5
Cryptographic Capabilities
The ACOS5-EVO supports a number of cryptographic algorithms, including:
•
ECC: Curves P-224/P-256/P-384/P-521
•
RSA: 512
–
4096 bits in 256 bits increments
•
AES: 128/192/256-bits (ECB, CBC)
•
DES/3DES: 56/112/168-bits (ECB, CBC)
•
Hash: SHA1, SHA224, SHA256, SHA384, SHA512
•
MAC: CBC-MAC (DES/3DES, AES), CMAC (3DES, AES)
Random Number Generation
•
Deterministic RNG according to FIPS 140-2
•
Non-deterministic RNG compliant to AIS-31
File Security
•
P
rivate and secret key file read access can be set to “Never”
•
File access condition capability with ISO 7816-compliant Secure Attribute-
Compact. File access is only allowed if the proper security conditions are met
(e.g., PIN submissions)
•
Command execution condition capability per Dedicated File (DF) with ISO 7816-
compliant Secure Attribute-Extended. Commands are allowed only if the proper
security conditions are met (e.g., PIN submission)
•
Secure Messaging function for confidential and authenticated data transfer
•
Mutual authentication (terminal-co-card and card-to-terminal) with session key
generation for encryption and MAC
•
Anti-tearing Function Support
Compliance to Standards
•
Compliance with ISO 7816 Parts 1,2.3,4, 8, and 9
•
Compliance with FIPS 140-2 Level 3
•
Certified with Common Criteria ELA 5+ (Chip Level)