = ToHexBytes("005CD352A259A8F2");

byte[] cryptogram_data = Append(host_challenge, card_challenge, ToHexBytes("8000000000000000"));
    
byte[] cryptogram_session = MACEncrypt(cryptogram_iv, cryptogram_key, cryptogram_data);
// cryptogram_session = A9A159B6CB28156194027554A8603DDF 59A7313E1B3293B2

//

// DES_MAC4_ISO9797_M1
private byte[] MACEncrypt(byte[] iv, byte[] key, byte[] data) 
{
    try
    {
        MACTripleDES mac = new MACTripleDES(key);
        TripleDES tdes = new TripleDESCryptoServiceProvider();
        tdes.Mode = CipherMode.CBC;
        tdes.Padding = PaddingMode.None;
        MemoryStream streamOut = new MemoryStream();
        CryptoStream streamCrypto = new CryptoStream(streamOut, tdes.CreateEncryptor(key, iv), CryptoStreamMode.Write);
        streamCrypto.Write(data, 0, data.Length);
        streamCrypto.FlushFinalBlock();
        return streamOut.ToArray();
    }
    catch (Exception ex)
    {
        MessageBox.Show(ex.Message);
    }
    return new byte[0];
}

Solution

  • DES_MAC4_ISO9797_M1 is working fine, my mistake was using a different sequence counter betweeninit_update and plain of enc_session, cmac_session, and dek_session. After I match all sequence counter, everything works fine.