P
ERFORMING
D
OWNLOADS
File Authentication Requirements
104
V
X
810 R
EFERENCE
G
UIDE
The File
Authentication
Process During an
Application
Download
In the following example of a typical file authentication process, it is assumed that:
•
An application is being downloaded to prepare a V
x
810 deployment device for
deployment. That is, a sponsor certificate and a signer certificate are
downloaded in batch mode to GID1 SRAM of the receiving device, together
with the application to authenticate.
•
A signature file is generated for each executable that comprises the
application on the download computer using the VeriShield File Signing Tool,
with the signer certificate, signer private key, and signer password as required
inputs. These signature files are also downloaded onto the receiving device.
In a typical batch application download, file authentication proceeds as follows:
1
All certificate files (*.crt), signature files (*.p7s), and application files (*.out,
*.lib, *.fon, *.vft, *.dat, and so on) download to the V
x
810 deployment device in
batch mode.
2
When the device restarts after the download, the file authentication module
searches the SRAM-based file system for the following two file types:
•
Authenticated certificate files (*.crt) to add to the permanent certificate
tree.
•
Signature files (*.p7s) that authenticate corresponding target application
files.
Certificate files and signature files can download into the SRAM of any file
group. For this reason, the file authentication module searches through the
entire file system (all file groups) for new files with these filename extensions
each time the device restarts.
3
The file authentication module builds a list of all newly detected certificates
and signature files. If no new certificates or signature files are located, the
module just returns. If one or more new files of this kind are detected, the file
authentication module starts processing them based on the list.
4
Certificates are always processed first (before signature files). The processing
routine is called one time for each certificate in the list. If a certificate is
authentic, it is noted, and the next certificate is processed. This process
continues in random order until all certificates are authenticated.
When a certificate file in the processing list is authenticated, the “Authentic”
message is displayed below the corresponding filename. If it fails to be
authenticated, the “Failed” message is displayed for five seconds and the
device beeps three times. The routine resumes processing and continues until
all certificates are successfully processed.
The processing routine gives both visible and audible indications if a specific
certificate authenticates successfully. The file authentication module does not
halt the process if a certificate fails to authenticate, but continues to the next
step, which is authenticating signature files.
Содержание DUET Vx810
Страница 1: ...VeriFone Part Number 24964 Revision B Vx810 Reference Guide ...
Страница 14: ...VX810 OVERVIEW Features and Benefits 14 VX810 REFERENCE GUIDE ...
Страница 90: ...VeriShield File Signing Tool 90 VX810 REFERENCE GUIDE ...
Страница 130: ...PERFORMING DOWNLOADS Back to Back Application Downloads 130 VX810 REFERENCE GUIDE ...
Страница 148: ...Information Messages 148 VX810 REFERENCE GUIDE ...
Страница 150: ...PORT PINOUTS COM Port 150 VX810 REFERENCE GUIDE ...
Страница 158: ...GLOSSARY 158 VX810 REFERENCE GUIDE ...